OpenID Foundation Workshop
April 15, 2024
| openid.net
1
1
Nat Sakimura – OpenID Foundation Chairman
Welcome
2
Note Well Statement
NOTICE: An OpenID IPR contribution agreement is not mandatory in order to participate in this workshop. If participants provide feedback, they (on behalf of themselves and any organization they represent) are deemed to agree that: Attendee gives the OIDF the right to use their feedback and comments. Attendee grants to the OpenID Foundation a perpetual, irrevocable, non-exclusive, royalty-free, worldwide license, with the right to directly and indirectly sublicense, to use, copy, license, publish, and distribute and exploit the Feedback in any way, and to prepare derivative works that are based on or incorporate all or part of the Feedback for the purpose of developing and promoting OpenID Foundation specifications and enabling the implementation of the same. Also, by giving Feedback, attendee warrants that they have rights to provide this feedback. Please note that feedback is not treated as confidential, and that OpenID Foundation is not required to incorporate feedback into any version of an OIDF specification.
***Please note that the workshop is being recorded and will be published to the OIDF website
3
Thank you!
4
Workshop Agenda
5
TIME | TOPIC | PRESENTERS |
12:30-12:35pm | Welcome | Nat Sakimura |
12:35-12:50pm | eKYC & IDA WG Update | Mark Haine |
12:50-1:05pm | AuthZEN WG Update | David Brossard & Omri Gazitt |
1:05-1:20pm | AB/Connect WG Update | Michael Jones |
1:20-1:35pm | FAPI WG Update | Nat Sakimura |
1:35-1:50pm | MODRNA WG Update | Bjorn Hjelm |
1:50-2:05pm | DCP WG Update | Kristina Yasuda & Joseph Heenan |
2:05-2:20pm | Shared Signals WG Update | Tim Cappalli |
2:20-2:30 | BREAK |
|
5
Workshop Agenda
continued
6
TIME | TOPIC | PRESENTERS |
2:20-2:30 | BREAK |
|
2:30-2:40 | OIDF Certification Program Update + Roadmap | Joseph Heenan |
2:40-2:55pm | Death & the Digital Estate Community Group | Dean Saxe |
2:55-3:05pm | Sustainable & Interoperable Digital Identity (SIDI) Hub Update | Gail Hodges |
3:05-3:30pm | Listening Session: Post-Quantum Computing & Identity. What are your concerns? What is OIDF’s role? | Gail Hodges, Nancy Cam-Winget, John Bradley, Rick Byers, Andrea D’Intino |
3:30-3:55pm | Listening Session: AI & Identity. What are your concerns? What is OIDF’s role? | Nancy Cam-Winget, Kaelig Deloumeau-Prigent, Mike Kiser, Geraint Rogers |
3:55-4:00pm | Closing Remarks | Nat Sakimura |
6
OpenID Foundation
Work Group Updates
7
Work Group Focus
Mission & Vision
Security Analysis
Conformance
AB/Connect
FAPI
Digital Credentials Protocols
AuthZen
Shared
Signals
eKYC
& IDA
MODRNA
iGOV
Policy
Focus today
8
Mark Haine
eKYC & IDA Work Group
9
eKYC & IDA Working Group Overview
Objective of the Working Group
Published Specifications
Working group deliverables since last workshop
OpenID Connect for Identity Assurance 1.0 – ID4
OpenID Connect for Identity Assurance 1.0
OpenID Identity Assurance schema definition 1.0
OpenID Attachments 1.0
OpenID Connect for Identity Assurance Claims Registration 1.0
SPLIT
10
eKYC & IDA Working Group Progress - IDA drafts
"OpenID Connect for Identity Assurance 1.0" - openid-connect-4-identity-assurance.md
"OpenID Identity Assurance schema definition 1.0 draft" - openid-ida-verified-claims.md
"OpenID Connect for Identity Assurance Claims Registration 1.0 draft" - openid-connect-4-ida-claims.md
With particular thanks to Taka, Kosuke, Nat, and Dima for their detailed review and Hodari for hard work on PRs
OpenID Connect for Identity Assurance 1.0
OpenID Identity Assurance schema definition 1.0
OpenID Connect for Identity Assurance Claims Registration 1.0
11
eKYC & IDA Working Group Progress - other Activities
Next Steps
12
Working Group external achievements
13
David Brossard, Omri Gazitt
AuthZEN Work Group Update
14
Motivation: why authorization is critical
15
Motivation: why standards are needed
16
Proposed Working Group Purpose
Authorization Protocols and Formats
Intra-org
Inter-org
Between components
Between systems
17
AuthZEN WG Scope and Objectives
18
Deliverables and Specifications
19
Anticipated Audience or Users
20
Proposers
Co-Chairs
21
Where to find us
22
April 2024 Update
23
Michael B. Jones
OpenID Connect Work Group
24
OpenID Connect Working Group Overview
Initiatives of the Working Group
25
OpenID Connect Working Group Specifications
Final Specifications
Specifications Under Development
26
Working Group Progress & Opportunities
Working group deliverables since last workshop in October 2023
Challenges and opportunities facing the working group
27
ISO Publicly Available Submission (PAS) for OpenID Connect
Submission of OpenID Connect specs for republication by ISO/IEC JTC 1
28
Working Group Roadmap
DATE | DELIVERABLES | ASPIRATIONS | NOTES |
Q2 2024 | Final OpenID Federation Implementer’s Draft | Finish bringing text up to OpenID Connect quality standards | Can discuss specifics this week |
Q3 2024 | ISO PAS specifications for OpenID Connect published | Make OpenID Connect specs available to those with treaty-based procurement processes | ISO publication expected after conclusion of five-month ballot period |
Q4 2024 | Final Federation Spec | Trust establishment for broad set of use cases | Having Final spec will accelerate deployments |
29
Tenth Anniversary of OpenID Connect
30
What the Working Group Plans to Accomplish at IIW This Week
What sessions do you plan to hold?
