Global Trust Framework Survey
Abstract
As a key deliverable of the BCTF Work Group this document shall provide a comprehensive overview of Trust Framework implementation whether as pilot projects or in operation.
Editors
Rainer Hörbe
Intellectual Property Notice
The BCTF Discussion Group operates under Creative Commons Share-Alike Attribution IPR Option and the publication of this document is governed by the policies outlined in this option.
Data Collection and Distribution
Data is collected from the sources mentioned below and from polls in the IDM community. There might be a bias towards education and public sector federations, as those tend to publicize their achievements more openly. Also federations of the WebSSO-class might be preferred due to their better visibility to users. A study to make data more representative would be needed and volunteers are wanted. E.g. WS-Trust seems to be under-represented and segregation between enterprise and federation use is not easy to achieve from some variables.
Analysis
# of Federations: Breakdown by Industry
Comment: The highest number of federations is in the public sector, followed by research and higher education. Industry (ICT, Finance, Transport) have a smaller share. |
# of Federations: Breakdown by Technical Protocol
# of Federations: Distribution by User Type
Top 5 Federations in 4 Categories: IDP, RP, Transactions and Users
Project Name | Description | Geog. scope | Industry | IDPs | RPs | Transactions [m/year] | Users [m| |
UK Access Management Federation | NREN | UK | R&E | 900 | 236 |
| 3 |
InCommon | NREN | US | R&E | 274 | 958 | 5 | |
AAI@EduHr | NREN | HR | R&E | 222 | 100 | 100 | 0,7 |
FEIDE/Uninett | NREN | NO | R&E | 202 | 150 | 6 | 0,7 |
WAYF/Forskningsnettet | NREN | DK | R&E | 130 | 110 | 5,5 |
|
|
|
|
|
|
|
|
|
IGTF | Grid computing | global | Science | 86 | 2500 |
|
|
InCommon | NREN | US | R&E | 274 | 958 | ||
SWITCHaai | NREN | CH | R&E | 47 | 581 |
|
|
UK Access Management Fed. | NREN | UK | R&E | 900 | 236 |
|
|
Portalverbund | G2G | AT | Public | 50 | 204 |
|
|
|
| ||||||
NETS | Payment | nordic | Fin |
|
| 500 | 7 |
Certipath | Supply Chain | global | Man | 20 | 100 | 400 | 2 |
BankID | B2C, G2C | SE | Pub |
|
| 400 | 3,5 |
AAI@EduHr | NREN | HR | R&E | 222 | 100 | 100 | 0,7 |
SWITCHaai | NREN | CH | R&E | 47 | 581 | 15 | 0,3 |
|
|
|
|
|
|
|
|
Mobile Phone Network | Mobile phones | global | ICT |
|
|
| 1600 |
Google-Yahoo-Facebk | Social logins | global | ICT | 3 |
|
| 1500 |
Rakuten | eCommerce | JP | Trade | 1 |
|
| 62 |
JAL | Travel | JP | Trans | 1 |
|
| 15 |
PIV | G2G | US | Pub |
|
|
| 8 |
Legend
ISIC: UN industry classification
Status: pilot, prod(uction), research. This survey has a focus on trust frameworks in production
Service Type: PA: Authentication (physical acess), LA: Authentication (logical acess), AT: Attributes, DS: Digital signature, DA: Delegated Authorization, E: Encryption
Trust Federation Constellations:
- C20 (SP-centric)
- C23 (central SP=IDP)
- C30 (Intra-organizational IDM)
- C31 (Ruling Party IDM)
- C32 (Identity Federation)
- C33 (Cross-Boder Federation)
- C50 (Enterprise Federation)
- Cxx 4-Corner Model
