The document provides an extensive overview of OAuth 1.0, OAuth 2.0, and OpenID Connect, including their structures, flows, and implementation details. It outlines the various authorization processes, including request and access token generation, and highlights differences between OAuth 1.0 and OAuth 2.0 flows. Additionally, it includes references to relevant RFCs and examples related to Twitter and Facebook integration for understanding these protocols.
The document discusses graph databases and their properties. Graph databases are structured to store graph-based data by using nodes and edges to represent entities and their relationships. They are well-suited for applications with complex relationships between entities that can be modeled as graphs, such as social networks. Key graph database technologies mentioned include Neo4j, OrientDB, and TinkerPop which provides graph traversal capabilities.
The document provides an extensive overview of OAuth 1.0, OAuth 2.0, and OpenID Connect, including their structures, flows, and implementation details. It outlines the various authorization processes, including request and access token generation, and highlights differences between OAuth 1.0 and OAuth 2.0 flows. Additionally, it includes references to relevant RFCs and examples related to Twitter and Facebook integration for understanding these protocols.
The document discusses graph databases and their properties. Graph databases are structured to store graph-based data by using nodes and edges to represent entities and their relationships. They are well-suited for applications with complex relationships between entities that can be modeled as graphs, such as social networks. Key graph database technologies mentioned include Neo4j, OrientDB, and TinkerPop which provides graph traversal capabilities.
Torsten Lodderstedt is the CTO of yes.com, an open banking ecosystem. He discusses open banking prior to PSD2, including challenges like screen scraping. PSD2 obliges financial institutions to provide access to account information and payment initiation to authorized third parties. Beyond PSD2, different parties have differing interests. Identity is important for digital society. Financial institutions can leverage verified identity data as an identity provider and authentication service. OpenID Connect can represent verified identity claims with metadata for legal compliance and international interoperability. This representation allows for privacy-preserving inquiries.
Enabling Large-Scale Multi-Party Federations with OpenID Connect - OpenID Sum...OpenID Foundation Japan
?
The document discusses the implementation and benefits of OpenID Connect for establishing large-scale multi-party federations, particularly within the research and education sector, where it is gaining interest. It contrasts OpenID Connect with SAML, highlighting its scalability, maintainability, and trust chain approach for federations. The OpenID Connect Federation specification and its capabilities, as well as ongoing developments and future events for interoperability, are also detailed.
Personal Digital Transformation and Holistic Digital Identity - OpenID Summit...OpenID Foundation Japan
?
The document discusses the advancements and shortcomings in personal digital transformation (PDT) and digital identity from the perspective of identity professionals. While enterprises have achieved streamlined technologies and increased security, they have failed to address the evolving needs of individuals as digital services expand, leading to potential issues with privacy and digital relationships. It emphasizes the need for a robust digital identity system that accommodates an individual's 'selfness' and 'whoness' to adapt to the nuances of digital life.
2. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
はじめに
? vB初
? 表嶄M令
?OpenIDファウンデ`ション?ジャパン コミュニティ?リ`ド
?@shingoym
? 垢儲_俛
?OpenIDファウンデ`ション?ジャパン 並嫋帷L
?@tkudos
? 云セッションのテ`マ
? クラウドの噸式とともにIDB亊室gが吩?嶷勣來をしてきました。
エンタ`プライズIT偏におけるビジネス婢_とOpenID Connectを
嶄伉とした室gトレンドについて盾hします。
1
3. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
バズワ`ドを埆えて
2
暫臚擇ら噸式豚へ 云鯉議に噸式し兵めてきたクラウド
Source: http://www.gartner.co.jp/press/html/pr20130903-01.html
4. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
コンシュマライゼ`ションのn
3
Cとして聞っていたクラウド?サ`ビスがBにも盃奮していく
Source: http://www.slideshare.net/CloudIDSummit/01-cis2013-opening-durand
6. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
(Source) Chuck Mortimore (Salesforce), ^Open, Mobile, Social ̄,
Cloud Identity Summit 2011 Proceedings http://bit.ly/pBXcgM
エンタ`プライズのウチとソト
5
7. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
エンタ`プライズのウチとソト
(Source) Chuck Mortimore (Salesforce), ^Open, Mobile, Social ̄,
Cloud Identity Summit 2011 Proceedings http://bit.ly/pBXcgM 6
8. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
エンタ`プライズのウチとソト
ID砿尖システム
プロビジョニング
アクセス砿尖 / SSO
ディレクトリ?
(Source) Chuck Mortimore (Salesforce), ^Open, Mobile, Social ̄,
Cloud Identity Summit 2011 Proceedings http://bit.ly/pBXcgM 7
9. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
ユ`ザ`二Iが箔める仝ソリュ`ション々も篁
?Identity based SI
? ユ`ザ`二Iを ^identity-enabled ̄ にする
システム?インテグレ`ション
?Identity based Software / Service
? ソフトウェア/サ`ビス?スタックの嶄伉に
アイデンティティを了崔づける
8
10. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
ユ`ザ`二Iが箔める仝アイデンティティ?ソリュ`ション々
アイデンティティ砿尖のアウトソ`シングの枠へ
9
Source: http://www.slideshare.net/CloudIDSummit/01-cis2013-opening-durand
11. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
ユ`ザ`二Iが箔める仝アイデンティティ?ソリュ`ション々
モバイルアプリSSO
?AZA (Authorization Agent)
10
Source: http://www.slideshare.net/CloudIDSummit/cis13-authorization-agent-aza-mobile-protocol
12. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
ユ`ザ`二Iが箔める仝アイデンティティ?ソリュ`ション々
パ`トナ`二Iやサプライヤ`、エンドユ`ザ`
との佚mvS_羨
11
ポリシ`メ`カ`
Trust Framework
ProviderTFP
IDk佩
Identity Service
ProviderIdP
ID鞭秘
Relying Party
RP
J協O鉾
旋喘宀
J協
J協
O
サ`ビス
旋喘賦
サ`ビス戻工
サ`ビス
旋喘賦
サ`ビス戻工
デ`タB亊
弐s 弐s
O
僥伏鬚
サ`ビス
僥伏鬚
サ`ビス
サプライヤ`
二I
バイヤ`
二I
ステ`クホルダ`gで
IDB亊するための
ポリシ`を貨協ポリシ`に児いて
IdPとRPをJ協
13. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
ユ`ザ`二Iが箔める仝アイデンティティ?ソリュ`ション々
二IシステムのAPI晒によるチャネル寄
12
コンテンツ/
C嬬
PC/亊。鬚
Webサイト
スマ`トフォン鬚
Webサイト/アプリ
芙T
二I
翌何鬚API
Web
API
パ`トナ`二I
/SaaS
パ`トナ`
Webサイト
糾n、
オフィス
PC、亊。極挑
參翌の
デバイス
芙坪IDでの旗尖
アクセスをS辛
芙坪IDでの旗尖
アクセスをS辛
芙坪IDでの旗尖
アクセスをS辛
芙Tの
芙坪IDで
旗尖アクセス
芙Tの
芙坪IDで
旗尖アクセス
芙Tの
芙坪IDで
旗尖アクセス
芙坪IDで
ログイン
芙坪IDで
ログイン
IDB亊によってパ`トナ`サイト/
アプリケ`ションと芙Tの芙坪IDを
ひもづけ、どの芙TがWeb APIに
アクセスしているかを委燐する
18. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
SCIM: プロビジョニングAPIの併
System for Cross-domain Identity Management
? SCIM鬉離ラウドサ`ビスではユ`ザ`?プロビジョニングAPIが
慌宥晒されるため、ユ`ザ`二I箸鬉諒帷gが恷弌に
? SCIMでは仝スキ`マ々と仝プロトコル々を協x
? スキ`マ: ユ`ザ`やグル`プなどのJSON燕F。勣周に鬉犬辛嬬
? プロトコル: RESTful API。CRUD (伏撹/歌孚/厚仟/茅)、碧、ディスカ
バリ、匯凄┘丱襯I尖など
ユ`ザ`二I
A芙
プロビ
ジョニング
システム
SCIM Service Provider
RESTful API)
SaaS A芙
SCIM Service Provider
RESTful API)
SaaS B芙
JSON
SCIM
Consumer
JSON
17
19. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
Enterprise Identity Working Group (EIWG)
エンタ`プライズ?アイデンティティWG
? 2012定12埖、OpenIDファウン
デ`ション?ジャパンとJNSA
アイデンティティ砿尖WGが慌
揖でO羨
? 仝OpenID ConnectとSCIMの
エンタ`プライズ旋喘ガイド
ライン各々を恬撹し、
エンタ`プライズID砿尖を
もっとシンプルにするための
檀試咾鯰个
18
20. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
仝OpenID ConnectとSCIMの
エンタ`プライズ旋喘ガイドライン各々
? エンタ`プライズIT鬚吋ラウドサ`ビス並I宀を
鵑法徭芙サ`ビスにOpenID ConnectとSCIMを
旋喘するにあたり篇すべき朕とm喘圭隈を盾h
? エンタ`プライズh廠蒙嗤の勣周
?箭: ファイアウォ`ル撹、J^レベル/壅J^、奉來厚仟など
? 晩云のユ`ザ`二I蒙嗤の勣周
?箭: MA咾篌嬲奉の燕F圭隈、h忖とiみの燕、匯堵
並咾覆
? ガイドラインは書瘁巷_嚠協
19
21. Copyright 2013 OpenID Foundation Japan - All Rights Reserved.
EIWGに歌紗するには
? SIer?システムベンダ`
? OpenIDファウンデ`ション?ジャパン氏Tになっていただく駅勣が
あります
? エンタ`プライズ鬚SaaS?クラウド?ASP並I宀
? OpenIDファウンデ`ション?ジャパン氏Tになっていただく駅勣は
ありません。そのままご歌紗けます
? エンドユ`ザ`二IIT何TのID砿尖システム毅輝宀
? OpenIDファウンデ`ション?ジャパン氏Tになっていただく駅勣は
ありません。そのままご歌紗けます
20
☆はOpenIDファウンデ`ション?ジャパンにおい栽わせください瘁峰