20
国内外事例から見る ID 連携・認証連携の 傾向と対策 近藤学 <[email protected]> 日本およびアジア太平洋地域マネージングディレクター 1

Security days 2015

Embed Size (px)

Citation preview

  • ID

    1

  • Market: Enterprise Security Business Model: Subscription Offices: Denver, Boston, Vancouver,

    London, San Francisco, Halifax, Tel Aviv, Singapore, Tokyo

    Employees: 340

    SUMMARY

    NEXT GEN Identity Company

    1,200+ customers

    99%customer

    satisfaction

    93%customerretention

    Forrester Wave - IAM

    Strategies

    Capa

    bilitie

    s

    Okta

    OneLogin

    Symplified

    NetIQ

    CentrifyMcAfee

    ForgeRock

    LeadersMajor PlayersContenders

    Covisint

    IBM

    CA

    RSA

    Ping

    Oracle

    Global Leaders & Innovators Market Leader

    IDC Marketscape: Federation & SSO

    Nearly 50% of the Fortune 100 5 of the 5 largest U.S. banks 5 of the 6 largest media providers 6 of the 10 largest biopharmas 3 of the 5 largest healthcare plans

    Customer Summary

    SI, TECH & SAAS PARTNERS

  • Ping Identity

    3

    WHAT YOU GET: Single Sign-on Identity Federation Cloud Identity Store Desktop & Mobile Dock OAuth, SCIM,

    WHAT YOU GET: Web & Mobile Access Access Control Policy Session Management API Security OAuth, OIDC, .

    WHAT YOU GET: Mobile MFA Authentication Policy Primary Factor Secondary Factor OTP (disconnected, SMS)

    SSO ACCESS MFA

    PING PLATFORM SERVICES Directory Integration Social Identity Integration Legacy IAM Integration SaaS Integration App Server Integration Custom Integration

    Protocol Engines (SAML, OpenID, OAuth, OpenID Connection. SCIM, WS*)

    Admin APIs Developer APIs SDK, Playground, Portal

    App Catalog Attribute Mapping

    Reports, Logs Dashboards

  • 4SAML OpenID OAuthOpenID Connect

    WS-Federation WS-Trust WebSSOAPI

    ID

    Web ID

    Web (ID )

    Identity Provider (IdP) Service Provider (SP)

  • 5

    ID

    Workforce Partners Customers

    Portals Intranets / extranets Mobile devices

    Active Directory Databases Social identities Web access

    management (WAM) Legacy IAM

    SaaS, custom and legacy apps

    Mobile apps Web services APIs

  • Identity is the next perimeter()

  • A (/ SSO)

    7

    SSO

    ID AD Web

    US

    Europe

    APAC

  • A (/ SSO)

    8

    SSO

    IdP SAML SP WS-Fed/OIDC/SAML proxy

    ID SAML IdP

    US

    Europe

    APAC

    SAML Token

    WS-Fed/OIDC/SAML

  • Federation Hub

    9

    IdP SP Federation Protocol

    IdP SP Federation Protocol

    PingFederate 7.3

  • IT/ B (Oce365 SSO)

    10

    SSO

    SSO

    DirSync AD IDM

  • C ( O365 SSO)

    11

    SSO

    O365 SSO ActiveSync ok

  • D (Facebook )

    12

    Web ()

    Facebook SNS

    SSO

  • E ( + )

    13

    Web

    Federated SSO + ACL

  • F (/ ID + SSO)

    14

    SSO

    ID

    ID IDaaS

    SSO Web app

    SSO

  • G (SSO + )

    15

    SSO

    AD + PingID Swipe and go

  • PingID

    16

    Swipe to Sign On

    QR

  • Confidential

    PingID (cont.)

    17

  • 18

    365 MFA ()

    Identity

    ()

    IDaaS

  • Our Next Gen Identity Platform

    19

  • Confidential

    THANK YOU

    https://www.facebook.com/pingidentityJP