What hallway/table conversations do you want to have?
What demos are you presenting?
Logistics:
31
Nat Sakimura
FAPI Work Group Update
32
Working Group Overview
Objective of the Working Group
Some notable aspects
33
Working Group Progress & Opportunities
Published Specifications
34
Working Group Progress & Opportunities
Implementer’s Drafts
35
Working Group Progress & Opportunities
White Papers
Formal Analysis
Certification
36
Working Group Roadmap
DATE | DELIVERABLES | ASPIRATIONS | NOTES |
Q2 2024 | | FINAL for FAPI 2.0 Security Profile | |
Q3 2024 | | FINAL for FAPI 2.0 Message Signing | |
37
Bjorn Hjelm
MODRNA Work Group
38
Working Group Overview
Objective of the Working Group
Published Specifications
Specifications Under Development
39
Working Group Progress & New Opportunities
Preparing the MODRNA Discovery Profile to Implementer’s Draft review and vote.
The Working group is working on new documents including CIBA Errata, CIBA Extension and IETF draft to an IANA registry for CIBA endpoint parameters as well as discussions to create drafts for (3GPP) MCX Profile and profile for (GSMA) RCS Verification Authority API.
The Working Group is actively engaged in outreach activities including the following:
40
Current Working Group Roadmap
DATE | DELIVERABLES | ASPIRATIONS | NOTES |
Q2 2024 |
|
|
|
Q3 2024 |
| | |
Q4 2024 |
| | |
41
Kristina Yasuda
Joseph Heenan
Digital Credentials Protocols (DCP)
Work Group Update
42
OpenID for Verifiable Credential Issuance
OpenID for Verifiable Credentials
Issuer
(Website)
Verifier
(Website)
Wallet
(user’s device, cloud or hybrid)
Issue Credentials
Present Credentials
Self-Issued OP v2
OpenID for Verifiable Presentations
OpenID for Verifiable Presentations over BLE
User Interactions
Security and Trust in OpenID for Verifiable Credentials
OID4VC High Assurance Interoperability Profile (HAIP)
43
Progress
44
Implementations
45
Next Steps
46
Tim Cappalli
Shared Signals Work Group Update
47
Problem: Authentication only happens at the time of login
Shared Signal Framework
End User/Device
Session
Account
Realtime Protection
Security Signal
Continuous Monitoring
Sharing Intelligence
Robotic Remediation
Continuous Mitigation
48
Shared Signal Framework Technical Overview
PUSH based SET Delivery RFC 8935
Security Event Token (SET) RFC 8417
Sub-ID for SET
POLL based SET Delivery RFC 8936
JSON Web Token RFC 7519
JSON Web Key RFC 7517
JSON Web Encryption RFC 7516
CAEP :- Session control
RISC :- Account protection
Secure multi stream Webhook communication layer
IETF technology standards used by the SSF Framework
49
Two New Chairs
Shayne Miel
Cisco
Sean O’Dell
The Walt Disney Company
50
The Chairs
Atul
Tim
Shayne
Sean
51
Working Group Activities Overview
Specifications Under Development
Interoperability
Developer Events
52
Industry Updates and Progress
Third party Identity providers can now connect to Apple Business Manager by supporting OpenID Connect, SCIM and OpenID SSF. Currently Apple supports Microsoft Entra ID, Google Workspace and will open to other Identity providers.
Okta's account security events (SSF) will allow Okta to notify Apple Business Manager whenever an important account security event (such as password reset) occurs.
