It insulates developers from complex systems.
When an application??™s access to identity data is
abstracted out into an STS, the application developers
can be freed from having to address the factors of trust,
attribution, and examination of the identity information
because that can be factored out and kept in the STS.
The application itself need only be concerned with the
business at hand.
327
Decoupling of the systems provides options for hosting
and limits exposure.
With the identity store completely decoupled from the
application, an organization can make better choices in
the hosting of the application. Scaling of the application
may take place separately from the STS??”perhaps the
application needs to be replicated globally and having it
connected to the identity store complicates that. Certain
components may also be outsourced where appropriate,
without exposing the entire system to the external organization.
Finally, with the authentication and identity
store no longer connected with the application, a compromise
of one system need not affect the other.
Managing Identities Used by Other Organizations
Historically, identity management solutions concentrated user
identity information into a centralized store that can be accessed
by different systems??”inside the same domain.
Pages:
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469