-
Identity Management System
- Identity Register
- Logical aspects: Uniqueness. Fully qualified user names / name spaces, Credentials, Other attributes
- Storage
- Directory - Heirarchical, Multiple values
- Database - frequently relational
- Virtual directory - abstraction over several Identity information source(s)
- Import / Export
- Identity information source(s)
- Authoritative source and legal copies
- Principal and Credential Management - lifecycle of principals and credentials (self-service, workflows, administration). Includes identity proofing and verification
- Audit Repository - logs operational events. Protection and controlled access.
- Service Provisioning - provides identity information to a relying party
- Overt provisioning - e.g. SCIM
- Just in time provisioning or ephemeral
- Assertions as part of Authentication
- Attribute Pull
- Authentication
- LDAP
- Kerberos
- ...
- Federation services - discovery, identity assertions, attribute retrieval
- Identity Register
-
Relying Systems (Parties) concerns that may be shared by IMS
- Sessions
- Access Control
- Binding of identity to non-identity data 2. IGA extends the Principal and Credential Managment to include access control Policies, Rules, Roles
-
Protocols that connect the Identity Management System and the Relying Systems