Contributing Partners
TUG, SIC
Executive Summary
In identity- and access management (IAM), an identity provider (IdP) forwards identity attributes to a service provider (SP) on an untrusted network. The Transport Layer Security (TLS) protocol protects the integrity and the confidentiality of these attributes in transit, but it only establishes protection in between nodes and not from one end to the other end, which means that intermediaries, such as IdPs, have access to sensitive information.