• Home
  • Blog
  • About
  • Contact
CloudAve
Software in Business. The Business of Software.
  • Business
    • Analysis
    • Entrepreneurship
    • Marketing
    • Strategy
    • Small business
  • Technology
    • Application Software
    • Infrastructure
    • Open Source
    • Mobile
    • Platforms
    • Product reviews
    • Security
  • Misc
    • Design
    • Just for fun
    • Trends & Concepts
  • Sponsors
Browse: Home / AuthN, AuthZ and Gluecon

AuthN, AuthZ and Gluecon

By Eric Norlin on April 26, 2010

As I’ve mentioned many times in the past, I’m not an engineer. Still, along the way, even the non-engineers like me pick up some tidbits of knowledge. One of the things I learned in my years spent in identity management (”IdM”) is the difference between Authentication (”AuthN”) and Authorization (”AuthZ”). And, as it turns out, that learning is useful.

Take the confusion over OAuth and OpenID. OAuth is “Open Authorization,” while OpenID is an authentication mechanism. While AuthZ and AuthN sometimes feel very similar, they’re actually a pretty different operation.

Authentication is about verifying a person as they login to an application. Authentication can be 1 factor, 2 factor, 9 factor, whatever. It could require DNA if it feels like it. OpenID is about maintaining the “authenticated state” across different sites — what all of us call single sign on (SSO).

Authorization is about granting the ability to access resources or use an application without requiring that the authenticated state be passed across the websites. You LOG IN to twtiter. But you don’t have to log in to a twitter app that wants to gain authorization to your twitter data. You, the authenticated person, *authorize* the application to have access to those resources. The app doesn’t need you to authenticate. And the state of your authentication doesn’t need to persist across the two sites. Hence, the oft-used analogy of the “valet key” being compared to OAuth — it “authorizes” the valet to use certain resources in the car (drive it in a given radius, etc), but it does not “authenticate” the valet to be “logged in” to the car.

As this article points out, OAuth is becoming THE big deal in identity management (in the consumer space). And rightfully so. Authentication is important, but *authorization* can be leveraged. Authorization is built for network effects.

Not that authentication isn’t necessary. It is. It’s just not as sexy.

Fortunately, you can get both sides of the equation at Gluecon, as we’ll be covering OAuth (including the new Web Access Resource Protocol work), and the whole SAML/OpenID complex. If you’re building cloud or web apps, you simply have to understand the implications of all sides of this one. And you can get that at Glue.

We’re 30 days from the conference, so don’t delay — use “twit2″ to take 10% off of your registration, and register today.

(Cross-posted at Glue )

Share:

  • Twitter
  • Facebook
  • LinkedIn
  • Google +1
  • StumbleUpon

Posted in General | Tagged authn, authz, conferences, gluecon, oauth, openid

Eric Norlin

« Previous Next »
feed mail facebook twitter linkedin

Sponsor Posts

The Next Revolution for Finance -- Embedded Analytics
The Next Revolution for Finance -- Embedded Analytics
4 Ways Customer Service Teams Can Help During a Crisis
4 Ways Customer Service Teams Can Help During a Crisis
Want to Boost CRM Adoption? Eliminate These 4 Obstacles
Want to Boost CRM Adoption? Eliminate These 4 Obstacles
HR Tech Vendors: Who’s Out There?
HR Tech Vendors: Who’s Out There?
  • Tags
  • Calendar
  • Comments

accy2 amazon android Apple aws briefs cloud cloud computing collaboration conferences Enterprise enterprise 2.0 Entrepreneurship facebook google humor iaas IBM innovation insights integration ipad iphone marketing microsoft netsuite open source openstack paas platform services saas salesforce.com sap Security Social Business social media software as a service Startup Advice startups Tech Market Analysis twitter vc funding venture capital vmware xero

May 2013
M T W T F S S
« Apr    
 12345
6789101112
13141516171819
20212223242526
2728293031  
  • Ashoo tuli: Very informative.
  • Jarret Pazahanick: Thanks for the comment...
  • Hiks: Thanks Jarret. It’s really a very...
  • Vijay: Good Article… I have been working...
  • jarretpazahanick: Thanks Joost for the kind...
  • joost van assen: That is very good information...
  • jarretpazahanick: Volker – Here is a...
  • Chal: Hi Jarret, Could you please advise on how...
  • Volker Kuecherer: Do you have any information...
  • Experiencia Cloud (BETA): What Makes Cloud...
  • Abhishek: I see nothing wrong with rewarding...
  • CloudAve: always insightful Mark Suster...
  • fred zimny's serve4impact: See on...
  • CloudAve: 5 Key Essentials of Cloud Workloads...
  • jasonlkn: It’s natural … especially...

Archives

Authors

  • Adron Hall
  • Ben Kepes
  • Chirag Mehta
  • Chris Yeh
  • Christian Reilly
  • Colin Berkshire
  • Dan Morrill
  • Dan Pepper
  • Dave Michels
  • Dave Roberts
  • Hutch Carpenter
  • Jacob Morgan
  • Jarret Pazahanick
  • Jason M. Lemkin
  • Jeffrey Vocell
  • Joel York
  • John Taschek
  • Krishnan Subramanian
  • Mark Fidelman
  • Mark Suster
  • Martijn Linssen
  • Michael Krigsman
  • Ofir Nachmani
  • Paul Miller
  • Rakesh Malhotra
  • Randy Bias
  • Sadagopan
  • Scott Bils
  • Zoli Erdos
Sponsored by: