- Identity ManagementCore Issues
- Understanding Network Identity and Federated Identity
- Introduction to SAML
- SAML Architecture
- SAML Usage Scenarios
- The Role of SAML in J2EE-Based Applications and Web Services
- Introduction to Liberty Alliance and Their Objectives
- Liberty Alliance Architecture
- Liberty Usage Scenarios
- The Nirvana of Access Control and Policy Management
- Introduction to XACML
- XACML Data Flow and Architecture
- XACML Usage Scenarios
- Summary
- References
References
[Anne1] Anne Anderson. âA Comparison of EPAL and XACML.â Sun Microsystems. July 12, 2004.
http://research.sun.com/projects/xacml/CompareEPALandXACML.html
[Anne2] Anne Anderson. âIEEE Policy 2004 Workshop 8 June 2004âComparing WSPL and WS-Policy.â IEEE Policy 2004.
http://www.policy-workshop.org/2004/slides/Anderson-WSPL_vs_WS-Policy_v2.pdf
[Anne3] Anne Anderson. âAn Introduction to the Web Services Policy Language (WSPL).â Sun Microsystems Laboratories. 2004.
[KingPerkins1] Chris King and Earl Perkins. âThe Role of Identity Management in Information Security: Part IâThe Planning View.â
[Liberty] Liberty Alliance ProjectâOfficial Web site
[Liberty12FFArch] Thomas Watson, et al. âLiberty ID-FF Architecture Overview.â OASIS.
http://www.projectliberty.org/specs/liberty-idff-arch-overview-v1.2.pdf
[LibertyIDWSF] Liberty Alliance. Liberty ID-WSF Security Mechanisms. Version 1.2.
http://www.projectliberty.org/specs/liberty-idwsf-security-mechanisms-v1.2.pdf
[Liberty12Tutorial] Alexandre Stervinou. âLiberty Specifications Tutorial.â Liberty Alliance.
[OASIS] OASISâOfficial Web site
[OpenSAML] OpenSAMLâOfficial Web site
[SecurityBreach2004] Information Security Breaches Survey 2004.
[SAML-TC] OASIS SAMLâTechnical Committee
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security
[SAML11Core] OASIS. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V1.1. September 2, 2003.
http://www.oasis-open.org/committees/download.php/3406/oasis-_sstc-saml-core-1.1.pdf
[SAML11Diff] OASIS. Differences between OASIS Security Assertion Markup Language (SAML) V1.1 and V1.0. May 21, 2003.
http://www.oasis-open.org/committees/download.php/3412/sstc-saml-diff-1.1-draft-01.pdf
[SAML11Security] OASIS. Security and Privacy Considerations for the OASIS Security Assertion Markup Language (SAML) V1.1. September 2, 2003.
http://www.oasis-open.org/committees/download.php/3404/oasis-_sstc-saml-sec-consider-1.1.pdf
[SAML2Core] OASIS. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0. Working Draft 10. April 10, 2004.
http://www.oasis-open.org/committees/download.php/6347/sstc-saml-core-2.0-draft-10-diff.pdf
[SAML2Scope] OASIS. SAML Version 2.0 Scope and Work Items.
http://www.oasis-open.org/committees/download.php/6277/sstc-saml-scope-2.0-draft-17.pdf
[SAML2Profiles] OASIS. Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0. March 15, 2005.
http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf
[SourceID] SourceIDâOfficial Web site
[SPML-TC] OASIS SPMLâTechnical Committee
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=provision
[Systinet] Systinet article: SAML Support on Smartcard.
http://www.theserverside.com/resources/article.jsp?l=Systinet-Web services-part-6
[WebServicesLifeCycle] Ray Lai. âWeb Services Life Cycle: Managing Enterprise Web Services.â Sun Microsystems. October 2003.
http://wwws.sun.com/software/sunone/whitepapers/wp_mngwebsvcs.pdf
[XACML-TC] OASIS XACMLâTechnical Committee
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml
[XACML11] OASIS. eXtensible Access Control Markup Language (XACML) Version 1.1. Committee Specification. August 7, 2003.
http://www.oasis-open.org/committees/xacml/repository/cs-xacml-specification-1.1.pdf
[XACML2] OASIS. eXtensible Access Control Markup Language (XACML) Version 2.0. Working Draft 09. April 16, 2004.
http://www.oasis-open.org/committees/download.php/6433/oasis-xacml-2.0-core-wd-09.zip
[XACML2changes] Daniel. âDifferences Between XACML Versions 1.0 and 2.0.â January 7, 2005.
http://blog.parthenoncomputing.com/xacml/archives/2005/01/the_differences.html
[XACML2SAML2] OASIS. SAML 2.0 Profile of XACML. Committee Draft 02. November 11, 2004.
http://docs.oasis-open.org/xacml/access_control-xacml-2.0-saml_profile-spec-cd-02.pdf