Identity in the cloud era
Nowadays, there are plenty of standards, protocols, and practices related to identity. Some of them have been outlined in the previous chapter and are must-know concepts for an identity expert. Regardless, these concepts can get very complicated.
Just to give a brief idea of what we are talking about, the following is a list (but not an exhaustive report) of the available standards at the time of writing. It is important to note that some of the standards or protocols we have mentioned are still in draft (under development) at the time of writing:
- Passwordless:
- World Wide Web Consortium (W3C):
- WebAuthn
- FIDO:
- Client to Authenticator Protocol (CTAP)
- World Wide Web Consortium (W3C):
- Authentication/authorization:
- OpenID Foundation:
- OpenID Connect
- Continuous Access Evaluation Protocol (CAEP)
- Shared Signals and Events
- FastFed
- OpenID Connect Federation (https://openid.net/specs/openid-connect-federation-1_0.html)
- IETF:
- OAuth
- System for Cross-Domain Identity Management (SCIM)
- Grant Negotiation...
- OpenID Foundation: