As the cloud grows in scale and mass, cloud providers face an increasingly complex array of security and authentication issues. The Cloud Security Alliance (CSA) hopes to tackle some of those challenges by promoting a standards-based approach to handling large-scale cloud services, and particularly, mobile authentication within the cloud.
The organization has signed a Memorandum of Understanding with the Fast Identity Online (FIDO) group that has the two teams working together to promote a standardized approach to cloud services authentication. According to the CSA, providing scalable authentication from mobile devices to multiple, heterogeneous cloud providers is a crucial component toward the growth of cloud solutions. With mobile devices increasingly becoming the primary point of access to cloud services, authentication and identity standards must be able to handle the challenges of securing mobile connections to the cloud.
"The last 12 months has seen a shift in the cloud authentication landscape as more and more providers are looking to add additional layers of protection," said Jim Reavis, CEO, Cloud Security Alliance. "The security and usability challenges this creates means that a standards-based approach is the only practical direction.”
"FIDO shares many of the same aims as the Cloud Security Alliance," added Michael Barrett, president of the FIDO Alliance. "As we have been working on a common, industry standard for strong authentication, we have found ourselves engaged with cloud service providers who have clear requirements to deliver simple, strong authentication to meet their customers' needs. By working together, the CSA and the FIDO Alliance will be able to ensure that these emerging standards meet these needs."
The two groups share a number of common members, including Google, Microsoft, Nok Nok Labs, Ping Identity, RSA, SafeNet and Salesforce.com. The crossover is a testament to how closely intertwined cloud enablement, mobility and authentication have become, as well as members’ commitment to promoting standard-based solutions to both cloud and mobile authentication.
The CSA has established a Mobile Working Group that is specifically dedicated to meeting the challenges of mobile authentication and the cloud. For its part, FIDO is working on specifications to support a full range of authentication technologies like biometrics, including fingerprint and iris scanners as well as voice and face recognition. The group’s specifications are designed to work with existing communications standards and solutions like USB security tokens and smart cards.
Edited by
Cassandra Tucker