End User Class: B= Business, C=Consumer/Citizen, D=Device
Trust Federation Project Overview
Project Name | Description | Country | ISIC (Industry Classification) Computed | Status | since | #Relying Party | #Registered Users [m] | Service Type (summary) | C20 (SP-centric) | C23 (central SP=IDP) | C30 (Intra-organizational IDM) | C31 (Ruling Party IDM) | C32 (Identity Federation) | C33 (Cross-Boder Federation) | C50 (Enterprise Federation) | C35 4-Corner Model | End User Class | Technial Protocols |
Air Canada | Companies in the Air Canada Group | CA | H (Trans) | prod | LA | x | B | SAML | ||||||||||
Can. Banking Fed. | B2B-federtion of leading banks (clearing) | CA | K (Fin) | prod | x | B | SAML | |||||||||||
Canadian Access Federation CAF | NREN Federation Canada | CA | M/P (R&E) | prod | 14 | 1 | LA | x | B | SAML | ||||||||
Cyber AuthN Renewal | G2B, G2C (Federal) | CA | O (Pub) | prod | LA | x | C | SAML | ||||||||||
NaviNet SSO Service | navinet.net - Aetna secure SP | UK | Q (Health) | prod | LA | B | SAML | |||||||||||
Bipac | Political lobbying | US | M (Science) | prod | 2005 | LA | x | C | SAML | |||||||||
eduTech school | New York State - Identity Federation for state schools | US | P (Edu) | prod | LA | x | B | SAML | ||||||||||
FICAM | Federal government enabling private IdPs to provide citizens with identity for public online services | US | O (Pub) | prod | LA | x | C | SAML | ||||||||||
FIXs | Federation to provide physical access control to military installations | US | O (Pub) | prod | 2004 | PA | x | C | PKI | |||||||||
FRAC | Credentials to allow emergency response officials to quickly and easily access government buildings and reservations. Uses the PIV-I standard for Interoperability with PIV smart cards. | US | O (Pub) | pilot | PA/LA | x | B | PKI | ||||||||||
GFIPM | Justice: Global Federated Identity and Privilege Management Inter-Federation with US FBI (2010) | US | O (Pub) | LA | C | ? | ||||||||||||
GM OnStar | In-car owner online services | US | G (Trans) | prod | PA/LA | x | C | |||||||||||
InCommon | R&E federation | US | M/P (R&E) | prod | 958 | 5 | LA | x | B | SAML | ||||||||
NASA Access Launchpad | NASA Secure Token Service Credential Verifier | US | I (ICT) | prod | 6 | LA | x | B | SAML | |||||||||
NIH iTrust | Research collaboration between National Institute of Health and Universities (InCommon) | US | M (Science) | prod | LA | x | B | SAML | ||||||||||
PIV | Personal Identity Verification for US government employees and contractors | US | O (Pub) | prod | 2004 | 8 | PA/LA/DS | x | B | PKI | ||||||||
Rapattoni MLS | Multiple Listing Service (Real Estate) | US | L (Real Est) | prod | LA | B | SAML | |||||||||||
AGOSP | AU Government Online Service Point (Portal) | AU | O (Pub) | prod | ||||||||||||||
Australian Access Federation AAF | NREN Federation Australia | AU | M/P (R&E) | prod | 88 | LA | x | B | SAML | |||||||||
IMAGER | Identity Management for Australian Government Employees | AU | O (Pub) | prod | B | |||||||||||||
VANguard | B2G | AU | O (Pub) | prod | B | |||||||||||||
CARSI | NREN Federation China | CN | M/P (R&E) | pilot | 2006 | 30 | 1 | LA | x | B | SAML | |||||||
INFED | NREN Federation India | IN | M/P (R&E) | pilot | LA | x | B | SAML | ||||||||||
au easy payment (au Kantan Kessai) | The KDDI's authentication and payment provider allows customers to combine their content or service charges and au communication charges, and make payments online using an Android equipped smart phone or a computer with an internet connection. Leverages OpenID 2.0 between KDDI (as payment service provider) and its partner sites e.g. content providers, ecommerce sites. | JP | I (ICT) | prod | 2010 | C | OpenID | |||||||||||
GakuNin | NREN Federation Japan | JP | M/P (R&E) | prod | 2010 | 26 | 1 | LA | x | B | SAML | |||||||
JAL | Travel Federatin | JP | H (Trans) | prod | 2007 | 15 | LA | x | C | OpenID | ||||||||
miixi Graph API | social logins | JP | I (ICT) | prod | 2010 | C | OpenID | |||||||||||
NTT Docomo Login | eCommerce Federation | JP | I (ICT) | prod | 2010 | C | OpenID | |||||||||||
NTT ID Login Service | The NTT Communications' identity provider gateway allows users to log in to public websites with their account issued by NTT subsidiaries including NTT Docomo, NTT Communications (OCN) and NTT Resonant (goo). | JP | I (ICT) | prod | 2010 | C | OpenID | |||||||||||
Rakuten | eCommerce Federation | JP | G (Trade) | prod | 2009 | 62 | LA | x | C | OpenID | ||||||||
SoftBank Payment | Another mobile carrier billing service by SoftBank | JP | I (ICT) | prod | 2011 | C | OpenID | |||||||||||
Yahoo! Auth | eCommerce Federation | JP | G (Trade) | prod | 2008 | LA | C | OpenID | ||||||||||
MyIFAM | NREN Federation Malaysia | MY | M/P (R&E) | prod | 2012 | LA | x | B | SAML | |||||||||
NZ igovt (NZ Govt) | Centralised pseudonymous logon/authn (and distributed access) to govt services for citizens | NZ | O (Pub) | prod | 2007 | 18 for 35 services | 1 | LA | x | C | SAML | |||||||
RealMe | NZ SSO service with verified identities | NZ | O (Pub) | pilot | C | SAML | ||||||||||||
Tuakiri New Zealand Access Federation | NREN Federation New Zealand | NZ | M/P (R&E) | prod | 5 | LA | x | B | SAML | |||||||||
OMAN_KID | NREN Federation Oman | OM | M/P (R&E) | pilot | LA | x | B | SAML | ||||||||||
ULAKAAI | NREN Federation Turkey | TR | M/P (R&E) | pilot | 2011 | LA | x | B | SAML | |||||||||
VBMK | Victorian Business Master Key | AU | O (Pub) | prod | 2006 | LA | x | C | SAML | |||||||||
UAE Federation | NREN Federation UASE | UAE | M/P (R&E) | planned | LA | x | B | SAML | ||||||||||
Aconet Id Federation | NREN Federation Austria | AT | M/P (R&E) | prod | 2008 | 27 | LA | x | B | SAML | ||||||||
Austrian Bürgerkarte | Austrian Citizen Card | AT | O (Pub) | prod | 2002 | LA/DS | x | C | PKI | |||||||||
Portalverbund | G2G, some B2G for federal, state, local and independed public bodies | AT | O (Pub) | prod | 2001 | 204 | LA/Z | x | x | x | B | Prop | ||||||
Unternehmensserviceportal | Government to business portal | AT | O (Pub) | prod | 2012 | 16 | LA/Z | x | B | SAML | ||||||||
Belgium eID | Belgium eID Card (BELPIC) | BE | O (Pub) | prod | LA/DS | x | C | SAML | ||||||||||
Fedict | Belgium Gov'T IAM Service (Federal, Regiaons, local) | BE | O (Pub) | prod | LA | x | SAML | |||||||||||
