Introduction: Bring-Your-Own-Identity (henceforth “BYOI”) is one of the emerging trends among organizations which are in process of streamlining its IT governance solutions to make more flexible and mobile in nature. BYOI addresses the problem of registering/remembering multiple credentials for different applications and suggests to adopt/leverage open industry standards by means of integrating with social networking sites (E.g. Facebook, Google, Yahoo etc.).
Background and Business Driver: Bring-Your-Own-Device (BYOD) policy iss quite well known to all as this allows employees to bring in personalized devices like smart phones, tablet, even laptops to their workplace to access secure company information and applications. BYOD was successful as it resulted many advantages like increase in productivity, increased …show more content…
The basic principle on which OpenID works is called “decentralized authentication” and its primary purpose is to establish “who you are”. It barres the third-party applications intending to integrate with OpenID supported identity provider from writing its own site-specific authentication logic. In this way, a user can login to multiple OpenID enabled website using a single existing social site userid/password combination. Under the hood, OpenID provider grants an URL like unique identifier to its users (E.g. Yahoo OpenID identifier would look like https://me.yahoo.com/a/uaStkHdgs_7BxVAc1FofG0xxxxxxxxxxxxxx.xxxxxck-) and the identifier is then matched once user authenticates to OpenID provider using the provider specific user credential. Point to be noted here, user would need to enter user ID and password in the provider Sign In page (say Yahoo! Sign In page) ONLY, not in any other application login page. Therefore, no website will ever see your password. Some market leading OpenID providers are Google, Yahoo!, Microsoft