Claims-based identity

Claims-based identity is a common way for applications to acquire the identity information they need about users inside their organization, in other organizations, and on the Internet.[1] It also provides a consistent approach for applications running on-premises or in the cloud. Claims-based identity abstracts the individual elements of identity and access control into two parts: a notion of claims, and the concept of an issuer or an authority.[2]

Identity and claims

A claim is a statement that one subject, such as a person or organization, makes about itself or another subject. For example, the statement can be about a name, group, buying preference, ethnicity, privilege, association or capability. The subject making the claim or claims is the provider. Claims are packaged into one or more tokens that are then issued by an issuer (provider), commonly known as a security token service (STS).[2]

The name "claims-based identity" can be confusing at first because it seems like a misnomer, attaching the concept of claims to the concept of identity appears to be combining authentication (determination of identity) with authorization (what the identified subject may and may not do). However a closer examination reveals that this is not the case. Claims are not what the subject can and cannot do. They are what the subject is or is not. It is up to the application receiving the incoming claim to map the is/is not claims to the may/may not rules of the application. In traditional systems there is often confusion about the differences and similarities between what a user is/is not and what the user may/may not do. Claims-based identity makes that distinction clear.

Security token service

Once the distinction between what the user is/is not and what the user may/may not do is clarified, it is possible that the authentication of what the user is/is not (the claims) can be handled by a third party. This third party is called the security token service. To better understand the concept of security token service, consider the analogy of a night club with a doorman. The doorman wants to prevent under-age patrons from entry. To facilitate this he requests a patron to present a driver's license, health insurance card or other identification (the token) that has been issued by a trusted third party (the security token service) such as the provincial or state vehicle license department, health department or insurance company. The nightclub is thus relieved of the responsibility of determining the patron's age. It only has to trust the issuing authority (and of course make its own judgment of the authenticity of the token presented). With these two steps completed the nightclub has successfully authenticated the patron with regard to the claim that he or she is of legal drinking age.

Continuing the analogy, the nightclub may have a membership system, and certain members may be regular or VIP. The doorman might ask for another token, the membership card, which might make another claim; that the member is a VIP. In this case the trusted issuing authority of the token would probably be the club itself. If the membership card makes the claim that the patron is a VIP, then the club can react accordingly, translating the authenticated VIP membership claim to a permission such as the patron being permitted to sit in the exclusive lounge area and be served free drinks. Note that not all uses of the term "authentication" include claims acquisition.[3] The only difference is that authentication is limited to the binding of the user to the information contained about the user in the target site as no attribute data (claim) is required to complete an authentication. As privacy concerns become more important, the ability of digital entities to authenticate users without access to personal attributes becomes increasingly important.

Benefits

Claims-based identity has the potential to simplify authentication logic for individual software applications, because those applications don't have to provide mechanisms for account creation, password creation, reset, and so on. Furthermore, claims-based identity enables applications to know certain things about the user, without having to interrogate the user to determine those facts. The facts, or claims, are transported in an "envelope" called a secure token.

Claims-based identity can greatly simplify the authentication process because the user doesn't have to sign in multiple times to multiple applications. A single sign in creates the token which is then used to authenticate against multiple applications, or web sites. In addition, because certain facts (claims) are packaged with the token, the user does not have to tell each individual application those facts repeatedly, for instance by answering similar questions or completing similar forms.

See also

References

  1. ^ David Chappell (February 2011). "Claims Based Identity for Windows" (PDF). Microsoft Corporation. Retrieved 28 July 2011.
  2. ^ a b Microsoft (Jun 3, 2011). "Claims Based Identity & Access Control Guide Documentation" (PDF). Microsoft Corporation. Retrieved 28 July 2011.
  3. ^ IDESG. "Identity Model". Retrieved 5 May 2017.

Read other articles:

Artikel ini tidak memiliki referensi atau sumber tepercaya sehingga isinya tidak bisa dipastikan. Tolong bantu perbaiki artikel ini dengan menambahkan referensi yang layak. Tulisan tanpa sumber dapat dipertanyakan dan dihapus sewaktu-waktu.Cari sumber: Nama julukan – berita · surat kabar · buku · cendekiawan · JSTOR Nama julukan atau nama panggilan (Inggris: nickname) adalah nama seseorang yang bukan nama asli yang diberikan oleh orang tuanya. Nama jul...

 

Catatan tulisan tangan Christopher Columbus di buku Marco Polo Il Milione edisi dalam bahasa Latin Sastra perjalanan adalah genre satra yang termasuk di antaranya adalah sastra luar ruangan, buku panduan perjalanan, penulisan alam, dan memoar perjalanan.[1] Salah satu penulis memoar perjalanan awal dalam kesusastraan Barat adalah Pausanias, seorang ahli geografi Yunani abad ke-2. Dalam periode modern awal, buku Journal of a Tour to the Hebrides (1786) karya James Boswell, membantu ter...

