home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Technology Business Applications
W O R K S H O P  
Making ID Management Manageable

  August 7, 2003
  By Lori MacVittie


>> continued from previous page

Opening Up
TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Opening Up
arrow
At Liberty To Show Your Passport
arrow
Step By Step
arrow
Sites to See

The circle of trust may sound a lot like Microsoft's Passport, but it's very different. First, the Liberty Alliance is producing specifications based on open standards, such as SAML (Security Assertion Markup Language), XML, HTTP and WSDL (Web Services Description Language); Passport is a Microsoft proprietary service based solely on Kerberos. Passport runs on Windows and Internet Explorer only, but the Liberty Alliance's standards can work across any operating system and browser platform.

Liberty specifications aren't interoperable with Microsoft's Passport, but that doesn't mean the two won't ever meet: An ID provider acting as both a Passport site and part of a circle of trust can map between the two identity technologies (see "At Liberty To Show Your Passport," below).



The Liberty Alliance uses open standards from the World Wide Web Consortium (W3C) and the Organization for the Advancement of Structured Information Standards (OASIS) in its specs. The earlier Version 1 and 1.1 alliance specs recommend using a third-party domain service to store a user's cookie. Then any site within the domain's circle of trust could read that cookie.

Although that option remains part of the most recent Liberty Alliance spec, Version 1.2, it's no longer encouraged because cookie management and reading cookies across domains pose security risks--and raise the ire of privacy-minded consumers.

The new version also recommends OASIS' SAML as a way to pass identity information between two sites. SAML is an XML framework for exchanging authentication and authorization data between different security systems and Web services. With SAML, identity information is hidden for privacy reasons so it can't be traced to the user. This provides better security for personal data, but requires a high level of trust between the service provider and identity provider.

The Liberty Alliance spec includes two methods of passing this information among the identity provider, user agent (browser) and service provider, both of which use browser-redirection (see "A Federation of Federations").



A Federation of Federations

click to enlarge

One method is to use HTTP get to pass a SAML assertion (a statement about an end user, such as an attribute). The catch is that the length of the URL and assertion can't exceed the browser's URL-length limitations. Another method is HTTP post, which doesn't have such a restriction. HTTP post lets you embed a SAML assertion within an HTML form to pass it between providers. The downside of this approach, however, is that it's more difficult to code and requires scripting to transfer the browser automatically between the service provider and the identity provider.

A SAML artifact, which is a pointer to a SAML assertion, is often used and passed via HTTP get to make implementation smoother for the browser. For the service provider to retrieve the full SAML assertion, the identifier must be visible, albeit opaque.

Enter the Circle

Federation occurs when a second site or service provider joins the circle of trust. This is the process of associating a user's identity at one site with his or her identity at another. The result is a unified identity among all members in a single circle of trust, as long as the user opts in for it.

The members of the circle designate the identity provider, which typically stores the user's opt-in agreement. Even after authorizing the federation, the user still has to agree to each business or service provider association. That ensures privacy.

Of course, given the nature of the Web, you aren't really logged on to all sites at once. It's more like a single sign-on: After a user signs on to Member A, he or she doesn't have to sign on again to visit any other member of the circle. Beware, though, that if you are "Joe Smith" to Member A and "Jsmith" to Member B, you will be known throughout the circle by your logon from the first site. So if you sign on to A and then visit Member B, you'll be known on both sites as "Joe Smith." Conversely, if you sign on to Member B and then visit Member A, you'll be known as "Jsmith" to both sites during that session. This scenario also applies among business partners and inside your organization with the Liberty Alliance architecture.

Although single sign-on products have been available from vendors such as Netegrity and Oblix for some time, the Liberty Alliance standards are advancing the broader federated identity model more quickly and widely. Building a federated identity infrastructure among your business partners not only cuts overhead and simplifies ID management in-house--it also opens the door for new business opportunities within your circle of trust.

Lori MacVittie is a Network Computing technology editor working in our Green Bay, Wis., labs. Write to her at lmacvittie@nwc.com.

Post a comment or question on this story.


start top  Introduction At Liberty To Show Your Passport 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights