
Single Sign On (SSO) (also known as Enterprise Single Sign On
or "ESSO") is the ability for a user to enter the
same id and password to logon to multiple applications within an
enterprise. As passwords are the least secure authentication mechanism,
single sign on has now become known as reduced sign on (RSO) since more
than
one type of authentication mechanism is used according to enterprise
risk models.
For example, in an enterprise using SSO software, the user logs on with
their id and password. This gains them access to low risk information
and multiple applications such as the enterprise portal. However, when
the user tries to access higher risk applications and information, like
a payroll system, the single sign on software requires them to use a
stronger form of authentication. This may include digital certificates,
security tokens, smart cards, biometrics or combinations thereof.
Single sign on can also take place between enterprises using federated
authentication. For example, a business partner's employee may
successfully log on to their enterprise system. When they click on a
link to your enterprise's application, the business partner's single
sign on system will provide a security assertion token to your
enterprise using a protocol like SAML, Liberty Alliance, WS Federation
or Shibboleth. Your enterprise's SSO software receives the token,
checks it, and then allows the business partner's employee to access
your enterprise application without having to sign on.
Single sign on federated authentication also works with your employees.
For example, an employee who is trying to access your outsourced
benefits supplier to update their benefits information would click on
the benefits link on your intranet. Your enterprise's single sign on
software would then send a security assertion token to the benefits
supplier. The benefits supplier's SSO system would then take the token,
check it and grant access to your employee without making them sign on.
Password
Authentication
Single
Sign On Authentication Access
Control Authentication Authentication-Enterprise
Security Authentication
Strength Authentication
Transaction
Authentication
Management User
Authentication Authentication
Federation Biometric
Authentication PKI
Authentication Token
Authentication Wireless
Authentication Document
Authentication
Authentication - Outsourcing