OASIS ratifies security markup

Members of the Organization for the Advancement of Structured information Standards (OASIS) have ratified Security Assertion Markup Language (SAML) version 2.0 as an OASIS standard, a move that some observers see as a significant step toward so-called federated networks.

Those networks share already existing repositories of identity information. SAML 2.0 will allow for a single Web-based sign-on for people needing to move information across separate security domains, a necessity for the kind of inter-agency communications being pushed at all levels of government.

SAML 2.0 acts as the "convergence point" for major identity federation initiatives being deployed today such as SAML 1.x varieties, Liberty ID-FF and the Internet2.s Shibboleth effort, said Rob Philpott, senior consulting engineer at RSA Security and co-chairman of the OASIS security services technical committee.

"Some of (SAML 2.0) features fill in important 'gaps' observed in practical deployments (such as) the attribution profiles and metadata specification that simplify agreement between businesses participating in a federation," said Prateek

Mishra, the other committee co-chairman and one of the SAML developers. Other features include encryption, pseudonyms and user content that enable confidentiality and privacy of user information, he said.

Robinson is a freelance journalist based in Portland, Ore. He can be reached at brian@hullite.com.

About the Author

Brian Robinson is a freelance writer based in Portland, Ore.

The Fed 100

Read the profiles of all this year's winners.

Featured

  • Shutterstock image (by wk1003mike): cloud system fracture.

    Does the IRS have a cloud strategy?

    Congress and watchdog agencies have dinged the IRS for lacking an enterprise cloud strategy seven years after it became the official policy of the U.S. government.

  • Shutterstock image: illuminated connections between devices.

    Who won what in EIS

    The General Services Administration posted detailed data on how the $50 billion Enterprise Infrastructure Solutions contract might be divvied up.

  • Wikimedia Image: U.S. Cyber Command logo.

    Trump elevates CyberCom to combatant command status

    The White House announced a long-planned move to elevate Cyber Command to the status of a full combatant command.

  • Photo credit: John Roman Images / Shutterstock.com

    Verizon plans FirstNet rival

    Verizon says it will carve a dedicated network out of its extensive national 4G LTE network for first responders, in competition with FirstNet.

  • AI concept art

    Can AI tools replace feds?

    The Heritage Foundation is recommending that hundreds of thousands of federal jobs be replaced by automation as part of a larger government reorganization strategy.

  • DOD Common Access Cards

    DOD pushes toward CAC replacement

    Defense officials hope the Common Access Card's days are numbered as they continue to test new identity management solutions.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group