• Home
  • Blog
  • About
  • Contact
CloudAve
Software in Business. The Business of Software.
  • Business
    • Analysis
    • Entrepreneurship
    • Marketing
    • Strategy
    • Small business
  • Technology
    • Application Software
    • Infrastructure
    • Open Source
    • Mobile
    • Platforms
    • Product reviews
    • Security
  • Misc
    • Design
    • Just for fun
    • Trends & Concepts
  • Sponsors
Browse: Home / AuthN, AuthZ and Gluecon

AuthN, AuthZ and Gluecon

By Eric Norlin on April 26, 2010

As I’ve mentioned many times in the past, I’m not an engineer. Still, along the way, even the non-engineers like me pick up some tidbits of knowledge. One of the things I learned in my years spent in identity management (”IdM”) is the difference between Authentication (”AuthN”) and Authorization (”AuthZ”). And, as it turns out, that learning is useful.

Take the confusion over OAuth and OpenID. OAuth is “Open Authorization,” while OpenID is an authentication mechanism. While AuthZ and AuthN sometimes feel very similar, they’re actually a pretty different operation.

Authentication is about verifying a person as they login to an application. Authentication can be 1 factor, 2 factor, 9 factor, whatever. It could require DNA if it feels like it. OpenID is about maintaining the “authenticated state” across different sites — what all of us call single sign on (SSO).

Authorization is about granting the ability to access resources or use an application without requiring that the authenticated state be passed across the websites. You LOG IN to twtiter. But you don’t have to log in to a twitter app that wants to gain authorization to your twitter data. You, the authenticated person, *authorize* the application to have access to those resources. The app doesn’t need you to authenticate. And the state of your authentication doesn’t need to persist across the two sites. Hence, the oft-used analogy of the “valet key” being compared to OAuth — it “authorizes” the valet to use certain resources in the car (drive it in a given radius, etc), but it does not “authenticate” the valet to be “logged in” to the car.

As this article points out, OAuth is becoming THE big deal in identity management (in the consumer space). And rightfully so. Authentication is important, but *authorization* can be leveraged. Authorization is built for network effects.

Not that authentication isn’t necessary. It is. It’s just not as sexy.

Fortunately, you can get both sides of the equation at Gluecon, as we’ll be covering OAuth (including the new Web Access Resource Protocol work), and the whole SAML/OpenID complex. If you’re building cloud or web apps, you simply have to understand the implications of all sides of this one. And you can get that at Glue.

We’re 30 days from the conference, so don’t delay — use “twit2″ to take 10% off of your registration, and register today.

(Cross-posted at Glue )

Share:

  • Twitter
  • Facebook
  • LinkedIn
  • Google +1
  • StumbleUpon

Posted in General | Tagged authn, authz, conferences, gluecon, oauth, openid

Eric Norlin

« Previous Next »
feed mail facebook twitter linkedin

Sponsor Posts

Why ERP Is Out, and Unified Finance and HR Is In
Why ERP Is Out, and Unified Finance and HR Is In
20 Motivational Sales Quotes to Amp You Up!
20 Motivational Sales Quotes to Amp You Up!
4 Ways to Solve Customer Service Issues
4 Ways to Solve Customer Service Issues
The Cloud Company: People or Money?
The Cloud Company: People or Money?
  • Tags
  • Calendar
  • Comments

accy2 amazon Amazon Web Services android Apple aws briefs cloud cloud computing collaboration conferences Enterprise enterprise 2.0 Entrepreneurship facebook google humor iaas IBM innovation insights integration ipad iphone marketing microsoft netsuite open source openstack paas saas salesforce.com sap Security Social Business social media software as a service Startup Advice startups Tech Market Analysis twitter vc funding venture capital vmware xero

June 2013
M T W T F S S
« May    
 12
3456789
10111213141516
17181920212223
24252627282930
  • Greg Hodgkiss: Hi Chris. Data Insurance for...
  • Greg Hodgkiss: Hi Scott. Cloud Insurance is...
  • James cage: Interesting take on the need to...
  • I am OnDemand: MadeiraCloud, a new cloud...
  • Geek Minds Think Alike: in his presentation, at...
  • Axel: the Verizon issue is big enough alone for...
  • hell wit ms: Bill Gates doesn’t run the...
  • Chris Yeh (@chrisyeh): I’m astounded the...
  • Zoli Erdos: Kevin, It’s a huge book,...
  • Kevin Dougan: Can you re-post the link to the...
  • Alex: I think it is important to make any...
  • Rakesh Malhotra: Excellent point Richard and I...
  • Richard Muirhead (@richardmuirhead): Hi...
  • Jamie Smith: It’s so sad that we have to have...
  • john golke: great article Rakesh.

Archives

Authors

  • Adron Hall
  • Ben Kepes
  • Chirag Mehta
  • Chris Yeh
  • Christian Reilly
  • Colin Berkshire
  • Dan Morrill
  • Dan Pepper
  • Dave Michels
  • Dave Roberts
  • Hutch Carpenter
  • Jacob Morgan
  • Jarret Pazahanick
  • Jason M. Lemkin
  • Jeffrey Vocell
  • Joel York
  • John Taschek
  • Krishnan Subramanian
  • Mark Fidelman
  • Mark Suster
  • Martijn Linssen
  • Michael Krigsman
  • Ofir Nachmani
  • Paul Miller
  • Quinton Wall
  • Rakesh Malhotra
  • Randy Bias
  • Sadagopan
  • Scott Bils
  • Zoli Erdos
Sponsored by: