SlideShare uma empresa Scribd logo
1 de 3
Today, services like authorization and authentication are delivered via APIs: JSON /
REST HTTP “endpoints.” Some of the most popular authentication API’s on the Internet
are using different profiles of OAuth2. Because consolidation increases efficiency,
Google, Microsoft, Yahoo, and others came together to define one standard profile for
OAuth 2.0 authentication: OpenID Connect.
OpenID Connect documents a single profile of OAuth2 that can be used by any Internet
domain. One standard for domain authentication will simplify security for application
developers (web and mobile), make end users more secure, and enable easier integration
of mobile devices and cloud agents.
See Toshiba Cloud TV in Action.
Specifically, OpenID Connect defines several endpoints to enable domains to offer : (1)
user authentication; (2) client registration; (3) client authentication; (4) user claims; (5)
client claims; and (6) discovery. Industry analysts are predicting that sso service is on a
trajectory for significant adoption.
The standard should be finalized by the end of 2013. Nat Sakimura (NTT) , Vice-
Chairman of the OpenID Foundation, has said this about OpenID Connect: “we are
done apart from formalities.”
Learn more about OpenID Connect via slides from Microsoft’s Michael B. Jones.
The partnership with Toshiba has driven the implementation of a number of features to
the OX platform. For example, they wanted to build a highly available “cluster” of
authentication servers delivered across multiple geographic regions to ensure business
continuity. This would enable Toshiba engineers to take a server out for maintenance,
and just add it back later.
Toshiba has also been helpful with testing and benchmarking. OX has been in
production there since last year, so we have also been able to observe the behavior of the
platform over time, while handling significant load.
For reasons like these, Toshiba decided in 2012 to align with OpenID Connect. As Gluu’s
open source “OX” platform performed well in the identity provider saml (“OP”)
Internop, Toshiba decided it was preferable to use OX rather than write their own
implementation.
Gluu has also built features to enable Toshiba to use the central publication of multi-
party federation metadata to enable globally delivered websites to trust identity
providers in different regions (Japan, US, and Europe) without persisting any personally
identifiable data outside of the region. Although JSON multiparty federation metadata is
not currently a feature of OpenID Connect, Gluu has documented its implementation at
the OpenID Foundation in the Emerging Work Section.
Toshiba is keen to promote the OX open source platform within the Smart TV Alliance,
which is why they authorized the May 1, 2013 press release. Adoption of the OX open
source platform will help members of the Smart TV Alliance collaborate on the
development of an Internet scale, interoperable security infrastructure, a goal everyone
wants to achieve.
Gluu provides services to companies that want to use the OX platform: Design, Build,
Operate, and Transfer (DBOT). We were able to help Toshiba engineers jumpstart their
development effort and to provide some tactical feature enhancements in the open
source project to support their rollout.
Article resource:-https://sites.google.com/site/thegluuserver/how-why-gluu-s-open-
source-authorization-and-authentication-platform-was-chosen-by-toshiba-for-new-
cloud-tv

Mais conteúdo relacionado

Destaque

سلسلة العربية بين يديك المطورة
سلسلة العربية بين يديك المطورةسلسلة العربية بين يديك المطورة
سلسلة العربية بين يديك المطورةArabicForAll
 
194a
194a194a
194aO J
 
中國古塔之最 (Music)2011.
中國古塔之最 (Music)2011.中國古塔之最 (Music)2011.
中國古塔之最 (Music)2011.Y YU
 
Jesús brayan soscué yotengo
Jesús brayan soscué yotengoJesús brayan soscué yotengo
Jesús brayan soscué yotengodontuttobrayan
 
148a
148a148a
148aO J
 
181a
181a181a
181aO J
 
105a
105a105a
105aO J
 
123a
123a123a
123aO J
 
158
158158
158O J
 
本年度最佳的 E mail (rev)
本年度最佳的 E mail (rev)本年度最佳的 E mail (rev)
本年度最佳的 E mail (rev)Y YU
 
