Standardizing Identity Federation: SAML, WS-Security, and Liberty Alliance
The Liberty Alliance, an organization behind the creation of Security Assertion Markup Language (SAML), has been working to establish a unified standard for identity federation. SAML 2.0, due for release, is expected to incorporate the Liberty Alliance's work, promoting a single standard for account linking, single-sign-out, and trust establishment between organizations. Microsoft and IBM have developed separate stacks of OASIS-approved standards, including WS-Federation, which defines federated identity mapping methods using the WS-Security specification. This framework enables secure messaging, allowing developers to attach WS specifications that support specific security functions.
Key Takeaways:
- SAML, developed by the Liberty Alliance, is a key component in identity federation standardization, with SAML 2.0 due to incorporate Liberty Alliance's work.
- WS-Federation, developed by Microsoft and IBM, defines federated identity mapping methods, utilizing the WS-Security specification.
- WS-Security offers a framework for secure messaging, enabling attachment of WS specifications for specific security functions, including WS-Trust.
- Effective federated identity systems model business relationships and aim to achieve dynamic federation.
- Entrust, IBM Tivoi, Netegrity, Oblix, RSA Security, Sun Microsystems, and Trustgenix offer tools to help establish a foundation for federated identity.
- Implementation begins with a comprehensive assessment, followed by the establishment of a trusted relationship between organizations.
- A spokesman for the Liberty Alliance emphasizes the importance of stating terms in the context of specific roles, privileges, and authorizations within a partner's IT infrastructure.
Statistics:
- WS-Security is at version 1.0, regarded as a fundamental component of the Web services protocol stack.
- The Liberty Alliance has been certifying products for technical compliance and practical interoperability with its standards.
- Organizations, including Microsoft and IBM, have participated in the development of standards for identity federation.
- Tools from multiple organizations are available to support the establishment of a foundation for federated identity.
- A comprehensive assessment is the first step in implementing a federated identity system.
Sources:
- McAllister, Neil. [Exact source or publication not specified]
- Liberty Alliance. [Exact source or publication not specified]
- OASIS. [Oasis Open Standards Consortium]
- Entrust. [Exact source or publication not specified]
- IBM. [IBM Corporation]
- Netegrity. [Exactly as mentioned in the original text]
- Oblix. [Exactly as mentioned in the original text]
- RSA Security. [Exactly as mentioned in the original text]
- Sun Microsystems. [Exactly as mentioned in the original text]
- Trustgenix. [Exactly as mentioned in the original text]