LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What does the central-identity model mean for the relying party and for the identity provider?

The RP delegates identification and authentication to a trusted specialist, so it stores no identity proofs or credentials, can obtain attested attributes, and needs no identity processes such as password resets. The IdP, in turn, collects user data from many domains, which is lucrative to monetise, enables powerful profiling and surveillance, and makes its aggregated store a rewarding target for attackers.

From the RP's view, delegation is almost pure gain:

  • No credentials or identity proofs on its own systems, so a breach exposes less.
  • Attested attributes (verified name, e-mail, age) come for free from the IdP.
  • No identity processes to run: password reset, account recovery and MFA enrolment are the IdP's job.

From the IdP's view, the model concentrates both value and risk:

  • Data about users from many different domains makes it worthwhile to collect and monetise usage data.
  • Multi-dimensional profiles feed targeting and profiling tools that amount to a very efficient form of surveillance.
  • The aggregated data store becomes an increasingly attractive attack target.

The asymmetry is the political core of IAM: the party that gains convenience (RP and user) is not the party that gains the data (IdP).

Go deeper:

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026