Standardizing Identity Federation: SAML, WS-Security, and Liberty Alliance

The Liberty Alliance, an organization behind the creation of Security Assertion Markup Language (SAML), has been working to establish a unified standard for identity federation. SAML 2.0, due for release, is expected to incorporate the Liberty Alliance's work, promoting a single standard for account linking, single-sign-out, and trust establishment between organizations. Microsoft and IBM have developed separate stacks of OASIS-approved standards, including WS-Federation, which defines federated identity mapping methods using the WS-Security specification. This framework enables secure messaging, allowing developers to attach WS specifications that support specific security functions.

Key Takeaways:

  • SAML, developed by the Liberty Alliance, is a key component in identity federation standardization, with SAML 2.0 due to incorporate Liberty Alliance's work.
  • WS-Federation, developed by Microsoft and IBM, defines federated identity mapping methods, utilizing the WS-Security specification.
  • WS-Security offers a framework for secure messaging, enabling attachment of WS specifications for specific security functions, including WS-Trust.
  • Effective federated identity systems model business relationships and aim to achieve dynamic federation.
  • Entrust, IBM Tivoi, Netegrity, Oblix, RSA Security, Sun Microsystems, and Trustgenix offer tools to help establish a foundation for federated identity.
  • Implementation begins with a comprehensive assessment, followed by the establishment of a trusted relationship between organizations.
  • A spokesman for the Liberty Alliance emphasizes the importance of stating terms in the context of specific roles, privileges, and authorizations within a partner's IT infrastructure.

Statistics:

  • WS-Security is at version 1.0, regarded as a fundamental component of the Web services protocol stack.
  • The Liberty Alliance has been certifying products for technical compliance and practical interoperability with its standards.
  • Organizations, including Microsoft and IBM, have participated in the development of standards for identity federation.
  • Tools from multiple organizations are available to support the establishment of a foundation for federated identity.
  • A comprehensive assessment is the first step in implementing a federated identity system.

Sources:

  • McAllister, Neil. [Exact source or publication not specified]
  • Liberty Alliance. [Exact source or publication not specified]
  • OASIS. [Oasis Open Standards Consortium]
  • Entrust. [Exact source or publication not specified]
  • IBM. [IBM Corporation]
  • Netegrity. [Exactly as mentioned in the original text]
  • Oblix. [Exactly as mentioned in the original text]
  • RSA Security. [Exactly as mentioned in the original text]
  • Sun Microsystems. [Exactly as mentioned in the original text]
  • Trustgenix. [Exactly as mentioned in the original text]