{"id":5671,"date":"2013-02-04T16:41:52","date_gmt":"2013-02-04T16:41:52","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=cb8d76aed99e52b3d01d248a931518a5"},"modified":"2013-02-04T16:41:52","modified_gmt":"2013-02-04T16:41:52","slug":"single-sign-on-not-only-a-game-changer-but-a-money-maker","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/single-sign-on-not-only-a-game-changer-but-a-money-maker\/","title":{"rendered":"Single sign-on: not only a game-changer, but a money-maker!"},"content":{"rendered":"<p><em>by Brian Spector, CEO, <a href=\"https:\/\/certivox.com\/\">CertiVox <\/a><\/em><\/p>\n<p>Time was when SSO simply meant being able to automatically pass login credentials from one application to another, so that a user could work across several applications at once, without having to sign into each of them separately. Remember that?<\/p>\n<p>But a sea-change is taking place within SSO. The notion of logging in once in order to use many different applications is still at its core, but the <em>nature<\/em> of that login is changing radically. It is no longer sufficient to have the right login credentials. Instead, you have to be identified as the individual <em>to whom those correct login credentials rightfully belong<\/em>.<\/p>\n<p>As we put it in our paper <em>The Death of Username and Password<\/em>, &ldquo;On the internet, nobody cares if you&rsquo;re a dog &ndash; but they do need to know <em>which<\/em> dog you are!&rdquo;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Multi-factor magic<\/strong><\/p>\n<p>SSO&rsquo;s new-found robustness lies in multi-factor authentication &#8211; defined as something you have, plus something you know, plus an additional identifying factor. Think of an ATM &#8211; it authenticates you on the basis of something you have (your bank card), something you know (your PIN), and, additionally, the information contained on the card&rsquo;s magnetic strip. One is useless without the others.<\/p>\n<p>The challenge has always been in translating this into a software-based approach, enabling an online user to authenticate simply by using their computer. But this capability now exists. With nothing more complex than a browser, a PIN (entered using an on-screen pinpad) and an automatically generated cryptographic key, users can authenticate online <em>more securely<\/em> than when they use their ATM!<\/p>\n<p>The scalability potential here would previously have been unimaginable. Usernames and passwords, with their fixed 1-to-1 relationships, <a href=\"https:\/\/blog.certivox.com\/brian_spector\/2012\/07\/13\/if-it-ain\u2019t-there-they-cant-grab-it\/\">stored in a file, are intrinsically too risky<\/a> to scale (as LinkedIn&rsquo;s loss of over 6,000,000 logins to a hacker showed!)<\/p>\n<p>Multi-factor authentication, on the other hand, provided it is built on something called &ldquo;elliptic curve cryptography-based authenticated key agreement protocols&rdquo; &ndash; phew! &#8211; &nbsp;can be robust enough to scale to <em>many<\/em> <em>millions of users<\/em>. This is because it simultaneously authenticates personal identity, the identity of the browser <em>and<\/em> the identity of the devices being used, <em>without <\/em>recourse to<em> <\/em>a fixed 1-to-1 relationship. If one of these factors is incorrect or missing, authentication can&rsquo;t happen.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Scalable &nbsp;= saleable!<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>For this self-same reason &ndash; scalability &ndash; service providers and their partners are suddenly into a whole new ball game here. If scale is no barrier to <em>use<\/em>, then it&rsquo;s also no barrier to <em>sale<\/em>. So, excitingly, service providers and their partners now have the option of <em>reselling<\/em> the very same authentication services that they themselves use, so that their customers, in turn, can use them to secure their own end-users.<\/p>\n<p>This is one snowball effect that should leave all of us feeling warm inside! If you want to learn more, we&rsquo;re on Booth 704, or you can come to one of the technical or business sessions listed below:<\/p>\n<ul>\n<li>&middot;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>Technical Track<\/strong> &ndash; 4<sup>th<\/sup> Feb&nbsp; between 08:15-17:00 &ndash; <strong><\/strong><\/li>\n<li>&middot;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>Partner Theatre<\/strong> &ndash;&nbsp; 5<sup>th<\/sup> Feb&nbsp; at 12:45 &ndash; <em>Growing Your Revenues with Single Sign-On, Multi-Factor Authentication for the Cloud and Mobile<\/em>&nbsp; &ndash; Frank Boening (CertiVox)<\/li>\n<li>&middot;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>Developer Track<\/strong> &ndash; 6<sup>th<\/sup> Feb at 10:30 &ndash; <em>Extending APS packages with Single Sign-On <\/em>&ndash; Brian Spector and Gene Myers (CertiVox)<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>by Brian Spector, CEO, CertiVox<br \/>\nTime was when SSO simply meant being able to automatically pass login credentials from one application to another, so that a user could work across several applications at once, without having to sign into each of them &#8230;<\/p>\n","protected":false},"author":41,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-5671","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/5671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=5671"}],"version-history":[{"count":0,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/5671\/revisions"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=5671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=5671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=5671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}