On Identity Assurance in the Presence of Federated Identity Management Systems
This paper addresses the appropriate management of risk in federated identity management systems by presenting an identity assurance framework and supporting technologies. The paper starts by discussing the risk mitigation framework that should be part of any identity assurance solution. The authors then demonstrate how their model based assurance technologies can be used to report success of an identity assurance programme. The authors discuss how this approach can be used to gain trust within a federated identity management solution both by communicating the nature of the assurance framework and that risks are successfully being mitigated.