SlideShare a Scribd company logo
© 2016 ForgeRock. All rights reserved.
Chris Adriaensen
Senior Customer Engineer
chris.adriaensen@forgerock.com
@chrisadriaensen | @ForgeRock
An Open Standard
for Consent-Driven
Personal Data Sharing
© 2017 ForgeRock. All rights reserved.
© 2016 ForgeRock. All rights reserved.
BUSINESS DRIVERS
TECHNOLOGY FEATURES
PRIVACY
Transparency
Visualization of
Personal Data
Smart Things
Explosion of
Personal Data
Customer
Relationship
Management
Consent
Access of
Personal Data
Regulation
Government &
Industry Bodies
Privacy Drivers & Features
© 2017 ForgeRock. All rights reserved.
2
© 2016 ForgeRock. All rights reserved.
© 2017 ForgeRock. All rights reserved.
FEATURE
Privacy Approaches
Manual
TRANSPARENCY
Request Implicit
CONSENT
ACCESS SHARINGDATA
3
© 2016 ForgeRock. All rights reserved.
Requesting PartyClientsResources AccessResource Owner
User Interface
(GUI / PUI)
Application Interface
(REST / SOAP)
User Interface
(GUI / PUI)
Application
4
Privacy Architecture
© 2017 ForgeRock. All rights reserved.
© 2016 ForgeRock. All rights reserved.
Resource Owner
User Interface
(GUI / PUI)
Requesting PartyClientsResources Access
User Interface
(GUI / PUI)
Application Interface
(REST / SOAP)
Application
5
Privacy Challenge
© 2017 ForgeRock. All rights reserved.
?
IDIDIDID
ID
ID
ID
ID
ID
?
IDIDIDID
© 2016 ForgeRock. All rights reserved.
Requesting Party
User Interface
(GUI / PUI)
Resource Owner
User Interface
(GUI / PUI)
ClientsResources Access
Application Interface
(REST / SOAP)
Application
6
Transparency Identity Solution
© 2017 ForgeRock. All rights reserved.
ID
ID
ID
ID
ID
ID
ID
ID
IdentityID
© 2016 ForgeRock. All rights reserved.
Requesting Party
User Interface
(GUI / PUI)
Resource Owner
User Interface
(GUI / PUI)
ClientsResources Access
Application Interface
(REST / SOAP)
Application
7
Consent Access Solution
© 2017 ForgeRock. All rights reserved.
ID
ID
ID
ID
ID
IDID
Access
ID
ID
Identity
© 2016 ForgeRock. All rights reserved.
© 2017 ForgeRock. All rights reserved.
FEATURE
Privacy Approaches
Manual
TRANSPARENCY
Request Implicit
CONSENT
Strategy Explicit
API’s
SSH, LDAP, SQL,
SOAP & REST
Automated
SOAP & REST
ACCESS SHARINGDATA
Portal
8
© 2016 ForgeRock. All rights reserved.
CONSUMERENTERPRISE
OASIS
9
Open Standards
© 2017 ForgeRock. All rights reserved.
IETF, OIDF & KANTARA
OIDC
Identity
Federation
UMA
Access
Federation
OAuth
Access
Control Consent
Security Scalability
Browser
Client
Generic
Client
Statefull
Design
Stateless
Design
XML /
SOAP
JSON /
REST
JWT
Identity
2000+ 2010+
SAML
Identity
Federation
XACML
Access
Federation
WS-*
Access
SAML
Identity
© 2016 ForgeRock. All rights reserved. 10
OAuth 2.0 Standard
© 2017 ForgeRock. All rights reserved.
Resource
Server
Authorization
Server
Resource
Owner
Client
Access Validate
Manage
Authorize
Control
Owner-to-App
Sharing
Synchronous
Consent
Access
Integration
Access
Tokens
© 2016 ForgeRock. All rights reserved. 11
User Managed Access Standard
© 2017 ForgeRock. All rights reserved.
Resource
Server
Authorization
Server
Requesting
Party
Client
Authorize
Access Protect
Resource
Owner
Manage Manage
Control
Negotiate
Owner-to-Party
Sharing
Asynchronous
Consent
Access
Federation
Access
Tokens
© 2016 ForgeRock. All rights reserved.
Requesting PartyClientsResources AccessResource Owner
User Interface
(GUI / PUI)
Application Interface
(REST / SOAP)
User Interface
(GUI / PUI)
Application
12
Consent Standards
© 2017 ForgeRock. All rights reserved.
OAuth 2.0
Device Flow
OAuth 2.0
A/I Grant
User Managed
Access
OpenIDConnect
© 2016 ForgeRock. All rights reserved.
© 2017 ForgeRock. All rights reserved.
FEATURE
Privacy Approaches
Manual
TRANSPARENCY
Request Implicit
CONSENT
Strategy Explicit
API’s
SSH, LDAP, SQL,
SOAP & REST
Standards
SCIM, SAML &
OpenID Connect
OAuth 2.0 &
OpenID Connect
Automated
UMA
SOAP & REST
ACCESS SHARINGDATA
Portal
13
© 2016 ForgeRock. All rights reserved. 14
SolutionChallenge
Health Care Platform
Smart Devices
Unified Identity Platform
Patient Security
Patient Privacy
Patient Satisfaction
Patient Consent
Identity of Things
Patient Relationships
Single Patient View
© 2017 ForgeRock. All rights reserved.
“We are now able to design
innovative data-sharing and
consent technologies into our
HealthSuite Digital Platform
that make it possible to foster
consumer and patient trust.”
Jeroen Tas, CEO, Healthcare
Informatics Solutions & Services
© 2016 ForgeRock. All rights reserved. 15
DEMO
Session
© 2017 ForgeRock. All rights reserved.
© 2016 ForgeRock. All rights reserved.
Chris Adriaensen
Senior Customer Engineer
chris.adriaensen@forgerock.com
@chrisadriaensen | @ForgeRock
© 2017 ForgeRock. All rights reserved.
End of
SHOW

