Identity Brokering
Overview
An Identity Broker is an intermediate service that interconnects multiple SPs with different IDPs. As an intermediate service, the broker is accountable for establishing trust relationship with an external IDP to use the identities for accessing services exposed internally by SP.
From a user point of view, an identity broker enables a user-centric way to maintain identities across multiple realms. An account can be associated with one or more identities from multiple IdPs or can even be established based on the identity data obtained from them.
An IDP is generally based on a specific protocol that is used for authentication and authorization purposes. IdP can be any business vendors or partners or social providers (such as Facebook or Google) whose users require access to one or more services. It can also be a cloud-based identity service that you would like to integrate with.
IdPs are typically based on the following protocols:
- OpenID Connect 1.0
- OAuth 2.0
Identity Provider(IDP) Brokering
When using Identity Provider(IDP) platform for identity brokering, then users are not enforced to provide credentials for authentication against a realm. Instead, users are displayed with a list of IDPs through which they can authenticate themselves. Identity Provider(IDP) identity brokering service provides following solutions out-of-the-box:
- The capability to configure an IDP of your choice such as Ping Identity, OKTA, miniOrange, RSA, Facebook, Google, Twitter and many more.
- When you have an IDP of your choice established, then Identity Provider(IDP) platform allows you to use KOBIL specific MFA products on top to ensure advanced security.
- Identity Provider(IDP) platform also provides advanced Risk Bits Information from your mobile applications (integrated with mID SDK) as an additional security factor that could be used in Fraud Detection techniques.
A default IdP can also be configured via Identity Provider(IDP) platform. If a default IDP is chosen, then users will not be given options, but they will be redirected to the default provider directly.
Benefits of Identity Provider(IDP) Brokering Service
Following are some of the main benefits of using Identiy One Brokering service:
- You do not need to understand any complicated SSO protocols such as Open ID and OAUTH.
- You could enable applications using HTTPS calls easily.
- You could enable social login to web applications without any difficulty of understanding how everything works.
- When you obtain Access Tokens from any client applications, then you could insert a custom based code and extend the applications as you need.