IIW 2008b Report November 10-12 2008, Mountain View Abbie Barbir Nortel OASIS IDtrust Steering.

Slides:



Advertisements
Similar presentations
Yahoo! OpenID and OAuth 1 Allen Tom Yahoo! Membership Architect OpenID Foundation Board
Advertisements

Performance Challenges for the Open Web Stanford CS193H 29 September 2008.
Overview of Web Services
Jabber and Extensible Messaging and Presence Protocol (XMPP) Presenter: Michael Smith Cisc 856 Dec. 6, 2005.
Cross Platform Single Sign On using client certificates Emmanuel Ormancey, Alberto Pace Internet Services group CERN, Information Technology department.
By: Ansuya Chauhan.
Higgins 1: A species of Tasmanian long-tailed mouse 2: An open source identity framework being developed at the Eclipse Foundation.
Web Services and the Semantic Web: Open Discussion Session Diana Geangalau Ryan Layfield.
The Widgets Shall Inherit the Web Widget Summit 4 November 2008.
T Network Application Frameworks and XML Service Federation Sasu Tarkoma.
Portable Contacts and vCardDAV Joseph Smarr IETF 74, March 25, 2009 draft-smarr-vcarddav-portable-contacts-00.
Mashing Up with User-Centric Identity America Online LLC John Panzer, Praveen Alavilli.
1 Higgins 1: a species of Tasmanian long-tailed mouse 2: the name of an open source collaboration of IBM, Novell, Oracle, Parity…
In a world with lots of socially-aware sites… …and lots of “open social web” building blocks…
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ITU-T Identity Management Update Bilel Jamoussi, Chief, SGD/TSB ITU Abbie Barbir, Q10/17 Rapporteur.
© 2009 The MITRE Corporation. All rights Reserved. April 28, 2009 MITRE Public Release Statement Case Number Norman F. Brickman, Roger.
Web Services Security Multimedia Information Engineering Lab. Yoon-Sik Yoo.
OpenID Connect Update and Discussion Mountain View Summit – September 12, 2011 Mike Jones – Microsoft John Bradley – Independent Nat Sakimura – Nomura.
Information Card Interoperability Michael B. Jones – Microsoft October 2008.
OpenID And the Future of Digital Identity Alicia Bozyk April 1, 2008.
OAuth option for mHealth Brief Profile Proposal for 2013/14 presented to the IT Infrastructure Planning Committee R Horn (Agfa Healthcare)
SAML-based Delegation in Shibboleth Scott Cantor Internet2/The Ohio State University.
IDENTITY MANAGEMENT Hoang Huu Hanh (PhD), OST – Hue University hanh-at-hueuni.edu.vn.
SCC Activities C. Tilton. Standards Are applied to SOMETHING Within some CONTEXT Something = ID Ecosystem Context = Use Cases 2.
Web Service Standards, Security & Management Chris Peiris
Identity Management in Education. Welcome Scott Johnson, NetProf, Inc. Creator of OmnID Identity Management for Education
Social networking task force Jeff Jaffe Ann Bassetti Steve Holbrook 14 May
Identity Management Report By Jean Carreon and Marlon Gonzales.
SAML Right Here, Right Now Hal Lockhart September 25, 2012.
Dr. Bhavani Thuraisingham October 2006 Trustworthy Semantic Webs Lecture #16: Web Services and Security.
1 Emergency Alerts as RSS Feeds with Interdomain Authorization Filippo Gioachin 1, Ravinder Shankesi 1, Michael J. May 1,2, Carl A. Gunter 1, Wook Shin.
SAML 2.1 Building on Success. Outline n Summary of SAML 2.0 n Work done since 2.0 n Objectives of SAML 2.1 n Proposed Task List n Undecided Issues n Invitation.
1 DHCP Authentication Discussion INTAREA meeting, 70th IETF Vancouver, Canada Jari Arkko and Ralph Droms.
Serving society Stimulating innovation Supporting legislation Danny Vandenbroucke & Ann Crabbé KU Leuven (SADL) AAA-architecture for.
WS-Security Protocol Ramkumar Chandrasekharan CS 265.
Openid Connect
Authority of Information Technology Application National Center of Digital Signature Authentication Ninh Binh, June 25, 2010.
Semantic Web Technologies Research Topics and Projects discussion Brief Readings Discussion Research Presentations.
© 2008 by Matt Flaherty & Mary Ruddy; made available under the EPL v1.0 Security & Identity : From present to future Matt Flaherty, IBM Mary Ruddy, Meristic.
Claims-Based Identity Solution Architect Briefing zoli.herczeg.ro Taken from David Chappel’s work at TechEd Berlin 2009.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Living in a Network Centric World Network Fundamentals – Chapter 1.
Federated Identity Graduates Nate Klingenstein Internet2 APAN 27 高雄台湾, March 3, 2009.
Justin Richer The MITRE Corporation October 8, 2014 Overview of OAuth 2.0 and Blue Button + REST.
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential.
OASIS Cloud Authorization TC (CloudAuthZ) Rakesh Radhakrishnan, TC Member.
Jeju Island, Korea, 13 – 16 May 2013Identity Management and Identification Systems GSC17-PLEN-43 ITU-T IDENTITY MANAGEMENT UPDATE Bilel Jamoussi, Chief,
In a world with lots of socially-aware sites… …and lots of “open social web” building blocks…
IETF 67 – SPEERMINT WG Presence Use Cases draft-houri-speermint-usecase-presence-00 Avshalom Houri – IBM Edwin Aoki – AOL LLC Sriram Parameswar - Microsoft.
Experiences Deploying OpenID for a Broad User Base Security and Usability Considerations Breno de Medeiros Identity Management 2009, September
Integrating the Healthcare Enterprise Improving Clinical Care: Enterprise User Authentication For IT Infrastructure Robert Horn Agfa Healthcare.
Presented by: Sonali Pagade Nibha Dhagat paper1.pdf.
OpenID Connect Working Group May 10, 2016 Mike Jones Identity Standards Architect – Microsoft.
Workshop on Security for Web Services. Amsterdam, April 2010 Applying SAML to Identity Data Exchange.
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Web site lifecycles Problem is that web sites live forever –Out of date sites with.
OASIS IDtrust Member Section June Leung Chair, OASIS IDtrust Member Section Steering Committee
OpenID Connect: An Overview Pat Patterson Developer Evangelist Architect
CLASSe PROJECT: IMPROVING SSO IN THE CLOUD Alejandro Pérez Rafael Marín Gabriel López
Web Authorization Protocol WG Hannes Tschofenig, Derek Atkins.
Access Policy - Federation March 23, 2016
Federation made simple
OGSA-WG Basic Profile Session #1 Security
Working in Groups in Canvas
Data and Applications Security Developments and Directions
OpenID Connect Working Group
OpenID Connect Working Group
OpenID Connect Working Group
A few recent days in the news…
OpenID Connect Working Group
OpenID Connect Working Group
Presentation transcript:

