LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

Which topologies are advantageous for a relying party, and which for the user?

For the RP, the IdP-centred and hub-and-spoke models are most convenient because they mean a single integration partner, while the RP-centred model widens reach at the cost of multiple integrations. For the user, the IdP-centred model and hub-and-spoke give single sign-on with one identity, but user-centric models are the ones that leave the user in control of their data.

From the RP's seat the question is integration effort and audience:

  • IdP-centred and hub-and-spoke: one partner, one protocol, attested attributes, no identity processes to run.
  • RP-centred: larger audience, but the RP carries the integration burden of every IdP.
  • Isolated: full control, full cost.

From the user's seat the question is convenience against privacy and dependency:

  • IdP-centred and hub-and-spoke: one identity and SSO, but a central observer and a dependency on it.
  • Isolated: no observer, but an account per service.
  • User-centric: the identity is theirs, the issuer is out of the loop, but they carry the responsibility for it.

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026