+ All Categories
Home > Documents > The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE...

The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE...

Date post: 22-May-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
29
© 2012 IBM Corporation IBM Security Services The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security ArchitectIBM Security Services [email protected]
Transcript
Page 1: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

The Challenges of Web single sign-on

GSE Event

September 7, 2012

Serge Vereecke Security Architect– IBM Security Services

[email protected]

Page 2: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Agenda

Single sign-on technology

Why single sign-on

Challenges of single sign-on

Technology journey of SSO

SSO use case

Lessons learned

Summary

Page 3: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Single sign-on technologies

Single sign-on

Goal of SSO

Technology failed to live up to consumer expectations

Page 4: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Single sign-on technologies

Terminology & synonyms

Definition & properties

Page 5: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

5

Single sign-on : user perspective

Figure 1. Unified, Policy-Based Security for the Web

BEFORE

and other J2EE

SSingle user registry

Unified policy

AFTER

Centralized audit

Access Manager Security Services

Page 6: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

6

Single sign-on : IT perspective •

Page 7: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Single sign-on technologies

Classes of SSO

Page 8: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Technology shifts

Technology shift impact on SSO •

Page 9: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO Technology journey

Kerberos technology

Page 10: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO Technology journey

Web access management technology

Page 11: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO Technology journey

Federated Identity technology

Page 12: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Scenario: Provide Federated SSO to employees and customers,

using internal and partner applications

Employee Portal

Customer Portal

Federated Identity

Management

Portal

Server

Travel Services Provider

401K

Regional Insurance

Providers

Billing Processing

Customers Existing Web Access

Management Solution

(e.g. TAMeb)

Tax/Salary information

Education

Financial/401K/Benefits

Travel Bookings

We all use this everyday!

Page 13: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO Technology journey

Web services technology

Page 14: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO Technology journey

Requestor

Policy

Security Token

Security

Token

Service

Policy

Security Token

Provider

Policy

Security Token

Claims

Claims

Claims

1. Get Token

2. Send

Message (including token)

3. Validate Token

Identity Federation and Web Services requires trust This trust is based on agreements between partners & expressed as policies

Trust can be enabled by technology Trust requirements expressed as infrastructure policies and requirements Security tokens include identity information; Cryptographic keys used to sign Security Tokens

Technology needs to be standards based Standard ways to express and exchange policies that reflect trust relationships Agreed token format, information content, signing and encryption methods

Page 15: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO Technology journey

User centric identity technology

Page 16: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

OAuth – What is it?

User wants to share information (Resource Owner)

User wants to access information (Consumer or Client)

OAuth Service Provider

Provides Access based on Resource Owner’s authorization

Delegated Authorization for enabling the sharing of information

Page 17: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

OAuth – What is it?

Delegated Authorization for enabling the sharing of information

Page 18: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO Technology journey

Page 19: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Customer example: Securing access and SSO to banking

applications

Page 20: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Customer example: Securing access and SSO to banking

applications

Page 21: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Customer example: Securing access and SSO to banking

applications

Page 22: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Customer example: Securing access and SSO to banking

applications

TAMeB WebSEAL server

Proof of

server

identity

User identity

Credential

WebSphere Application Server

Web Authenticator

Java Subject

Credential

PDPrincipal

ETAI

Proof of

server

identity

Credential

Forwarded

request

· Validate origin

· Return identity

Cre

dentia

l

Pro

of o

f

serv

er

identity

Java S

ubje

ct

Cre

dentia

l

PD

Prin

cip

al

Build credential

Page 23: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Customer example: Securing access and SSO to banking

applications

Browser WebSEAL instance LRR application

(SharePoint 2010)

Need to Local

Response

Request

Redirect to Local Response Redirect URL

Http://websealhostname/lrr/

handler.aspx?TAM_OP=value?MACRO=value

Request to Local Response Redirect URL Generate

page

Response

Page 24: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Customer example: Securing access and SSO to banking

applications

Page 25: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Web Application

SharePoint 2010

TMRP++ STS

HTTP(S)

Web Application

TFIM STS

HTTP(S)

Browser

TAM WebSEAL

SSO Architecture -

25

EAI

TAI++

TAI++

User management system

Page 26: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

SSO use case : lessons learned

Page 27: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Scenario: Securing access to SaaS and Services in Cloud

SMB A

Enterprise

B

FIM

BG

FIM

BG

Google Apps

• Single Sign On to Salesforce.com CRM resources based on authentication to the

enterprise directory only

• Access Salesforce.com CRM resources in context and based on web & email

launch points (providing the user with seamless navigation across applications)

Tivoli Federated Identity Manager

SAML

SAML

Partners/Consumers

Merged Companies

Application Providers

Page 28: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Summary

Page 29: The Challenges of Web single sign-on - GSE Belux The... · The Challenges of Web single sign-on GSE Event September 7, 2012 Serge Vereecke Security Architect– IBM Security Services

© 2012 IBM Corporation

IBM Security Services

Questions?


Recommended