untitled

Similar documents
Encryption Security

SAML

ppt

PowerPoint プレゼンテーション

sp c-final

All Rights Reserved, Copyright FUJITSU LIMITED All Rights Reserved, Copyright FUJITSU LIMITED

XMLを基盤とするビジネスプロトコルの動向

untitled

untitled

untitled

Testing XML Performance

2009 NTT Corporation. All rights reserved.

セキュリティ関連XML規格の紹介

"CAS を利用した Single Sign On 環境の構築"

untitled

"CAS を利用した Single Sign On 環境の構築"

BIG‑IP Access Policy Manager | F5 Datasheet

Oracle Identity Managementの概要およびアーキテクチャ

Dec , IS p. 1/60

Liberty for XML cons

wpEnterpriseSvr.doc

SSO Sales/Tech combined webinar template

Windows Oracle -Web - Copyright Oracle Corporation Japan, All rights reserved.

属性認証ハンドブック

untitled

WebサービスとCORBA

WebLogic 6.0

CA Federation ご紹介資料

日本オラクルのSOA戦略

金融分野のTPPsとAPIのオープン化:セキュリティ上の留意点

( )

NLC配布用.ppt

"CAS を利用した Single Sign On 環境の構築"

Vol.55 No (Mar. 2014) 1,a) , SAML/ID-WSF ID-WSF A Proposal and an Evaluation of Technology on Federated Identity and

Copyright XML 2005,2006 All rights reserved. XML Consortium Web Web Web Web Web Web Web

Oracle Service-Oriented Architecture Suite

Sun_XMLcons.sxi

スライド 1

オープンソース・ソリューション・テクノロジ株式会社 会社紹介

JPGRID-GGF0205 第 5 回 GGF 調査会 globusworld 参加報告 株式会社 SRA グローバルITサービスカンパニー開発部産業第 4グループ 平野基孝 Programs 8 Tutorial 2: Grid Services and Web Services 8 Track

Elastic stack Jun Ohtani 1

本 日 の 議 題 アーキテクトが 直 面 しているビジネスの 課 題 アプローチ 方 法 Liberty Allianceの 問 題 への 取 り 組 み 事 例 : 連 携 認 証 およびwebサービスの 実 際 ベネフィット

Plan of Talk CAS CAS 2 CAS Single Sign On CAS CAS 2 CAS Aug. 19, 2005 NII p. 2/32

FIDO FIDO Authentication and Its Technology: Technical Specifications and Standardization Activities Hidehito GOMI Wataru OOGAMI FIDO Fast IDentity On

セキュリティ関連XML規格の紹介

Zurich, CH Brussels, BE Wrocław, PO Toronto, CA Ottawa, CA Herzliya, IL Almaden, US Detroit, US Tokyo, JP Boulder, US TJ Watson, US Tokyo, JP Atlanta,


A B, ID End-User 3 How do I get an OpenID?, 4

OSSTech OpenSSO社内勉強会資料

untitled

LAN BYOD Bring Your Own Device Ballagas, et al. PC PC LAN Business Insider PC LAN LAN Henderson, et al. LAN P P Peer-to-Peer Gember, et al. UDP HTTP L

untitled

,,, J-SOX ISMS PCIDSS,, IM/VoIP/VoD Copyright 2008 Juniper Networks, Inc. 2

スライド タイトルなし

橡CoreTechAS_OverView.PDF

_02-5.ppt

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

untitled


fiš„v5.dvi

WCAG 2.0 W3C/WAI ( ) 2 24 December,

外部SQLソース入門

外国語学部 紀要30号(横書)/03_菊地俊一

Microsoft PowerPoint - 【資料3】Open ID概要.ppt

Zurich, CH Brussels, BE Wrocław, PO Toronto, CA Ottawa, CA Herzliya, IL Almaden, US Boulder, US Detroit, US TJ Watson, US Tokyo, JP Tokyo, JP Atlanta,

i

今後の認証基盤で必要となる 関連技術の動向 株式会社オージス総研テミストラクトソリューション部八幡孝 Copyright 2016 OGIS-RI Co., Ltd. All rights reserved.

of one s information (hearsay, personal experience, traditional lore), or epistemological stance may be expected of all speakers. This is especially t

Web-ATMによる店舗向けトータルATMサービス

Web Web ( (SOAP (SOAP/http (WSDL UDDI 1. 2.XML 3. (XDoS http, https SOAP XML Web/App ( App

オントロジ入門


CAS Yale Open Source software Authentication Authorization (nu-cas) Backend Database Authentication Authorization Powered by A

ESA_UI_1110.PDF

WS-I Basic Profile 1.0 の概説

NKK NEWS 2012

バーゼル4

Oracle_for_SAP :29 PM ページ 2 2 3

kiri_17.pdf

つるい27-5月号PDF.indd

PingFederate SAML SSO での ISE 2.1 ゲスト ポータルを設定する

オープンソース・ソリューション・テクノロジ株式会社 会社紹介

PDFŠp…f†[…^

sec( ).ppt


<Documents Title Here>

HOLON/MD

untitled

Microsoft SharePoint Server 2010SharePoint Server 2010Web SharePointSharePoint Server 2010 SharePoint SharePoint Server 2010 SharePoint SharePoint Sha

