SlideShare a Scribd company logo
Director	
  of	
  Security	
  
Prabath	
  Siriwardena	
  
Bring	
  Your	
  Own	
  
Iden5ty	
  (BYOID)	
  with	
  
WSO2	
  Iden5ty	
  Server	
  
April	
  23,	
  2014	
  
2	
  
About	
  WSO2	
  
๏  Global	
  enterprise,	
  founded	
  in	
  2005	
  by	
  
acknowledged	
  leaders	
  in	
  XML,	
  web	
  
services	
  	
  technologies,	
  standards	
  	
  and	
  
open	
  source	
  
๏  Provides	
  only	
  open	
  source	
  plaKorm-­‐as-­‐
a-­‐service	
  for	
  private,	
  public	
  and	
  hybrid	
  
cloud	
  deployments	
  
๏  All	
  WSO2	
  products	
  are	
  100%	
  open	
  
source	
  and	
  released	
  under	
  the	
  Apache	
  
License	
  Version	
  2.0.	
  
๏  Is	
  an	
  Ac5ve	
  Member	
  of	
  OASIS,	
  Cloud	
  
Security	
  Alliance,	
  OSGi	
  Alliance,	
  AMQP	
  
Working	
  Group,	
  OpenID	
  Founda5on	
  
and	
  W3C.	
  
๏  Driven	
  by	
  Innova5on	
  
๏  Launched	
  first	
  open	
  source	
  API	
  
Management	
  solu5on	
  in	
  2012	
  
๏  Launched	
  App	
  Factory	
  in	
  2Q	
  2013	
  
๏  Launched	
  Enterprise	
  Store	
  and	
  
first	
  open	
  source	
  Mobile	
  solu5on	
  
in	
  4Q	
  2013	
  
3	
  
What	
  WSO2	
  delivers	
  
4	
  
5	
  
Gartner	
  predicts,	
  by	
  the	
  end	
  of	
  2015,	
  50%	
  of	
  all	
  
new	
  retail	
  customer	
  iden<<es	
  will	
  be	
  based	
  on	
  
social	
  network	
  iden<<es.	
  	
  
6	
  
Facebook	
  is	
  only	
  second	
  to	
  China	
  and	
  India	
  in	
  terms	
  of	
  
its	
  user	
  base.	
  
7	
  
Facebook	
  vs.	
  Internet	
  User	
  vs.	
  World	
  Popula<on	
  
8	
  
9	
  
Facebook vs. China vs. India
10	
  
Enterprise Identity ßà Social Identity
IT	
  consumeriza<on	
  is	
  an	
  emerging	
  topic	
  or	
  trend	
  for	
  
last	
  few	
  years.	
  
11	
  
The	
  ini<al	
  consumeriza<on	
  hype	
  was	
  focused	
  on	
  the	
  
bring	
  your	
  own	
  device	
  (BYOD)	
  trend.	
  
	
  
12	
  
13	
  
Bring	
  Your	
  Own	
  Device	
  (BYOD)	
  	
  
à	
  	
  
Bring	
  Your	
  Own	
  Iden<ty	
  
(BYOID)	
  
The	
  rise	
  of	
  BYOID	
  is	
  being	
  driven	
  by	
  users'	
  "iden<ty	
  
fa<gue”.	
  
14	
  
 The	
  analyst	
  firm	
  Quocirca	
  confirms	
  that	
  in	
  Europe	
  58	
  
percent	
  transact	
  directly	
  with	
  users	
  from	
  other	
  businesses	
  
and/or	
  consumers;	
  for	
  the	
  UK	
  alone	
  the	
  figure	
  is	
  65	
  
percent.	
  
15	
  
In	
  U.S	
  only,	
  	
  mergers	
  and	
  acquisi<ons	
  volume	
  totaled	
  to	
  
$865.1	
  billion	
  in	
  the	
  first	
  nine	
  months	
  of	
  2013,	
  
according	
  to	
  Dealogic.	
  
16	
  
17	
  
What drives BYOID?
SAML	
  2.0	
  /	
  OpenID	
  /	
  OAuth	
  2.0	
  /	
  OpenID	
  Connect	
  
18	
  
SAML	
  1.0	
  à	
  Nov	
  2002	
  |	
  SAML	
  1.1	
  à	
  Sept	
  2003	
  |	
  SAML	
  
2.0	
  à	
  2005	
  
	
  
19	
  
OpenID	
  was	
  ini<ated	
  by	
  the	
  founder	
  of	
  LiveJournal,	
  
Brad	
  Fitzpatrick.	
  
