Avoco Secure Announces Universal Identity Broker
Avoco Secure today announced it will launch the first "universal identity broker", a new product call Open2Connect that will make it much easier and more seamless for users to access online resources such as websites, documents, etc. using any identification/authentication method, including username/password, Information Cards, OpenID®, X509 digital certificate, Windows Live® ID, SAML, etc.
The Open2Connect UIB system ensures that a user can utilise any preferred login method, as long as that method contains the information required by the site to allow access (called a "claim"). Examples of claims include names, email addresses, or account numbers. The UIB can also go a step further by controlling access to the web resource through associating levels of assurance with the login, for example specifying that the claim must originate from a specified source.
The whole login process is handled by the UIB: the user simply clicks on the login button as usual -- vital in retaining usability of websites. The UIB will then present the user with choices of login method from their preferred list -- showing only those that the website will accept (because they contain the correct claim). The communication between the login method, the identity provisioning site (as appropriate) and the website is all handled by the UIB.
"What UIB means for the Information Card community is that there is a new approach both to usability and to integration of Information Cards with other identity protocols like OpenID," said Sandy Porter, VP Business Development for Avoco Secure. "We believe that UIB technology can be deployed, for example, by a large identity provider to service a large population of users over a large number of relying party websites, where it would be almost impossible for those sites to all agree to use one identity protocol. The UIB makes the experience seamless for users no matter what protocol the sites are using, even plain old username and password."
For complete details, see the full press release.
- Drummond Reed's blog
- Login to post comments

Comments
Hello
.further by controlling access to the web resource through associating levels of assurance with the login, for example specifying that the claim must originate from a specified source