Identity management at Southwest Airlines

Opinion
Oct 6, 20033 mins

* How Oblix helped Southwest Airlines implement secure logon for its airplane mechanics

Last year the hot topic was federated identity and it’s still a major buzz phrase now. But last year vendors were surprised that customers, on looking at their federation products, latched onto the single sign-on part and ignored the rest. SSO within the enterprise was the hot product over the past 12 months. The rest of the federation “bag of tricks” is still trying to attract attention.

Maybe the whole federation package is just too much for an organization to take on at one time. Last July (“Taking baby steps toward provisioning,” https://www.nwfusion.com/newsletters/dir/2003/0630ds2.html ) I talked about Courion’s approach to provisioning applications – start small and build the package one step at a time. It’s an extension of something I said a couple of years ago in that the secret is to turn out a simple, but useful application fairly quickly when rolling out new identity-based services and applications to the enterprise (“The secret to success,” https://www.nwfusion.com/newsletters/dir/2001/01139290.html).

Now I can point to someone who is doing the same for business-to-business federation projects.

Oblix, no stranger to either identity management or electronic provisioning, evidently studied and learned a lot from these examples. It has now launched SHAREid, a SAML (Security Assertion Markup Language) enabled cross-enterprise SSO service. SAML, of course, is the underlying transport for the Liberty Alliance federation specification and can also be used with the competing WS_Federation spec as well as with Internet2’s Shibboleth specification.

It all came about so that Southwest Airlines’ (SWA) mechanics could more efficiently fix its airplanes.

SWA uses Boeing 737 aircraft exclusively. But aircraft manuals can be very thick as well as frequently updated. The solution is online manuals. But Boeing doesn’t want just any Tom, Dick or Osama reading its manuals so the online site is heavily guarded with identity management tools. This meant SWA’s mechanics needed not only to log on to the site but also keep re-authorizing their sessions. This wasted time according to the mechanics’ union and workers wanted compensation – or a better method.

The two companies put their technology heads together, called in their identity management partner, Oblix, and came up with a secure way for the mechanics to log on at SWA and be background authenticated (and re-authorized) at Boeing as needed using the SHAREid product over SAML.

SHAREid could be valuable to your business, also. While it does work as part of Oblix’ NetPoint family of identity products, it doesn’t rely on any particular part of that suite and can work in conjunction with other SAML-enabled identity solutions. See Oblix Web site for more details about the product (link below).

The really important lesson, though, is that so-called “point solutions,” or “baby steps” can be the best way to get what appears to be an overwhelmingly huge project off the ground.