Sun Java System Access Manager 7 2005Q4 Federation and SAML Administration Guide

Identity Federation

Federation, as it has evolved with regard to the World Wide Web, begins with the notion of identity. Sending and receiving email, checking bank balances, finalizing travel arrangements, accessing utility accounts, and shopping are just a few online services for which a user might define an identity. Now, in order to access the service, the user logs in to the service provider, a networked entity that provides services to other entities.

If a user accesses these services, many user accounts have been configured separately. This virtual phenomenon offers an opportunity to fashion a system for users to federate their disparate service provider identities.

Identity federation allows the user to link, connect, or bind the local identities that have been created for the multiple service providers. The linked local identities, referred to as a federated identity, allow the user to log in to one service provider site and click through to an affiliated service provider without having to reauthenticate or reestablish identity.