Inicie Su Negocio Online El Caso Del Turismo
Inicie Su Negocio Online El Caso Del TurismoInicie Su Negocio Online El Caso Del Turismo
Inicie Su Negocio Online El Caso Del TurismoHugo Aguayo
 
165a
165a165a
165aO J
 

Destaque (20)

HannaKawasaki120430
HannaKawasaki120430HannaKawasaki120430
HannaKawasaki120430
 
سلسلة العربية بين يديك المطورة
سلسلة العربية بين يديك المطورةسلسلة العربية بين يديك المطورة
سلسلة العربية بين يديك المطورة
 
194a
194a194a
194a
 
中國古塔之最 (Music)2011.
中國古塔之最 (Music)2011.中國古塔之最 (Music)2011.
中國古塔之最 (Music)2011.
 
Jesús brayan soscué yotengo
Jesús brayan soscué yotengoJesús brayan soscué yotengo
Jesús brayan soscué yotengo
 
FRUTAS Y VERDURAS ?
FRUTAS Y VERDURAS ?FRUTAS Y VERDURAS ?
FRUTAS Y VERDURAS ?
 
Laporan ppdb 2014
Laporan ppdb 2014Laporan ppdb 2014
Laporan ppdb 2014
 
148a
148a148a
148a
 
sensibilizacion
sensibilizacionsensibilizacion
sensibilizacion
 
181a
181a181a
181a
 
La Edad Media
La Edad MediaLa Edad Media
La Edad Media
 
105a
105a105a
105a
 
123a
123a123a
123a
 
UCA UNIDAD 2
UCA UNIDAD 2UCA UNIDAD 2
UCA UNIDAD 2
 
158
158158
158
 
本年度最佳的 E mail (rev)
本年度最佳的 E mail (rev)本年度最佳的 E mail (rev)
本年度最佳的 E mail (rev)
 
Rol domingo
Rol domingoRol domingo
Rol domingo
 
LITERACIA E CAPACITAÇÃO
LITERACIA E CAPACITAÇÃOLITERACIA E CAPACITAÇÃO
LITERACIA E CAPACITAÇÃO
 
Inicie Su Negocio Online El Caso Del Turismo
Inicie Su Negocio Online El Caso Del TurismoInicie Su Negocio Online El Caso Del Turismo
Inicie Su Negocio Online El Caso Del Turismo
 
165a
165a165a
165a
 

Semelhante a How & why gluu’s open source authorization and authentication platform was chosen by toshiba for new cloud tv

At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...
At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...
At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...Sckipio
 
Open Standards in Identity Management
Open Standards  in  Identity ManagementOpen Standards  in  Identity Management
Open Standards in Identity ManagementPrabath Siriwardena
 
A Survey on IoT Architecture
A Survey on IoT ArchitectureA Survey on IoT Architecture
A Survey on IoT ArchitectureIJASRD Journal
 
OSGi - Four Years and Forward - J Barr
OSGi - Four Years and Forward - J BarrOSGi - Four Years and Forward - J Barr
OSGi - Four Years and Forward - J Barrmfrancis
 
WSO2 ITALIA SMART TALK #4 - Telefonica Use Case
WSO2 ITALIA SMART TALK #4 - Telefonica Use CaseWSO2 ITALIA SMART TALK #4 - Telefonica Use Case
WSO2 ITALIA SMART TALK #4 - Telefonica Use CaseProfesia Srl, Lynx Group
 
The Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdfThe Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdfTechugo
 
The Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdfThe Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdfTechugo
 
MuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoft
MuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoftMuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoft
MuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoftJitendra Bafna
 
Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...
Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...
Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...mfrancis
 
5G, IoT and AI. Overview strategy for business_Rev20200505
5G, IoT and AI. Overview strategy for business_Rev202005055G, IoT and AI. Overview strategy for business_Rev20200505
5G, IoT and AI. Overview strategy for business_Rev20200505Agustin Francisco Melian
 
