Many companies still struggle with integrating partners using traditional identity federations. Even more challenging is the integration of machine identities into the Identity Fabric, especially since many of these non-human identities do not exist in traditional identity management systems.
In both cases, the fundamental issue is the integration of external identity systems, where complete control is not always possible. At SBB AG, we build on trust frameworks, such as those outlined in NIST IR 8149 or NIST SP 800-63C for understanding and defining trust and risk. This approach allows us to clearly account for the trust we delegate to others and regain it through a modern, policy-based access architecture and other mitigating measures.
Using specific examples from the B2B sector and the Machine Identity Initiative at SBB AG we will illustrate, how we established a transparent and highly scalable collaboration model for a wide range of partners and applications with just a few simple trust-building blocks. Applying the same principles, we are making significant strides towards better integrating non-human identities into the Identity Fabric. Ultimately, these patterns can also be extended to the principles of Self-Sovereign Identity in the future.
SBB AG is the largest employer for the development of custom software in Switzerland. Our IAM services support thousands of applications in a heterogeneous environment, ranging from modern business applications in multi-cloud environments to mission-critical software in on-premises or OT systems.