OpenID Specification Work UpdateOpenID Retail Summit – March 8, 2011Mike Jones – Microsoft
Spec Work OngoingExisting OpenID 2.0 specifications in use nowAlready work fine for many use casesActive working occurring to extend specifications for new use casesMobile phones and other limited platforms“Facebook Connect” style functionality for easy registrationEasier deployment than OpenID 2.0
Working GroupSpec work occurring in “Artifact Binding” working groupIncorporates submissions to former “Connect” working groupMerger sometimes called “OpenID ABC”Almost certainly not final branding!OpenID specs developed via an open processAll free to participate
WG ParticipantsKey working group participants:Nat Sakimura – Nippon Research Institute – JapanJohn Bradley – Independent – ChileBreno de Medeiros – Google – USPaul Tarjan – Facebook – USAxel Nennker – Deutsche Telekom – GermanyKick Willemse – Independent – NetherlandsTony Nadalin – Microsoft – USMike Jones – Microsoft – USBy no means an exhaustive list!
New Spec Building BlocksBuild on OAuth 2.0Use JavaScript Object Notation (JSON)JSON Web Token (JWT) claims representationGoal:  Easy implementation on all modern web platforms
Spec StructureOpenID AB spec contains in two partsCore – abstract specificationBinding – OAuth 2 based bindingJSON Web Token (JWT) spec with signingNext version will add encryptionOther specs like UMA are looking to adopt itDiscovery a separate specWill refer to OAuth 2.0 specs once finished
Spec ProgressCurrent statusCore – 70% doneBindings – 75% done  (pending OAuth 2.0 completion)Discovery – 80% (working from SWD)JWT – 90% done for tokens and signatureEncryption remains to be specifiedOAuth 2.0 – 95%Target:  Complete drafts by Internet Identity Workshop (IIW) in May
Implementation StatusOpenID ABCDemo version of core and artifact binding available in PHP (BitBucket)Code needs updates for current JWT and yesterday’s spec resultsJSON Web Token (JWT)Implementations for Java, PHP, Python, Ruby, .NET
ABC CapabilitiesArtifact BindingUserInfo EndpointSimple RPsHigher LoASession ManagementUnregistered ClientsOAuth 2 IntegrationUse of JWTsSingle Logout
Open Spec IssuesKinds of identifiers are supportedHarmonization with OAuth 2Permissioning distributed attribute providersClaims specification and integrationTrust metadata formats and transports
IdentifiersNeed to define the supported formats and normalization rulesE-mail Addresshttp/https URLPhone Number?
Use of SummitsMay IIW : Review drafts, make remaining decisionsMunich:  Brief participants on progress, specs - gather inputTokyo:  Test implementations; learn from implementation and deployment experiencesColorado:  Interop work – potentially in cooperation with OSISLondon:  Brief participants on progress, specs - gather inputNov IIW:  Spec refinement and/or finalization
Discussion & ResourcesArtifact Binding Working Group Wiki Pagehttp://wiki.openid.net/w/page/12995134/Artifact-BindingArtifact Binding Mailing Listhttp://lists.openid.net/mailman/listinfo/openid-specs-abMy blog:http://self-issued.info/

More Related Content

PDF
Semantic Search with Infolution - White paper by Ruud van der Pol (Infolution)
PPTX
OpenID Foundation iGov Working Group Update - October 22, 2018
PPTX
Kodak - OpenID Retail Summit at PayPal
PPTX
UsingMiles - OpenID Retail Summit at PayPal
PPTX
MDM/MAM/MIM Workshop - CIS 2013
PPTX
Mobile Devices in the Enterprise: What IT needs to know
PPTX
PayPal OpenID User Experience
PPTX
CIS 2015 Mobile SSO
Semantic Search with Infolution - White paper by Ruud van der Pol (Infolution)
OpenID Foundation iGov Working Group Update - October 22, 2018
Kodak - OpenID Retail Summit at PayPal
UsingMiles - OpenID Retail Summit at PayPal
MDM/MAM/MIM Workshop - CIS 2013
Mobile Devices in the Enterprise: What IT needs to know
PayPal OpenID User Experience
CIS 2015 Mobile SSO

