Consumer Identity and Access Management (CIAM) has emerged as the fastest-growing area within IAM because enterprises increasingly need to serve external customers, not just employees, while delivering a smoother digital experience. CIAM systems provision, authenticate, authorize, and store consumer identity data gathered from multiple (sometimes non-authoritative) sources, often improving onboarding through mobile devices and social logins. However, implementing CIAM introduces scale and governance challenges: consumer identities can outnumber employee identities by orders of magnitude, and organizations must meet stringent privacy requirements (e.g., GDPR, PSD2) alongside anti-fraud regulations. At the same time, CIAM creates opportunities to use rich customer data streams for marketing analytics.
NRI Secure Technologies’ Uni-ID Libra (version 2.2) is a CIAM offering in Japan, originally developed in 2008 and rebranded in 2017. It provides core CIAM functions—authentication, authorization, and risk analysis—via a management console and REST APIs, and reportedly serves about 100 million consumer identities across 20+ large Japanese customers. Its ID repository uses a single extensible schema, supports SCIM 2.0 provisioning, and exposes REST/JSON APIs. Consumer self-registration and consent management are supported with privacy-by-default toggles, fine-grained options including parental controls, and the ability to withdraw consent; it also supports data portability and deletion (“right to be forgotten”), though some actions require administrator intervention. Data is encrypted and processing is logged.
Authentication options include password, FIDO UAF, and multiple OTP channels, with roadmap expansion to FIDO U2F/FIDO2 and passwordless “magic link”-style email login. Federation/authorization supports OIDC/OAuth 2.0, SAML 2.0, and JWT, with planned CIBA and FAPI support. Risk-adaptive authentication uses device, location, IP, and behavioral signals plus threat intelligence, can trigger step-up MFA, and integrates operationally via APIs and monitoring tools. Deployment supports on-prem, IaaS, or hosted single-tenant microservices, but market and support are largely Japan-centric and some administrative/security capabilities are missing.
See All Locations
See All Locations