SlideShare a Scribd company logo
Single Sign‐On for Mobile 
                                  Simplify Secure Mobile App Access to Enterprise Resources 


         Layer 7’s solution for mobile Single  
           Sign‐On (SSO) provides mobile 
        enterprise applications with a secure 
            method of authenticating and 
          authorizing users against existing 
          enterprise identity management 
        infrastructure. The solution includes 
         SDKs for most common platforms, 
             including Android and iOS. 

                                                                                                                                                    
                                                                The Challenge: Secure Mobile Access to the Enterprise 
Learn More About Layer 7’s Mobile 
                                                                Identity and authentication assurance needs to be balanced against the 
Access Solutions 
                                                                assets in use. When mobile apps leverage enterprise data and services, 
            Phone 
                                                                the risk of security being compromised is increased. The cost goes 
             +1‐800‐681‐9377  
             (toll free within North America)  
                                                                beyond a tarnished brand name – breaches can put a business at risk.   
             or +1‐604‐681‐9377 
            Email                                              The Solution: Mobile Single Sign‐On 
             info@layer7.com                                    Layer 7’s solution for mobile SSO simplifies the process through which 
            Web                                                apps require users to sign in to the enterprise. The solution leverages the 
             www.layer7.com                                     underlying security in a device’s operating system to effectively create a 
            Facebook                                           secure sign‐on container for apps. 
             www.facebook.com/layer7 
            Twitter                                            Layer 7 offers a complete end‐to‐end, standards‐based and proven 
             @layer7                                            security solution for mobile SSO. This solution uses OAuth 2.0, OpenID 
                                                                Connect and JWT standards. Communication is secured through Layer 
                                                                7’s SecureSpan Mobile Access Gateway. 
                                                                The Mobile Access Gateway is lightweight, low‐latency mobile 
                                                                middleware with integrated security and management controls designed 
                                                                to help enterprises safely and reliably expose internal assets to 
                                                                developers and remote apps, as mobile APIs.  
                                                                While the Gateway solves critical mobile‐specific identity, security, 
                                                                adaptation, optimization and integration challenges, the mobile SSO 
                                                                solution delivers SSO libraries for device developers. By providing a 
                                                                simple API consumption layer on the mobile platform, all the complex 
                                                                OAuth and OpenID Connect protocol handshakes between mobile device 
                                                                and Gateway are abstracted out. The mobile app obtains an access 
                                                                token using OAuth. The user context is shared across a group of 
                                                                applications via OpenID Connect. 
                                                                The client SDK is available for iOS and Android devices, while support for 
                                                                other platforms is planned for future releases.

                      Copyright © 2013 Layer 7 Technologies Inc. All rights reserved.  SecureSpan and the Layer 7 Technologies design mark are  
                      trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 


          
 Features & Benefits 

    Features 

                                              Flexible architecture with hooks for optional trust bootstrap via crypto material from 
    Multi‐layered approach                     external sources (SIM, OTP, CAC) 
    to mobile security                        Multifactor authentication for high assurance level protection 
                                              Policy configured per app, user or device to tailor use cases 

                                              Continuous device validation through One Time Password (OTP), for device registration 
    Validation of device  
                                              Re‐registration procedure triggered by admin or usage patterns 
    and user identity                         PKI provisioning  

    Lost device tracking                      Track device activity (failed/successful) authentications 
    and blockage from                         Track device location through GPS data or network services 
    admin portal                              Revoke access to user, device and apps from admin view 

                                              Integrate into Microsoft‐based security through Active Directory, ADFS and Claims 
    Integration with existing 
                                              Extend CA SiteMinder directory service to mobile clients 
    backend identity 
                                              Integrate with Oracle Access Management 
    management systems                        Leverage LDAP directory services for client without custom client 

    Benefits 

                                              Sign in once for all enterprise apps under the same domain 
                                              Simplify PKI‐based certificate delivery and provisioning to mobile devices 
                                              Deploy OTP for a higher assurance level  
    Mobile app security  
                                              Enable multi‐factor authentication 
                                              Integrate with HW security modules 
                                              Enable context‐based authorizations 

