OpenID Protocol Explained

10

Click here to load reader

description

A description about how the OpenID protocol works in about 7 minutes

Transcript of OpenID Protocol Explained

Page 1: OpenID Protocol Explained

Browser(User-Agent)

Desired Site(OpenID Consumer)

(Relying Party) OpenIDProvider

This is the person who desires to access a web site.

This is the browser he is using to access the web.

Person has:

Name: AlexID: http://alex.provider.com/

This is site that the user really want to access. For this example he wants to access his bank called “Big Bank”.

This is site that is going to prove that Alex is really Alex.

http://bigbank.com/ http://provider.com/

Identity Page

This addressrepresents Alex

Page 2: OpenID Protocol Explained

Browser(User-Agent)

Alex Allentown

Me!

http://alex.provider.com/ Identity Page

Page 3: OpenID Protocol Explained

Browser(User-Agent)

UserName:

I will log In ONCE

http://alex.provider.com/ Identity Page

OpenIDProvider

aallen321

**************Password:

LOGIN

Page 4: OpenID Protocol Explained

Browser(User-Agent)

OK, You are logged in to the OpenID service.

OK!

http://alex.provider.com/ Identity Page

OpenIDProvider

Page 5: OpenID Protocol Explained

Browser(User-Agent)

Desired Site(OpenID Consumer)

(Relying Party)

Big BankEnter your OpenID:http://alex.provider.com

LOGIN

http://bigbank.com/

Need to access the bank.

OpenIDProvider

Identity Page

Page 6: OpenID Protocol Explained

Browser(User-Agent)

Desired Site(OpenID Consumer)

(Relying Party)

http://bigbank.com/

I clicked “Login”

http://alex.provider.com/

Headers:openid.server = http://provider.com/a.cgiopenid.delegate = http://provider.com/a.cgi

Identity Page

Page 7: OpenID Protocol Explained

Browser(User-Agent)

Desired Site(OpenID Consumer)

(Relying Party)

Send redirect

I am waiting

http://provider.com/a.cgi

Parameters:openid.mode = checkid_setupopenid.identity = http://alex.provider.com/openid.return_to = http://bigbank.com/...

OpenIDProvider

Page 8: OpenID Protocol Explained

Browser(User-Agent)

Desired Site(OpenID Consumer)

(Relying Party)

Send redirect

I am waiting

Additional Parameters:openid.mode = id_resopenid.identity = http://alex.provider.com/openid.return_to = http://bigbank.com/... openid.signed = mode,identity,return_toopenid.assoc_handle = XXXXXopenid.sig = YYYYY

http://bigbank.com/...

OpenIDProvider

Page 9: OpenID Protocol Explained

Browser(User-Agent)

Desired Site(OpenID Consumer)

(Relying Party)

I am waiting

Same parameters as request exceptopenid.mode = check_authentication

Response in body: is_valid:true

OpenIDProvider

Page 10: OpenID Protocol Explained

Browser(User-Agent)

Desired Site(OpenID Consumer)

(Relying Party)

Big BankYou are logged in!What would you like to do?

OK! Now I canget things done.

OpenIDProvider

Identity Page

Finally … generatepage for display