Novell, CA Push to Secure Identity, Security in Cloud

What's one of the thorniest problems preventing secure and automated connections between internal IT infrastructure and external cloud service providers? Identity and authentication. Here's a look at the players trying to solve this riddle and what it all means to IT.

By Kevin Fogarty

Thu, August 06, 2009CIO

Two major identity management companies are forging ahead with products designed to satisfy what a cloud-computing consortium calls one of the trickiest problems preventing secure and automated connections between internal IT infrastructures and external service providers: identity and authentication.

Last week at The Burton Group's Catalyst Conference, Novell demonstrated a pre-release version of its Cloud Security Service, designed to synchronize login and authentication data between external clouds and internal systems without exposing internal security data.

At the same conference, CA demonstrated a product called Federation Manager, designed to provide single sign-on across several internal and external cloud or SaaS applications.

The problem the two are offering to solve is federated identity management—the need to connect and synchronize user data between external service providers and internal IT security measures.

[For timely cloud computing news and expert analysis, see CIO.com's Cloud Computing Drilldown section. ]

Without external services managed by identity management specialists such as Novell, CA and others, use of cloud-computing services could get snarled in a web of manual updates and processes that are too much trouble to implement and present far too much potential for error, according to Rich Mogull, a former Gartner analyst who now runs the Securosis, L.L.C security consultancy.

"Managing user authentication internally is not that big a deal, and it's not a big problem services you log into over the Web or FTP or whatever, because you're using a single user credential to sign in to something," Mogull says. "With SaaS and cloud environments you're extending your infrastructure, which essentially means you'd have to manually recreate all your users in that cloud and synchronize all the changes manually as well."

Whose Identity Answer Looks Promising?

Both Microsoft and VMware have promised their own takes on identity management for cloud computing, but a host of third parties is also beginning to crowd the market.

Relative small fry such as Radiant Logic, for example, touts its RadiantOne Identity and Context Virtualization Platform as a two-part solution to identity management. Its Identity Correlation and Synchronization Server aggregates and synchronizes identity data from end-user and cloud organizations, while its Virtual Directory Server provides authentication and access control.

Others, such as PingIdentity take a tighter focus, providing secure single sign-on to one or two SaaS applications at a time.

"People don't think of it that way, but SaaS is as much a cloud environment as other cloud services," Mogull says.

In addition to specific products, OASIS and other standards organizations have been working on security specifications such as the Security Assertion Markup Language (SAML), the Web Services Federation Language (WS-Federation), or earlier Liberty Identity Federation Framework (ID-FF).

CA

More from IT Drilldown « Back to Virtualization
CASE STUDY
Disaster Can Inspire Quick Move to Desktop Virtualization
In the wake of a hurricane, a Texas hospital system's IT group overcame user reluctance to virtualize desktop PCs. Here's a look at their journey and the thorny little issue that Citrix just solved a few weeks ago: USB port support. Full Story »

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization MarketSpace
 
SPONSORED LINKS
 

Removing Barriers To Better Server Virtualization Efficiency

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

Seven Design Requirements for Web 2.0 Threat Protection

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

A Clear View Toward Virtualization

White Paper: Right-Sizing Your Power Infrastructure

Taking a Seat at the Executive Table: The Reality of Virtualization

Server Consolidation: Leveraging the Benefits of Virtualization

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Managed Security for a Not-So-Secure World

White Paper: 5 Best Practices for Smartphone Support

White Paper: Next Generation Remote Infrastructure Management

Keeping Your Members Safe from Online Scams and Predators

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

eZine: A Roadmap to Reducing IT Complexity

 
 
RESOURCE CENTER