your oauth/oidc servers. simpler yet more secure. · 2/27/2020  · oauth 2.0 oidc (openid connect)...

10
Introduction to “Authlete” Your OAuth/OIDC Servers. Simpler Yet More Secure. Authlete, Inc.

Upload: others

Post on 22-Sep-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

Introduction to “Authlete”Your OAuth/OIDC Servers. Simpler Yet More Secure.

Authlete, Inc.

Page 2: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

OAuth and OIDC are the Foundation for Open APIs

Credit cards

Stocks and pension

accounts

Account Information

Money Transfer

Credit Information

Managing multiple accounts

Money transfer using apps

Third Parties(e.g. Fintechs)

API Providers(e.g. Banks)

Users

Authorized access

by users

App XYZ

- Better CX

- New consumer

behavior

API Access

AuthorizationWho grants what API access to

which third party clients

OAuth 2.0

OIDC (OpenID

Connect)

Page 3: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

• Service providers can’t follow the

standardization process

– A lot of new extensions and practices

are being created

• Poor API access authorization could

lead to security incidents

– Customers of the providers could

become victims

Difficulties in Adopting OAuth/OIDC Standards

Source: https://tools.ietf.org/wg/oauth/, https://openid.net/wg/fapi/

Page 4: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

IDaaS“No deployment needed”

Offering limited general-purpose

features

IAM Software“Flexible customization”

Conflict with existing IdM / user

authN

API Gateways“Tightly integrated”

Lack of focus on API authZcapabilities

Problems in Traditional API Authorization Approaches

Difficult to optimize IDaaS for

your APIs and business

Non-negligible cost to migrate

the existing assets

Slow to support up-to-date API

security stds such as FAPI, eKYC

Page 5: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

“Semi-hosted” Architecture

Providing All Features as APIs

The Leader in Supporting the

Latest OAuth/OIDC Standards

Authlete: A New Approach of “API Authorization Engine”

Page 6: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

Authlete Fits in Any Form of Existing SystemsExposing Web APIs for OAuth/OIDC Processing and Token Management

API Infrastructure

Existing Systems

Authorization Server

Authorization

Decision Logic

User

Authentication

Consent

Management

Privilege

Management

Authlete

Au

tho

riza

tio

n

Back

en

d A

PIs

Tokens and

Config DB

Authorization and Token

Requests

API Requests

OAuth/OIDC Processing Requests

Externalizing Cumbersome

OAuth/OIDC Processing and

Token Management

Authorization Status

Check

Externalizing Access

Token Verification

Authorization

Frontend

API Servers / Gateways

/data /function /transaction /…

API Clients

Websites

Mobile

Devices

Networked

Devices

Page 7: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

A Broad Range of Use CasesFrom Banks to Entertainments

Grand Prize IBM AwardGrand Prize

Minna No Ginko (TBD) *

Banking

Fintech

Personal Data Bank

Integrated Solution

IoT HR Entertainment

* In evaluation

Awards

Page 8: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

SmartHROne of the Largest HR Management SaaS in Japan Has Been Utilizing Authlete For Years

“Quite a rich set of Web

APIs”

“High maintenance ability

for anyone from anywhere”

“Continuous adoption of

the latest standards is

trustworthy”Source: https://speakerdeck.com/mserizawa/smarthr-niokeru-authlete-falsehuo-yong

Page 9: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

9

Try Authlete for Free at www.authlete.com

Page 10: Your OAuth/OIDC Servers. Simpler Yet More Secure. · 2/27/2020  · OAuth 2.0 OIDC (OpenID Connect) ... PowerPoint Presentation Author: Jamie Lemon Created Date: 5/25/2020 6:51:34

Thank You

www.authlete.com