Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Table of Contents
minLevel3
maxLevel3
typeflat
separatorpipe

Edit History

  • PaulT: 10/16/09: Changed preconditions so that Alice is pre-configured with Ohio State IdP and Equifax --now we need to update the mockups to align

Preconditions

  • Alice already has a multi-protocol browser add-on (aka selector, smart client, etc.)
  • Alice has configured her add-on with:
    • OpenIDsOpenID: Yahoo, AOL, Google, Facebook, Janrain
    • SAML IdPs: Ohio State
    • InfocardsInfocard: Equifax Identity Card, PayPal
  • Alice wants to login to the NIH site
  • Alice has never been to this site before
  • Alice is not logged in to any of her five OpenIDs at the moment
  • Alice has not defined a "default" OpenID, SAML or InfoCard
  • The site is a SAML, OpenID, and IMI/InfoCard compatible RP
  • The site trusts Yahoo, AOL, Google, as well as Equifax, Citigroup, Silicon Wave (?), Acxiom

...

  1. The user clicks on a "sign in" button on the NIH site
    1. The addon reads some data that tells it stuff like:
    2. That the site is an RP for OpenID, IMI and SAML protocols (unusually it does not support username/password!)
    3. The list of attributes that the site wishes to receive and for each attribute the list of authorities that the RP trusts. In our case the site is going to request only a non-correlateable identifier (aka an IMI "PPID", aka an OpenID "directed" identity) and that it trusts only Yahoo, AOL, Google, as well as Facebook, Equifax, Citigroup, Silicon Wave, Acxiom to issue this attribute
  1. The add-on displays a login window. It consists of a dropdown showing two
    1. It prominently shows the following accounts that could be used immediately (because Alice has these accounts and the NIH site accepts these accounts)
    , as well as one account
    1. :
      1. Google
      2. Ohio State
      3. Yahoo
      4. Equifax
      5. AOL
      6. PayPal
    2. Its also shows accounts that Alice could
    potentially
    1. use if she
    signed up with Google to get one (but she doesn't have one at present):
  2. Google
  3. Yahoo
  4. AOL
    1. first registered with these IdPs
      1. Acxiom
      2. Wave Systems
      3. Citigroup
  5. Alice clicks on Google
  6. Alice authenticates to Google
  7. Alice agrees to share Google attributes with NIH

...