Solutions Products Customers Partners Resources Company
Follow Us on:

Scalable solution for cross-domain web services security

Cloud, SOA, mobile, and B2B all rely on web services. Most services need to authenticate the clients and the users that request access. Cross-domain authentication requires additional management of trust relationships and a secured method of federating identity. Vordel Security Token Service offers a simple, reliable, and scalable way to control access to services across Cloud, SOA, mobile, and B2B domains.

Vordel Security Token Service (STS) is an authentication broker that handles security token generation, exchange, transmission, and validation across different technologies. The STS is a standard based solution that secures identity across different domains, while avoiding the complexity and cost of managing direct client-to-service security integrations.

Secure Identity with Signed Security Tokens

With web services getting more federated, credentials are being handled by more intermediaries than before, increasing security and compliance risks. Vordel STS encapsulates identity data in signed tokens such as SAML and Kerberos to enable secured federation of identity data. The STS can append or replace a token's claim and attribute data with up-to-date information from a trusted identity provider such as the enterprise directory. This enables better downstream authorization and audit at the web services. Vordel STS is integrated with all the leading identity management platforms to handle authentication, token issuance and validation.

Mediate Tokens From Different Platforms

With new mobile and Cloud clients and existing SOA and B2B clients, the task of authenticating clients is ever more complex, involving different technologies and standards. While SAML (Security Assertion Markup Language) has become the most popluar security token standard and has been adopted by major Cloud service providers such as Salesforce.com and Google, there are numerous other token standards like Kerberos that are widely used. Using Vordel STS to convert different client tokens to a standard based token such as SAML relieves web services the burden of handling multiple token types. With the ability mediate and cache tokens, STS simplifies single sign-on acrosss services built on different technologies.

Broker Trust Relationships Across Domains

For a service to validate the authenticity and integrity of a client's credential, it must have a trust relationship with the client either directly or through a broker. Managing direct trust relationships for a large number of endpoints is simply not scalable, especially for cross-domain relationships. Vordel STS brokers PKI based trust relationships between clients and services and automates token negotiation using WS-Trust and WS-Federation standards. Vordel leverages open standards to maximize interoperability with leading application, SOA, and identity management products.