Summary

  • Kenneth J. Klingenstein helped research institutions move from one-off access arrangements toward a federation in which local authentication, shared attribute meanings, signed metadata and local authorization remained distinguishable.
  • The design did not make trust automatic. It made trust governable by assigning different evidence and duties to the identity provider, the service provider and the federation operator.

The decisive moment in a federated login is easy to miss. A researcher reaches an online collection run by another institution. The page redirects to the researcher’s university, the familiar sign-in succeeds, and the collection opens. No new account appears to have been created. The experience feels like one continuous service.

Operationally, it is a chain of separate decisions. The home institution authenticates a person under its own procedures. It issues a statement about that event and may attach attributes. The receiving service checks the statement and applies a local access rule. Between them lies information about endpoints, roles and verification keys, together with rules about who may participate and what claims are supposed to mean. The page can open even though no actor controls the whole chain.

Klingenstein’s contribution belongs in that middle layer. The Internet Hall of Fame records both his earlier work expanding networking in the American West and his later leadership in Internet identity and trust. In 1999, while serving as chief technologist at the University of Colorado Boulder, he was assigned to lead the Internet2 Middleware Initiative. Internet2’s own account credits the initiative with Shibboleth, InCommon, eduPerson and related community infrastructure. It also makes clear that this was collective work, not the invention of one person.

Klingenstein has described the early group as following R. L. “Bob” Morgan and searching for a way to share authentication information and attributes. Their compact ambition was to authenticate locally and act globally. That formulation carried an institutional judgment. Universities already had accounts, directories and local security practices. Replacing them with one central identity system would have concentrated control and required every campus to accept the same operating model. Federation tried to make the existing domains cooperate.

The Shibboleth project grew from the Internet2 middleware effort in 2000 and connected with the OASIS work on the Security Assertion Markup Language. Version 1.0 was released in 2003. A 2004 account co-written by Morgan, Scott Cantor, Steven Carmody, Walter Hoehn and Klingenstein describes two deliberately separate components: an identity provider at the user’s home organization and a service provider protecting the remote resource.

The identity provider handles the familiar login and produces an assertion. The service provider validates what it receives and supplies attributes to the application. The application, not the identity provider, decides whether those attributes satisfy its access policy. “Authenticated” and “permitted” are therefore not synonyms. A technically valid assertion can still meet a mistaken, obsolete or overbroad local rule.

Attributes made that distinction practical. A library might need to know that someone belongs to an eligible group without receiving a permanent campus username. A scientific service might need an entitlement rather than a full personal profile. The eduPerson schema gave research and education institutions common names and definitions for such claims. Its specification is unusually candid: an affiliation value has practical use across institutions only when definition and practice have broad consensus.

That sentence turns vocabulary into infrastructure. If one campus uses “member” for current staff while another includes alumni and contractors, identical text can support different decisions. If an identifier may be reassigned, a service that treats it as permanent can attach a new person to an old record. The eduPerson document consequently distinguishes scope, persistence, privacy, uniqueness and reassignment. Meaning has a lifecycle, just as keys and servers do.

Shibboleth also offered attribute-release controls. The home institution could decide which information to send to a particular service, and designs could use opaque or transient identifiers in place of a widely recognizable login name. These mechanisms created options for data minimization; they did not guarantee privacy. Defaults, administrator policy, user understanding, service logging and later correlation still determine what can be learned about a person.

Protocol interoperability solved only part of the problem. The 2004 authors listed choices that participants still had to align: security mechanisms, attribute definitions, server discovery, account-management accuracy, handling of personal information and eligibility to join. Negotiating all of these separately between every campus and every service would produce a dense mesh of contracts and configuration. A federation made a shared agreement reusable.

InCommon supplied that organizational layer in the United States. Klingenstein’s twentieth-anniversary account says the team realized that a relying party needed a reason to trust information supplied by another institution. The answer was not a magical trust flag. It was an operating structure able to identify participant organizations and their officers, process metadata, publish expectations, run services, resolve disputes and terminate participation.

Metadata is where this institution becomes machine-readable. The OASIS specification allows an entity to publish roles, service endpoints, supported bindings and key material for verifying signatures or encrypting messages. InCommon’s operating policy describes collecting participant metadata, evaluating changes, digitally signing the result and making it available for participants to retrieve. A self-signed certificate can be usable in this setting because the federation’s controlled registration and signed distribution establish the binding. The certificate alone does not establish the institution.

This creates a registry between login domains, but not a central account database. The federation operator distributes statements about systems and participants. The identity provider remains responsible for its users and assertions. The service provider remains responsible for validation and access. InCommon’s Baseline Expectations make the three roles explicit because reliability depends on all three.

The historical achievement was to reduce the number of relationships that had to be improvised without erasing autonomy. Shared metadata reduced manual endpoint and key exchange. Common attributes reduced semantic translation. A community policy reduced repeated eligibility and trust negotiations. Open software gave institutions an implementation they could inspect and operate. None of these layers removed the need for judgment; together they made the judgment repeatable.

That is also the limit of the familiar phrase “single sign-on.” It describes what the user sees, not what an investigator must prove. After a disputed access, the useful questions are distributed. Which identity provider authenticated the subject, when and with what context? Which assertion did it issue, for which audience and lifetime? Which attributes were released under which rule? Which metadata and verification key did the service trust? Which local policy turned those claims into permission?

A successful page load answers none of those questions by itself. Klingenstein’s deeper legacy is not that the login became invisible. It is that the interfaces of institutional trust became explicit enough to govern. The federation worked when two domains could remain different and still produce a decision whose parts could be named.

Sources