IBM og Microsoft har ramt målet med denne slags arbejde meget godt i deres målsætning for WS-Federation:
"
The primary goals of Federated Identity Services are as follows:
- Reduce the cost of identity management by reducing duplication of effort; each individual�s identity is almost always already managed by a trusted organization (such as the individual�s bank, employer, or physician).
- Leverage the work these existing identity managers have already done by giving other parties access (as required and with appropriate privacy protection) to the relevant identity information.
- Preserve the autonomy of all parties � an identity manager�s choice of authentication technology should not impose that technology on parties who rely on its identity information. An identity manager�s choice of operating system, or networking protocol, or database, should not impose the same choice on its partners.
- Respect business� pre-existing trust structures and contracts. Signing up to receive identity information from an identity provider must not require an organization to establish a trust relationship with any party other than the identity provider, and must not require adoption of any specific user authentication technology.
- Protect individuals� privacy by respecting and strongly enforcing user preferences governing the use of individually identifiable information, observing governmental and regional privacy rules, seeking the user�s consent for new uses, and implementing strong recordkeeping and accountability mechanisms to ensure that privacy practices are followed.
- Build on open standards to enable secure reliable transactions for businesses and individuals.
"
-
Federation of Identities in a Web Services World side 4.
Ovenstående er de helt overordnede mål med det tekniske arbejde. Disse mål kan konkretiseres til følgende tekniske målsætninger:
- Det er målet at skabe grundlag for en *føderation af nationale web services",
- ... hvor der opretholdes "Single-Sign-On" (SSO) og
- ... hvor det er muligt for serviceudbydere at overbevise sig om brugeres identitet og autenticitet
- ... samt for alle parter i føderationen at kunne opretholde uafviselighed af beskeder, svar og andre vigtige data
- ... ved brug af åbne internationale og nationale standarder (konkret OCES, SAML og OIO)
- ... på en effektiv måde
- ... og uden at introducere unødige "single points of failure"
- ... så løsningen kan skalere til at kunne håndtere en stor del af (helst al) system-til-system integration mellem systemer i sundhedssektoren
- ... uden at tvinge parterne til specifikke platforms-, leverandør- eller værktøjsvalg.
Topic revision: r22 - 2007-09-20 - 10:19:14 -
JanRiis