Leveraging OpenID To connect Vehicle to the Cloud
ALS 2017 Tokyo
Fulup Ar Foll Lead Architect fulup@iot.bzh
Leveraging OpenID To connect Vehicle to the Cloud ALS 2017 Tokyo - - PowerPoint PPT Presentation
Leveraging OpenID To connect Vehicle to the Cloud ALS 2017 Tokyo Fulup Ar Foll Lead Architect fulup@iot.bzh Who Are We ? Securing AGL V2C with OpenIDconnect May-2017 2 V2C Multiple Requirements Car to Cloud Telematics Car
ALS 2017 Tokyo
Fulup Ar Foll Lead Architect fulup@iot.bzh
May-2017
Securing AGL V2C with OpenIDconnect
2
May-2017
Securing AGL V2C with OpenIDconnect
3
May-2017
Securing AGL V2C with OpenIDconnect
4
Facebook, Paypal, …)
May-2017
Securing AGL V2C with OpenIDconnect
5
Cluster
Carte handling Localistion management POI
CAN GPS
Geopositioning Virtual Signal
Multi ECU & Cloud Aware Architecture
Entertainement
CAN-BUS Virtual Signal
Gyro, Acelerometer CAN-BUS LIN-BUS Engine-CAN-BUS ABS
Transport & ACL Head Unix
Direction Indication
Cloud
Log Analytics
No-SQL Engine Statistics & Analytics
Transport & ACL My Car Portal
Paiement Subcriptions Preference
Preferences & Custumisation
MongoDB Engine Paiement Service
Cluster Virtual Signal
Transport & ACL Navigation Service
Maintenance Portal
Know Bugs Maintenances Service Packs
May-2017
Securing AGL V2C with OpenIDconnect
6
May-2017
Securing AGL V2C with OpenIDconnect
7
May-2017
Securing AGL V2C with OpenIDconnect
8
Agent-2 Car Environement Agent-3 Engine Agent-4 Remote Signal
CAN Bus-A LIN Bus-A Audio CAN Bus-B Cluster-Unit
...
Smart City RVI Cloud
Transport + Acess Control
Navigation Service
Carte handling POI management etc...
Log/Supervision Service
Carte handling POI management etc...
MultiMedia Service
Media Player Radio Interface etc...
Distributed Application Architecture
MAC Enforcement Smack Cgroups NameSpace Containers
Start,Stop,Pause,Install,Remove,...
May-2017
Securing AGL V2C with OpenIDconnect
9
(Facebook, Google, Paypal, …), but also by many governments
May-2017
Securing AGL V2C with OpenIDconnect
10
Companies involve OpenId Development Contributors included a diverse international representation of industry, academia and independent technology leaders: AOL, Deutsche Telekom, Facebook, Google, Microsoft, Mitre Corporation, mixi, Nomura Research Institute, Orange, PayPal, Ping Identity, Salesforce, Yahoo! Japan, among other individuals and organizations.
May-2017
Securing AGL V2C with OpenIDconnect
11
Slide Credit Nov Matake, OpenID Japan
May-2017
Securing AGL V2C with OpenIDconnect
12
Slide credit axway.com
May-2017
Securing AGL V2C with OpenIDconnect
13
ws-client:tcp://hostname:port/MyAPI ws-server:tcp://hostname:port/MyAPI
Local Binding Remote Binding
(1) Request API (2) Request AuthZ (clientID@IDP, scope, ..)
Identity Agent
(3) Forward AuthZ Request
IDP (Identity Provider)
e.g. www.mycarportal.net
(4) Request AuthZ on behalf Remote (clientID, scope, ..)
Consent/Authentication User UI
(5) Redirect Authentication URL for User consent (7) User Consent/Authentication Interaction (7) Forward IDP redirect (9) Return AuthCode (10) Forward AuthCode (11) Forward AuthCode (12) Provide AuthCode (13) Receive User Info
May-2017
Securing AGL V2C with OpenIDconnect
14
(UsrID) Local User Profile
(AppID) Local App Profile
(FedID) IDP pseudonym
Identity Agent Data Structure
May-2017
Securing AGL V2C with OpenIDconnect
15
May-2017
Securing AGL V2C with OpenIDconnect
16
videos which are related to the installation of the project, last ones demonstrate protocols through a live debug session]
Warning: When searching for information you should be aware that OpenID- connect has 100% different from OpenID-v1/v2.