20	
  
By	
  the	
  end	
  of	
  2009	
  –	
  there	
  were	
  more	
  than	
  one	
  billion	
  
OpenID	
  accounts.	
  
	
  
21	
  
OpenID	
  started	
  to	
  fade	
  due	
  to	
  OAuth	
  2.0	
  and	
  OpenID	
  
Connect.	
  
	
  
22	
  
OpenID	
  Connect	
  is	
  a	
  profile	
  built	
  on	
  top	
  OAuth	
  2.0.	
  
	
  
23	
  
OAuth	
  is	
  not	
  about	
  authen<ca<on	
  –	
  but,	
  delegated	
  
authoriza<on.	
  	
  
	
  
24	
  
The	
  standard	
  based	
  iden<ty	
  federa<on	
  is	
  the	
  entry	
  
point	
  to	
  BYOID.	
  
25	
  
Internet	
  Iden<ty	
  always	
  -­‐	
  has	
  an	
  unsolved	
  problem	
  
	
  
26	
  
SAML	
  2.0	
  dominated	
  Iden<ty	
  Federa<on	
  in	
  last	
  decade	
  
–	
  OpenID	
  Connect	
  and	
  JWT	
  possibly	
  lead	
  the	
  next.	
  
	
  
27	
  
Any	
  iden<ty	
  management	
  system	
  to	
  qualify	
  to	
  
support	
  BYOID	
  -­‐	
  should	
  simply	
  go	
  beyond	
  standard	
  
support	
  for	
  Iden<ty	
  Federa<on	
  protocols.	
  
	
  
28	
  
How	
  would	
  you	
  mediate,	
  transform	
  iden<ty	
  tokens	
  
between	
  different	
  standards	
  or	
  protocols	
  ?	
  
29	
  
WSO2	
  Iden<ty	
  Server	
  is	
  an	
  open	
  source	
  Iden<ty	
  and	
  
En<tlement	
  management	
  server,	
  which	
  supports	
  SAML	
  
2.0,	
  OpenID,	
  OAuth	
  2.0,	
  OpenID	
  Connect,	
  XACML	
  3.0,	
  
SCIM,	
  WS-­‐Federa<on	
  (passive)	
  and	
  many	
  other	
  iden<ty	
  
federa<on	
  palerns.	
  
	
  
30	
  
31	
  
Operators	

ServiceProviders
32	
  
Operators	

ServiceProviders	

SAML 2.0	

OpenID Connect / SAML 2.0	

OpenIDConnect	

OpenIDConnect
33	
  
SAML 2.0	

OpenID Connect / SAML 2.0
34	
  
SAML 2.0	

SAML 2.0	

SAML 2.0	

SAML 2.0
35	
  
Operators	

ServiceProviders
36	
  
1	

 Scenario - 1
http://ebuy.federationdemo.com:9766/ebuy/
37	
  
2	

OpenID Connect	

Request	

Scenario - 1
1502808989
38	
  
3	

OpenID Connect	

Request	

Scenario - 1
39	
  
4	

< credentials >	

Scenario - 1
User : tom_imobile	

Password: tom_imobile
40	
  
4	

 Scenario - 1
41	
  
5	

OpenID Connect	

Response	

Scenario - 1
42	
  
6	

OpenID Connect	

Response	

Scenario - 1
43	
  
7	

 Scenario - 1
44	
  
1	

 Scenario - 2
http://azone.federationdemo.com:9766/azone/
9477808989
45	
  
2	

OpenID Connect 	

Request	

Scenario - 2
46	
  
3	

SAML2.0 Request	

Scenario - 2
47	
  
3	

OAuth 2.0	

Scenario - 2
48	
  
4	

< credentials >	

Scenario - 2
49	
  
4	

OAuth 2.0 response	

Scenario - 2
50	
  
5	

SAML2 Response	

Scenario - 2
51	
  
6	

OpenID Connect	

Response	

Scenario - 2
52	
  
7	

 Scenario - 2
53	
  
Business	
  Model	
  
Contact	
  us	
  !	
  

