Presentation is loading. Please wait.

Presentation is loading. Please wait.

Identity in the Cloud (ID-Cloud) Towards standardizing Cloud Identity www.oasis-open.org.

Similar presentations


Presentation on theme: "Identity in the Cloud (ID-Cloud) Towards standardizing Cloud Identity www.oasis-open.org."— Presentation transcript:

1 Identity in the Cloud (ID-Cloud) Towards standardizing Cloud Identity www.oasis-open.org

2 Cloud Identity Management n TC works to address Identity Management challenges related to Cloud Computing n Cloud Identity Management is considered a top security concern n Identity Management is not completely solved at Enterprise level l Standards are evolving n Cloud is a new paradigm, so the same problems in new packaging

3 What is it we do? 3 Main objectives: n Identifying detailed Use Cases l Identity deployment, provisioning and management in a cloud context n Define Interoperability Profiles for Identity in the Cloud l Profiles will be based on use and combinations of existing standards, protocols and formats n Gap Analysis of existing Identity Management standards and protocols when applied in the context of Cloud l Based on Use Cases and Interoperability Profiles l Feed analysis back to the WG responsible for a standard

4 What is it we do? n Other objectives: l Glossary on Cloud Identity n Harmonized set of definitions, terminologies and vocabulary on Identity in the context of Cloud l Do not re-invent the wheel n Build on existing standards and specifications l Strong liaison relationships with other international working groups n ITU-T, Cloud Security Alliance

5 How serious are we about this? n Our Technical Committee chairs are: l Anil Saldhana (Red Hat) l Tony Nadalin (Microsoft) n Amongst the member of the Technical Committee are: l Red Hat, IBM, Microsoft, CA Technologies, Cisco Systems, SAP, EBay, Novell, Ping Identity, Safe Net, Symantec, Boeing Corp, US DOD, Verisign, Akamai, Alfresco, Citrix, Cap Gemini, Google, Rackspace, Axciom, Huawei, Symplified, Thales, Conformity, Skyworth TTG, MIT, Jericho Systems, PrimeKey, Aveksa, Mellanox, Vanguard Integrity Professionals, NZ Govt...

6 Current Status n Three stages: l Use Case formalization (ETA: May/June ’11) l Defining the Interoperability Profiles for Identity in the Cloud (ETA: December ’11) l Gap Analysis of existing Identity Management Standards

7 Details on Use Cases n Received 35 Use Cases of Identity Management in the Cloud l Structure of Use Cases: n Description / user story n Goal / Desired outcome n Categories covered n Applicable Deployment Models n Actors n Systems n Notable Services n Dependencies n Assumptions n Process Flow

8 Details on Use Cases n Categorizations: l Authentication n Single Sign On (SSO) n Multi factor Authentication l Infrastructure Identity Establishment l General Identity Management n Infrastructure IdM n Federated IdM l Authorization l Account & Attribute Management n Account & Attribute Provisioning l Security Tokens l Audit & Compliance

9 Details on Use Cases n Applicable Deployment and Service Models: l Deployment Models: n Private n Public n Community n Hybrid l Service Models: n SaaS n PaaS n IaaS n Other

10 Details on Use Cases n High Ranked Use Cases: l Managing Identities at all levels in the Cloud l Need for Federated Single Sign On across multiple environments l Enterprise to Cloud SSO l Auditing l Multi-factor Authentication for Privileged User Access

11 Resources n OASIS Technical Committee Homepage http://www.oasis-open.org/committees/id-cloud/ n OASIS Technical Committee Wiki http://wiki.oasis-open.org/id-cloud/FrontPage n Wiki Page with links to member submissions http://wiki.oasis-open.org/id-cloud/MemberSubmissions Gershon.Janssen@gmail.com www.gershonjanssen.com


Download ppt "Identity in the Cloud (ID-Cloud) Towards standardizing Cloud Identity www.oasis-open.org."

Similar presentations


Ads by Google