Ping broadening scope of identity wares

News
Jun 5, 20063 mins

PingIdentity this week is expected to add support for additional identity protocols to its software and introduce a new middleware product to tie Web-based applications into corporate authentication deployments.

The two pieces of authentication software are designed to help users integrate their identity infrastructures with those of partners and make it easier to support many forms of authentication, including two-factor authentication that is becoming a requirement for the online banking industry.

With the introduction of PingFederate 4.0, the company is adding support for Versions 1.0 and 1.1 of the Security Assertion Markup Language (SAML), a standard for exchanging authentication and authorization information. PingFederate already supports SAML 2.0. Ping also is adding support for WS-Federation, which was developed by IBM and Microsoft, and is supported in Microsoft’s Active Directory Federation Services technology that shipped with Windows Server 2003 Release 2 and IBM’s Tivoli Federated Identity Manager.

In July, Ping plans to ship PingLogin, Java-based middleware that helps companies tie their consumer-based Web applications into their overall authentication, single sign-on and identity federation infrastructure. The software centralizes the use and management of many forms of authentication, including biometrics and one-time passwords. Instead of building authentication per application, users can rely on PingLogin as a hub that provides access control.

Users already plan to roll out PingFederate 4.0 and its expanded protocol support to broaden their ability to integrate with partners and customers.

“Our situation is that we have to be as standards compliant as possible,” says Terry Field, manager of software development for Infohrm, a provider of online human resources applications in Australia. Field says because Infohrm is a small firm serving a number of very large companies, it cannot dictate what identity federation technology they use. “The advantage of using a tool like PingFederate is that it reduces the barrier to usage, it drives up the usability of our tool,” he says. Field says he chose Ping over about a dozen other vendors because it required little code change to integrate the technology into its application.

Besides expanded protocol support, PingFederate 4.0 offers a configuration wizard based on the protocols deployed, delegated administration based on a set of four user roles, logging and auditing of administrative actions, and an upgrade engine. Ping competes with IBM, Microsoft, HP, Novell, Sun, Oracle, RSA Security and others.

PingFederate 4.0 is free for the first six months or 100,000 “identity transactions,” which are the equivalent of SAML assertion exchanges. After that, users will pay a yearly subscription fee, which is $10,000 per 1 million transactions or $30,000 for unlimited transactions for a year including support and maintenance. PingLogin also is free for the first six months or 100,000 transactions. After that, the software is $100,000 per server with a limit of two CPUs.