Key to the World - Information Security Magazine - Page 1
BITS & BOLTS
SAML's portable trust makes federated identity work.

The way most e-commerce works--B2B and B2C--is that a person signs on to a Web site and provides his credentials, which are verified through stored identities typically only valid for that session and that domain. It's a cumbersome process that slows the user experience and transactions, and requires expensive identity stores and management systems.

The idea behind Web services and federated identities is that you only need one identity to access multiple accounts and resources across different, trusted domains. The magic behind the process is Security Assertion Markup Language (SAML), the standard that breathes life into the growing world of XML-based communications.

SAML, developed by OASIS in collaboration with several identity management vendors, provides a means for trusted parties to leverage federated identities and for trusted third parties to act as an authority for hundreds or thousands of service providers simultaneously. In theory, this means that one identity can be ported across trusted domains to provide transparent access to data, applications and resources. It's the foundation of Web services and promises to improve user experiences and save enterprises money.

SAML 1.1 and 2.0 (pending approval) provide an XML-based framework for entities to make claims, or "assertions," and flexibly allow entities to exchange attribute, authentication and authorization information.

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

SAML effectively eliminates the spider web of one-to-one trust relationships, which serve as the foundation for most of today's identity-dependent platforms.

This was first published in January 2005