Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

25
© 2016 ForgeRock. All rights reserved. Identity: The Future's So Bright, I Gotta Wear Shades Daniel Raskin, SVP Product Management Allan Foster, VP Global Partner Enablement Sydney Identity Summit

Transcript of Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

Page 1: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Identity: The Future's So Bright, I Gotta Wear

ShadesDaniel Raskin, SVP Product Management

Allan Foster, VP Global Partner EnablementSydney Identity Summit

Page 2: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Relationship Management

Page 3: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Identity

Users

Page 4: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Identity

Identity

Identity

Identity

Identity

Identity

Identity

Identity

Identity

Identity

Identity

Identity

Users, Devices, Things & Services

Page 5: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Identity Management Evolves to Relationship Management

Identity Lifecycle Management Users, Devices, Things & Services

Page 6: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Contextual Identity

Page 7: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Contextual SecurityTaking Safety to the Next Level

Passwordless Authentication

Register Device for First Time

Authorise consent child purchase

Authorise family members to use account

Authorise Data to Device / Thing

Page 8: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Did you just request to transfer $1,000,000.

Taro is trying to purchase Footloose on Amazon .

Is that ok?

Kayoko is requesting access to your car

Are you trying to open your front door?

We noticed you are accessing our service on a iPhone. Would you like to register this device?

Would you like to authorise purchasing Showtime on your Samsung TV?

Contextual IdentityEnriching the Experience

Page 9: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Contextual IdentityAuthentication, Authorisation and Consent

User Managed Access

Sharing X-Ray with Doctor

Page 10: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

MicroservicesArchitecture

Page 11: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

SOA is Dead, but Services on the Rise!

1990s and EarlyPre-SOA

Monolith to change

2000sTraditional SOA

Autonomous but coordinated

PresentMicroservices

Decoupled and Independent

PWC, Agile coding in enterprise IT: Code small and local

Page 12: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Service to Service InteractionAuthentication, Authorisation and Consent

https://api.telstra.com/v1/mobileconnect/userinfo

Authenticate API Authorise API Calls Authenticate API

Page 13: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Scaling to Support Distributed Cloud ArchsStateless Architecture

• Flexible deployment option to address cloud elasticity and massive horizontal scalability

• Configuration can be on a per-realm basis

• Stateless = state information is encoded in JWT token

• Stateful = tokens persisted in the Core Token Service

OpenAM Server

OpenAM Server

OpenAM Server

AWS1 AWS2 AWS3

Microservices Client App

Distributed Cloud Environment

Page 14: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

CloudReadiness

Page 15: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Hybrid Cloud – One Cloud Many Pieces

Page 16: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

The Cloud Conundrum

No Portability! Identity Baked in and Constrained to Each Cloud!

Page 17: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

OAuth2/OIDC OAuth2/OIDC OAuth2/OIDC OAuth2

The Abstraction of Identity … Again

Page 18: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Cloud Automation

Page 19: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Cloud Native: Cattle versus Pets

Page 20: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Cloud Native: Cattle versus Pets

Cattle• Cattle are numbers• They are almost identical• When ill, get another (Kill it!)• Thousands of cattle on farm

Pets• Pets have names like “pussnboots”• They are lovingly hand raised• When ill, nursed back to health• 1 or 2 pets in house

Elastic Inelastic

Page 21: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Container Management & Deployment

ProductConfiguration

ProductManifests

ForgeRock Images

JavaImage

TomcatImage

Other Images

DOCKER REPOSITORY

Page 22: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

PlatformUbiquity

Page 23: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

We Must Be Better

Authentication Authorization Multi-Factor Adaptive Risk Self Service Directory API Security GRC …

Page 24: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Unified Platform

UMA Provider Mobile OTP App Synchronization Auditing

LDAPv3 REST/JSON

Replication Access Control

Schema Management

Caching

Auditing

Monitoring

Groups

Password Policy

Active Directory Pass-

thru

Reporting

Authentication Authorization Provisioning User Self-Service Authentication OIDC / OAuth2

Federation / SSO User Self-Service Workflow Engine Reconciliation Password Replay SAML2

Adaptive Risk Stateless/Stateful Registration Role Provisioning Message Transformation

API Security Scripting

Built from Open Source Projects:

UMA Resource

Access Management Identity Management Identity Gateway

Directory Services

Com

mon

RES

T AP

I

Com

mon

Use

r Int

erfa

ce

Com

mon

Aud

it/Lo

ggin

g

Com

mon

Scr

iptin

g

Page 25: Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades

© 2016 ForgeRock. All rights reserved.

Identity Relationship Management: Talkin’ Bout a Revolution

Relationship Management

CloudAutomation

CloudReadiness

PlatformUbiquity

MicroservicesArchitecture

Contextual Identity