LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

How do the different topologies compare with regard to data protection and privacy?

Isolated identities spread the user's data over many providers of uneven quality; central and IdP-centred models concentrate it at one IdP that can profile every login; full mesh keeps identities at the user's home organisation with no global observer; hub-and-spoke puts a broker in the position to see every authentication in the federation; user-centric models take the issuer out of the usage path entirely.

Topology Who sees what
Isolated Each RP holds its own copy of identity data and credentials; many small honeypots, no cross-site profile
Central / IdP-centred The IdP is in every login and can build a cross-RP profile; one large honeypot
RP-centred The RP sees which IdP each user chose; each IdP sees the logins to that RP
Full mesh The home IdP sees its own users' logins to partner RPs; no single party sees everything
Hub-and-spoke The broker sees every authentication and, through its proxy, the content of the assertions
User-centric / SSI The issuer learns nothing at usage time; only the RP sees what the user chooses to disclose

The rule of thumb: the more a topology centralises convenience, the more it centralises observation. Privacy-preserving designs either avoid the central party or blind it, which is the motivation for the self-sovereign approach.

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026