Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

62
© 2016 ForgeRock. All rights reserved. A Citizen-Centric Approach to Identity ForgeRock Executive Breakfast

Transcript of Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

Page 1: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

A Citizen-Centric Approach to Identity

ForgeRock Executive Breakfast

Page 2: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

FORGEROCK IS THE LEADING, NEXT-GENERATION, IDENTITY SECURITY SOFTWARE PLATFORM.

2010 Founded

10 Offices worldwide with headquarters in San Francisco

350+ Employees

450+ Customers

30+ Countries

$52M Funding to date (thru Series C) by Accel Partners, Foundation Capital and Meritech Capital Partners

Page 3: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Improving the Quality of Government Services with Citizen-Focused Identity

Management

Daniel RaskinSVP Product Management

Page 4: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

What are the trends?

Page 5: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Hype Cycle for Digital Government Technology, 2016

Page 6: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

The Top 10 Strategic Technology Trends for Government in

2016

Page 7: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Top Investment Areas

CIOs in the Asia/Pacific and EMEA regions indicate digitalization is a much higher priority than their North American peers.

Page 8: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Digital Transformation – Top Three Expected Outcomes

Page 9: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

2016 CIO Agenda: A Government PerspectiveKey Findings•Digital service transformation is at the embryonic stage of maturity in government •Analytics, infrastructure and cloud computing continue to be the top three technology priorities for government CIOs in all tiers and regions – however security and privacy concerns at an all-time high •CIOs report a 34% adoption rate of bimodal IT in government, slightly lagging behind private industry (38%)

Page 10: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

What is the role of identity?

Page 11: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Identity Access Management Identity Relationship ManagementCustomers(millions)

On-premises

People

Applicationsand data

PCs

Endpoints

Workforce(thousands)

Partners andSuppliers

Customers(millions)

On-premises PublicCloud

PrivateCloud

People

Things(Tens of millions)

Applicationsand data

PCs PhonesTabletsSmart

WatchesEndpoints

Digital Transformation & Customer Engagement RequireIdentity Relationship Management (IRM)

PROPRIETARY AND CONFIDENTIAL

Page 12: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Unified, Omnichannel Citizen Experience

Single View Contextual Adaptive Privacy & ConsentIntelligenceSecurity

Persistent Identity

Persistent Identity Across Government Channels

PROPRIETARY AND CONFIDENTIAL

Mobile ReadyOpen DataCitizen ServicesBusiness ServicesSmart City

Page 13: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Identity Management Evolves to Relationship Management

Identity Lifecycle Management Users, Devices, Things & Services

Page 14: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Contextual SecurityTaking Safety to the Next Level

Passwordless Authentication

Register Device for First Time

Authorize Access to Citizen Services

Authorize family members to use account

Authorize Data to Device / Thing

Page 15: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Did you just submit your taxes?

Did you just register a new car?

Kayoko is requesting access to your 2015 taxes. Ok?

Did you just conduct a transaction on our citizen portal?

We noticed your are using a new iPhone.

Would you like to register this device?

Did you request access to your birth certificate online?

Contextual IdentityEnriching the Experience

Page 16: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Contextual IdentityAuthentication, Authorization and Consent

Mobile PassportCitizen Government Official

Page 17: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

SOA is Dead, but Services on the Rise!

1990s and EarlyPre-SOA

Monolith to change

2000sTraditional SOA

Autonomous but coordinated

PresentMicroservices

Decoupled and Independent

PWC, Agile coding in enterprise IT: Code small and local

Page 18: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

SOA is Dead, but Services on the Rise!

1990s and EarlyPre-SOA

Monolith to change

2000sTraditional SOA

Autonomous but coordinated

PresentMicroservices

Decoupled and Independent

PWC, Agile coding in enterprise IT: Code small and local

Page 19: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Service to Service InteractionAuthentication, Authorization and Consent

https://api.australia.gov/v1/userinfo

Authenticate API Authorize API Calls Authenticate API

Page 20: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Scaling to Support Distributed Cloud ArchsStateless Architecture

• Flexible deployment option to address cloud elasticity and massive horizontal scalability

• Configuration can be on a per-realm basis

• Stateless = state information is encoded in JWT token

• Stateful = tokens persisted in the Core Token Service

OpenAM Server

OpenAM Server

OpenAM Server

AWS1 AWS2 AWS3

Microservices Client App

Distributed Cloud Environment

Page 21: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 22: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

The Cloud Conundrum

No Portability! Identity Baked in and Constrained to Each Cloud!

Page 23: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

OAuth2/OIDC OAuth2/OIDC OAuth2/OIDC

OAuth2

The Abstraction of Identity … Again

Page 24: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Cloud Automation

Page 25: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Cloud Native: Cattle versus Pets

Page 26: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Cloud Native: Kangaroos versus Koala Bears

Page 27: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Cloud Native: Cattle versus Pets

Cattle•Cattle are numbers•They are almost identical•When ill, get another (Kill it!)•Thousands of cattle on farm

Pets•Pets have names like “pussnboots”•They are lovingly hand raised•When ill, nursed back to health•1 or 2 pets in house

Elastic Inelastic

Page 28: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Container Management & Deployment

ProductConfiguration

ProductManifests

ForgeRock Images

JavaImage

TomcatImage

…Other Images

DOCKER REPOSITORY

Page 29: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

PlatformUbiquity

Page 30: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

We Must Be Better

Authentication Authorization Multi-Factor Adaptive Risk Self Service Directory API Security GRC …

Page 31: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Unified Platform

UMA Provider Mobile OTP App Synchronization Auditing

LDAPv3 REST/JSON

Replication Access Control

Schema Management

Caching

Auditing

Monitoring

Groups

Password Policy

Active Directory Pass-thru

Reporting

Authentication Authorization Provisioning User Self-Service Authentication OIDC / OAuth2

Federation / SSO User Self-Service Workflow Engine Reconciliation Password Replay SAML2

Adaptive Risk Stateless/Stateful Registration Role Provisioning Message Transformation

API Security Scripting

Built from Open Source Projects:

UMA Resource

Access Management Identity Management Identity Gateway

Directory Services

Page 32: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

U.S. Federal Customers

Homeland Security

Navy

DISA

Labor

Treasury

Energy

Commerce

Defense

Page 33: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

NorwayAll Gov’t Agencies

Global Government Success …

BelgiumCitizen ID

CanadaCitizen Services

New ZealandCitizen Services

FranceUnemployment, Retiree Services

AustraliaTax Office

UKNHS, BBC

SwitzerlandNational Court

System

Page 34: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Identity Relationship Management: Talkin’ Bout a Revolution

Relationship Management

CloudAutomation

CloudReadiness

PlatformUbiquity

MicroservicesArchitecture

Contextual Identity

Page 35: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Thank You

Page 36: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Doing Authorisation, Consent, and Delegation

Right With UMAEve Maler

VP Innovation & Emerging Technology@xmlgrrl

Page 37: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved. 37flickr.com/photos/vincrosbie/16301598031/ CC BY-ND 2.0

Page 38: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

flickr.com/photos/vincrosbie/16301598031/ CC BY-ND 2.0

Page 39: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.flickr.com/photos/delmo-baggins/3143080675 CC BY-ND 2.0

Page 40: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Attribute sharing scenariosIn the next stage of the project … [t]he team will be investigating and testing this to further address the thorny issues of trust and transparency when gaining citizens’ permission. … “[E]ligibility for some services can be quite dynamic, for example, as the level of an individual’s in-work benefits varies, and it may be necessary to carry out on-going eligibility checks from time to time. UMA gives the individual a place to go online where they can see and manage all the consents they have given to different organisations. Until now, managing ongoing consent was tricky,” [Ian Litton] added. “Typically, you asked individuals to consent at a point in time. They tick the T&Cs, which they never see again. UMA should fix that problem.”-- UKA Local Digital, 3 March 2016

Page 41: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Consumer/clinical health IoT scenarios

Page 42: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

resourceowner

requestingparty

authorizationserver

resourceserver

managedelegate

control

negotiateprotect

authorize

access manage

client

consentrevokedeny

Bruce Wayne shares device data with Dr. McCoy

Page 43: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 44: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 45: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 46: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 47: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 48: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 49: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 50: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 51: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 52: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 53: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Page 54: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Why enable personal data sharing?

clinical research better caredata accuracy

Page 55: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Why ensure personal control of sharing?

new IoT needs new regulatory pressures

Page 56: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

The same architecture applies to Google Apps-style delegation

“The enterprise interpretsaccess controlas damage and routes around it.”

Page 57: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Why enable constrained delegation?

security/authn governance APIs/IoT

Page 58: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Why formalize federated authorization?

business ownership standard access model

Page 59: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

The CMO and the CPO can and must meet in the middle

“Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment. …In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller…”

We value personal data as an assetOur customers’ wishes have valueOur customers have their own reasons to share, not share, and mash up data, which we can address as value-add

Risk management perspective Business perspective

Page 60: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

The ForgeRock Identity Platform includes two UMA components

authorization serverresource server

client(sample code

provided)

UMA Provider(access management)

UMA Protector(gateway)

Page 61: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

ForgeRock

ForgeRock

ForgeRockIdentity

ForgeRock

Forgerock.com

Forgerock.com/blog

Thank you!

Page 62: Canberra Executive Breakfast - A Citizen-Centric Approach to Identity

© 2016 ForgeRock. All rights reserved.

Questions?

Wrap Up•Feedback Forms•Your Local ForgeRock Team

Adam ButlerFederal Government Director

Adam BivianoSenior Solutions Architect