• No results found

Enterprise Identity Management Reference Architecture

N/A
N/A
Protected

Academic year: 2021

Share "Enterprise Identity Management Reference Architecture"

Copied!
38
0
0

Loading.... (view fulltext now)

Full text

(1)

<Insert Picture Here>

Enterprise Identity Management Reference

Architecture

(2)

<Insert Picture Here>

Agenda

Introduction

• Virtualization • Access Management • Provisioning

Demo Architecture

• Reference Architecture • Provisioning

• Virtualization & Access Management (WebSSO)

• Solution Components

Scenarios

Conclusion

(3)

<Insert Picture Here>

(4)

Basic Concepts

What is Identity Management?

Identity Management (IdM) is an

integrated system of

business processes, policies and technologies

that

enable organizations to facilitate and

control their users'

access to critical online applications and

resources

— while protecting confidential personal and business information from unauthorized users.

(5)

Basic Concepts

Virtualization

A way to provide a consolidated view of distributed user

identity from multiple, often disparate, data sources without

having to construct an entire directory infrastructure.

Implemented in the form of middleware, a virtual directory is a

lightweight service that operates between applications and identity data. A virtual directory receives queries and directs them to the appropriate data sources…

(6)

Basic Concepts

Access Management

Web Access Management controls access to Web resources, providing: * Authentication Management

* Policy-based Authorization

* Audit & Reporting Services (optional) * Single sign-on Convenience

(7)

Basic Concepts

Enterprise Provisioning

Typically managed by a CIO, and necessarily involves human resources

and IT departments cooperating to:

•give users access to data repositories or grant

authorization to systems, networks applications and databases

based on a unique user identity, and appropriate for their use

hardware resources, such as computers, mobile phones and pagers.

As its most central responsibility, the provisioning process monitors

access rights and privileges to ensure the security of an

enterprise's resources and user privacy. As a secondary responsibility, it

ensures compliance and minimizes the vulnerability of

systems to penetration and abuse.

(8)

<Insert Picture Here>

(9)

Virtualization

LDAP v2/3.0 MS AD DB

Provisioning

Trusted Res.

App 1 App 2 App 3

Access Management (AAA) – WebSSO, FGA, Risk Management

Building Blocks of Architecture

(10)
(11)

Virtualization

Identity Information Proxy

3 User Repositories

• MS Active Directory – Employees

• Sun iPlanet Dir. Server – Contractors

• MyCompany CRM Database - Customers

Virtualized View: dc=mycompany,dc=ovd – LDAP

listener

Employees: ou=Employees,dc=mycompany,dc=ovd

Contractors: ou=Contractors,dc=mycompany,dc=ovd

Customers: ou=Customers,dc=mycompany,dc=ovd

(12)
(13)

<Insert Picture Here>

(14)

Oracle Identity Manager

Benefits

• Reduced administration cost

• Cost effective regulatory compliance

• Improved security

• Improved service level

Features

• Identity life-cycle management for the heterogeneous enterprise

• Approval and provisioning workflows

• Complete integration solutions: OOTB connectors & Adapter Factory

• Deep integration to ERP and HRMS

• Audit and compliance reporting and process automation

Oracle

Oracle

Identity Manager

(15)

Oracle Access Manager

Benefits

• Centralized and consistent security across heterogeneous environments

• Reduced administration cost

• Improved end user experience

Features

• Web single-sign-on

• Common policy management

• Multi-level, multi-factor authentication management

• Workflow driven self-service and delegated administration

• Web Services interfaces

Oracle Access

Oracle Access

Manager

(16)

Oracle Virtual Directory

Benefits

• Rapid application deployment

• Tighter controls on identity data

• Real-time identity information access

Features

• Modern Java & Web Services technology

• Virtualization, proxy, join & routing capabilities

• Superior extensibility

• Scalable multi-site administration

• Direct data access

Oracle

Oracle

Virtual Directory

(17)

<Insert Picture Here>

(18)

Userid: umut

First Name: umut

Last Name: ceyhan

Organization: Consultancy / Sales / HR / Finance

Employee Type: Full-Time / Part-Time / Contractor

User Title: Sales Consultant / Account Manager etc.

Location: Athens / London / Berlin

(19)

Identity Roles

•Consultancy Role (Members of Consultancy

Organization)

Target Resources:

MS Active Directory (OU=Consultancy)

MS Exchange (mail quota 5MB)

Oracle Internet Directory

Denied Resources: iPlanet Dir. Server

•Sales Role (Members of Sales Organization)

Target Resources:

MS Active Directory (OU=Sales)

MS Exchange (mail quota 10MB)

Oracle Internet Directory

(20)

Identity Roles

•Contractor Role (Contractors)

Target Resources:

Sun iPlanet Dir. Server

Denied Resources:

MS Active Directory

MS Exchange

Self Service Request Resource without Role:

(21)

On-boarding (JOIN)

• Reconciliation: HR – Consultant Role

Provision Targets: AD, Exchange, OID

• Reconciliation: HR – Contractor Role

Provision Targets: iPlanet Dir. Server

• Manual Creation of Customer Identity

On Sample CRM application

Demo

(22)

Walking through Virtualized Services

MS Active Dir., iPlanet, Oracle DB

Features of OVD

Demo

(23)

Access Management & WebSSO Services

Checking Central AuthN, AuthZ, Auditing Policies:

Employee Portal, Contractor Portal, Customer Portal

Brief info for integration with custom applications

WNA Integration for better user convenience

Demo

(24)

Change in User Profile (MOVE)

Trusted Recon for Identity Profile Attributes from HR

Organization Change: Consultancy



Sales

Role Change in HR: Contractor



Consultant Role

Demo

(25)

Self Service Request for Mobile Phone

Request for entitlements

Approval workflow for Mobile Phone

Review & Modify of requested entitlements by

Manager

Manual Provisioning workflow

Manual provisioning by Delegated Administrator

Demo

(26)

Off-boarding (LEAVE)

Status change in user information in HR

Automatical user deprovisioning

Demo

(27)

Reporting

Operational Reports: Who has what etc. 22

Historical Reports: Who had what etc. 15

Attestation

Configuration and Running: Mobile Phone Attest.

SOD features

Access policies

Demo

(28)

<Insert Picture Here>

(29)

Leader in Magic Quadrants

Magic Quadrant Disclaimer: The Magic Quadrant is copyrighted by Gartner, Inc. and is reused with permission. The Magic Quadrant is a graphical representation of a marketplace at and for a specific time period. It depicts Gartner's analysis of how certain vendors measure against criteria for that marketplace, as defined by Gartner. Gartner does not endorse any vendor, product or service depicted in the Magic Quadrant, and does not advise technology users to select only those vendors placed in the "Leaders" quadrant. The Magic Quadrant is intended solely as a research tool, and is not meant to be a specific guide to action. Gartner disclaims all warranties, express or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

(30)

Market Leader According To

“Oracle has established itself as Leader.”

- The Forrester Wave: Identity And Access Management, Q1 2008

Oracle reached the top of our

evaluation through a combination of the breadth, depth, interoperability, and packaging of its IAM features alongside the strategy and current state of market execution on its application-centric identity vision.

- The Forrester Wave: Identity And Access Management, Q1 2008

(31)

Service Oriented Security

(32)

Service Oriented Security

Business Drivers

Security is not an infrastructural issue any

more

NO BOLTING-ON SECURITY

Security Always at Application lifecycle

(33)

Service-Oriented Security

Fine Grained Authorization Security as a Service Identity Governance SOA Enabled Applications

Expected Solutions

(34)

<Insert Picture Here>

(35)
(36)

<Insert Picture Here>

(37)

Case Study – Swedish Police

• Significant cost avoidance (est. over $1M) for identity synchronization, workflow & administration functionality • Establishment of automated role & rule-based assignment of access privileges to all managed systems • Improvement of information quality by centralizing user records and cleaning existing data

• Detailed and easily accessible audit functionality

BUSINESS CHALLENGE

• Establish secure and centralized mgt of identities across multiple enterprise directories &

applications - incorporation of process workflows • End users and managers have poor visibility into

in-process and completed provisioning workflows • Protect against locally administered changes to

user entitlements directly w/in the target systems • Poor mgt of user certificates within RSA Keon

RESULTS

ORACLE SOLUTION

• Oracle Identity Manager selected over Novell in March 2005

• Highly flexible and extensible product

• Superior support for onboarding and analysis mechanisms for orphan account detection • Support for rollback/undo and escalation • Mature product with solid architecture • Flexibility and customizability

(38)

Case Study – Polish Police

• Single Clustered LDAP repository of all employees and authentication attributes • Single point of Identity creation (including PKI)

• 24/7 availability - local distributed LDAP’s with fallback to central server • Access Policies management – both central and delegated

BUSINESS CHALLENGE

• Highest requirement for security and availability • Need for strong encryption (PKI), delegated

management

• Support for local and central applications • Environment has “Non touchable” applications

and also is not a 100% reliable Network

RESULTS

ORACLE SOLUTION

• Oracle Identity and Access Management Suite • Oracle Internet Directory in Multimaster Cluster HA • Oracle VPD

• Oracle Consulting Services • Oracle Partner Services

References

Related documents

If in Movable signs, you should move the Moon to a sensitive zone (Don’t move the ascendant as said above). If it is a fixed sign depositor, move the Sun and forget about the Moon.

Verizon Enterprise Solution - Identity &amp; Access Management (professional and managed services) - Security Awareness Training.. - Security

Plastic strain profiles along a vertical line drawn on the outer surface of the specimen (dotted black line) at four different stages of the progress of the Lu¨ders bands in a

FuxiAgent FuxiAgent Job scheduling Resource request and response Node management and status collection Job submission APP Worker APP Worker APP Worker FuxiAgent

Considerando-se as plantas tal como realmente são, e não quanto Considerando-se as plantas tal como realmente são, e não quanto ao seu uso e propriedades

This clause gives loads and ranges of values for the factors used in proof of competence calculations when determining load effects. They result from gravity

This study was designed to determine if psychiatric screening tools could be used to predict NOK likely to have psychiatric illness as a consequence of the ICU experience.

In this study, the immediate maintenance effects on roughness and rutting of three interventions including overlay, overlay with an additional base layer and mill