Belnet R&E Federation | NREN Federation Belgium | BE | M/P (R&E) | prod | 2010 | 5 | LA | x | B | SAML | ||||||||
CAFe | NREN Federation Brasil | BR | M/P (R&E) | prod | 2010 | 13 | LA | x | B | SAML | ||||||||
SWITCHaai | NREN Federation Switzerland | CH | M/P (R&E) | prod | 2005 | 581 | LA | x | B | SAML | ||||||||
eduID.cz | NREN Federation Czeck | CZ | M/P (R&E) | prod | 42 | LA | x | B | SAML | |||||||||
Deutsche Telekom | Netzausweis (Net ID-Card) IDP-Service | DE | I (ICT) | prod | 13 | C | SAML | |||||||||||
DFN-AAI | NREN Federation Germany | DE | M/P (R&E) | prod | 2007 | 106 | LA | x | B | SAML | ||||||||
NemLog-In | "Easy Log-in" for Danish citizens | DK | O (Pub) | prod | LA | C | SAML | |||||||||||
WAYF/Forskningsnettet | NREN Federation Denmark | DK | M/P (R&E) | prod | 110 | x | B | SAML | ||||||||||
NETS | Scandinavian countries: Payment and related services, employing identity federation | DK/FI/IS/NO/SE | K (Fin) | prod | 7 | LA/DS | x | C | SAML | |||||||||
Catcert | Spanish regional implementations (Catalonia) | ES | O (Pub) | prod | 2003 | 4 | LA | x | C | SAML | ||||||||
DNI electrónico | Spanish national eID-Card | ES | O (Pub) | prod | 2006 | 3 | PA/LA/DS | x | C | |||||||||
SIR | NREN Federation Spain | ES | M/P (R&E) | prod | 2008 | 200 | 1 | LA | x | B | SAML | |||||||
epSOS | B2B for Health Care Professionals - cross border | EU | Q (Health) | pilot | 2012 | LA/Z | x | B | WS-Trust | |||||||||
GÉANT/SA3 | R&E network | EU | M/P (R&E) | LA | x | B | SAML | |||||||||||
PEPPOL | Provide cross-border electronic public procurement (B2G) | EU | O (Pub) | pilot | x | B | SAML | |||||||||||
SEPA | Single Euro Payments Area (SEPA) governed by the European Payment Council | EU | K (Fin) | prod | LA | x | B | Prop | ||||||||||
STORK | Federate national eIDs within Europe (STORK1: G2C, STORK 2: B2C) | EU | O (Pub) | pilot | 2011 | x | C | SAML | ||||||||||
Trust Service Status List | List of accredited CAs that provide qualified or advanced signatures, operated by the European commission. | EU | O (Pub) | prod | 2010 | x | C | PKI | ||||||||||
e-SWB "e-Signature without borders" | electronic Signature | EU, RU | prod | DS | x | C | PKI | |||||||||||
Haka/Funet | NREN Federation Finland | FI | M/P (R&E) | prod | 124 | x | B | SAML | ||||||||||
KATSO | AuthN & AuthZ for eGov services | FI | O (Pub) | prod | 2006 | LA/Z | x | B | SAML | |||||||||
Mobiilivarmenne | Operator run Mobile PKI AuthN | FI | O (Pub) | prod | 2010 | LA | x | C | ETSI MSS | |||||||||
Netposti | Postal Service | FI | O (Pub) | prod | SAML | |||||||||||||
Netso | Federation of motor insurance companies | FI | K (Fin) | prod | 2007 | B | SAML | |||||||||||
Tunnistus.fi | IdP Proxy service for Banks and eID cards (C2G; federated with Vetuma) | FI | O (Pub) | prod | 2004 | LA | x | C | SAML | |||||||||
TUPAS | Federation of Banks in the role of IdPs for citizen facing Government and Commercal SPs (C2G) | FI | O (Pub) | prod | x | C | TUPAS (proprietory) | |||||||||||
Vetuma | IdP Proxy service for Banks, eID cards and Mobile PKI | FI | O (Pub) | prod | 2006 | SAML | ||||||||||||
