All the latest UK technology news, reviews and analysis

Web services nears federated ID nirvana

by Tom Sanders at Digital ID World in San Francisco

13 May 2005

Be the first to comment

  • Tweet this

Microsoft will add an identity meta system to its current web services development tools to allow for interoperability between authentication technologies.

The system adds an abstraction layer between the web service and the authentication technology, allowing the web service to deal with multiple authentication methods without the need for code adjustments.

It will allow for user identities and rights to be verified between anything from modern internet software to legacy mainframe applications, the company said in a presentation at the Digital Identity World conference in San Francisco.

The technology will enable federated applications, software that relies on claims made by other applications. Although such applications are available today, their number is limited because they are complex and have to deal with multiple authentication standards which do not always interoperate.

"Until we have technologies like WS-Security that allow you to describe these complex relationships, we are going to be stuck with very fixed topologies," John Shewchuck, vice president of distributed systems at Microsoft, told vnunet.com.

"Today we have solutions that allow you to go from a single identity provider to a single relying party based on user name and password. You might be able to tweak the technology and get it to do more complicated things, but it's hard."

Rather than providing the web service with an actual log-in name and password, the abstraction layer sends a claim, or security token, which states that a user's identity has been verified.

A useful analogy would be a pub that needs to know whether a customer is above the legal drinking age, but not their actual date of birth.

The technology reaches interoperability through the use of existing standards under the WS-* banner, such as WS-Metadata exchange and WS-Trust.

The notion of an identity meta system is new, but the technologies that Microsoft used to get there have been around for some time. This makes it easy for providers of software development kits to add support.

Microsoft will ship a software kit that allows developers to create web services using these federated identities within a couple of weeks, according to Shewchuck.

The kit will be part of Indigo, a development tool for web services, of which a pre-release version was made available last March. The final product is slated for release by 2006.

Windows Server 2003 will add support for the technology through Active Directory Federation Services in the upcoming R2 update due later this year, Shewchuck told vnunet.com.

Although Microsoft's development tools will be limited to its .Net language, other vendors will release tools for languages such as Java and PHP.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Digital Account executive 25k Fulham

Digital Account Executive Fulham, London 25k A great...

Oracle Apps DBA

Our global consultancy client currently seeks a number...

Support Analyst x 1/2 (Apple Mac OSX/Windows) - Bristol/Bath

Support Analyst x 1/2 Skills: Apple Mac OSX, Windows...

Network Consultant - London - 55-65k

Network Consultant - London - 55-65k My client are...

To send to more than one email address, simply separate each address with a comma.