Question
By which criteria can IAM models be classified?
Answer
By the user's view (who issues and who controls the identity), by topology (how the IAM components are distributed across systems and organisations), by data flow (federation versus provisioning), and by target group or field of use (B2E, B2C, B2B, ...).
* The four classification axes; every real deployment has a position on each. *
The four taxonomies look at the same systems from different angles, and a real deployment has a position in each of them:
- User's view: who issues the identity and who controls it? This separates externally determined identities from user-centric ones.
- Topology: where do the components (identity provider, registration authority, relying party) run, and do they belong to the same organisation? This yields isolated, central, federated and brokered layouts.
- Data flow: do identities travel at login time (federation) or are they copied into the target systems beforehand (provisioning)?
- Target groups and fields of use: business-to-employee, business-to-consumer, business-to-business, guests, government, IoT and machines all impose different requirements.
Keeping the axes separate avoids a common muddle: "Google login" is a statement about topology (IdP-centred), "SSI" is a statement about the user's view (fully user-controlled), and "SCIM" is a statement about data flow (provisioning).
Note saved — thanks!
Question
How do IAM models differ from the user's point of view, and what are examples of each class?
Answer
Externally determined identities are issued and controlled by an identity service; user-centric identities are controlled by the subject, either partially (issued by a service, held by the subject, as in PKI certificates or the Swiss E-ID) or fully (issued and controlled by the subject, the SSI vision).
* From externally determined to fully self-sovereign: control over the identity moves step by step to the subject. *
| Externally determined | User-centric, partially controlled | User-centric, fully controlled | |
|---|---|---|---|
| Issuer of the identity | Identity service | Identity service | Subject |
| Control over the identity | Identity service | Subject | Subject |
| Examples | Classical identities (federation, provisioning) | PKI: X.509 certificates, the German nPA, the Swiss E-ID | Self-sovereign identity (vision) |
The dividing line is control: who holds the identity data and decides when it is used. With a classical account, the service holds everything and is part of every login. With a certificate or an E-ID credential, the service issues it once, but the subject keeps it and presents it without the issuer being involved. The fully self-sovereign case, where even the issuing is in the subject's hands, is still a vision rather than everyday practice.
Go deeper:
X.509 (Wikipedia) — the certificate standard behind the partially user-controlled class: issued by a CA, held and used by the subject.
Note saved — thanks!