Top Banner
Identity Management for the Next Decade Johann Dilantha Nallathamby WSO2 Technical Lead
21

WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Aug 08, 2015

Download

Technology

WSO2
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Identity Management for the Next Decade

Johann Dilantha NallathambyWSO2

Technical Lead

Page 2: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

The Past...

Too many IAM standards?

Page 3: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

The Future...

Use cases driven over specification driven

Integration inside and out

Page 4: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Key differentiators in IAM products...

● Embrace strategy over tactics● Rapid time to value and low operational costs● Access Control is more of a Business problem

than IT problem● Deployment flexibility● Customizable with minimal coding

Page 5: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Three disrupting forces of the new information age

Page 6: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Why IAM products suite the cloud ?

● Mostly standardized● Cost effective● Extends the same security model that is on-

premise to cloud● Can effectively handle the distributed nature of

SaaS applications

Page 7: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Challenges in Mobile..

● SSO for Native Application○ Native Application WG

● Dynamic Client Registration● Client side data encryption

○ How to secure the key?● Bring Your Own Device (BYOD)

○ Desktop Virtualization○ OS Containerization○ App Wrapping○ Selective wipe

Page 8: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Future of Authentication

● Gartner predicted “Zero Trust Authentication” way back in 2010.

● Multifactor Factor Authentication○ Key fobs○ Smartphone + authenticator tools○ Smartphone + fingerprint○ Smartphone + QR code scanner

● Fast IDentity Online (FIDO) Alliance

Page 9: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

What happens to Social Login ?● Corporate User Directories BYOI

● The surge in BYOD might even fuel this transition.

● Consumer Identity is the next big thing○ National Strategy for Trusted Identities in

CyberSpace (NSTIC)○ UK Government Identity Assurance Program○ Dubai e-Gov - Dubai Connect

Page 10: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Future of IAM

More,● Context Based Access Control

○ Is XACML dead? No.

● More compliance○ PCI DSS, NIST, HIPAA

Page 11: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

The Enterprise Identity Bus (EIB) from WSO2

● Separation of concerns between Application layer and the Identity layer

● No universal standard● Can’t modify the clients as well as the backend

applications/services

Page 12: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

The EIB Architecture

Page 13: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Back-End Extensibility..

Page 14: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Dynamic UX..

Page 15: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Dynamic UX..

Page 16: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Gadgets Based Dashboard

Page 17: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Workflow Execution

Page 18: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

User Managed Access (UMA) 1.0

Page 19: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Privileged Account Management (PAM)

PAM requires better integration with IAM systems ● Password change frequency

○ Never○ Frequently○ Per session○ On demand

● Timely provisioning● Better role management capabilities

Page 20: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Security Information Management (SIM)● WSO2 platform has the nuts and bolts to build a

SIM solution.● WSO2 DAS - High performing, highly scalable

data analysis○ Reports and dashboards on identity data○ Trend analysis and risk scores

● WSO2 CEP - Real time alerting○ Intrusion detection and intrusion prevention

● WSO2 Machine Learner - Build machine learning algorithms for tasks such as fraud detection, anomaly detection, classification, etc.

Page 21: WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade

Thank You