Federated Identity Primer
Book information
Description
Identity authentication and authorization are integral tasks in today's digital world. As businesses become more technologically integrated and consumers use more web services, the questions of identity security and accessibility are becoming more prevalent. Federated identity links user credentials across multiple systems and services, altering both the utility and security landscape of both. In Federated Identity Primer, Derrick Rountree. Front Cover Federated Identity Primer Copyright Page Contents Preface What to Expect from this Book 1 Introduction to Identity 1.1 Introduction 1.2 What Is Identity? 1.2.1 Physical Identity 1.2.1.1 Components of Your Physical Identity 1.2.1.2 Protecting Your Physical Identity 1.2.1.3 Only One Physical Identity 1.2.2 Digital Identity 1.2.2.1 Components of Your Digital Identity 1.2.2.2 Protecting Your Digital Identity 1.2.2.3 Only One Digital Identity 1.3 The Internet Identity Problem 1.4 Summary 2 What Is Federated Identity? 2.1 Introduction 2.2 Authentication and Authorization 2.2.1 Authentication 2.2.1.1 Types of Authentication 2.2.1.1.1 Username and Password 2.2.1.1.2 Biometrics 2.2.1.1.3 User Certificates 2.2.1.1.4 Kerberos 2.2.1.1.5 One-Time-Use Token 2.2.1.1.6 Risk-Based Authentication 2.2.1.1.7 Custom Authentication Tokens 2.2.1.2 Other Authentication Concepts 2.2.1.2.1 Mutual Authentication 2.2.1.2.2 Multifactor Authentication 2.2.2 Authorization 2.3 Access Control 2.3.1 Mandatory Access Control 2.3.2 Discretionary Access Control 2.3.3 Role-Based Access Control 2.4 Federated Service Model 2.4.1 Identity Provider 2.4.1.1 Credential Store 2.4.2 Service Provider 2.5 Federated Identity 2.5.1 Authentication vs Authorization with Federated Identity 2.5.2 Federated Identity Advantages and Disadvantages 2.5.2.1 Advantages 2.5.2.1.1 Security of User Credentials 2.5.2.1.2 Seamless User Experience 2.5.2.1.3 Applications only Make Authorization Decisions 2.5.2.1.4 Reduce Account Management 2.5.2.1.5 Reduce Number of Usernames and Passwords 2.5.2.1.6 Ease Merger and Acquisition Activity 2.5.2.1.7 Highly Extensible 2.5.2.2 Disadvantages 2.5.2.2.1 One Key to the Kingdom 2.5.2.2.2 Requires Specialized Infrastructure 2.5.2.2.3 Need to Conform to Same Standards 2.5.2.2.4 It’s Really New 2.6 Summary 3 Federated Identity Technologies 3.1 Introduction 3.2 OpenID 3.2.1 Using OpenID 3.3 OAuth 3.3.1 Evolution of OAuth 3.3.1.1 OAuth 1.0 and 1.0a 3.3.1.2 OAuth WRAP 3.3.1.3 OAuth 2.0 3.4 Security Tokens 3.4.1 Simple Web Tokens 3.4.1.1 SWT Attributes 3.4.2 JSON Web Tokens 3.4.2.1 JWT Components 3.4.2.2 JWT Claims 3.4.2.3 JWT Creation 3.4.3 Security Assertion Markup Language 3.4.3.1 SAML Components 3.4.3.1.1 SAML Assertions 3.4.3.1.2 SAML Protocols 3.4.3.1.3 SAML Bindings 3.4.3.1.4 SAML Profiles 3.4.3.2 The Evolution of SAML 3.4.3.2.1 SAML v1.0 3.4.3.2.2 SAML v1.1 3.4.3.2.3 SAML 2.0 3.4.3.2.3.1 SAML 2.0 Assertions 3.5 Web Service Specifications 