[WG-UMA] Cloud-enabled Enterprise API Security & UMA

Neil McEvoy neil.mcevoy at l5consulting.net
Tue Jun 19 06:24:29 EDT 2012


Wouldn't the use of something like OpenID Connect provide the
simplification? Then UMA is built on this?


> Dear Domenico,
>
> That's a very interesting enterprise use case. I will definitely have a
> closer look at it :)
>
> So far I was a bit skeptical that enterprise scenarios can be addressed
> by UMA appropriately since there is such a lot of commercial solutions
> around role-based access control, enterprise rights management, mobile
> device management, and corporate identity management.
>
> May be exactly this large amount of different solutions could be our
> advantage if we could simplify administrators' life with a UMA
> integration ... and, additionally, decrease the number of consultants
> you need to master all the dependencies above ;)
>
> Cheers and a nice weekend
> Mario
>
>
> Am 15.06.2012 16:25, schrieb Domenico Catalano:
>> Hi,
>>
>> here is a new scenario with possible implication for Cloud-enabled
>> Enterprise use case:
>>
>> The Organization X decides to extend own business leveraging a Cloud
>> computing platform and the mobile.
>> Basically, they decide to expose (RESTful) APIs for mobile application
>> integration, to allow external mobile apps access to the platform.
>> They protect the API platform using CopMonkey's Authorization Manager.
>> They develop a mobile app that use the API platform.
>> A Requesting Party (Bob) downloads and installs the mobile app on his
>> smartphone.
>> Any interaction with the API platform will be authorized by the AM,
>> which is able to verify the claims provided by the Requester (on behalf
>> of the Requesting Party).
>>
>> Does it make sense ?
>>
>> Cheers,
>> Domenico
>>
>>
>>
>>
>>
>>
>> _______________________________________________
>> WG-UMA mailing list
>> WG-UMA at kantarainitiative.org
>> http://kantarainitiative.org/mailman/listinfo/wg-uma
>
> --
> Mario Hoffmann (Dipl.-Inform.)
> Head of Department "Secure Services & Quality Testing"
>
> ** Please make note of our new name Fraunhofer AISEC,
>     formerly Fraunhofer SIT-Munich
>
> Fraunhofer Research Institution AISEC
> Parkring 4, 85748 Garching near Munich (Germany)
>
> WWW:  http://www.aisec.fraunhofer.de
> Tel:  +49 (0)89/ 322 9986-177 (fixed)
>        +49 (0)151/121 68100 (mobile)
> _______________________________________________
> WG-UMA mailing list
> WG-UMA at kantarainitiative.org
> http://kantarainitiative.org/mailman/listinfo/wg-uma
>


-- 
Neil McEvoy
Founder and President
Level 5 Consulting Group
http://L5consulting.net



More information about the WG-UMA mailing list