Similar to Spec Update - OpenID Retail Summit at PayPal (20)

PDF
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
PPT
OpenID Progress EEMA Conference
PDF
Maker of Things - the open IoT cloud for makers chapter.
PDF
OpenID Foundation Connect Working Group Update - October 22, 2018
PDF
OpenID Connect "101" Introduction -- October 23, 2018
PPTX
Open id specifications_work_update-tokyo_2011
PPT
WS-* Specifications Update 2007
PPT
Microsoft .Net Framework 2 0
PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
DOCX
SachinBC_Resume
PPT
Mule tcat server
PPT
Mule anypoint connector dev kit
PPT
Mule anypoint connector
PDF
OpenID for SSI
PDF
Resin.io overview (2016 July)
PPT
FIWARE IoT Proposal & Community
PDF
Using Node-RED for building IoT workflows
PDF
Light-up-your-out-of-the-box LightSwitch Application
DOCX
jimnresumesse
PDF
The WebKit project (LinuxCon North America 2012)
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Progress EEMA Conference
Maker of Things - the open IoT cloud for makers chapter.
OpenID Foundation Connect Working Group Update - October 22, 2018
OpenID Connect "101" Introduction -- October 23, 2018
Open id specifications_work_update-tokyo_2011
WS-* Specifications Update 2007
Microsoft .Net Framework 2 0
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
SachinBC_Resume
Mule tcat server
Mule anypoint connector dev kit
Mule anypoint connector
OpenID for SSI
Resin.io overview (2016 July)
FIWARE IoT Proposal & Community
Using Node-RED for building IoT workflows
Light-up-your-out-of-the-box LightSwitch Application
jimnresumesse
The WebKit project (LinuxCon North America 2012)
Ad

More from Ashish Jain (11)

PPTX
Mobile SSO using NAPPS
PPTX
Angies List - OpenID Retail Summit at PayPal
PPTX
eBay - OpenID Retail Summit at PayPal
PPTX
OpenID Retail Summit at PayPal - PayPal Identity
PPTX
PayPal Identity Services - Innovate 2010
PPTX
Open Id Summit
PPTX
Say no to Bottled water
PPT
Open ID Security Issues
PPT
Consumer Privacy
PPT
Identity Enabling Web Services
PPT
Concordia
Mobile SSO using NAPPS
Angies List - OpenID Retail Summit at PayPal
eBay - OpenID Retail Summit at PayPal
OpenID Retail Summit at PayPal - PayPal Identity
PayPal Identity Services - Innovate 2010
Open Id Summit
Say no to Bottled water
Open ID Security Issues
Consumer Privacy
Identity Enabling Web Services
Concordia
Ad

Recently uploaded (20)

PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPTX
Tartificialntelligence_presentation.pptx
PDF
Five Habits of High-Impact Board Members
PPTX
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
STKI Israel Market Study 2025 version august
PPTX
Benefits of Physical activity for teenagers.pptx
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PDF
Getting Started with Data Integration: FME Form 101
PDF
Hybrid model detection and classification of lung cancer
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
A review of recent deep learning applications in wood surface defect identifi...
PDF
August Patch Tuesday
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PPTX
Chapter 5: Probability Theory and Statistics
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PPTX
O2C Customer Invoices to Receipt V15A.pptx
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PPT
Geologic Time for studying geology for geologist
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Tartificialntelligence_presentation.pptx
Five Habits of High-Impact Board Members
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
1 - Historical Antecedents, Social Consideration.pdf
STKI Israel Market Study 2025 version august
Benefits of Physical activity for teenagers.pptx
Assigned Numbers - 2025 - Bluetooth® Document
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
Getting Started with Data Integration: FME Form 101
Hybrid model detection and classification of lung cancer
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
A review of recent deep learning applications in wood surface defect identifi...
August Patch Tuesday
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Chapter 5: Probability Theory and Statistics
Univ-Connecticut-ChatGPT-Presentaion.pdf
O2C Customer Invoices to Receipt V15A.pptx
sustainability-14-14877-v2.pddhzftheheeeee
Geologic Time for studying geology for geologist

