A federated identity system enables a user’s digital identity and authentication to be recognised across multiple independent organisations or domains without each maintaining separate credentials. It relies on trust relationships between identity providers and relying parties, exchanging assertions via protocols such as SAML, OpenID Connect, and OAuth. Federation underpins single sign-on, cross-organisation access, and trust-framework governance.

Content

  • Federation works by having an identity provider issue signed assertions (tokens) that relying parties trust, using standards like OpenID Connect, SAML, and OAuth 2.0 to convey authentication and attribute claims. Effective federation depends on agreed trust frameworks defining assurance levels, attribute semantics, and liability, balancing single-sign-on convenience against the systemic risk of a compromised identity provider.