 

العلاقات الأمريكية السيراليونية الولايات المتحدة سيراليون   الولايات المتحدة   سيراليون تعديل مصدري - تعديل   العلاقات الأمريكية السيراليونية هي العلاقات الثنائية التي تجمع بين الولايات المتحدة وسيراليون.[1][2][3][4][5] مقارنة بين البلدين هذ...

العلاقات الصومالية الكرواتية الصومال كرواتيا   الصومال   كرواتيا تعديل مصدري - تعديل   العلاقات الصومالية الكرواتية هي العلاقات الثنائية التي تجمع بين الصومال وكرواتيا.[1][2][3][4][5] مقارنة بين البلدين هذه مقارنة عامة ومرجعية للدولتين: وجه ال...

 

Disused railway station in Garstang, Lancashire Garstang TownThe site of the former station (1996)General informationLocationGarstangEnglandCoordinates53°54′14″N 2°46′29″W / 53.9038°N 2.7746°W / 53.9038; -2.7746Grid referenceSD492455Platforms1 (initially) 2 later addedOther informationStatusDisusedHistoryOriginal companyGarstang and Knot-End RailwayPre-groupingKnott End RailwayPost-groupingLondon, Midland and Scottish RailwayKey dates5 December 18...

 

2022 film by Steven LaMorte The Mean OneTheatrical release posterDirected bySteven LaMorteScreenplay by Flip Kobler Finn Kobler Story bySteven LaMorteBased onHow the Grinch Stole Christmas!by Dr. SeussProduced by Amy Schumacher Steven LaMorte Martine Melloul Starring David Howard Thornton Krystle Martin Chase Mullins John Bigham Erik Baker Flip Kobler Amy Schumacher CinematographyChristopher SheffieldEdited byMathew RoscoeMusic byYael BenamourProductioncompanies Sleight of Hand Productions Am...

Voce principale: Vicenza Calcio. SS Lanerossi VicenzaStagione 1968-1969 Sport calcio SquadraVicenza Calcio Allenatore Umberto Menti (1ª-16ª) Ettore Puricelli (17ª-30ª) Presidente Giuseppe Farina Serie A12º[1] Coppa ItaliaPrimo turno Maggiori presenzeCampionato: Carantini, Calosi (30) Miglior marcatoreCampionato: Tumburus (6) StadioRomeo Menti 1967-1968 1969-1970 Si invita a seguire il modello di voce Questa voce raccoglie le informazioni riguardanti la Società Sportiva Laneross...

 

Logo internasional untuk waralaba Pokemon Generasi kesembilan (Generasi IX) dari waralaba Pokémon (saat ini jumlahnya belum ditentukan) diperkenalkan dalam judul permainan video utama pada konsol Nintendo Switch Pokémon Scarlet dan Violet . Pokémon pertama dari generasi ini diumumkan pada 27 Februari 2022 dalam presentasi Pokémon Presents.[1] Daftar Pokémon Nama Nomor PokédexNasional Tipe Berevolusi dari Berevolusi ke Catatan Inggris Jepang Primer Sekunder Sprigatito Nyaoha (ニ...

 

Cold War incident in divided Berlin Berlin Crisis of 1961Part of Cold WarU.S. M48 tanks face Soviet T-54 tanks at Checkpoint Charlie, October 1961.Date4 June – 9 November 1961LocationCheckpoint CharlieResult 'Stalemate' Erection of the Berlin Wall on 12–13 August 1961Belligerents  Soviet Union East GermanySupported by: Warsaw Pact (Except Albania)  United States West GermanySupported by: NATOCommanders and leaders Nikita Khrushchev Walter Ulbricht John F. Kennedy ...

艾哈迈德·塞古·杜尔总统杜尔、代表几内亚共和国在美国马里兰访问华盛顿特区期间抵达安德鲁斯空军基地。 (1982年6月) 第一任几内亚总统任期1958年10月2日—1984年3月26日前任无,职务设立继任路易斯·兰萨纳·贝阿沃吉 个人资料出生(1922-01-09)1922年1月9日 法兰西第三共和国法属西非法拉纳逝世1984年3月26日(1984歲—03—26)(62歲) 美國克利夫兰, 俄亥俄州墓地科奈克里大清�...

 

Wagering of money on a game of chance or event with an uncertain outcome Several terms redirect here. For other uses, see Gamble (disambiguation), Gambler (disambiguation), Betting (disambiguation), and Bets (disambiguation). Caravaggio, The Cardsharps (c. 1594), depicting card sharps. Gambling (also known as betting or gaming) is the wagering of something of value (the stakes) on a random event with the intent of winning something else of value, where instances of ...