Web Microsoft 2008 R2 Database Database!! Database 04 08

21 Key Exchange method for portable terminal with direct input by user

〈論文〉組織改革の成果に関する予備的調査--社内カンパニー制導入が財務的業績に与える影響

IBPC Osaka Event Topics International Affairs Department, Investment Promotion Project

Salesforce DX.key

Page 1 of 6 B (The World of Mathematics) November 20, 2006 Final Exam 2006 Division: ID#: Name: 1. p, q, r (Let p, q, r are propositions. ) (10pts) (a

雲の中のWebアプリケーション監視術!~いまなら間に合うクラウド時代の性能監視入門~


SAML認証

untitled

WS-I Basic Profile 1.0 の概説

Transcription:

WEB SAML 2.0 RSA 2005 SAML 2.0 2 1

3 Federated Identity The agreements, standards, and technologies that make identity and entitlements portable across autonomous domains. The Burton Group Web 4 2

Scope of Current Deployments Complexity [ ] : 2006 Enterprise B2B B2B Partner Networks Large Large Public Public Networks B2C/G2C Adoption Timeline 5 SAML Liberty ID-FF WS-Federation The purpose of SAML is to define, enhance, and maintain a standard XMLbased framework for creating and exchanging authentication and authorization information Aims to provide open standard and business guidelines for federated identity management spanning all network devices One of the WS-* specifications that defines mechanisms to allow different security realms to federate by allowing and brokering trust of identities, attributes, authentication between participating Web services. OASIS 150 consumer and technologies companies, including BofA, AmEx, Fidelity, GM, Sony, Vodafone, Sun, RSA Microsoft, IBM, RSA, BEA, VeriSign SAML 1.0 (Q2 02) Liberty 1.1 (Q1 03) WS-Fed (TBD) SAML 1.1 (Q2 03) Liberty ID-FF 1.2 (Q4 03) SAML 2.0 (Q1 05) 6 3

SAML Liberty ID-FF WS-Federation Many implementations available, including open source toolkits Sun, Ping Identity, Phaos, Trustgenix RSA has announced intent to support by Q4 2004 Microsoft, IBM, RSA, and a few other vendors have announced intent to support and produced prototypes Web SSO Attribute Exchange Authentication Query Authorization Query Enhanced Web SSO (e.g. acct. linking, privacy, session mgmt.) Other specs (ID-WSF and ID-SIS) support additional use cases Web SSO (passive requestor profile) Smart client (active requestor profile) Smart client (LECP) - -6 12-18 7 SAML Liberty Liberty ID-FF 1.2 Liberty 1.1 SAML 2.0 SAML 1.1 SAML 1.0 Q1 2005 Q4 2002 ( SAML 2.0 Liberty ID-FF1.2 8 4

SAML 2.0 9 SAML SAML Security Assertion Markup Language) SSO XML XML XML XML XACML 10 5

SAML WEB 11 SAML Profiles Bindings Authn Context Protocols Assertions MataData 12 6

SAML Assertion XML ID Relying SAML Asserting SAML 13 SAML Authentication Assertion Attribute Assertion Authorization Decision Assertion 14 7

SAML 15 Asserting Relying ( SAML Web Asserting Relying A 16 8

Asserting Relying ( SAML (Attribute Authority) Relying Asserting A SAML SOAP Exec 17 Asserting Relying ( SAML (Authentication Authority) Requesting Asserting A SAML SOAP Response 18 9

BAP (Browser Artifact Profile) BPP (Browser Post Profile) Browser/Artifact Profile Asserting Replying SSO Replying Asserting Browser/POST Profile BAP SSO Asserting Replying PKI/ 19 SAML Web SSO (BAP) It s me! Portal App A App B A Who are you? XyzCorp.com 20 10

SAML Web SSO (BAP), continued 1 XyzCorp.com 2 Portal App A App B Asserting Party (AP) A via a back-channel exchange 1. B 2. 3. RP 4. RP AP 5. RP B 4 ABCCorp.com BPP FIMBAP 3 5 Relying Party (RP) B 21 SAML Web SSO (BPP) XyzCorp.com 2 Portal App A App B 1 Asserting Party (AP) A 1. B 2. 3. RP 4. RP B SAML BPP SSO SAML compliance SAML1.1 3 Relying Party (RP) ABCCorp.com 4 B 22 11

SAML 2.0 SAML 1.1 SAML SAML 1.1 23 SAML 2.0 Conformance Requests Assertions and Protocol Bindings Profiles Metadata Authentication Context Security and Privacy Considerations Glossary 24 12

SAML 2.0 Metadata Enhanced Client or Proxy(ECP) 25 SAML 2.0 OASIS SAML1.X Liberty ID-FF ID Web ID 26 13

14