                                              Leverage client libraries to hide the complexity of OAuth and OpenID Connect 
    Mobile developer 
                                              Provide UI elements for user sign‐in 
    enablement                                Enable cross‐device token sharing with devices in proximity  

                                              Enhanced user experience (UX) 
                                              Minimal password typing 
    End user enablement  
                                              Consistent UI for all enterprise apps across devices  
    and best‐in‐class user                    Client‐side tooling skinned to service provider brand 
    experience                                Transparent view of authorizations 
                                              Control Center app to assist in SSO and enhanced features like cross‐device token sharing 
                                          




                                              Access grant without browser redirection for authentication 
                                              Leverage optimized tokens for mobile consumption 
    Mobile Access optimization  
                                              Ensure seamless flow of sign‐in session as user switches devices 
                                              Integrate with enterprise identity services 



To learn more about Layer 7, call us today at +1‐800‐681‐9377 (toll free within North America) or +1‐604‐681‐9377. 
You can also: email us at info@layer7.com; friend us on Facebook at facebook.com/layer7; visit us at layer7.com; 
follow us on Twitter (@layer7). 


                Copyright © 2013 Layer 7 Technologies Inc. All rights reserved.  SecureSpan and the Layer 7 Technologies design mark are  
                trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 

More Related Content

PDF
Enable Secure Mobile & Web Access to Microsoft SharePoint
PDF
OAuth in the Real World featuring Webshell
PPTX
Trends in Web APIs Layer 7 API Management Workshop London
PPTX
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
PDF
Adapting to Digital Change: Use APIs to Delight Customers & Win
PDF
5 Steps for End-to-End Mobile Security with Consumer Apps
PDF
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
PPTX
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Enable Secure Mobile & Web Access to Microsoft SharePoint
OAuth in the Real World featuring Webshell
Trends in Web APIs Layer 7 API Management Workshop London
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
Adapting to Digital Change: Use APIs to Delight Customers & Win
5 Steps for End-to-End Mobile Security with Consumer Apps
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...

What's hot (20)

PPTX
5 Reasons Why APIs Must be Part of Your Mobile Strategy - Scott Morrison, Dis...
PDF
CA API Management: A DevOps Enabler
PDF
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
PDF
How to Choose the Right API Management Solution
PDF
CA API Gateway
PDF
5 pillars of API Management
PDF
Melbourne API Management Seminar
PDF
Mastering Digital Channels with APIs
PDF
API strategy with IBM API connect
PDF
Best Practices for API Management
PDF
Enabling the Multi-Device Universe
PPTX
A New Breed of Technical Leaders: The 101 to Defining Your API Business Stra...
PDF
Mobile Risk Analysis: Take Your Mobile App Security to the Next Level
PDF
Your New Digital Business & APIs
PDF
Design - Start Your API Journey Today
PDF
Takeaways from API Security Breaches Webinar
PDF
Enable and Secure Business Growth in the New Application Economy
PDF
apidays LIVE JAKARTA - Enterprise API management in agile integration by Ragh...
PDF
IBM API Connect - overview
PPTX
Introduction to IBM API Management
5 Reasons Why APIs Must be Part of Your Mobile Strategy - Scott Morrison, Dis...
CA API Management: A DevOps Enabler
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
How to Choose the Right API Management Solution
CA API Gateway
5 pillars of API Management
Melbourne API Management Seminar
Mastering Digital Channels with APIs
API strategy with IBM API connect
Best Practices for API Management
Enabling the Multi-Device Universe
A New Breed of Technical Leaders: The 101 to Defining Your API Business Stra...
Mobile Risk Analysis: Take Your Mobile App Security to the Next Level
Your New Digital Business & APIs
Design - Start Your API Journey Today
Takeaways from API Security Breaches Webinar
Enable and Secure Business Growth in the New Application Economy
apidays LIVE JAKARTA - Enterprise API management in agile integration by Ragh...
IBM API Connect - overview
Introduction to IBM API Management
Ad

Viewers also liked (12)