More Related Content

PPTX
The Hitchhiker's Guide to the Land of OAuth
PPTX
Internet of Things Security & Privacy
PDF
The Future is Now: What’s New in ForgeRock Identity Management
PDF
The Future is Now: What’s New in ForgeRock Access Management
PDF
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
PDF
Sydney Identity Summit: Addressing the New Threat Landscape with Continuous S...
PDF
Sydney Identity Unconference Introduction and Highlights
PPTX
NYC Identity Summit Business Day: Continuous Security
The Hitchhiker's Guide to the Land of OAuth
Internet of Things Security & Privacy
The Future is Now: What’s New in ForgeRock Identity Management
The Future is Now: What’s New in ForgeRock Access Management
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
Sydney Identity Summit: Addressing the New Threat Landscape with Continuous S...
Sydney Identity Unconference Introduction and Highlights
NYC Identity Summit Business Day: Continuous Security

What's hot (20)

PPTX
Identity Live London 2017 | Ashley Stevenson
PDF
The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017
PDF
Beyond username and password it's continuous authorization webinar
PDF
NYC Identity Summit Tech Day: Authorization for the Modern World
PPTX
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
PPTX
NYC Identity Summit Tech Day: Best Practices for API Security
PPTX
ForgeRock Gartner 2016 Security & Risk Management Summit
PDF
ForgeRock Platform Release - Summer 2016
PDF
The Relationship Model
PDF
Internet of Things Security & Privacy
PDF
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
PPTX
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
PDF
Identity Tech Talks #3 FIDO futur of authentication
PDF
Sydney Identity Summit: Doing Authorisation, Consent and Delegation Right wit...
PPTX
Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades
PDF
Technical Case Study: McKesson - Employing the Open Identity Stack
PDF
ForgeRock: Identity Relationship Management is the Foundation for Your Digita...
PPTX
User-Managed Access: Why and How? - Access Control in Digital Contract Contexts
PDF
Web application firewall advanced
PDF
The Future of Digital Identity in the Age of the Internet of Things
Identity Live London 2017 | Ashley Stevenson
The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017
Beyond username and password it's continuous authorization webinar
NYC Identity Summit Tech Day: Authorization for the Modern World
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
NYC Identity Summit Tech Day: Best Practices for API Security
ForgeRock Gartner 2016 Security & Risk Management Summit
ForgeRock Platform Release - Summer 2016
The Relationship Model
Internet of Things Security & Privacy
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
Identity Tech Talks #3 FIDO futur of authentication
Sydney Identity Summit: Doing Authorisation, Consent and Delegation Right wit...
Sydney Identity Summit: The Future's So Bright, I Gotta Wear Shades
Technical Case Study: McKesson - Employing the Open Identity Stack
ForgeRock: Identity Relationship Management is the Foundation for Your Digita...
User-Managed Access: Why and How? - Access Control in Digital Contract Contexts
Web application firewall advanced
The Future of Digital Identity in the Age of the Internet of Things
Ad

Similar to UMA - An Open Standard for Consent-Driven Personal Data Sharing (20)

PPTX
Identity Live Sydney 2017 - Daniel Raskin
PPTX
Identity Live London 2017 | Daniel Raskin
PPTX
Identity Live Sydney 2017 - Ashley Stevenson
PPTX
Victor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - Dusseldorf
PPTX
Microservices architecture
PDF
Connected Car: Putting Digital Identity Behind the Wheel
PDF
Security On The Edge - A New Way To Think About Securing the Internet of Things
PPTX
Identity Live Paris 2017 | Monetising Digital Customer Relationships
PPTX
Peer-to-Server Media in WebRTC (Enterprise Connect 2014)
PPTX
An Approach for Multi-Tenancy Through Apache Knox
PPTX
Webinar: Identity Wars: The Unified Platform Awakens
PPTX
DeveloperWeek 2015 - WebRTC - Where to start and how to scale
PPTX
Directory Services with the ForgeRock Identity Platform - So What’s New?
PPTX
Trust No One: The New Security Model for Web APIs - SecTor talk by Greg Kliew...
PPTX
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
PPTX
Webinar: "Entitlements: Taking Control of the Big Data Gold Rush"
PDF
Serverless Software Architecture - Gears 17
PPTX
Pre-Con Ed: How to Provide Mobile Users With a Convenient, Yet Secure, Sessio...
PDF
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
PDF
Johannes Zijlstra - Sitecore 9 and GDPR
Identity Live Sydney 2017 - Daniel Raskin
Identity Live London 2017 | Daniel Raskin
Identity Live Sydney 2017 - Ashley Stevenson
Victor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - Dusseldorf
Microservices architecture
Connected Car: Putting Digital Identity Behind the Wheel
Security On The Edge - A New Way To Think About Securing the Internet of Things
Identity Live Paris 2017 | Monetising Digital Customer Relationships
Peer-to-Server Media in WebRTC (Enterprise Connect 2014)
An Approach for Multi-Tenancy Through Apache Knox
Webinar: Identity Wars: The Unified Platform Awakens
DeveloperWeek 2015 - WebRTC - Where to start and how to scale
Directory Services with the ForgeRock Identity Platform - So What’s New?
Trust No One: The New Security Model for Web APIs - SecTor talk by Greg Kliew...
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
Webinar: "Entitlements: Taking Control of the Big Data Gold Rush"
Serverless Software Architecture - Gears 17
Pre-Con Ed: How to Provide Mobile Users With a Convenient, Yet Secure, Sessio...
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
Johannes Zijlstra - Sitecore 9 and GDPR
Ad

More from Chris Adriaensen (7)

PPTX
AWS Scalable Architectures - Serverless
PDF
Beyond Consumers - Devices As 1st Class Identities
PDF
A Marvelous Guide To Internet Security
PPTX
EU Single Digital Market - eIDAS To The Rescue
PPTX
Trust - A Rare Commodity (Extended)
PPTX
The Relationship Battle
PPTX
De Burger in Controle? Standaarden en Technologie voor Persoonlijke Gegevenst...
AWS Scalable Architectures - Serverless
Beyond Consumers - Devices As 1st Class Identities
A Marvelous Guide To Internet Security
EU Single Digital Market - eIDAS To The Rescue
Trust - A Rare Commodity (Extended)
The Relationship Battle
De Burger in Controle? Standaarden en Technologie voor Persoonlijke Gegevenst...

Recently uploaded (20)

PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Machine learning based COVID-19 study performance prediction
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Big Data Technologies - Introduction.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Electronic commerce courselecture one. Pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
cuic standard and advanced reporting.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Cloud computing and distributed systems.
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Reach Out and Touch Someone: Haptics and Empathic Computing
Machine learning based COVID-19 study performance prediction
Dropbox Q2 2025 Financial Results & Investor Presentation
Big Data Technologies - Introduction.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Electronic commerce courselecture one. Pdf
Building Integrated photovoltaic BIPV_UPV.pdf
cuic standard and advanced reporting.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Diabetes mellitus diagnosis method based random forest with bat algorithm
MYSQL Presentation for SQL database connectivity
20250228 LYD VKU AI Blended-Learning.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Cloud computing and distributed systems.
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Advanced methodologies resolving dimensionality complications for autism neur...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf

UMA - An Open Standard for Consent-Driven Personal Data Sharing

  • 1. © 2016 ForgeRock. All rights reserved. Chris Adriaensen Senior Customer Engineer chris.adriaensen@forgerock.com @chrisadriaensen | @ForgeRock An Open Standard for Consent-Driven Personal Data Sharing © 2017 ForgeRock. All rights reserved.
  • 2. © 2016 ForgeRock. All rights reserved. BUSINESS DRIVERS TECHNOLOGY FEATURES PRIVACY Transparency Visualization of Personal Data Smart Things Explosion of Personal Data Customer Relationship Management Consent Access of Personal Data Regulation Government & Industry Bodies Privacy Drivers & Features © 2017 ForgeRock. All rights reserved. 2
  • 3. © 2016 ForgeRock. All rights reserved. © 2017 ForgeRock. All rights reserved. FEATURE Privacy Approaches Manual TRANSPARENCY Request Implicit CONSENT ACCESS SHARINGDATA 3
  • 4. © 2016 ForgeRock. All rights reserved. Requesting PartyClientsResources AccessResource Owner User Interface (GUI / PUI) Application Interface (REST / SOAP) User Interface (GUI / PUI) Application 4 Privacy Architecture © 2017 ForgeRock. All rights reserved.
  • 5. © 2016 ForgeRock. All rights reserved. Resource Owner User Interface (GUI / PUI) Requesting PartyClientsResources Access User Interface (GUI / PUI) Application Interface (REST / SOAP) Application 5 Privacy Challenge © 2017 ForgeRock. All rights reserved. ? IDIDIDID ID ID ID ID ID ? IDIDIDID
  • 6. © 2016 ForgeRock. All rights reserved. Requesting Party User Interface (GUI / PUI) Resource Owner User Interface (GUI / PUI) ClientsResources Access Application Interface (REST / SOAP) Application 6 Transparency Identity Solution © 2017 ForgeRock. All rights reserved. ID ID ID ID ID ID ID ID IdentityID
  • 7. © 2016 ForgeRock. All rights reserved. Requesting Party User Interface (GUI / PUI) Resource Owner User Interface (GUI / PUI) ClientsResources Access Application Interface (REST / SOAP) Application 7 Consent Access Solution © 2017 ForgeRock. All rights reserved. ID ID ID ID ID IDID Access ID ID Identity
  • 8. © 2016 ForgeRock. All rights reserved. © 2017 ForgeRock. All rights reserved. FEATURE Privacy Approaches Manual TRANSPARENCY Request Implicit CONSENT Strategy Explicit API’s SSH, LDAP, SQL, SOAP & REST Automated SOAP & REST ACCESS SHARINGDATA Portal 8
  • 9. © 2016 ForgeRock. All rights reserved. CONSUMERENTERPRISE OASIS 9 Open Standards © 2017 ForgeRock. All rights reserved. IETF, OIDF & KANTARA OIDC Identity Federation UMA Access Federation OAuth Access Control Consent Security Scalability Browser Client Generic Client Statefull Design Stateless Design XML / SOAP JSON / REST JWT Identity 2000+ 2010+ SAML Identity Federation XACML Access Federation WS-* Access SAML Identity
  • 10. © 2016 ForgeRock. All rights reserved. 10 OAuth 2.0 Standard © 2017 ForgeRock. All rights reserved. Resource Server Authorization Server Resource Owner Client Access Validate Manage Authorize Control Owner-to-App Sharing Synchronous Consent Access Integration Access Tokens
  • 11. © 2016 ForgeRock. All rights reserved. 11 User Managed Access Standard © 2017 ForgeRock. All rights reserved. Resource Server Authorization Server Requesting Party Client Authorize Access Protect Resource Owner Manage Manage Control Negotiate Owner-to-Party Sharing Asynchronous Consent Access Federation Access Tokens
  • 12. © 2016 ForgeRock. All rights reserved. Requesting PartyClientsResources AccessResource Owner User Interface (GUI / PUI) Application Interface (REST / SOAP) User Interface (GUI / PUI) Application 12 Consent Standards © 2017 ForgeRock. All rights reserved. OAuth 2.0 Device Flow OAuth 2.0 A/I Grant User Managed Access OpenIDConnect
  • 13. © 2016 ForgeRock. All rights reserved. © 2017 ForgeRock. All rights reserved. FEATURE Privacy Approaches Manual TRANSPARENCY Request Implicit CONSENT Strategy Explicit API’s SSH, LDAP, SQL, SOAP & REST Standards SCIM, SAML & OpenID Connect OAuth 2.0 & OpenID Connect Automated UMA SOAP & REST ACCESS SHARINGDATA Portal 13
  • 14. © 2016 ForgeRock. All rights reserved. 14 SolutionChallenge Health Care Platform Smart Devices Unified Identity Platform Patient Security Patient Privacy Patient Satisfaction Patient Consent Identity of Things Patient Relationships Single Patient View © 2017 ForgeRock. All rights reserved. “We are now able to design innovative data-sharing and consent technologies into our HealthSuite Digital Platform that make it possible to foster consumer and patient trust.” Jeroen Tas, CEO, Healthcare Informatics Solutions & Services
  • 15. © 2016 ForgeRock. All rights reserved. 15 DEMO Session © 2017 ForgeRock. All rights reserved.
  • 16. © 2016 ForgeRock. All rights reserved. Chris Adriaensen Senior Customer Engineer chris.adriaensen@forgerock.com @chrisadriaensen | @ForgeRock © 2017 ForgeRock. All rights reserved. End of SHOW