3.5.1 WS-Security 3.5.2 WS-SecurityPolicy 3.5.3 WS-SecureConversation 3.5.4 WS-Trust 3.5.5 WS-Federation 3.6 Windows Identity Foundation 3.6.1 WIF Features 3.6.1.1 Claims-Aware Applications 3.6.1.2 Identity Delegation 3.6.1.3 Custom Token Servers 3.6.1.4 Step-Up Authentication 3.7 Claims-Based Identity 3.7.1 CBA Description and Overview 3.7.1.1 Claims 3.7.1.2 Token 3.7.1.3 Issuer 3.7.1.3.1 Secure Token Server 3.7.1.3.1.1 CBA Authentication Process 3.7.1.4 The Application 3.7.2 Active and Passive Clients 3.7.2.1 Passive Clients 3.7.2.1.1 Passive Client Flow 3.7.2.2 Active Clients 3.7.2.2.1 Active Client Flow 3.7.3 Cross-Realm Federation with CBA 3.8 Summary 4 Deployment Options 4.1 Introduction 4.2 Making a Choice 4.2.1 Flexibility 4.2.2 Management and Maintenance 4.2.3 Availability 4.2.4 Security 4.2.5 Cost 4.3 Active Directory Federation Services 4.3.1 ADFS 2.0 Functionality 4.3.1.1 Claims-Based Authentication Clients 4.3.1.2 SAML 4.3.1.3 Federation with Other STSs 4.3.2 ADFS 2.0 Components 4.3.2.1 Federation Service 4.3.2.2 Federation Proxy Servers 4.3.2.3 Attribute Stores 4.3.2.4 Relying Parties 4.3.2.5 Endpoints 4.3.3 ADFS 2.0 Federation Server Configuration Wizard 4.4 Microsoft ACS 4.4.1 ACS Functionality 4.4.1.1 Authentication 4.4.1.2 Authorization 4.4.1.2.1 Role-Based Access Control 4.4.1.2.2 Claims-Based Access Control 4.4.1.3 Federation 4.4.1.4 Security Token Flow and Transformation 4.4.1.5 Trust Management 4.4.1.6 Administration 4.4.1.7 Automation 4.4.2 ACS Components 4.4.2.1 Service Namespace 4.4.2.2 Identity Providers 4.4.2.3 Relying Party 4.4.2.4 Rules and Rule Groups 4.4.2.5 Service Identities 4.4.2.6 Certificates and Keys 4.4.2.7 ACS Management Portal 4.4.2.8 ACS Management Service 4.4.2.9 Login Pages and Home Realm Discovery 4.4.3 Using ACS 4.4.3.1 Home 4.4.3.2 Trust Relationships 4.4.3.2.1 Identity Providers 4.4.3.2.2 Relying Party Applications 4.4.3.2.3 Rule Groups 4.4.3.3 Service Settings 4.4.3.3.1 Certificates and Keys 4.4.3.3.2 Service Identities 4.4.3.4 Administration 4.4.3.4.1 Portal Administrators 4.4.3.4.2 Management Service 4.4.3.5 Development 4.4.3.5.1 Application Integration 4.5 Summary
Similar books
Federated Identity Primer
2012 · PDF
The basics of cloud computing. understanding the fundamentals of cloud computing in theory and practice
2014 · PDF
Windows 2012 Server Network Security Securing Your Windows Network Systems and Infrastructure
2013 · PDF
Security for Microsoft Windows System Administrators : introduction to key information security concepts
Windows 2012 Server Network Security: Securing Your Windows Network Systems and Infrastructure
2013 · MOBI
Windows 2012 Server Network Security: Securing Your Windows Network Systems and Infrastructure
2013 · EPUB
The Basics of Cloud Computing: Understanding the Fundamentals of Cloud Computing in Theory and Practice
2013 · MOBI
The Basics of Cloud Computing: Understanding the Fundamentals of Cloud Computing in Theory and Practice
2013 · EPUB