Identity
Provider
Relying
Party
CardSpace
3. Request is
forwarded to IP.
1. RP makes request.
5. User reviews token.
6. Token is
returned.
4. IP returns
security token. 2. User picks a
card.
Figure 3-6 The request made by the RP being brokered to the IP
Cards contain information
about how
they can be used
185
The metadata contains the information needed to connect to the
IP and request a security token. The metadata also provides
CardSpace with information about the digital identity that the
card represents so that it can help guide the user. The main data
contained in a card includes the following:
Display information. This can include an image to use
on the card, as well as a name for the card.
Where to contact the IP. The identity exposes a web
service that produces the security tokens; naturally
enough, this is called the Security Token Service, or STS.
The URL of the STS is contained within the card.
How to authenticate to the IP. Along with containing
where the STS is published, it is also necessary to know
what authentication the user will need to perform to
retrieve the security token.
Supported claims list. Data expresses the types of claims
an IP will provide.
Pages:
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302