Quiz Entry - updated: 2026.09.17
How do the different topologies compare with regard to data protection and privacy?
Isolated identities spread the user's data over many providers of uneven quality; central and IdP-centred models concentrate it at one IdP that can profile every login; full mesh keeps identities at the user's home organisation with no global observer; hub-and-spoke puts a broker in the position to see every authentication in the federation; user-centric models take the issuer out of the usage path entirely.
| Topology | Who sees what |
|---|---|
| Isolated | Each RP holds its own copy of identity data and credentials; many small honeypots, no cross-site profile |
| Central / IdP-centred | The IdP is in every login and can build a cross-RP profile; one large honeypot |
| RP-centred | The RP sees which IdP each user chose; each IdP sees the logins to that RP |
| Full mesh | The home IdP sees its own users' logins to partner RPs; no single party sees everything |
| Hub-and-spoke | The broker sees every authentication and, through its proxy, the content of the assertions |
| User-centric / SSI | The issuer learns nothing at usage time; only the RP sees what the user chooses to disclose |
The rule of thumb: the more a topology centralises convenience, the more it centralises observation. Privacy-preserving designs either avoid the central party or blind it, which is the motivation for the self-sovereign approach.