PDF
Value of SOA Governance for Cloud Computing
PDF
Not all XML Gateways are Created Equal
PDF
SSO - SIngle Sign On
PPTX
SSO introduction
PDF
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
PDF
Reusable APIs
PDF
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
PDF
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
PPTX
API Monetization: Unlock the Value of Your Data
PDF
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
PDF
Enterprise Single Sign-On - SSO
PDF
Api architectures for the modern enterprise
Value of SOA Governance for Cloud Computing
Not all XML Gateways are Created Equal
SSO - SIngle Sign On
SSO introduction
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Reusable APIs
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API Monetization: Unlock the Value of Your Data
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
Enterprise Single Sign-On - SSO
Api architectures for the modern enterprise
Ad

Similar to Single Sign-On for Mobile (20)

PDF
Entrust IdentityGuard Mobile
PPTX
Security and Mobile Application Management with Worklight
PDF
Mobile Application Security
PPT
Udløs potentialet i Enterprise Mobility, Vijay Dheap, IBM US
PDF
IBM Presentation for Mobile Developer Summit India
PDF
Mobile Enterprise Application Platform
PDF
Jerry Romanek series mobile development 2012 year end review
PDF
Mobile SSO: Give App Users a Break from Typing Passwords
PDF
Empower Enterprise Mobility with Microsoft EMS
PPTX
Con8902 developing secure mobile applications-final
PDF
SmartCard Forum 2011 - Evolution of authentication market
PPTX
ESET is introducing its brand new product ESET Secure Authentication
PDF
Entrust Enterprise Authentication
PDF
UK Innovate 2012 mobile keynote
PPT
In Today's Complex Multi Perimeter World, Are You Doing Enough to Secure Acce...
PDF
Signify Software Tokens
PDF
Signify Software Tokens
PPTX
PROACTEYE ACCESS MANAGEMENT
PPTX
The Future of Mobile Application Security
PPTX
Beyond MDM: 5 Things You Must do to Secure Mobile Devices in the Enterprise
Entrust IdentityGuard Mobile
Security and Mobile Application Management with Worklight
Mobile Application Security
Udløs potentialet i Enterprise Mobility, Vijay Dheap, IBM US
IBM Presentation for Mobile Developer Summit India
Mobile Enterprise Application Platform
Jerry Romanek series mobile development 2012 year end review
Mobile SSO: Give App Users a Break from Typing Passwords
Empower Enterprise Mobility with Microsoft EMS
Con8902 developing secure mobile applications-final
SmartCard Forum 2011 - Evolution of authentication market
ESET is introducing its brand new product ESET Secure Authentication
Entrust Enterprise Authentication
UK Innovate 2012 mobile keynote
In Today's Complex Multi Perimeter World, Are You Doing Enough to Secure Acce...
Signify Software Tokens
Signify Software Tokens
PROACTEYE ACCESS MANAGEMENT
The Future of Mobile Application Security
Beyond MDM: 5 Things You Must do to Secure Mobile Devices in the Enterprise

More from CA API Management (15)

PDF
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
PDF
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
PPTX
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
PDF
5 steps end to end security consumer apps
PPTX
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
PPTX
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
PDF
Using APIs to Create an Omni-Channel Retail Experience
PPTX
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
PDF
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
PPTX
The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...
PPTX
Is there an API in that (IoT)?
PDF
Mapping the API Landscape - Mike Amundsen, Director of API Architecture
PPTX
Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...
PPTX
Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...
PPTX
Enterprise on the Go - Devon Winkworth, Snr. Principal Consultant, Layer 7 @ ...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
5 steps end to end security consumer apps
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Using APIs to Create an Omni-Channel Retail Experience
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...
Is there an API in that (IoT)?
Mapping the API Landscape - Mike Amundsen, Director of API Architecture
Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...
Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...
Enterprise on the Go - Devon Winkworth, Snr. Principal Consultant, Layer 7 @ ...

Single Sign-On for Mobile

  • 1. Single Sign‐On for Mobile  Simplify Secure Mobile App Access to Enterprise Resources  Layer 7’s solution for mobile Single   Sign‐On (SSO) provides mobile  enterprise applications with a secure  method of authenticating and  authorizing users against existing  enterprise identity management  infrastructure. The solution includes  SDKs for most common platforms,  including Android and iOS.    The Challenge: Secure Mobile Access to the Enterprise  Learn More About Layer 7’s Mobile  Identity and authentication assurance needs to be balanced against the  Access Solutions  assets in use. When mobile apps leverage enterprise data and services,   Phone  the risk of security being compromised is increased. The cost goes  +1‐800‐681‐9377   (toll free within North America)   beyond a tarnished brand name – breaches can put a business at risk.    or +1‐604‐681‐9377   Email  The Solution: Mobile Single Sign‐On  info@layer7.com  Layer 7’s solution for mobile SSO simplifies the process through which   Web   apps require users to sign in to the enterprise. The solution leverages the  www.layer7.com  underlying security in a device’s operating system to effectively create a   Facebook      secure sign‐on container for apps.  www.facebook.com/layer7   Twitter  Layer 7 offers a complete end‐to‐end, standards‐based and proven  @layer7  security solution for mobile SSO. This solution uses OAuth 2.0, OpenID    Connect and JWT standards. Communication is secured through Layer  7’s SecureSpan Mobile Access Gateway.  The Mobile Access Gateway is lightweight, low‐latency mobile  middleware with integrated security and management controls designed  to help enterprises safely and reliably expose internal assets to  developers and remote apps, as mobile APIs.   While the Gateway solves critical mobile‐specific identity, security,  adaptation, optimization and integration challenges, the mobile SSO  solution delivers SSO libraries for device developers. By providing a  simple API consumption layer on the mobile platform, all the complex  OAuth and OpenID Connect protocol handshakes between mobile device  and Gateway are abstracted out. The mobile app obtains an access  token using OAuth. The user context is shared across a group of    applications via OpenID Connect.  The client SDK is available for iOS and Android devices, while support for  other platforms is planned for future releases. Copyright © 2013 Layer 7 Technologies Inc. All rights reserved.  SecureSpan and the Layer 7 Technologies design mark are   trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.   
  • 2.  Features & Benefits  Features   Flexible architecture with hooks for optional trust bootstrap via crypto material from  Multi‐layered approach   external sources (SIM, OTP, CAC)  to mobile security   Multifactor authentication for high assurance level protection   Policy configured per app, user or device to tailor use cases   Continuous device validation through One Time Password (OTP), for device registration  Validation of device    Re‐registration procedure triggered by admin or usage patterns  and user identity   PKI provisioning   Lost device tracking    Track device activity (failed/successful) authentications  and blockage from    Track device location through GPS data or network services  admin portal   Revoke access to user, device and apps from admin view   Integrate into Microsoft‐based security through Active Directory, ADFS and Claims  Integration with existing   Extend CA SiteMinder directory service to mobile clients  backend identity   Integrate with Oracle Access Management  management systems   Leverage LDAP directory services for client without custom client  Benefits   Sign in once for all enterprise apps under the same domain   Simplify PKI‐based certificate delivery and provisioning to mobile devices   Deploy OTP for a higher assurance level   Mobile app security    Enable multi‐factor authentication   Integrate with HW security modules   Enable context‐based authorizations   Leverage client libraries to hide the complexity of OAuth and OpenID Connect  Mobile developer   Provide UI elements for user sign‐in  enablement    Enable cross‐device token sharing with devices in proximity    Enhanced user experience (UX)   Minimal password typing  End user enablement    Consistent UI for all enterprise apps across devices   and best‐in‐class user   Client‐side tooling skinned to service provider brand  experience   Transparent view of authorizations   Control Center app to assist in SSO and enhanced features like cross‐device token sharing     Access grant without browser redirection for authentication   Leverage optimized tokens for mobile consumption  Mobile Access optimization    Ensure seamless flow of sign‐in session as user switches devices   Integrate with enterprise identity services  To learn more about Layer 7, call us today at +1‐800‐681‐9377 (toll free within North America) or +1‐604‐681‐9377.  You can also: email us at info@layer7.com; friend us on Facebook at facebook.com/layer7; visit us at layer7.com;  follow us on Twitter (@layer7).  Copyright © 2013 Layer 7 Technologies Inc. All rights reserved.  SecureSpan and the Layer 7 Technologies design mark are   trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners.