Distributed Identity Management University of Applied Sciences Rapperswil April 14, 2008 Corsin Camichel, ccamiche@hsr.ch
Agenda Traditional login process What is OpenID How OpenID works Live Demo For Developers Your Questions
Login Today How many accounts do you have? GMail, Yahoo Mail, Hotmail ... MySpace / FaceBook / StudiVZ ... How many different passwords do you use?
The Way A Login Works Register for an account (share your data) Verify your email address First login with the new account Server verifies credentials Repeat steps for any other website ... End up with 30 accounts on 30 websites
What is OpenID? new open standard for logging in identified by URI (AHV, finger print) http://openid.hsr.ch/ccamiche http://cocaman.ch Single-Sign-On (SSO) only one password used over 250 million accounts worldwide
The OpenID Way You create an OpenID You can use your Flickr account, Google Account or any other provider out there Go to the website Login with your OpenID Define what data you like to share That is it. You have created an account
OpenID Login
How It Works
The Process In Detail Creative Commons Wiki
Data not being shared Your Password Things you do not want to give the website (see my “ personas ”)
Developers I Create an user account based on OpenID data Respect the specs Becoming part of Firefox 3.0 & Internet Explorer 8 Big companies start to use OpenID (Yahoo, Google, VeriSign, Microsoft ...)
Developers II Many ready-to-use implementations for PHP, Java, Ruby ... Add-ons for CMS, Wikis and others No hassle with the detailed specification
Fears Phishing Man-in-the-middle attacks Remember: It is only an Authentication, NOT an Authorization system
More Information?! http://openid.net http://openid.net/developers/specs http://myopenid.com
Any Questions?
 

Openid Presentation - A Quick Introduction

  • 1.
    Distributed Identity ManagementUniversity of Applied Sciences Rapperswil April 14, 2008 Corsin Camichel, ccamiche@hsr.ch
  • 2.
    Agenda Traditional loginprocess What is OpenID How OpenID works Live Demo For Developers Your Questions
  • 3.
    Login Today Howmany accounts do you have? GMail, Yahoo Mail, Hotmail ... MySpace / FaceBook / StudiVZ ... How many different passwords do you use?
  • 4.
    The Way ALogin Works Register for an account (share your data) Verify your email address First login with the new account Server verifies credentials Repeat steps for any other website ... End up with 30 accounts on 30 websites
  • 5.
    What is OpenID?new open standard for logging in identified by URI (AHV, finger print) http://openid.hsr.ch/ccamiche http://cocaman.ch Single-Sign-On (SSO) only one password used over 250 million accounts worldwide
  • 6.
    The OpenID WayYou create an OpenID You can use your Flickr account, Google Account or any other provider out there Go to the website Login with your OpenID Define what data you like to share That is it. You have created an account
  • 7.
  • 8.
  • 9.
    The Process InDetail Creative Commons Wiki
  • 10.
    Data not beingshared Your Password Things you do not want to give the website (see my “ personas ”)
  • 11.
    Developers I Createan user account based on OpenID data Respect the specs Becoming part of Firefox 3.0 & Internet Explorer 8 Big companies start to use OpenID (Yahoo, Google, VeriSign, Microsoft ...)
  • 12.
    Developers II Manyready-to-use implementations for PHP, Java, Ruby ... Add-ons for CMS, Wikis and others No hassle with the detailed specification
  • 13.
    Fears Phishing Man-in-the-middleattacks Remember: It is only an Authentication, NOT an Authorization system
  • 14.
    More Information?! http://openid.nethttp://openid.net/developers/specs http://myopenid.com
  • 15.
  • 16.