* The goal of federated identity
endif; ?>It’s one of those concepts that, to me at least, is obscured by it’s own name: federated identity.
In a nutshell, the goal of said technology is to offer users the ability to authenticate themselves to their local network and then be able to pass that authentication to partners for access to services or data on the partner’s network. The idea is to ease user management and the associated costs, improve network security, provide a means to document regulatory compliance and fuel e-commerce and Web services that let partners share computing resources.
Our Technology Update author (rxiong@ datapower.com) notes that there are several XML standards for federating identity across domains: Security Assertion Markup Language (SAML), Liberty Alliance and Web Services Federation Language (WS-Federation). They can be used to eliminate duplicate user repositories, while letting companies intermix standards-compliant products from different vendors.
For example, an XML/SAML-aware gateway or proxy can be used to enforce access control efficiently and handle other Web services security processing such as XML threat protection, schema validation and message security.
SAML and Liberty Alliance are converging: SAML 2.0 is under public review and will incorporate more advanced features from Liberty Alliance, such as single logout and account linking.
Meanwhile, in a recent story Network World’s John Fontana (jfontana@nww.com) said early adopters of federated identity wares were reporting some of those benefits mainly in combination with business partners with whom they already have a relationship. Those relationships, they say, are the place to start because they reduce the trust and legal issues inherent in sharing user data and exposing corporate systems.
Both those issues are major sticking points to adoption of federation. Users are concerned not only about liabilities in handling sensitive and often private data, but how partners will use or share that information with others through federation, which could expose otherwise confidential data.https://www.nwfusion.com/news/tech/2004/112904techupdate.html
It’s an interesting topic you’ll be hearing more about in the coming year. For more on our Technology Update, see:




