- Identity ManagementCore Issues
- Understanding Network Identity and Federated Identity
- Introduction to SAML
- SAML Architecture
- SAML Usage Scenarios
- The Role of SAML in J2EE-Based Applications and Web Services
- Introduction to Liberty Alliance and Their Objectives
- Liberty Alliance Architecture
- Liberty Usage Scenarios
- The Nirvana of Access Control and Policy Management
- Introduction to XACML
- XACML Data Flow and Architecture
- XACML Usage Scenarios
- Summary
- References
References
[Anne1] Anne Anderson. “A Comparison of EPAL and XACML.” Sun Microsystems. July 12, 2004.
http://research.sun.com/projects/xacml/CompareEPALandXACML.html
[Anne2] Anne Anderson. “IEEE Policy 2004 Workshop 8 June 2004–Comparing WSPL and WS-Policy.” IEEE Policy 2004.
http://www.policy-workshop.org/2004/slides/Anderson-WSPL_vs_WS-Policy_v2.pdf
[Anne3] Anne Anderson. “An Introduction to the Web Services Policy Language (WSPL).” Sun Microsystems Laboratories. 2004.
[KingPerkins1] Chris King and Earl Perkins. “The Role of Identity Management in Information Security: Part I–The Planning View.”
[Liberty] Liberty Alliance Project–Official Web site
[Liberty12FFArch] Thomas Watson, et al. “Liberty ID-FF Architecture Overview.” OASIS.
http://www.projectliberty.org/specs/liberty-idff-arch-overview-v1.2.pdf
[LibertyIDWSF] Liberty Alliance. Liberty ID-WSF Security Mechanisms. Version 1.2.
http://www.projectliberty.org/specs/liberty-idwsf-security-mechanisms-v1.2.pdf
[Liberty12Tutorial] Alexandre Stervinou. “Liberty Specifications Tutorial.” Liberty Alliance.
[OASIS] OASIS–Official Web site
[OpenSAML] OpenSAML–Official Web site
[SecurityBreach2004] Information Security Breaches Survey 2004.
[SAML-TC] OASIS SAML–Technical Committee
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security
[SAML11Core] OASIS. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V1.1. September 2, 2003.
http://www.oasis-open.org/committees/download.php/3406/oasis-_sstc-saml-core-1.1.pdf
[SAML11Diff] OASIS. Differences between OASIS Security Assertion Markup Language (SAML) V1.1 and V1.0. May 21, 2003.
http://www.oasis-open.org/committees/download.php/3412/sstc-saml-diff-1.1-draft-01.pdf
[SAML11Security] OASIS. Security and Privacy Considerations for the OASIS Security Assertion Markup Language (SAML) V1.1. September 2, 2003.
http://www.oasis-open.org/committees/download.php/3404/oasis-_sstc-saml-sec-consider-1.1.pdf
[SAML2Core] OASIS. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0. Working Draft 10. April 10, 2004.
http://www.oasis-open.org/committees/download.php/6347/sstc-saml-core-2.0-draft-10-diff.pdf
[SAML2Scope] OASIS. SAML Version 2.0 Scope and Work Items.
http://www.oasis-open.org/committees/download.php/6277/sstc-saml-scope-2.0-draft-17.pdf
[SAML2Profiles] OASIS. Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0. March 15, 2005.
http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf
[SourceID] SourceID–Official Web site
[SPML-TC] OASIS SPML–Technical Committee
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=provision
[Systinet] Systinet article: SAML Support on Smartcard.
http://www.theserverside.com/resources/article.jsp?l=Systinet-Web services-part-6
[WebServicesLifeCycle] Ray Lai. “Web Services Life Cycle: Managing Enterprise Web Services.” Sun Microsystems. October 2003.
http://wwws.sun.com/software/sunone/whitepapers/wp_mngwebsvcs.pdf
[XACML-TC] OASIS XACML–Technical Committee
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml
[XACML11] OASIS. eXtensible Access Control Markup Language (XACML) Version 1.1. Committee Specification. August 7, 2003.
http://www.oasis-open.org/committees/xacml/repository/cs-xacml-specification-1.1.pdf
[XACML2] OASIS. eXtensible Access Control Markup Language (XACML) Version 2.0. Working Draft 09. April 16, 2004.
http://www.oasis-open.org/committees/download.php/6433/oasis-xacml-2.0-core-wd-09.zip
[XACML2changes] Daniel. “Differences Between XACML Versions 1.0 and 2.0.” January 7, 2005.
http://blog.parthenoncomputing.com/xacml/archives/2005/01/the_differences.html
[XACML2SAML2] OASIS. SAML 2.0 Profile of XACML. Committee Draft 02. November 11, 2004.
http://docs.oasis-open.org/xacml/access_control-xacml-2.0-saml_profile-spec-cd-02.pdf