lunedì lug 19, 2010

Oracle Community for Security at Security Summit 2010

The last 10th of June (after 10 days since I've been joined at Oracle :) I've presented at Security Summit Rome 2010, where I've delivered a speech about Oracle Identity Management towards Cloud Computing. 

Security Summit is organized by CLUSIT (Italian Information Security Association) which was born based on the experiences of other European Information Security Associations such as CLUSIB (B), CLUSIF (F), CLUSIS (CH), CLUSSIL (L) to be the reference regarding Information Security.

Oracle has participated at the Security Summit (Rome 2010) through the Oracle Community for Security, managed by Alessandro Vallega (Business Development at Oracle), which goal is to create partner community on security to extend competences, and share experiences on security, including Identity Management, Data Protection, Compliance, IT Risk Management, Biometry and Strong Authentication. 

My presentation (Slideshare) has outlined how to leverage existing Identity and Access Management infrastructure, and how to extend Service-Oriented Security and standards-based interactions to successfully secure assets in the cloud.

You can find all conference proceedings here. (Don't forget photos :)

venerdì ott 16, 2009

The Cube of Identity

Next week there will be the ICT Security Forum at Rome, and I'm preparing a speech for this event about "Identity in the Cloud: what's next trust level", where I'm going to talk about how the new paradigms as Web 2.0, Software as a Service (SaaS) and cloud computing have introduced new needs related the security and the privacy of the information and how digital identity is critical and success factor to manage authentication and authorization complexity in a distributed environment, and what kind of level of assurance can be reached.

With the prospective to give to the audience an harmonized unique graphic view of the most important open identity standard technologies, I've created a Cube.

The idea to use a Cube as representation of open Identity technologies was borne when I've studied the Venn of Identity with the goal to introduce OAuth protocol in the Venn graph. Discussing with Eve Maler about this opportunity, she suggested the need to separate the front-channel from back-channel, she also mentioned that she hadn't found a way to combine OAuth with the original Venn in a way she was happy, as you can see in the her recently publishing a Venn of Identity in web Service. I thought, this can be reachable with the front-face and back-face of a Cube!!  

As you can see in the above cube picture, each front-face have a corresponding back-face (i.e. OpenID->OAuth, SAML->Id-WSF, InfoCard->WS-\*) or if you rotate (imagine) the cube you can have different prospectives (inter-enterprise/SaaS, consumer, ect.).  There are also some other interesting aspects as adjacent property, related to create an hybrid system (See bootstrapping the Identity metasystem), that is, combining or chaining systems and enabling transaction between them (i.e SAML -> OpenID, InfoCard -> ID-WSF, SAML->OAuth). Is this a magic cube of Identity? Comment it ;)

These models/systems could open interesting opportunity for the Italian National Centre for IT in Public Administration (CNIPA) which is involved in defining a National Federated Identity Management system based on SAML2.0, implementing a user-centric mechanism used to authorize and control the access to application services over SPCoop (Public Cooperative System). 

mercoledì set 17, 2008

Fedlet: la federazione fatta semplice

La Fedlet semplifica il processo di federazione dell'identità digitale. Molto spesso accade che la fase d'inizializzazione di un processo l'identità federata ed in particolare la creazione del Circle-of-Trust (tra l'Identity Provider e il Service Provider) è reso complicato dalle operazioni di installazione delle componenti applicative di federazione, dalla configurazione degli stessi e dai test d'interoperabilità. Per facilitare questo aspetto fondamentale relativo alle operazioni di amministrazione, Sun Microsystems ha inventato la Fedlet che indirizza proprio l'esigenza di semplificazione delle attività di amministrazione in fase di startup e alla creazione del COT.

La Fedlet è un implementazione "lightweight" del protocollo di Single SignOn basato SAML2 (per i Service Provider), integrabile in un'applicazione web Java EE. La Fedlet è un nuova funzione di OpenSSO (Sun Federated Access Manager).

La Fedlet è estremamente leggera, è puo essere integrata all'interno dello strato applicativo del Service Provider, e fa in modo d'interagire con l'Identity provider attraverso la specifica SAML POST profile, con il quale è possibile propagare gli attributi degli utenti che fanno parte della SAML Response del IdP, che l'IdP invia alla Fedlet dopo l'operazione di autenticazione all'Identity Provider.

Per capire quanto è semplice e veloce il processo che realizza la Fedlet vi invito a guardare questo video.


Federated Identity Management, Security, Service Oriented Architecture


« aprile 2014