ISC Cloud13 Sill - Crossing organizational boundaries in cloud computing
ISC Cloud13 Sill - Crossing organizational boundaries in cloud computingISC Cloud13 Sill - Crossing organizational boundaries in cloud computing
ISC Cloud13 Sill - Crossing organizational boundaries in cloud computingAlan Sill
 
EduID Mobile App - Use-Cases, Concepts and Implementation
EduID Mobile App - Use-Cases, Concepts and ImplementationEduID Mobile App - Use-Cases, Concepts and Implementation
EduID Mobile App - Use-Cases, Concepts and ImplementationChristian Glahn
 
Enhancing Password Manager Chrome Extension through Multi Authentication and ...
Enhancing Password Manager Chrome Extension through Multi Authentication and ...Enhancing Password Manager Chrome Extension through Multi Authentication and ...
Enhancing Password Manager Chrome Extension through Multi Authentication and ...ijtsrd
 
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They KeyOAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They KeyMike Schwartz
 
IoT Standardisation Panel
IoT Standardisation PanelIoT Standardisation Panel
IoT Standardisation PanelDuncan Wilson
 

Semelhante a How & why gluu’s open source authorization and authentication platform was chosen by toshiba for new cloud tv (20)

At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...
At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...
At&t, ON Lab, ONOS project, Sckipio and PMC to unveil cord solution poc at op...
 
Open Standards in Identity Management
Open Standards  in  Identity ManagementOpen Standards  in  Identity Management
Open Standards in Identity Management
 
A Survey on IoT Architecture
A Survey on IoT ArchitectureA Survey on IoT Architecture
A Survey on IoT Architecture
 
OSGi - Four Years and Forward - J Barr
OSGi - Four Years and Forward - J BarrOSGi - Four Years and Forward - J Barr
OSGi - Four Years and Forward - J Barr
 
IOT.pptx
IOT.pptxIOT.pptx
IOT.pptx
 
WSO2 ITALIA SMART TALK #4 - Telefonica Use Case
WSO2 ITALIA SMART TALK #4 - Telefonica Use CaseWSO2 ITALIA SMART TALK #4 - Telefonica Use Case
WSO2 ITALIA SMART TALK #4 - Telefonica Use Case
 
The Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdfThe Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdf
 
The Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdfThe Top Technologies Used To Develop a Mobile App.pdf
The Top Technologies Used To Develop a Mobile App.pdf
 
MuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoft
MuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoftMuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoft
MuleSoft Surat Virtual Meetup#19 - Identity and Client Management With MuleSoft
 
Video report
Video reportVideo report
Video report
 
Tizen
TizenTizen
Tizen
 
Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...
Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...
Business and IoT Economic Alchemy or Another Anticlimax - March 2016 - OSGi A...
 
5G, IoT and AI. Overview strategy for business_Rev20200505
5G, IoT and AI. Overview strategy for business_Rev202005055G, IoT and AI. Overview strategy for business_Rev20200505
5G, IoT and AI. Overview strategy for business_Rev20200505
 
ISC Cloud13 Sill - Crossing organizational boundaries in cloud computing
ISC Cloud13 Sill - Crossing organizational boundaries in cloud computingISC Cloud13 Sill - Crossing organizational boundaries in cloud computing
ISC Cloud13 Sill - Crossing organizational boundaries in cloud computing
 
EduID Mobile App - Use-Cases, Concepts and Implementation
EduID Mobile App - Use-Cases, Concepts and ImplementationEduID Mobile App - Use-Cases, Concepts and Implementation
EduID Mobile App - Use-Cases, Concepts and Implementation
 
Enhancing Password Manager Chrome Extension through Multi Authentication and ...
Enhancing Password Manager Chrome Extension through Multi Authentication and ...Enhancing Password Manager Chrome Extension through Multi Authentication and ...
Enhancing Password Manager Chrome Extension through Multi Authentication and ...
 
