|
Identity federation (federated identity management) is about sharing digital
identities across multiple different organizations (security domains), or
business processes (applications), each completely independent from the other.
Web access control is an application, based to some extent on this concept,
allowing internal and/or external web users to access only those URLs they are
entitled to see due to their security settings or business needs. Identity
federation allows users of these different security domains and applications to
work together, as if they were one, while maintaining the privacy, security,
and independence of each user (or system) in this logical network. Web access
control delivers secure single sign-on across internal and external web enabled
applications, while simplifying system access for end users.
-
Simplify authentication and authorization of different people by implementing
accepted interaction standards
-
Streamline business processes and provide effective coordination between
business partners
-
Shorten process time significantly by allowing each identity in the process
chain to handle its part independently. Sing from India can pick up an order
John from Los Angeles requested when Sing was asleep, and complete it while
John is asleep
-
Simplify the communication and transaction messaging between partnering
organizations due to the standard structure
-
Lower the cost of doing business by standardizing and organizing broken
processes into a single one
-
Lower management cost and increase user satisfaction by allowing for
self-service and self-registration
-
Security
-
Communication
-
Trust-setting
-
Standard authentication for users and systems validation
-
Standard authorization for access permissions
-
Open information exchange
-
Protection of private information of users or systems in the federation
-
Maintenance of the independence of each organization within the federation.
Each organization should be able to administer their users independently of the
others
-
Management of users directory
-
Simple users allocation and groups creation
A few decades ago people thought EDI (Electronic Data Interchange) would
provide this solution, and it did so to some extent in the retail and several
other market segments. However EDI was proprietary, costly, and inflexible and
these factors limited its wide spread adoption. The Internet offers a standard,
open and low cost infrastructure to build such a solution on, and this is
exactly what the federated identity technologies are offering.
To learn more about identity federation and Web access control solutions,
please contact us.
|