What are the advantages and disadvantages of the IdP-centred federation model?
One central IdP serves several applications: the RP has only one communication partner with one identity type and one protocol, and the user has only one identity with single sign-on across the applications; the disadvantage for the user is that the IdP can build profiles. Examples are a student login, Google, Apple and Microsoft.
* IdP-centred: one identity provider serving several relying parties, with single sign-on. *
In the diagram one IdP sits in the middle with RP1 to RP4 around it; the subject authenticates once at the IdP and accesses any RP.
- Advantage for the RP: a single integration. One identity format, one protocol, one trust relationship to maintain.
- Advantage for the user: one identity, and single sign-on (SSO): after authenticating at the IdP once, the user reaches all connected applications without logging in again.
- Disadvantage for the user: the IdP takes part in every login and can profile the user's activity across all the RPs.
This is the standard enterprise and campus layout: a central directory with an SSO service in front, and every internal application delegating to it.
Go deeper:
Single sign-on (Wikipedia) โ benefits and criticisms of logging in once for everything.