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They KeyOAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
 
IoT Standardisation Panel
IoT Standardisation PanelIoT Standardisation Panel
IoT Standardisation Panel
 
IoT standardisation
IoT standardisationIoT standardisation
IoT standardisation
 
Latest technology trends Microsoft
Latest technology trends MicrosoftLatest technology trends Microsoft
Latest technology trends Microsoft
 

Mais de Gluu

Gluu server for educational institutions
Gluu server for educational institutionsGluu server for educational institutions
Gluu server for educational institutionsGluu
 
Pr from our recent nstic pilot award
Pr from our recent nstic pilot awardPr from our recent nstic pilot award
Pr from our recent nstic pilot awardGluu
 
The currency of identifiers
The currency of identifiersThe currency of identifiers
The currency of identifiersGluu
 
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...Gluu
 
Gluu sxsw 2015 interactive picks
Gluu sxsw 2015 interactive picksGluu sxsw 2015 interactive picks
Gluu sxsw 2015 interactive picksGluu
 
17 recommended requirements for an identity and access management poc
17 recommended requirements for an identity and access management poc17 recommended requirements for an identity and access management poc
17 recommended requirements for an identity and access management pocGluu
 
Top 10 applications for multi factor authentication in higher education
Top 10 applications for multi factor authentication in higher educationTop 10 applications for multi factor authentication in higher education
Top 10 applications for multi factor authentication in higher educationGluu
 
First o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluuFirst o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluuGluu
 
East hackathon api’s for art
East hackathon api’s for artEast hackathon api’s for art
East hackathon api’s for artGluu
 
Gluu’s vision
Gluu’s visionGluu’s vision
Gluu’s visionGluu
 
Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...Gluu
 
Currency of identifiers ii
Currency of identifiers iiCurrency of identifiers ii
Currency of identifiers iiGluu
 
Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...Gluu
 
Federated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs oxFederated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs oxGluu
 
Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0Gluu
 
Packt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access managementPackt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access managementGluu
 
Gluu oscon submission
Gluu oscon submissionGluu oscon submission
Gluu oscon submissionGluu
 
Go west young federation
Go west young federationGo west young federation
Go west young federationGluu
 
 Use case for asimba as saml proxy
 Use case for asimba as saml proxy Use case for asimba as saml proxy
 Use case for asimba as saml proxyGluu
 
Postcard from identity next 2013
Postcard from identity next 2013Postcard from identity next 2013
Postcard from identity next 2013Gluu
 

Mais de Gluu (20)

Gluu server for educational institutions
Gluu server for educational institutionsGluu server for educational institutions
Gluu server for educational institutions
 
Pr from our recent nstic pilot award
Pr from our recent nstic pilot awardPr from our recent nstic pilot award
Pr from our recent nstic pilot award
 
The currency of identifiers
The currency of identifiersThe currency of identifiers
The currency of identifiers
 
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
 
Gluu sxsw 2015 interactive picks
Gluu sxsw 2015 interactive picksGluu sxsw 2015 interactive picks
Gluu sxsw 2015 interactive picks
 
17 recommended requirements for an identity and access management poc
17 recommended requirements for an identity and access management poc17 recommended requirements for an identity and access management poc
17 recommended requirements for an identity and access management poc
 
Top 10 applications for multi factor authentication in higher education
Top 10 applications for multi factor authentication in higher educationTop 10 applications for multi factor authentication in higher education
Top 10 applications for multi factor authentication in higher education
 
First o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluuFirst o auth 2.0 and saml identity federation platform to be shown by gluu
First o auth 2.0 and saml identity federation platform to be shown by gluu
 
East hackathon api’s for art
East hackathon api’s for artEast hackathon api’s for art
East hackathon api’s for art
 
Gluu’s vision
Gluu’s visionGluu’s vision
Gluu’s vision
 
Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...Gluu and canonical to demonstrate instant application security using ubuntu j...
Gluu and canonical to demonstrate instant application security using ubuntu j...
 
Currency of identifiers ii
Currency of identifiers iiCurrency of identifiers ii
Currency of identifiers ii
 
Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...Shibboleth identity provider (idp) what it is, and why you should consider a ...
Shibboleth identity provider (idp) what it is, and why you should consider a ...
 
Federated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs oxFederated identity and open id connect why higher ed needs ox
Federated identity and open id connect why higher ed needs ox
 
Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0Web access management using o auth2 and saml – wam 2.0
Web access management using o auth2 and saml – wam 2.0
 
Packt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access managementPackt publishing book proposal api and mobile access management
Packt publishing book proposal api and mobile access management
 
Gluu oscon submission
Gluu oscon submissionGluu oscon submission
Gluu oscon submission
 
Go west young federation
Go west young federationGo west young federation
Go west young federation
 
 Use case for asimba as saml proxy
 Use case for asimba as saml proxy Use case for asimba as saml proxy
 Use case for asimba as saml proxy
 
Postcard from identity next 2013
Postcard from identity next 2013Postcard from identity next 2013
Postcard from identity next 2013
 

How & why gluu’s open source authorization and authentication platform was chosen by toshiba for new cloud tv

  • 1. Today, services like authorization and authentication are delivered via APIs: JSON / REST HTTP “endpoints.” Some of the most popular authentication API’s on the Internet are using different profiles of OAuth2. Because consolidation increases efficiency, Google, Microsoft, Yahoo, and others came together to define one standard profile for OAuth 2.0 authentication: OpenID Connect. OpenID Connect documents a single profile of OAuth2 that can be used by any Internet domain. One standard for domain authentication will simplify security for application developers (web and mobile), make end users more secure, and enable easier integration of mobile devices and cloud agents. See Toshiba Cloud TV in Action. Specifically, OpenID Connect defines several endpoints to enable domains to offer : (1) user authentication; (2) client registration; (3) client authentication; (4) user claims; (5) client claims; and (6) discovery. Industry analysts are predicting that sso service is on a trajectory for significant adoption.
  • 2. The standard should be finalized by the end of 2013. Nat Sakimura (NTT) , Vice- Chairman of the OpenID Foundation, has said this about OpenID Connect: “we are done apart from formalities.” Learn more about OpenID Connect via slides from Microsoft’s Michael B. Jones. The partnership with Toshiba has driven the implementation of a number of features to the OX platform. For example, they wanted to build a highly available “cluster” of authentication servers delivered across multiple geographic regions to ensure business continuity. This would enable Toshiba engineers to take a server out for maintenance, and just add it back later. Toshiba has also been helpful with testing and benchmarking. OX has been in production there since last year, so we have also been able to observe the behavior of the platform over time, while handling significant load. For reasons like these, Toshiba decided in 2012 to align with OpenID Connect. As Gluu’s open source “OX” platform performed well in the identity provider saml (“OP”) Internop, Toshiba decided it was preferable to use OX rather than write their own implementation.
  • 3. Gluu has also built features to enable Toshiba to use the central publication of multi- party federation metadata to enable globally delivered websites to trust identity providers in different regions (Japan, US, and Europe) without persisting any personally identifiable data outside of the region. Although JSON multiparty federation metadata is not currently a feature of OpenID Connect, Gluu has documented its implementation at the OpenID Foundation in the Emerging Work Section. Toshiba is keen to promote the OX open source platform within the Smart TV Alliance, which is why they authorized the May 1, 2013 press release. Adoption of the OX open source platform will help members of the Smart TV Alliance collaborate on the development of an Internet scale, interoperable security infrastructure, a goal everyone wants to achieve. Gluu provides services to companies that want to use the OX platform: Design, Build, Operate, and Transfer (DBOT). We were able to help Toshiba engineers jumpstart their development effort and to provide some tactical feature enhancements in the open source project to support their rollout. Article resource:-https://sites.google.com/site/thegluuserver/how-why-gluu-s-open- source-authorization-and-authentication-platform-was-chosen-by-toshiba-for-new- cloud-tv