Spec Update - OpenID Retail Summit at PayPal

  • 1. OpenID Specification Work UpdateOpenID Retail Summit – March 8, 2011Mike Jones – Microsoft
  • 2. Spec Work OngoingExisting OpenID 2.0 specifications in use nowAlready work fine for many use casesActive working occurring to extend specifications for new use casesMobile phones and other limited platforms“Facebook Connect” style functionality for easy registrationEasier deployment than OpenID 2.0
  • 3. Working GroupSpec work occurring in “Artifact Binding” working groupIncorporates submissions to former “Connect” working groupMerger sometimes called “OpenID ABC”Almost certainly not final branding!OpenID specs developed via an open processAll free to participate
  • 4. WG ParticipantsKey working group participants:Nat Sakimura – Nippon Research Institute – JapanJohn Bradley – Independent – ChileBreno de Medeiros – Google – USPaul Tarjan – Facebook – USAxel Nennker – Deutsche Telekom – GermanyKick Willemse – Independent – NetherlandsTony Nadalin – Microsoft – USMike Jones – Microsoft – USBy no means an exhaustive list!
  • 5. New Spec Building BlocksBuild on OAuth 2.0Use JavaScript Object Notation (JSON)JSON Web Token (JWT) claims representationGoal: Easy implementation on all modern web platforms
  • 6. Spec StructureOpenID AB spec contains in two partsCore – abstract specificationBinding – OAuth 2 based bindingJSON Web Token (JWT) spec with signingNext version will add encryptionOther specs like UMA are looking to adopt itDiscovery a separate specWill refer to OAuth 2.0 specs once finished
  • 7. Spec ProgressCurrent statusCore – 70% doneBindings – 75% done (pending OAuth 2.0 completion)Discovery – 80% (working from SWD)JWT – 90% done for tokens and signatureEncryption remains to be specifiedOAuth 2.0 – 95%Target: Complete drafts by Internet Identity Workshop (IIW) in May
  • 8. Implementation StatusOpenID ABCDemo version of core and artifact binding available in PHP (BitBucket)Code needs updates for current JWT and yesterday’s spec resultsJSON Web Token (JWT)Implementations for Java, PHP, Python, Ruby, .NET
  • 9. ABC CapabilitiesArtifact BindingUserInfo EndpointSimple RPsHigher LoASession ManagementUnregistered ClientsOAuth 2 IntegrationUse of JWTsSingle Logout
  • 10. Open Spec IssuesKinds of identifiers are supportedHarmonization with OAuth 2Permissioning distributed attribute providersClaims specification and integrationTrust metadata formats and transports
  • 11. IdentifiersNeed to define the supported formats and normalization rulesE-mail Addresshttp/https URLPhone Number?
  • 12. Use of SummitsMay IIW : Review drafts, make remaining decisionsMunich:  Brief participants on progress, specs - gather inputTokyo:  Test implementations; learn from implementation and deployment experiencesColorado:  Interop work – potentially in cooperation with OSISLondon:  Brief participants on progress, specs - gather inputNov IIW:  Spec refinement and/or finalization
  • 13. Discussion & ResourcesArtifact Binding Working Group Wiki Pagehttp://wiki.openid.net/w/page/12995134/Artifact-BindingArtifact Binding Mailing Listhttp://lists.openid.net/mailman/listinfo/openid-specs-abMy blog:http://self-issued.info/