English   Deutsch

Martin Kuppinger: Choosing the right Identity Provider

Choosing the right Identity Provider
Most organizations have more than one IT department
by Martin Kuppinger
mk@kuppingercole.com

It isn’t exactly a new idea, but designing your Identity and Access Management (IAM) with your users in mind always makes sense. But how about your customers and suppliers? After all, they, too, increasingly need to gain admittance to some of your internal applications and data. Unfortunately, internal directories usually aren’t up to the job, so choosing the right identity provider is growing more and more important.

When we say identity provider, we actually mean the service provider in charge of authenticating and authorizing users and determining which information they are allowed to see, depending on their pre-defined roles, their names and other attributes used to establish identity. Today, most organizations rely on their internal directories for this. And since there are usually quite a few of them, each is assigned a different task: Active Directory for initial authentication, corporate directories for internal users, various other directories for outsiders such as clients, customers, or business partners who access the system via the Web.

This internal perspective has its drawbacks, though. For instance, it forces external users to register and authenticate themselves for each partner separately, which can cause problems in industries that are well connected or which employ complex supply chains, as well as for customers wanting to reach an eCommerce website.

Some industries such as aerospace or automotive already boast well-entrenched identity providers such as Exostar or Covisint, but for others alternatives like OpenID or Information Cards are becoming increasingly popular. In Germany, the soon-to-be-released new government identity card, or nPA (“Neuer Personal-Ausweis”) also involves an external identity provider. And in fact it makes sense not to do everything yourself but to call instead on outside help. This is a growing trend, and it is being reinforced by things like the increasing use of identity federation and new standards such as claims-based authentication, which is part of Microsoft’s new Sharepoint release.

Internal IT departments should start focusing on transactions and interactions where an identity provider can improve the reliability, security and cost-effectiveness of access to systems and data. Whenever an external provider can do a better job, internal directories should be replaced by outsourcing. However, this means devoting greater attention than before to technical connection issues and understanding the concept federation, as well as graduated security models that work well with different identity providers.

This means that one size no longer fit all. Valuable and sensitive data and transactions need a different level of security than simple registration of potential customers at a website – Facebook may actually be good enough for identifying them. A modular and graduated approach is required to avoid built-in conflicts of interest between usability and security which can cause unnecessary friction. A clear and well-defined concept will enable organizations and enterprises to work well with all relevant user groups.

Created: 21.06.10, modified: 13.07.10

Information
Newsletter
Kuppinger Cole Identity Management Newsletter
Services
KCP provides strategic consulting services for vendor and user companies covering all areas of identity & access management.
Reports
Use KCP as an independent, objective, and neutral authority on the Market for Identity Management products and solutions
Podcasts
Free audio and video presentations on important IAM-topics
Current surveys
IAM-Studie 2010
PARTICIPATE 
Virtualization Security Trends & Insights
PARTICIPATE 
Blogs
Tim Cole
28.08.2010 11:53
Not Just Any Port in a Storm
READ 
European Identity Conference Blog
27.08.2010 04:45
Google authentication support
READ 
Martin Kuppinger
12.08.2010 11:34
Diving down to the details of access controls
READ 
Sachar Paulus
11.08.2010 10:05
The GRC Marketplace is shaking up: SAP and CA partnering on GRC
READ 
Sebastian Rohr
04.08.2010 20:18
Your token to VISA…
READ 
Felix Gaehtgens
19.02.2010 17:40
Gerry Gebel joins Axiomatics
READ 
Joerg Resch
17.02.2010 11:15
Identity Management is key to Smart Grid Security
READ 
Links
 Kuppinger Cole News

 Kuppinger Cole Podcasts

 Kuppinger Cole on Facebook

 Kuppinger Cole on Twitter

 Visit us at Xing

 IAM-Wiki

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2010 Kuppinger Cole