OASIS approves new single sign-on standard for e-business
Computerworld - The first version of the Security Assertion Markup Language (SAML) has been ratified by the standards group OASIS, giving Web site developers an open standard that will allow users to visit multiple unrelated sites after logging in with a secure single sign-on.
In an announcement today, the Organization for the Advancement of Structured Information Standards (OASIS), a Boston-based e-business standards group, said its members had approved SAML Version 1.0 as an OASIS Open Standard, adding it to a growing number of Web-based standards being created for business.
Last month, OASIS announced the adoption of a new ebXML Messaging Service Specification for business communications (see story).
SAML is an XML-based framework for Web services that allows authentication and authorization information to be exchanged among different Web sites or businesses. It includes single sign-on by a user and allows visitors to use sites hosted by multiple companies, making it easier for people to shop online without having to log in individually at each site.
A spokesman for OASIS could not be reached for comment early today.
"SAML lets companies implement single sign-on solutions that allow users to visit various Web sites without being repeatedly challenged for credentials," Joe Pato, who works for Hewlett-Packard Co. and is co-chair of the OASIS Security Services Technical Committee, said in a statement. "In addition, SAML makes it possible to include security information in documents used in business transactions. This is particularly relevant for Web services, where security is critical."
SAML incorporates industry-standard protocols and messaging frameworks, such as XML Signature, XML Encryption and SOAP. The specification can be integrated in standard environments such as HTTP and standard Web browsers, according to OASIS.
The SAML OASIS Open Standard was developed by a consortium of companies, including Baltimore Technologies PLC, BEA Systems Inc., Computer Associates International Inc., HP, IBM, Sun Microsystems Inc., VeriSign Inc. and other members of the OASIS Security Services Technical Committee.
"Ratification as an OASIS Open Standard means that developers can deploy SAML with confidence," Karl Best, OASIS director of technical operations, said in a statement.
OASIS is a nonprofit, global consortium that works to create and adopt e-business technology standards.
Read more about Applications in Computerworld's Applications Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Enabling Remote Employees with High Quality Video
- In this paper, we analyze the delivery of live and on-demand mobile video content. It focuses on specific ways in which organizations can...
- Switching Schedulers - Not As Complicated As You Think
- Changing or consolidating job schedulers may seem daunting. However, the benefits of switching to enterprise workload automation outweigh the risks. Read how BMC...
- A "YouTube-like" Experience For Employees
- Leading research firms are predicting that video is becoming a key component of workplace collaboration. More and more, employees are creating and sharing...
- The CFO Guide to Budgeting Software
- A mid-sized business needs the same financial performance control and measurement capabilities as a large corporation, but in a solution that's affordable, easy...
- Transition from Spreadsheet Budgets to Packaged Application
- This white paper details the problems that go with spreadsheet-based budgeting as well as the advantages of packaged applications. It also proposes a...
- Live Webcast
How to Reduce Complexity and Automate Your Partners for Efficient E-Business: - Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Live Webcast
A Geek's Guide to Presenting to Business People - Live Webcast: Wednesday, June 20th at 1:00 PM EDT
Join this live webinar with Paul Glen, author of Leading Geeks, to learn how to... - BMC Control-M - Single Point of Control Demo
- With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's...
- Operational Analytics - Changing the Competitive Dynamics of the Business
- Date/Time: June 5, 2012, 11:00 a.m., EDT, 4:00 p.m. BST / 3:00 p.m. UTC
Please join us for this webcast, as Dr. Barry... - Oracle Database Appliance Best Practices
- Business users increasingly demand 24x7 availability of their data while IT departments face the challenge of ensuring maximum availability while operating with limited...
- BMC Control-M - Single Point of Control Demo
- With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's...
- Sun Chemical Customer Success Story
- Sun Chemical, the world's largest producer of printing inks and pigments, quadrupled its complex batch environment with zero extra headcount using BMC Control-M's...