More Related Content

PDF
WSO2 Identity Server
PDF
Single sign on using WSO2 identity server
PPTX
WSO2 - Identity Server & API Manager - TeamOpenBravo - IF4050
PPTX
WSO2 Identity Server 5.3.0 - Product Release Webinar
PDF
SSO with the WSO2 Identity Server
PDF
Federation in Practice
PPTX
A CONTEMPLATION OF OPENIG DEEP THOUGHTS
PDF
Access control patterns
WSO2 Identity Server
Single sign on using WSO2 identity server
WSO2 - Identity Server & API Manager - TeamOpenBravo - IF4050
WSO2 Identity Server 5.3.0 - Product Release Webinar
SSO with the WSO2 Identity Server
Federation in Practice
A CONTEMPLATION OF OPENIG DEEP THOUGHTS
Access control patterns

What's hot (20)

PPTX
OpenIG Webinar: Your Swiss Army Knife for Protecting and Securing Web Apps, A...
PPTX
OpenAM - An Introduction
PPT
Incredible Edible Identity
PPTX
Directory Services with the ForgeRock Identity Platform - So What’s New?
PDF
OpenAM Best Practices - Corelio Media Case Study
PPTX
WSO2 Product Release Webinar: WSO2 Identity Server 5.2.0
PPTX
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting
PDF
The Future is Now: What’s New in ForgeRock Access Management
PPTX
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
PDF
Implementing WebAuthn & FAPI supports on Keycloak
PPTX
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
PPTX
Identity Management with the ForgeRock Identity Platform - So What’s New?
PPTX
OpenID Connect and Single Sign-On for Beginners
PDF
Shoot Me a Token: OpenAM as an OAuth2 Provider
PPTX
Identity Management for Web Application Developers
PDF
Implementing eGov
PDF
WSO2 Identity Server - Product Overview
PPTX
OpenAM: An Introduction
PPT
Open Identity Stack Roadmap
PDF
Technical Case Study: McKesson - Employing the Open Identity Stack
OpenIG Webinar: Your Swiss Army Knife for Protecting and Securing Web Apps, A...
OpenAM - An Introduction
Incredible Edible Identity
Directory Services with the ForgeRock Identity Platform - So What’s New?
OpenAM Best Practices - Corelio Media Case Study
WSO2 Product Release Webinar: WSO2 Identity Server 5.2.0
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting
The Future is Now: What’s New in ForgeRock Access Management
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
Implementing WebAuthn & FAPI supports on Keycloak
IDP Proxy Concept: Accessing Identity Data Sources Everywhere!
Identity Management with the ForgeRock Identity Platform - So What’s New?
OpenID Connect and Single Sign-On for Beginners
Shoot Me a Token: OpenAM as an OAuth2 Provider
Identity Management for Web Application Developers
Implementing eGov
WSO2 Identity Server - Product Overview
OpenAM: An Introduction
Open Identity Stack Roadmap
Technical Case Study: McKesson - Employing the Open Identity Stack
Ad

Viewers also liked (20)

PDF
Enterprise Single Sign On
PDF
OpenID Connect - An Emperor or Just New Cloths?
PPTX
Webinar: OpenAM 12.0 - New Featurs
PDF
Cloud Identity Webinar
PPTX
WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade
PPTX
Open Source Middleware for the Cloud: WSO2 Stratos
PDF
OpenID Connect Explained
PDF
OpenID Authentication by example
PDF
End-to-End Identity Management
PDF
WSO2Con ASIA 2016: WSO2 Cloud Strategy Update
PDF
Introduction to OpenID Connect
PPTX
OpenID Connect: An Overview
PPTX
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
PDF
2016 Year End Webinar - Are You Ready for Digital Transformation?
PDF
WSO2Con USA 2017: Hybrid Cloud and Container Architecture with Zero Touch Aut...
PDF
WSO2Con USA 2017: Cloud as a Delivery Channel
PPTX
Securing your APIs with OAuth, OpenID, and OpenID Connect
PDF
WSO2Con USA 2017: Journey of Migration from Legacy ESB to Modern WSO2 ESB Pla...
PPTX
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...
PDF
Are ESBs Relevant in the Age of Microservices?
Enterprise Single Sign On
OpenID Connect - An Emperor or Just New Cloths?
Webinar: OpenAM 12.0 - New Featurs
Cloud Identity Webinar
WSO2Con EU 2015: WSO2 Identity Server: Identity Management for the Next Decade
Open Source Middleware for the Cloud: WSO2 Stratos
OpenID Connect Explained
OpenID Authentication by example
End-to-End Identity Management
WSO2Con ASIA 2016: WSO2 Cloud Strategy Update
Introduction to OpenID Connect
OpenID Connect: An Overview
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
2016 Year End Webinar - Are You Ready for Digital Transformation?
WSO2Con USA 2017: Hybrid Cloud and Container Architecture with Zero Touch Aut...
WSO2Con USA 2017: Cloud as a Delivery Channel
Securing your APIs with OAuth, OpenID, and OpenID Connect
WSO2Con USA 2017: Journey of Migration from Legacy ESB to Modern WSO2 ESB Pla...
WSO2Con USA 2017: Multi-tenanted, Role-based Identity & Access Management sol...
Are ESBs Relevant in the Age of Microservices?
Ad

Similar to Bring your own Identity (BYOID) with WSO2 Identity Server (20)

PDF
WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges
PDF
The “I” in API is for Identity (Nordic APIS April 2014)
PDF
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
PPTX
Lecture 20101124
PPTX
WSO2Con USA 2014 - Identity Server Tutorial
PDF
Open Standards in Identity Management
PDF
[WSO2Con USA 2018] Identity APIs is the New Black
PPT
Identity 2.0 and User-Centric Identity
PDF
[WSO2Con EU 2018] Identity APIs is the New Black
PDF
WSO2Con ASIA 2016: Case Study: Identity in the WSO2 Ecosystem
PDF
The Future of Digital IAM
PPTX
IAM Overview Identiverse 2018
PPTX
Configuring Single Sign-On (SSO) via Identity Management | MuleSoft Mysore Me...
PDF
Patterns to Bring Enterprise and Social Identity to the Cloud
PPTX
Synergies across APIs and IAM
PPT
OpenID Progress EEMA Conference
PDF
Who’s Knocking? Identity for APIs, Web and Mobile
PDF
O Dell Secure360 Presentation5 12 10b
PDF
OpenID Connect "101" Introduction -- October 23, 2018
PDF
JDD2015: Security in the era of modern applications and services - Bolesław D...
WSO2Con Asia 2014 - Bring Your Own IDentity (BYOID) Benefits and Challenges
The “I” in API is for Identity (Nordic APIS April 2014)
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Lecture 20101124
WSO2Con USA 2014 - Identity Server Tutorial
Open Standards in Identity Management
[WSO2Con USA 2018] Identity APIs is the New Black
Identity 2.0 and User-Centric Identity
[WSO2Con EU 2018] Identity APIs is the New Black
WSO2Con ASIA 2016: Case Study: Identity in the WSO2 Ecosystem
The Future of Digital IAM
IAM Overview Identiverse 2018
Configuring Single Sign-On (SSO) via Identity Management | MuleSoft Mysore Me...
Patterns to Bring Enterprise and Social Identity to the Cloud
Synergies across APIs and IAM
OpenID Progress EEMA Conference
Who’s Knocking? Identity for APIs, Web and Mobile
O Dell Secure360 Presentation5 12 10b
OpenID Connect "101" Introduction -- October 23, 2018
JDD2015: Security in the era of modern applications and services - Bolesław D...

More from WSO2 (20)

PDF
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
PDF
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
PDF
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
PDF
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
PDF
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
PDF
Platformless Modernization with Choreo.pdf
PDF
Application Modernization with Choreo for the BFSI Sector
PDF
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
PDF
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
PPTX
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
PPTX
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
PPTX
WSO2Con 2025 - Building Secure Customer Experience Apps
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
PPTX
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
PPTX
WSO2Con 2025 - Architecting Cloud-Native Applications
PDF
Mastering Intelligent Digital Experiences with Platformless Modernization
PDF
Accelerate Enterprise Software Engineering with Platformless
PDF
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
Platformless Modernization with Choreo.pdf
Application Modernization with Choreo for the BFSI Sector
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - Architecting Cloud-Native Applications
Mastering Intelligent Digital Experiences with Platformless Modernization
Accelerate Enterprise Software Engineering with Platformless
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation

Recently uploaded (20)

PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Spectroscopy.pptx food analysis technology
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPT
Teaching material agriculture food technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
MIND Revenue Release Quarter 2 2025 Press Release
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
MYSQL Presentation for SQL database connectivity
Network Security Unit 5.pdf for BCA BBA.
Spectroscopy.pptx food analysis technology
Review of recent advances in non-invasive hemoglobin estimation
Teaching material agriculture food technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Unlocking AI with Model Context Protocol (MCP)
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Encapsulation theory and applications.pdf
Spectral efficient network and resource selection model in 5G networks
Advanced methodologies resolving dimensionality complications for autism neur...
“AI and Expert System Decision Support & Business Intelligence Systems”
Reach Out and Touch Someone: Haptics and Empathic Computing
The AUB Centre for AI in Media Proposal.docx
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Mobile App Security Testing_ A Comprehensive Guide.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm

Bring your own Identity (BYOID) with WSO2 Identity Server