VIRTU | Authenticate public sector employees for services within the public sector (G2G, some B2G) | FI | O (Pub) | prod | 2009 | LA | x | B | SAML | |||||||||
FC2 | eGov, commerce federation pilot | FR | O (Pub) | pilot | LA | x | C | ? | ||||||||||
Fédération Éducation-Recherche | NREN Federation France | FR | M/P (R&E) | prod | 2006 | 123 | 1 | LA | x | B | SAML | |||||||
Mon Service-public | Government service portal for citizens (health, tax, ..) | FR | O (Pub) | prod | 2008 | 3 | LA | C | SAML | |||||||||
Orange-FT | Orange is IdP with the use base of its telco services to a number of service providers | FR | I (ICT) | prod | 2010 | LA | x | C | multiple SAML, API, OpenID | |||||||||
PSA Partner Portal | Peugeot/Citroen Suppler Network | FR | C (Man) | prod | 2008 | x | B | |||||||||||
GRNET | NREN Federation Greece | GR | M/P (R&E) | prod | 2007 | 25 | LA | x | B | SAML | ||||||||
AAI@EduHr | NREN Federation Croatia | HR | M/P (R&E) | prod | 100 | 1 | LA | x | B | SAML | ||||||||
eduID.hu (HREF Federation) | NREN Federation Hungary | HU | M/P (R&E) | prod | 2010 | 50 | LA | x | B | SAML | ||||||||
Edugate | NREN Federation Ireland | IE | M/P (R&E) | prod | 20 | LA | x | B | SAML | |||||||||
RHnet | NREN Federation Island | IS | M/P (R&E) | prod | x | B | SAML | |||||||||||
ICAR | Interoperability and Application Cooperation between the regions | IT | O (Pub) | prod | 2009 | LA | SAML | |||||||||||
IDEM | NREN Federation Italy | IT | M/P (R&E) | prod | 69 | 3 | LA | x | B | SAML | ||||||||
Italy national eID | eID authentication process | IT | O (Pub) | planned | x | C | SAML | |||||||||||
Ministry of Transportation Motorists’ Portal | Ministry for road and post office bank federate in the area of fine payment (Traffic Ticket Collection) | IT | O (Pub) | prod | x | B | SAML | |||||||||||
Sistema Pubblico di Connettività | Public Connectivity System (SPC): Italian Government Federation | IT | O (Pub) | prod | 2005 | LA | x | B | SAML | |||||||||
LAIFE | NREN Federation Latvia | LV | M/P (R&E) | prod | 2010 | 2 | LA | x | B | SAML | ||||||||
DigiD | Dutch eID schmea for citizens | NL | O (Pub) | prod | 2006 | 9 | LA | C | SAML | |||||||||
EHerkenning | eReconition | NL | O (Pub) | prod | 2010 | 15 | LA | x | B | SAML | ||||||||
SURFnet | NREN Federation Netherlands | NL | M/P (R&E) | prod | 83 | 1 | LA | x | B | SAML | ||||||||
Altinn | Government portal to establish new businesses | NO | O (Pub) | prod | 2008 | 33 | 1 | B | SAML | |||||||||
FEIDE/Uninett | NREN Federation Norway | NO | M/P (R&E) | prod | 2003 | 150 | 1 | LA | x | B | SAML | |||||||
Norwegian ? | Railroad B2B network | NO | H (Trans) | prod | B | SAML | ||||||||||||
RCTSaai | NREN Federation Portugal | PT | M/P (R&E) | prod | 8 | LA | x | B | SAML | |||||||||
BankID | Swedish banks, every bank issues Ids | SE | O (Pub) | prod | 4 | x | C | SAML | ||||||||||
SWAMID/SUNET | NREN Federation Sweden | SE | M/P (R&E) | prod | 2007 | 140 | x | B | SAML | |||||||||
Skolfederation | Secondary/primary education (prod 2013) | SE | M/P (R&E) | pilot | 2012 | SAML | ||||||||||||
eID2 | National eID Federation (Svensk e-legitimation) | SE | O (Pub) | pilot | 2010 | SAML | ||||||||||||
ArnesAAI Slovenska izobra |