Previous Topic: Federation in Your Enterprise

Next Topic: User Identification Across the Partnership

Federation Business Case

A sample business case is best illustrated to understand how Federation Manager can solve a common business problem.

In this business case, Financepro is a financial planning firm that recently bought the banking firm BankLtd to provide private banking to its clients. These two companies have different information infrastructures, but they want to appear as one company to their customers. To solve this problem, they set up a federated partnership.

By establishing a federated relationship, the two companies can provide a seamless customer experience using single sign-on. Customers can travel between Financepro and BankLtd without constantly being challenged to authenticate. Additionally, the sharing of customer identities and customer information can further customize the user experience and cross-promote financial products offered by each partner.

The following illustration shows the federated partnership between Financepro and BankLtd. The flow of communication is based on Service Provider-initiated single sign-on.

Web SSO Sample Network

In the illustration, the following occurs:

  1. The user tries to access a federated resource at BankLtd.
  2. The user is redirected to the Financepro for authentication and the assertion is generated.
  3. The assertion is passed back to BankLtd.
  4. Single sign-on occurs based on either a SAML HTTP-Artifact or HTTP-POST. The user gets access to the target resource.

For this partnership to work, decide how the partnership functions before implementing the relationship using Federation Manager.

The issues you must consider include:

The decisions you make help structure the business partnership.