LOGBOOK

HELP

1 / 34
Other keys: show • Space: good • 1-4: rate • 0: skip • 5: flag

Question

By which criteria can IAM models be classified?

Answer

By the user's view (who issues and who controls the identity), by topology (how the IAM components are distributed across systems and organisations), by data flow (federation versus provisioning), and by target group or field of use (B2E, B2C, B2B, ...).

The four classification axes of IAM models: user view, topology, data flow and target group

* The four classification axes; every real deployment has a position on each. *

The four taxonomies look at the same systems from different angles, and a real deployment has a position in each of them:

  1. User's view: who issues the identity and who controls it? This separates externally determined identities from user-centric ones.
  2. Topology: where do the components (identity provider, registration authority, relying party) run, and do they belong to the same organisation? This yields isolated, central, federated and brokered layouts.
  3. Data flow: do identities travel at login time (federation) or are they copied into the target systems beforehand (provisioning)?
  4. Target groups and fields of use: business-to-employee, business-to-consumer, business-to-business, guests, government, IoT and machines all impose different requirements.

Keeping the axes separate avoids a common muddle: "Google login" is a statement about topology (IdP-centred), "SSI" is a statement about the user's view (fully user-controlled), and "SCIM" is a statement about data flow (provisioning).

or press any other key

Question

How do IAM models differ from the user's point of view, and what are examples of each class?

Answer

Externally determined identities are issued and controlled by an identity service; user-centric identities are controlled by the subject, either partially (issued by a service, held by the subject, as in PKI certificates or the Swiss E-ID) or fully (issued and controlled by the subject, the SSI vision).

Three classes stacked: externally determined, user-centric partially controlled, user-centric fully controlled, with control moving to the subject

* From externally determined to fully self-sovereign: control over the identity moves step by step to the subject. *

Externally determined User-centric, partially controlled User-centric, fully controlled
Issuer of the identity Identity service Identity service Subject
Control over the identity Identity service Subject Subject
Examples Classical identities (federation, provisioning) PKI: X.509 certificates, the German nPA, the Swiss E-ID Self-sovereign identity (vision)

The dividing line is control: who holds the identity data and decides when it is used. With a classical account, the service holds everything and is part of every login. With a certificate or an E-ID credential, the service issues it once, but the subject keeps it and presents it without the issuer being involved. The fully self-sovereign case, where even the issuing is in the subject's hands, is still a vision rather than everyday practice.

Go deeper:

  • doc X.509 (Wikipedia) — the certificate standard behind the partially user-controlled class: issued by a CA, held and used by the subject.
or press any other key