Title: Single SignOn architectures in Public Networks Liberty Alliance
1Single Sign-On architectures in Public Networks
(Liberty Alliance)
- Aries Fajar Dwiputera
- Mentor Dr.-Ing. S. Rupp
Seminar of Advanced Communication Services
INFOTECH SS 2005 University of Stuttgart
2IDENTITY CRISIS
3IDENTITY NEEDS
- CONVINIENCES
- User easiness and minimize user bad experience
(forgotten identity)
- STANDARDIZED
- Can be implemented across different platform and
device
- SECURE
- To avoid Identity Fraud
- PRIVACY
- Privacy must be controlled by the owner
- LOWER COST
- Services for everybody
4Agenda
- Problems
- Liberty Alliance Project
- Federated Identity
- Circle of Trust
- Liberty Architecture
- Single-Sign-On ( Authentication )
- Profiles ( Authorization )
- Single-Log-Out
- PGP Trust Relationship
- Comparison of Liberty Alliance and PGP
- Combination of Liberty Alliance and PGP
- Conclusion
- Questions and Answers
5Liberty Alliance Federated Identity
- Solve compatibility between environments
6Liberty Alliance -Circle of Trust
- User /
- Principal
- Identity
- Provider
- Service
- Provider
User
IDP
SP
7Liberty Alliance Architecture
Source www.projectliberty.org
8Liberty Alliance Single-Sign-On
User
Service Provider
Identity Provider
- Sign-on once at a Liberty enabled site -
Seamlessly signed-on - No need to authenticate
again.
9Liberty Alliance Profiles
- Different Profiles and Roles - Different
access rights? User Personalization
Roles Guest
Roles Reseller
Roles User
Roles Guest
10Liberty Alliance Single Sign Out
User
Service Provider
Identity Provider
Synchronized session logout functionality across
all sessions that were authenticated by a
particular identity provider.
11Agenda
- Problems
- Liberty Alliance Project
- Federated Identity
- Circle of Trust
- Liberty Architecture
- Single-Sign-On ( Authentication )
- Profiles ( Authorization )
- Single-Log-Out
- PGP Trust Relationship
- Comparison of Liberty Alliance and PGP
- Combination of Liberty Alliance and PGP
- Conclusion
- Questions and Answers
12PGP Trust Relationship
- Web of Trust
- Introducer
- Each others signature
- Decentralized
13Comparison Liberty Alliance and PGP
14Combination Liberty Alliance PGP
- Web of Trust between IDPs
- and SPs
- Circle of Trust between
- User-IDP
15CONCLUSION Combination Liberty Alliance and PGP
- Single-Sign-On
- Conveniences and easiness for the User
- Easy Key Management
- The burden switch away from the user
- Authenticate and Authorize
- User profiles and personalization
- Distributed Mobile
- Everything is connected and One-Time-Service
- Scalability
- Adding new element is easy
16THANK YOU