Launch of a free, non-commercial online Continuous Access Evaluation Protocol / Profile (CAEP) Transmitter
The mechanism for this conversation is continuous access evaluation (CAE), an industry standard based on Open ID Continuous Access Evaluation Profile (CAEP)
“These protocols (RISC and CAEP) enable identity providers and relying parties to exchange signaling around risk of particular sessions. Broad support for and development of these standards in the enterprise ecosystem will enable a variety of security use cases, ranging from limiting access to managed devices to quickly revoking access when accounts are compromised.”
WG submitted a set of recommendation to the UK Gov.
Developers guide to implementing SSF. Very through and easy to understand with set of sample codes for developers.
53
What’s new in SSF ID 2 : Multi Stream Support Improved
Subjects
Transmitter Metadata
Streams
Stream Events
Authorization Scheme
54
SSF Interoperability Event at Gartner IAM Summit, London
55
CAEP Interoperability Event Results
Participants | Transmitter | Receiver |
| ✅ | ✅ |
| ✅ | ✅ |
| ✅ | ✅ |
| ✅ | ✅ |
| | ✅ |
| ✅ | ✅ |
| ✅ | ✅ |
| ✅ | |
Demo Session In Action
Interop participants
56
How to participate
57
BREAK
10-minutes
Visit: www.OpenID.net
58
Joseph Heenan
Certification Program Update
59
Certification Overview
Objective
Current Certification Programs
Tests Under Development
Future Roadmap
60
Progress & Opportunities
Deliverables last 6 months
USA & Canada OpenBanking regulatory updates due to drop during 2024
61
Dean Saxe
Death & the Digital Estate Community Group
62
63
64
65
The Problem
66
The Problem
67
The Problem
68
The Problem
69
The Problem
70
The Problem
71
The Problem is International
72
The Digital Estate Community Group
73
The Digital Estate Community Group
74
The Digital Estate Community Group
75
The Digital Estate Community Group
76
The Digital Estate Community Group
77
The Digital Estate Community Group
78
The Digital Estate Community Group
79
The Digital Estate Community Group
80
Gail Hodges
Sustainable & Interoperable Digital Identity (SIDI) Hub Update
81
SIDI Hub
Strategy
Ben, Ian, Mike, Gail, Mark, Nick Thorne
Gail
82
SIDI Hub OIDF Board Update
Nat
Summits
Workstreams
Staffing
Funding
$220k direct + ~$43 indirect
= ~$263k Total Funding (OIDF 19%)
Structure
Communications
83
DRAFT: OIDF’s KPIs for SIDI Hub (Subgroup)
| 1Q 2024 | 2Q 2024 | 2H 2024 |
1.Community thought leadership |
|
|
|
2. OIDF WG & CG benefits |
|
|
|
3. New strategic relationships |
|
|
|
4. Optimize OIDF investment |
|
|
|
84
OIDF/ SIDI Advisor Nick Thorne
Gail
EC resolution to retain Nick for 3months, to revisit in June Board (SIDI Hub funded extension and/or OIDF extension)
85
Gail Hodges, Nancy Cam-Winget, John Bradley, Rick Byers and Andrea D’Intino
Listening Session: Post-Quantum Computing & Identity
86
Listening Session: PQC + Identity
Key Questions:
What concerns you about the intersection of AI + Post Quantum Cryptography? What is OIDF’s role (if any) to support the community?
1) Andrea intro Slides: https://docs.google.com/presentation/d/16g1NqI_g_d3oDljs1vY4hE_chXpJHDZvj77ecTi-KmM/edit#slide=id.p
Discussants:
87
Gail Hodges, Kaelig Deloumeau-Prigent, Mike Kiser, and Geraint Rogers
Listening Session: AI & Identity
88
Listening Session: AI + Identity
Key Questions:
What concerns you about the intersection of AI + Identity? What is OIDF’s role (if any) to support the community?
1) Deutche Telekom July 2023, 2.4M Vies: https://youtu.be/F4WZ_k0vUDM?si=nVyN7lO1kr6DZuNo
2) LLM Prompt
Discussants:
(Geraint, Timothy M reposts, Deutche Telekom July 2023) https://www.linkedin.com/posts/geraint-rogers-9953b21_thepowerofai-privacy-cybersecurity-activity-7130947125244252161-HmzE?utm_source=share&utm_medium=member_deskto
89
LLM Prompt to implement OIDC in JS
[Other steps inbetween…. but no step to use OIDF tests or certify]
xsxs
xsxs
xsxs
90
Closing Remarks &
Open Q&A
Visit: www.OpenID.net
91
Thank you.
Visit: www.OpenID.net
92