SlideShare a Scribd company logo
Nomura Research Institute
OpenID in the digital ID landscape:
a perspective from the past to the future
Nat Sakimura (@_nat_en)
Research Fellow, Nomura Research Institute
Chairman of the board, OpenID Foundation
www.kuppingercole.com
_nat_en
https://nat.Sakimura.org/youtube.php
https://www.linkedin.com/in/natsakimura
https://nat.sakimura.org
Nomura Research Institute
Nomura Research Institute
Nomura Research Institute
Nomura Research Institute
Open,
Sesame!
(Source)Albert Robida (1848-1926) - public domain
An example of
long-term weak
shared key
Nomura Research Institute
Rome
5
(Source)Roman soldiers on the cast ofTrajan's Column in theVictoria and Albert museum, London.– public domain
Shared weak
symmetric key,
rotated daily with
ACK based key
delivery protocol
Nomura Research Institute
MIT’s CTSS system
(1961) used
LOGIN &
PASSWORD –
An example
of individual
password
6
(Source) http://en.wikipedia.org/wiki/IBM_7090#mediaviewer/File:IBM_7094_console2.agr.JPG
Nomura Research Institute
Per
System
identity
7
Service 1
Service 2
Service N
Nomura Research Institute
8
Nomura Research Institute
9
IDENTITY
Nomura Research Institute
Nomura Research Institute
10
Real
Name
Professional
qualification
department
Geo-location
Employee
number
Entity Identity
Nomura Research Institute
11
Real
Name
Professional
qualification
department
Geo-location
Employee
number
Entity Authenticated IdentityAuthentication Server
Provides claims
username
password
Geo-location
Device info
Etc.
Identity
Register
Verification
(authenticatio
n)
Nomura Research Institute
12
(source)Created by the author based on ISO/IEC 24760-1 Identity management framework: Part1
Unknown※
Established
Active
Archived
Suspended
suspend
reactivate
maintain
delete
archive
activate
adjust
register
Re-establish delete
Identity
Management
Nomura Research Institute
13
Real
Name
Professional
qualification
department
Geo-location
Employee
number
Entity Authenticated IdentityAuthentication Server
Provides claims
username
password
Geo-location
Device info
Etc.
Identity
Register
Verification
(AuthN)
Nomura Research Institute
Per
System
identity
14
Service 1
IR
Service 2
Service N
IR
IR
Nomura Research Institute
Shared
identity
15
Service 1
Service 2
Service N
IR
IR
Nomura Research Institute
16
Nomura Research Institute
Shared
identity
17
Service 1
Service 2
Service N
IR
IR
password
Nomura Research Institute
Federated
identity
18
Service 1
Service 2
Service N
IdP IR
Get Token
ID Token
ID Token
Nomura Research Institute
19
OpenID Authentication 2.0
(key=value)
2002 2005 20142012
SAML 2.0
(XML, XML SIG,
SOAP)
SAML 1.0
2007
OAuth 1.0
(Key=value)
Nomura Research Institute
20
2007
2008
Nomura Research Institute
21
Nomura Research Institute
22
Nomura Research Institute
23
Nomura Research Institute
24
Nomura Research Institute
25
Nomura Research Institute
26
Nomura Research Institute
27
Nat Sakimura
(NRI)
John Bradley
(Mercenary working for NRI)
Breno de Madeiros
(Google)
Nomura Research Institute
Early design decisions:
1. No canonicalization
2. ASCII Armoring
3. JSON
4. REST
28
JSON Simple
Signature (JSS)
& Encryption (JSE)
Nomura Research Institute
Then, there was a
parallel work
Magic Signature
& JSON Token
29
John Panzer
Dirk Balfanz
Nomura Research Institute
And there came Mike Jones
 “You guys should come together and standardize
it at IETF. Don’t worry. I can take care of the
editing!”
30
JSON Simple
Signature (JSS)
& Encryption (JSE)
Magic Signature &
JSON Tokens
JWx
Nomura Research Institute
JWx
JWS: JSON Web Signature
JWE: JSON Web Encryption
JWT: JSON Web Token etc.
31
Nomura Research Institute
Early design decisions:
1. No canonicalization
2. ASCII Armoring
3. JSON
4. REST
5. JWx
32
Dick Hardt
Allen Tom
Nomura Research Institute
Early design decisions:
1. No canonicalization
2. ASCII Armoring
3. JSON
4. REST
5. JWx
6. Base on OAuth WRAP
33
2.0
Nomura Research Institute
34
OAuth 2.0
OpenID Authentication 2.0
(key=value)
2002 2005 2012
SAML 2.0
(XML, XML SIG,
SOAP)
SAML 1.0
2007 2014
OpenID Connect
(JSON, JWS, REST)
OAuth
1.0 Dave Recordon
Nomura Research Institute
35
Nomura Research Institute
HTTPS
OAuth 2.0
JWS/JWE/JWKS
ID Token
Nomura Research Institute
Over 90% of Azure
AD App
Authentication are
Over OpenID
Connect
as of
April
2018
36
Alex Simmons at EIC 2018
Nomura Research Institute
37
OpenID Financial-grade API (FAPI)
Security Profile
https://www.openbanking.org.uk/provider-categories/account-providers/
ABN AMRO Bank NV
AIB Group (UK) plc
Bank of Cyprus UK Ltd
Bank of Ireland (UK) Plc
Bank of Scotland plc
Barclays Bank Plc
Clydesdale Bank PLC
HSBC UK Bank Plc
ICBC (London) plc
Lloyds Bank PLC
etc…
Nomura Research Institute
That is perfectly fit for not only
Enterprise access control
Real
Name
Professional
qualification
department
Geo-
location
Employee
number
Entity Authenticated IdentityAuthentication Server
Provides Claims
username
password
Geo-location
Device info
Etc.
Identity
Register
AuthN
Log
Audit
Anomaly
Detection
Resource
PolicyPAP
PDP
PEP
metadata
PEP2
Admin
ID Token
Nomura Research Institute
Employee
Relationship
Management
(ERM)
But also …
Nomura Research Institute
Customer
Relationship
Management
(CRM)
40
Including Customer
on-boarding
… and
Nomura Research Institute
Social &
Bank
Identities
41
BYOID
Nomura Research Institute
Host your
own IdP
on-premise
/ cloud
42
Nomura Research Institute
It can be
on your
local
machine
43
Nomura Research Institute
Self-issued OP – Never taken away 44
HOSTED ON YOUR LOCAL
MACHINE.
NO NEED FOR IDP DISCOVERY
BECAUSE IT IS LOCAL.
USER IDENTIFIER IS THE HASH OF
THE PUBLIC KEY GENERATED BY
THE SOFTWARE.
Nomura Research Institute
3 Claims Models
Simple
AggregatedDistributed
45
Nomura Research Institute
Simple Claims 46
ID Token
IdP
Client
Nomura Research Institute
Aggregated claims 47
Signed Claims
(Token)
Signed Claims
(Token)
ID Token
IdP
Claims Provider
Claims Provider
Client
Claims are
Verifiable
Nomura Research Institute
Distributed Claims 48
Signed Claims
(Token)
ID Token including pinters
ClientClaims are
Verifiable
Nomura Research Institute
An example of on-
going activities on
the claims-set
49
 Minimum Viable
eKYC Framework
(eID/KYC Expert
Group @ EC)
Nomura Research Institute
CIBA: Client Initiated Backchannel Authentication
-- O2O: Online Authentication for Offline Transaction
 Use-case 1: Customer authentication @ Call centers
50
Nomura Research Institute
51Trusted Personal Data Management Service (TPDMS)
- Consent Management
 Worked on by Japanese government.
 Ethical Assistance to combat “Over
consenting”
 Note: Cambridge Analytica incident
happened because of “over consent”
 Public comment period for the
certification scheme started Nov. 22.
 Expected to find the first certified service
by the end of March.
 ISO/IEC 29100, 29134, 29184, 27552
 Kantara Initiative Consent Receipt
Nomura Research Institute
Projected Landscape
52
Signed Claims
(Token)
Signed Claims
(Token)
ID Token
Access Token
IdP
Claims
Provider
Claims
Provider
Client
Keys
Keys
eKYC
Continuous
AuthN +
Risk Info
FAPI+CIBA
Consent Management
(Ethical Assistance)
Nomura Research Institute
52
Nomura Research Institute
OpenID in the digital ID landscape:
a perspective from the past to the future
Nat Sakimura (@_nat_en)
Research Fellow, Nomura Research Institute
Chairman of the board, OpenID Foundation
www.kuppingercole.com
_nat_en
https://nat.Sakimura.org/youtube.php
https://www.linkedin.com/in/natsakimura
https://nat.sakimura.org

More Related Content

PDF
Luiz eduardo. introduction to mobile snitch
Yury Chemerkin
 
PDF
Learning from Biometric Fingerprints to prevent Cyber Security Threats
Speck&Tech
 
PPTX
Cyber crime &_info_security
Er Mahendra Yadav
 
PPTX
SoDA v2 - Named Entity Recognition from streaming text
Sujit Pal
 
PDF
Wikileaks: secure dropbox or leaking dropbox?
hackdemocracy
 
PDF
Bar Camp 11 Oct09 Hacking
Barcamp Kerala
 
PPTX
IoTNEXT 2016 - SafeNation Track
Priyanka Aash
 
PDF
注意看,這些Windows的Potatoes太狠了! 解析5種基於MS-RPCE的攻擊手法.pdf
slideshare779123
 
Luiz eduardo. introduction to mobile snitch
Yury Chemerkin
 
Learning from Biometric Fingerprints to prevent Cyber Security Threats
Speck&Tech
 
Cyber crime &_info_security
Er Mahendra Yadav
 
SoDA v2 - Named Entity Recognition from streaming text
Sujit Pal
 
Wikileaks: secure dropbox or leaking dropbox?
hackdemocracy
 
Bar Camp 11 Oct09 Hacking
Barcamp Kerala
 
IoTNEXT 2016 - SafeNation Track
Priyanka Aash
 
注意看,這些Windows的Potatoes太狠了! 解析5種基於MS-RPCE的攻擊手法.pdf
slideshare779123
 

Similar to OpenID in the Digital ID Landscape: A Perspective From the Past to the Future (20)

PDF
fingerprinting blackhat by pseudor00t
pseudor00t overflow
 
PDF
Structural Biology in the Clouds: A Success Story of 10 years
AlexandreBonvin2
 
PDF
Cryptographic Hardware And Embedded Systems Ches 2005 7th International Works...
trzxfhwh6798
 
PDF
DEFCON 23 - Patrick Mcneil and Owen - sorry wrong number
Felipe Prado
 
PPTX
Fundamentals of Network security
APNIC
 
PPT
Sneak Peek into the Future with Prof. Indranil Sengupta, IIT Kharagpur
Priyanka Aash
 
PDF
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
Priyanka Aash
 
PDF
Drone Emprit: Konsep dan Teknologi
Ismail Fahmi
 
PPTX
WOTS2E: A Search Engine for a Semantic Web of Things
Andreas Kamilaris
 
PDF
WiFi Data Leakage by Solomon Sonya
EC-Council
 
PPTX
IoT Workshop Indianapolis
Mike Branstein
 
PDF
IPv6 Security Talk mit Joe Klein
Digicomp Academy AG
 
PPT
Semantically-Enabling the Web of Things: The W3C Semantic Sensor Network Onto...
Laurent Lefort
 
PPTX
Smart Defense: Strategic Approach to fight contemporary Security, Privacy & A...
Abhinav Biswas
 
PPTX
Are TOR Hidden Services really hidden? Demystifying HS Directory surveillance...
Abhinav Biswas
 
PDF
Secure Node Code (workshop, O'Reilly Security)
Guy Podjarny
 
PPTX
Web Security Jumpstart
Satria Ady Pradana
 
PPTX
Web Security Workshop : A Jumpstart
Satria Ady Pradana
 
PDF
Network Coding Applications Christina Fragouli Emina Soljanin
sungsuboedi
 
PDF
Listening at the Cocktail Party with Deep Neural Networks and TensorFlow
Databricks
 
fingerprinting blackhat by pseudor00t
pseudor00t overflow
 
Structural Biology in the Clouds: A Success Story of 10 years
AlexandreBonvin2
 
Cryptographic Hardware And Embedded Systems Ches 2005 7th International Works...
trzxfhwh6798
 
DEFCON 23 - Patrick Mcneil and Owen - sorry wrong number
Felipe Prado
 
Fundamentals of Network security
APNIC
 
Sneak Peek into the Future with Prof. Indranil Sengupta, IIT Kharagpur
Priyanka Aash
 
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
Priyanka Aash
 
Drone Emprit: Konsep dan Teknologi
Ismail Fahmi
 
WOTS2E: A Search Engine for a Semantic Web of Things
Andreas Kamilaris
 
WiFi Data Leakage by Solomon Sonya
EC-Council
 
IoT Workshop Indianapolis
Mike Branstein
 
IPv6 Security Talk mit Joe Klein
Digicomp Academy AG
 
Semantically-Enabling the Web of Things: The W3C Semantic Sensor Network Onto...
Laurent Lefort
 
Smart Defense: Strategic Approach to fight contemporary Security, Privacy & A...
Abhinav Biswas
 
Are TOR Hidden Services really hidden? Demystifying HS Directory surveillance...
Abhinav Biswas
 
Secure Node Code (workshop, O'Reilly Security)
Guy Podjarny
 
Web Security Jumpstart
Satria Ady Pradana
 
Web Security Workshop : A Jumpstart
Satria Ady Pradana
 
Network Coding Applications Christina Fragouli Emina Soljanin
sungsuboedi
 
Listening at the Cocktail Party with Deep Neural Networks and TensorFlow
Databricks
 
Ad

More from Nat Sakimura (20)

PPTX
FAPI and beyond - よりよいセキュリティのために
Nat Sakimura
 
PDF
170724 JP/UK Open Banking Summit English Translation
Nat Sakimura
 
PDF
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
Nat Sakimura
 
PPTX
Introduction to the FAPI Read & Write OAuth Profile
Nat Sakimura
 
PDF
金融 API 時代のセキュリティ: OpenID Financial API (FAPI) WG
Nat Sakimura
 
PPTX
ブロックチェーン〜信頼の源泉の民主化のもたらす変革
Nat Sakimura
 
PPTX
Future Proofing the OAuth 2.0 Authorization Code Grant Protocol by the applic...
Nat Sakimura
 
PDF
OpenID Foundation FAPI WG: June 2017 Update
Nat Sakimura
 
PDF
API Days 2016 Day 1: OpenID Financial API WG
Nat Sakimura
 
PPTX
Financial Grade OAuth & OpenID Connect
Nat Sakimura
 
PPTX
OpenID Foundation Foundation Financial API (FAPI) WG
Nat Sakimura
 
PPTX
OpenID Foundation Foundation Financial API (FAPI) WG
Nat Sakimura
 
PPTX
車輪は丸くなったか?~デジタル・アイデンティティの標準化動向とそのゴール
Nat Sakimura
 
PDF
OAuth SPOP @ IETF 91
Nat Sakimura
 
PPTX
Oidc how it solves your problems
Nat Sakimura
 
PPTX
Transient client secret extension
Nat Sakimura
 
PDF
Introduction to OpenID Connect
Nat Sakimura
 
PPTX
Nc 30 sakimura-distribution_0604
Nat Sakimura
 
PPTX
Smartphone Native Application OP
Nat Sakimura
 
PPTX
Open idとcyber空間
Nat Sakimura
 
FAPI and beyond - よりよいセキュリティのために
Nat Sakimura
 
170724 JP/UK Open Banking Summit English Translation
Nat Sakimura
 
Introduction to 
the FAPI Read & Write OAuth Profile - Jan 2018 Updates
Nat Sakimura
 
Introduction to the FAPI Read & Write OAuth Profile
Nat Sakimura
 
金融 API 時代のセキュリティ: OpenID Financial API (FAPI) WG
Nat Sakimura
 
ブロックチェーン〜信頼の源泉の民主化のもたらす変革
Nat Sakimura
 
Future Proofing the OAuth 2.0 Authorization Code Grant Protocol by the applic...
Nat Sakimura
 
OpenID Foundation FAPI WG: June 2017 Update
Nat Sakimura
 
API Days 2016 Day 1: OpenID Financial API WG
Nat Sakimura
 
Financial Grade OAuth & OpenID Connect
Nat Sakimura
 
OpenID Foundation Foundation Financial API (FAPI) WG
Nat Sakimura
 
OpenID Foundation Foundation Financial API (FAPI) WG
Nat Sakimura
 
車輪は丸くなったか?~デジタル・アイデンティティの標準化動向とそのゴール
Nat Sakimura
 
OAuth SPOP @ IETF 91
Nat Sakimura
 
Oidc how it solves your problems
Nat Sakimura
 
Transient client secret extension
Nat Sakimura
 
Introduction to OpenID Connect
Nat Sakimura
 
Nc 30 sakimura-distribution_0604
Nat Sakimura
 
Smartphone Native Application OP
Nat Sakimura
 
Open idとcyber空間
Nat Sakimura
 
Ad

Recently uploaded (20)

PPTX
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
 
PDF
Revolutionize Operations with Intelligent IoT Monitoring and Control
Rejig Digital
 
DOCX
Top AI API Alternatives to OpenAI: A Side-by-Side Breakdown
vilush
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PPTX
Smart Infrastructure and Automation through IoT Sensors
Rejig Digital
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
Chapter 2 Digital Image Fundamentals.pdf
Getnet Tigabie Askale -(GM)
 
PDF
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
PDF
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
PDF
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
PDF
agentic-ai-and-the-future-of-autonomous-systems.pdf
siddharthnetsavvies
 
PDF
This slide provides an overview Technology
mineshkharadi333
 
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
AVTRON Technologies LLC
 
PDF
CIFDAQ'S Market Insight: BTC to ETH money in motion
CIFDAQ
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PPTX
How to Build a Scalable Micro-Investing Platform in 2025 - A Founder’s Guide ...
Third Rock Techkno
 
PPTX
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira Júnior
 
PDF
Test Bank, Solutions for Java How to Program, An Objects-Natural Approach, 12...
famaw19526
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
 
Revolutionize Operations with Intelligent IoT Monitoring and Control
Rejig Digital
 
Top AI API Alternatives to OpenAI: A Side-by-Side Breakdown
vilush
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
Smart Infrastructure and Automation through IoT Sensors
Rejig Digital
 
Software Development Methodologies in 2025
KodekX
 
Chapter 2 Digital Image Fundamentals.pdf
Getnet Tigabie Askale -(GM)
 
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
agentic-ai-and-the-future-of-autonomous-systems.pdf
siddharthnetsavvies
 
This slide provides an overview Technology
mineshkharadi333
 
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
AVTRON Technologies LLC
 
CIFDAQ'S Market Insight: BTC to ETH money in motion
CIFDAQ
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
How to Build a Scalable Micro-Investing Platform in 2025 - A Founder’s Guide ...
Third Rock Techkno
 
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira Júnior
 
Test Bank, Solutions for Java How to Program, An Objects-Natural Approach, 12...
famaw19526
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 

OpenID in the Digital ID Landscape: A Perspective From the Past to the Future