IIW 2008b Report November , Mountain View Abbie Barbir Nortel OASIS IDtrust Steering Committee

IIW 2008 Take home points..1 Many interactive and important session were proposed covering various topics. Full details at IIW 2008 wiki at Key involvement from Google, M/S, AOL and Yahoo 180 participants Focus was on using the technology in real market deployment. Google is pushing for taking OpenID in combination of other protocols main stream. Google is becomming an OpenID provider. Discovery is deemed to be very important. A 3.5 hour session was conducted on the topic led by Yahoo. Relation to XRDS, XRI and OAuth is important.

IIW 2008 Take home points..2 OAuth authors would like to standarize OAuth at the IETF as opposed to OASIS for various reasons: They do not feel that they will need to pay OASIS so that they can do their work They do work outside their companies as supporters of the work this means that their companies will not be interested in joining OASIS IPR issues need to be solved if they join a TC OASIS rule of having no more two individuals from a single company hinders the abililty of these individuals to join OASIS Some individulas can not afford the $300 fee to join OASIS. A BoF on OAuth was done at the November meeting of IETF A discussion list was established for OAuth Need to encage this community to get them to do work in IDTrust Discussions already started to get them at XRDS TC. Drummond to provide an update. Same problem occurs with the Open Web Foundation People. An OASIS wide policy is need to deal with the issue.

Important Sessions and impacts..1 Google OAuth & Federated Login Research see Goal is to give investigate how OAuth, OpenID, SAML, XRDS, SaaS, Strong/2ndFactorAuth, InformationCards, CardSpace, OpenSocial, Portable Contacts, WS-*, Geneva,.. technologies fit together Direct reserach on user login aspects and go to market strategies Requires IDTrust to focus on Social network aspects and OAuth in addition to XRI/XRDS. Google Strong Auth Usability and Demos was also covered see videos at

Important Sessions and impacts..2 Effort underway to standardize Portable Contacts – contact schema; discovery / auth; common operations – Focused on ease & speed of adoption – Active involvement from large & small players – More info & current draft spec: – IDTrust need to see what role it can play here

OpenID Authentication has been finalized; bunch of implementations; found lots of spec bugs Core specification can support oauth and addresses Current focus om making spec more readable, fixing bugs (eratta) and a security appendix Working on clarifying XRI Currently there's no firm message about whether RPs MUST support XRIs or not. Need to clarify how exactly XRI should be used with OpenID. Clarify if RPs can white or blacklist what OPs they accept, and vice-versa. Discovery of type of identifiers an RP supports. Updating discovery. Possibly including the XRD discovery. Clarifying whether association over SSL must/can use diffie-hellman. Exploratory work: Signature mechanisms. Looking at additionally supporting the mechanisms defined in OAuth so that they can be closer together. Possibly deprecating the current signature mechanism. Use of Public keys? Need coordination with them and see what they want to do with OpenID. Same participation problems like the OAuth

Browser Extension Convergence Quick inventory of the existing browser extensions: Firefox: Sxipper (OpenID, UN/PW), Higgins: HBX4FF (I-Card), OpenInfoCard (I-Card), DigitalMe (I-Card), OpenLiberty (SAML), Verisign Seatbelt (OpenID), IDIB (OpenID…) IE: Microsoft’s I-Card built-in, Higgins: HBX4IE A list of protocol “families” that each extension should support: Username/Password (Form-based, HTTP Auth, WS-Security) OpenID (OpenID, SAML); I-Card (ISIP‡IMI-TC) Kerberos; SAML (SAML SSO, SAML ECP) Browser-native add-on/extension/plug-in Flash, Java, Gears, Silverlight Browser Support for RP Auth Discovery Everyone agreed that creating common specs for this was a good idea. Could use XRDS as the basis for discovery of a relying party (RP) site’s authentication support for multiple protocols. The RP site would publish an XRDS document that would allow a “smart client” (well, a browser extension) to discover information about what protocols were supported and how they might be used to authenticate to the site. Possible new work in IDTRust

Need for a Common Terminology Exploring the Construction of Online Identity & Definition of Terms. IDTrust can take a lead role here. ITU-T has a current up to date document.

Conclusion Very Important event Need to keep involved OASIS was mentioned a lot in the meeting, the message is going forward to consider OASIS as an SDO Many opportunities to get involved Main obstacle is how this community can do their work in OASIS.