What is the full-mesh (cross-domain) federation model, and what are its pros and cons?
Several organisations, each with its own IdP and relying parties, federate identities mutually across their organisational boundaries; each exchanges all necessary identity information of its own systems with the partner organisations. Users get access everywhere with their home identity, but every organisation must set up and maintain trust with every other, which scales badly.
* Full mesh: organisations with their own IdP and RPs trust each other pairwise; a subject logs in at home and accesses a partner. *
In the diagram four organisations each own an IdP and an RP, and a subject from organisation 1 authenticates at its home IdP1 to access RP3 in organisation 3. The example is Switch-AAI and eduroam: a student of any Swiss university logs in to services and Wi-Fi at any other with the home institution's credentials.
Advantages:
- Users keep a single home identity and their organisation stays in control of it.
- No central party sees every login (unlike hub-and-spoke), which is good for privacy and for resilience.
Disadvantages:
- Trust relationships grow quadratically: with n organisations, up to n(n-1)/2 pairwise agreements, key exchanges and attribute mappings.
- Every organisation must expose and maintain interfaces towards all partners, and any change ripples through the whole mesh.
Large federations solve the scaling problem with shared metadata and common attribute standards, which edges the model towards hub-and-spoke.
Go deeper:
SWITCHaai (Switch help) — the Swiss academic federation: one university login for hundreds of services.
eduroam (Wikipedia) — Wi-Fi roaming with home-institution credentials, the same federation idea applied to network access.