Title :
Open Identity Management Framework for SaaS Ecosystem
Author :
Bin, Wang ; Yuan, Huang He ; Xi, Liu Xiao ; Min, Xu Jing
Author_Institution :
Res. Lab., IBM China, Beijing, China
Abstract :
As software-as-a-service (SaaS) becomes more and more popular, the identity management and federation among SaaS applications also become an important factor impacting the growth of SaaS ecosystem. Typically, there are three major functions to be enabled in identity federation: 1) single sign-on across different services. 2) Account provisioning to different services. 3) secure backend service call between services. Current SaaS delivery platforms provide these functions in an ad-hoc way, which might limit the growth of SaaS ecosystem. To overcome the limitations, this paper proposes an open identity framework, which leverages open identity protocol such as OpenID and OAuth. Moreover, an OAuth broker is proposed to mediate backend service calls among SaaS applications. The framework can bring benefits to all the roles involved in the ecosystem in a non-intrusive and user-centric way. Open is a good design principle, and it is also the attitude and sprit of collaboration. We think that a SaaS ecosystem based on open technologies could make the composition of services easier and accelerate the on-boarding of service providers. Moreover, more customers might also be attracted by the openness of the ecosystem.
Keywords :
Web services; protocols; security of data; OAuth broker; SaaS delivery platform; SaaS ecosystem; account provision; identity federation; open identity management framework; open identity protocol; secure backend service; single sign-on service; software-as-a-service; user-centric openID; Access protocols; Application software; Authentication; Conference management; Ecosystems; Engineering management; Helium; Identity management systems; Laboratories; Protection; Identity Federation; Identity Management; OAuth; OpenID; SaaS;
Conference_Titel :
e-Business Engineering, 2009. ICEBE '09. IEEE International Conference on
Conference_Location :
Macau
Print_ISBN :
978-0-7695-3842-6
DOI :
10.1109/ICEBE.2009.82