Microsoft says the perimeter defense surrounding networks today can be replaced with a distributed security model
LAS VEGAS – Microsoft last week laid out a future role for Active Directory in which it will employ user identity data to access applications and secure collaboration between users and partners on internal and external networks.
LAS VEGAS – Microsoft last week laid out a future role for Active Directory in which it will employ user identity data to access applications and secure collaboration between users and partners on internal and external networks.
Microsoft says the perimeter defense surrounding networks today can be replaced with a distributed security model that relies on sets of statements about a user, called a claim, to secure such tasks as verifying identity, validating payment or access, or personalizing services.
Users say this decentralized model has the ability to not only tighten security but cut costs for securing network resources. Those gains, however, will come with requirements for creating contractual and technological trust relationships among companies and among claim providers, and managing the risk inherent in those relationships
“As the perimeter goes away, the number of things you have to trust increases,” says Gil Kirkpatrick, CTO of NetPro, which develops Active Directory management tools. “Organizations will need to have policies for establishing trust with providers.”
Trust in the claims-based model has three components: the relying party, typically an application that requests the claim in order to decide what it can do for the user; the identity provider, which provides the claim; and the user, who decides what if any information he wants to provide to the application.
Microsoft is gearing up to build the infrastructure to support the model, the company says.
Directory provider v. Identity provider
“We are moving from being a directory provider to an identity provider,” says Stuart Kwan, director of program management for identity and access at Microsoft. He said the directory will take on a key role in Microsoft’s Identity Metasystem, a model for distributed identity architecture.
Coupled with an emerging technology Microsoft developed called Security Token Service (STS), a gateway to handle claims, Microsoft envisions an architecture that pushes claims out to applications that know how to interpret and act upon them.
Active Directory would become just one of many STS gateways in the distributed model.
Today, applications typically pull user access data from the directory to determine access rights to network services.
The push model not only provides information that is usable in many different places, it also affords network efficiencies, makes more identity more accessible to application developers, puts less stress on the directory, provides more flexibility in defining users and their rights, and gives the ability to federate identity with those outside the corporate network.
“You need extroverted systems, not introverted,” says Kim Cameron, Microsoft’s identity architect, who says the distributed model will replace today’s more rigid systems that are based on a single point of truth, typically a directory of user information.
He says identity systems that are rigid and cannot connect to other systems will become irrelevant and a competitive disadvantage.
The future is now
Some users see the value in the model and some are already moving in that direction using Active Directory Federation Services (ADFS), which shipped with Windows Server 2003 Release 2 in early 2006, as an identity federation hub. ADFS supports WS-Federation and WS-Trust, two standards key to running an STS.
There are also gateways from other vendors, such as IBM, Novell, Oracle, Sun and RSA that support the Security Assertion Markup Language (SAML), and technologies such as directories, Kerberos, meta-directories and certificate authorities that also can serve as claims transformers, adding data or validating existing information.
Version 2 of ADFS, which is scheduled to go into beta this summer and will ship next year, will be the first formal STS that Microsoft releases and will be coupled with Windows CardSpace, which shipped in Vista and is Microsoft’s claims container, and Windows Communication Foundation, a Web services middleware.
“We understand the claims model and we plan to use it,” says a directory and identity architect with a large financial services firm. “The model is a good general way to describe a user.” Today, the architect uses ADFS to exchange identity data with companies that provide outsourced applications to 150,000 of his users and to support partner access on an extranet.
The architect says establishing trust with those providers has been challenging. “Most of the time is spent on the phone getting them to implement what is needed,” he says. In the future, if the claims model is pervasive among partners, the architect says trust could be set up in a day.
“I think we can save a tremendous amount of money if we can deliver these business capabilities,” he said.
Today, ADFS and other technologies focus on providing identity services to Web applications, but the ultimate goal is for any application to accept claims, including old stalwarts such as Microsoft Word and Excel.
Relationships and identity
Microsoft envisions a model where claims not only include identity data, but express relationships such as group membership, provide statements saying, for example, that the user is a good credit risk, provide authorization for tasks such as downloading software, or validate how other claims were issued.
In the future, data from the directory would be transformed by the STS gateway into a properly formatted claim about the user and make the directory only one of many providers of user information.
“Claims transformation is the logic that takes incoming data about people in the organization and turns it into claims that are needed by the application,” says Microsoft’s Kwan.
That process is done by trusting the provider to validate the user’s information and not by providing the actual user data. For example, a users would never transfer their credit card numbers, they would have their banks issue claims validating their accounts and authorizing the transactions.
Kwan says a relationship between the data source and the STS means the application knows in advance the kind of data it will be getting.
“Now the application knows the claim sets, it knows the claims and can be prepared when those claims interact with it,” says Kwan.
He says Microsoft’s Identity Metasystem model would eventually provide even more capabilities, including role-based access control, the combination of roles and business processes, the ability for new claims such as location, and even more advanced authorization capabilities.
But he said the beauty of it all is that it builds on the directory infrastructure many companies have been rolling out and perfecting for years.
“This is not about throwing anything out,” Kwan says.




