Properly balanced, users won??™t be bombarded the nextgeneration
equivalent of ???Are you sure???? and will instead appreciate the clarity
of knowing what they have consented to and when.
Early adoption of CardSpace is focusing on situations where users are crossing a
trust boundary and/or when users have multiple identities within an organization
and need to make an explicit choice as to which identity they want to use.
This chapter generally speaks to applications where the user is crossing a trust
boundary, and when referring to identities for your organization, is speci?¬?cally
identifying users who are not employees, but customers.
Managing Identities for Your Organization
The STS that an organization uses to create security tokens effectively
isolates the identity store completely from the rest of
the system. Instead of the application having to access the data
in the identity store, the STS creates a token containing the information
the application needs and can encode that token in
any format. This leads to several valuable bene?¬?ts that can then
be taken advantage of:
The STS provides
several bene?¬?ts to
an organization??™s
efforts to manage
identities
326 Identity Providers
Identities are passed in lightweight tokens rather than
accessed through APIs.
Pages:
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467