 

Salah satu pengendali permainan untuk Nintendo Switch. Pengendali permainan atau stik kendali (bahasa Inggris: Game controller) adalah sejenis peranti/alat yang digunakan untuk mengendali sebuah permainan video. Pengendali permainan sangat penting dalam mengendali sebuah permainan video. Alat pengendali permainan video biasanya disambungkan ke sebuah konsol permainan video atau komputer pribadi. Alat ini juga dapat digunakan sebagai papan tombol, tetikus, atau paddle. Pengendali permainan...

Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada Desember 2022. Lenna KuurmaaLenna Kuurmaa in 2005Informasi latar belakangNama lainLennaLahir26 September 1985 (umur 38)Tallinn, EstoniaAsalEstoniaGenrePop,[1] rockInstrumenvokal, gitarLabelMortimer Snerd & Frontiers RecordsArtis terkaitVanilla Ninja...

 

Disused railway station in Standon Fitzwarren, Swindon StantonThe site of the station in 2018General informationLocationStanton Fitzwarren, WiltshireEnglandCoordinates51°36′49″N 1°45′02″W / 51.6137°N 1.7505°W / 51.6137; -1.7505Grid referenceSU173905Platforms1Other informationStatusDisusedHistoryOriginal companyGreat Western RailwayPre-groupingGreat Western RailwayPost-groupingGreat Western RailwayKey dates9 May 1883 (1883-05-09)Opened2 March ...

 

1987 cyberpunk original video animation series For the 1996 role-playing game published by R. Talsorian Games, see Bubblegum Crisis (role-playing game). Bubblegum CrisisBubblegum Crisis posterバブルガムクライシス(Baburugamu Kuraishisu)GenreCyberpunk[1]Girls with guns[2]Created byToshimichi Suzuki Original video animationDirected byKatsuhito Akiyama(chief director)Yasunori Ide (#1)Ken'ichi Yatagai (#2–3)Hiroki Hayashi (#4)Masami Ōbari (#5–6)Fumihiko Tak...

Slovenian mathematician (1873–1967) Josip PlemeljJosip Plemelj in 1920Born(1873-12-11)December 11, 1873Bled, Austria-HungaryDiedMay 22, 1967(1967-05-22) (aged 93)Ljubljana, Socialist Republic of SloveniaAlma materUniversity of Vienna (PhD, 1898)Known forSokhotski–Plemelj theoremScientific careerDoctoral studentsIvan Vidav Josip Plemelj (December 11, 1873 – May 22, 1967) was a Slovene mathematician, whose main contributions were to the theory of analytic functions and ...

 

Yak

Long-haired domesticated bovid For the progenitor species Bos mutus, see Wild yak. For other uses, see Yak (disambiguation). Yak A yak in the Nepalese Himalayas. Conservation status Domesticated Scientific classification Domain: Eukaryota Kingdom: Animalia Phylum: Chordata Class: Mammalia Order: Artiodactyla Family: Bovidae Subfamily: Bovinae Genus: Bos Species: B. grunniens Binomial name Bos grunniensLinnaeus, 1766 Synonyms Poephagus grunniens The yak (Bos grunniens), also known as the ...

 

Battle of the American Revolutionary War Battle of BenningtonPart of the American Revolutionary WarA 1780 map depicting troop positions at the start of the battleDateAugust 16, 1777LocationWalloomsac, New York42°56′19″N 73°18′16″W / 42.93861°N 73.30444°W / 42.93861; -73.30444Result American-Vermont victoryBelligerents  United States Vermont Republic  Great Britain Brunswick Hesse-Hanau IroquoisCommanders and leaders John Stark Seth Warner Friedric...

Historical work about the Indian region of Ladakh The Ladakh Chronicles, or La-dvags-rgyal-rabs (Tibetan: ལ་དྭགས་རྒྱལ་རབས, Wylie: La dwags rgyal rabs),[a] is a historical work that covers the history of Ladakh from the beginnings of the first Tibetan dynasty of Ladakh until the end of the Namgyal dynasty. The chronicles were compiled by the Namgyal dynasty, mostly during the 17th century, and are considered the primary written source for Ladakhi history.&...

 

Dubai Tennis Championships 2009Sport Tennis Data15 febbraio - 28 febbraio Edizione17a CampioniSingolare maschile Novak Đoković Singolare femminile Venus Williams Doppio maschile Rik De Voest / Dmitrij Tursunov Doppio femminile Cara Black / Liezel Huber 2008 2010 Il Barclays Dubai Tennis Championships 2009 è stato un torneo della categoria ATP World Tour 500 series dell'ATP World Tour 2009 e della categoria Premier del WTA Tour 2009. Entrambi gli eventi hanno avuto luogo nell'Aviation Club ...