• Home
  • About
  • Blog
  • Contact

← All posts

The Common Identity Protocols

May 16, 2018by Robert Broeckelmann
  • Federation
  • Kerberos
  • OAuth2
  • OpenID Connect
  • SAML
  • Identity

I’ve written blog posts on the following identity protocols. I’m creating this post to have a central place to refer to “identity protocols”. I will periodically update this list as I publish new posts with related material.

  • SAML2 profiles (and Use Cases)
  • OAuth2
  • OpenID Connect
  • SPNEGO
  • Kerberos
  • WS-Trust
  • WS-Federation

Originally published on Medium.

More articles

Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an Identity

August 20, 2026
  • Access Tokens
  • Authorization
  • Identity & Access Management

One of the most fundamental questions in any identity or authorization system is how does the system know that the party presenting a credential is actually entitled to use it?

Read article →: Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an Identity

Holder of Key vs. Proof of Possession: Two Sides of Cryptographic Identity

August 19, 2026
  • Access Tokens
  • Authentication
  • Identity & Access Management

For years, identity protocols have used phrases such as Holder of Key, Proof of Possession, Key Binding, and Bearer almost interchangeably.

Read article →: Holder of Key vs. Proof of Possession: Two Sides of Cryptographic Identity

Content Security Policy: Putting the Browser on a Security Diet

August 19, 2026
  • Application Security
  • Web Application Security
  • Security

Web applications have become remarkably powerful.

Read article →: Content Security Policy: Putting the Browser on a Security Diet
Site design by Yvette Richter Design
Contact Us|Privacy Policy

Proud sponsor of the Open Source IDPTools Project. Github project

© 2026 IYA Cyber Security. All rights reserved.

This site uses cookies for analytics and to remember this choice. See the Privacy Policy for what is collected and how to opt out.