Welcome!

Containers Expo Blog Authors: Elizabeth White, Liz McMillan, Pat Romanski, Amit Gupta, Stackify Blog

Related Topics: Containers Expo Blog, Microservices Expo

Containers Expo Blog: Article

SaaS Single Sign-On: It's Time for a Lighter Approach

A scripting identity federation solution is exactly what a SaaS application needs

SaaS brings a lot of advantages to businesses - no need to invest in purchasing and maintaining licenses and infrastructure, and no need to worry about upgrades and bug fixes. Larger companies, however, face a major challenge related to user authentication and management. Larger companies have invested a lot of time and effort in improving user productivity, compliance and security, and in cutting user management costs.

They have done so using technologies like single sign-on and centralized user management. SaaS applications are now challenging those efforts and threatening to bring them back to the situation where every user has several different usernames and passwords and the customers have several different user directories to maintain.

In order to be part of the solution, instead of being the actual problem, SaaS providers have to find fast and easy ways to make user experience and administration of their applications just as easy as for any on-premise application. They need to offer users single sign-on, and they have to make it possible for customers to use their centralized user management to manage access to SaaS applications as well. If this could be done in a way that is fast and easy to deploy by the customers, one of the worst barriers to wide-spread use of SaaS in large organizations would be eliminated.

Current ways to integrate SaaS applications with customer user management

Currently there are a few common ways for SaaS providers to give users single sign-on and/or to let customers use their internal user management solutions to manage access to the SaaS application:

  1. Identity federation
  2. Delegated authentication
  3. Encrypted links
  4. User directory synchronization

Identity federation, as a concept, is exactly what is needed – SaaS providers can offer customers single sign-on and automated user management based on current information in their internal user directory. Identity federation based on SAML, WS-Federation or ADFS, however, requires each customer to invest in and roll out software compliant with those technologies. Currently very few organizations have adopted such solutions, so there is not really an existing user base. Even if the software would be given away for free, it still requires lots of time and technical resources from the customer to setup and maintain it.

Delegated authentication provides users single sign-on by using an existing logon, for instance on a corporate intranet, to generate tokens that can be used to grant access to a SaaS application. However, delegated authentication does not bring any help to maintenance of user profiles and access rights, which still have to be maintained manually in the application. It also requires time and technical resources by the customer.

Encrypted links are probably the most common way to provide single sign-on from intranets to external applications. The challenge is of course that some encryption mechanism is needed by each customer, and that links can be copied and misused if there is no timestamp element in the link. Using timestamps, on the other hand, creates synchronization problems, which are hard enough to tackle within one organization but impossible with hundreds or thousands of customer organizations.

Synchronization of user directories does not enable single sign-on, but it makes it possible for users to use familiar accounts and passwords when logging on to the SaaS application. From a security point of view, copying such information to one or more external user directories is definitely a major risk. Then there are challenges related to conversions from one user directory to another, as well as challenges related to timing, frequency and automation of those conversions.

None of the methods described above really meets the value proposition of SaaS. Instead of starting to use the applications immediately, customers run into integration and rollout projects requiring time and technical resources. As a result the rollout of the SaaS application is significantly prolonged.

A lighter approach

Google Analytics, the SaaS application for monitoring web site usage, offers a different and interesting view to the problem. Each Analytics customer needs to integrate Analytics with its web site in order to be able to collect and monitor usage statistics. By choosing a scripting integration model requiring only a few lines of JavaScript on the web pages, Google managed to lower the requirements on the customers’ web sites and the technical skills required to do the integration. As a result, they managed to get hundreds of thousands of customers in 18 months. Achieving the same with an integration model based on a protocol or a web services interface would have been mission impossible.

A similar approach can be used to make identity federation easier and faster to roll out. With server side scripting in the existing intranets of SaaS customers, the need for separate identity provider software can be eliminated. Each intranet platform supports some kind of server side scripting, like Active Server Pages, Lotusscript or JavaServer Pages. These technologies are well known to customers, and the functionality required to provide customers single sign-on and identity federation requires a script of only about 50 lines. The need for training and support is similar to that of Google Analytics, which means that most customers can roll out the solution in their organization without the help of the SaaS provider.

We at Emillion developed Distal, which enables identity federation with the existing intranets of customers using server side scripting. Distal supports most common intranet platforms, such as Microsoft, Domino, Java and Apache, out of the box, and it integrates with most of the major access management suites and technologies. We believe that Distal is the easiest way for SaaS providers to offer their customers single sign-on, especially from their customers’ point of view.

Aditro, the Nordic leader in human resources solutions and services, deployed Distal into their Nordic HRM ASP service platform. Tero Ansio, Head of Aditro Human Resources explained the reasons exactly as described above: it is very easy for our customers to start using it immediately. Users can access the ASP applications directly via their intranet connection, and still we get reliable sign-on.”

A scripting identity federation solution is exactly what a SaaS application needs, as it adds little to the time and effort required to roll out a SaaS application in an organization. Any SaaS provider aiming at growth figures even close to those of Google Analytics should at least try it out.

 

More Stories By Kjell Backlund

Kjell Backlund, CEO of Emillion, is a seasoned software business entrepreneur with over 20 years experience in international business. He founded Emillion in 2001, with the vision that automating sign-on and user management would be essential to the success of SaaS and Service Desk applications(www.emillion.biz).

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
SYS-CON Events announced today that Yuasa System will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Yuasa System is introducing a multi-purpose endurance testing system for flexible displays, OLED devices, flexible substrates, flat cables, and films in smartphones, wearables, automobiles, and healthcare.
SYS-CON Events announced today that CAST Software will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. CAST was founded more than 25 years ago to make the invisible visible. Built around the idea that even the best analytics on the market still leave blind spots for technical teams looking to deliver better software and prevent outages, CAST provides the software intelligence that matter ...
SYS-CON Events announced today that Daiya Industry will exhibit at the Japanese Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Ruby Development Inc. builds new services in short period of time and provides a continuous support of those services based on Ruby on Rails. For more information, please visit https://github.com/RubyDevInc.
SYS-CON Events announced today that Evatronix will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Evatronix SA offers comprehensive solutions in the design and implementation of electronic systems, in CAD / CAM deployment, and also is a designer and manufacturer of advanced 3D scanners for professional applications.
As businesses evolve, they need technology that is simple to help them succeed today and flexible enough to help them build for tomorrow. Chrome is fit for the workplace of the future — providing a secure, consistent user experience across a range of devices that can be used anywhere. In her session at 21st Cloud Expo, Vidya Nagarajan, a Senior Product Manager at Google, will take a look at various options as to how ChromeOS can be leveraged to interact with people on the devices, and formats th...
SYS-CON Events announced today that Taica will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Taica manufacturers Alpha-GEL brand silicone components and materials, which maintain outstanding performance over a wide temperature range -40C to +200C. For more information, visit http://www.taica.co.jp/english/.
SYS-CON Events announced today that SourceForge has been named “Media Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. SourceForge is the largest, most trusted destination for Open Source Software development, collaboration, discovery and download on the web serving over 32 million viewers, 150 million downloads and over 460,000 active development projects each and every month.
Enterprises have taken advantage of IoT to achieve important revenue and cost advantages. What is less apparent is how incumbent enterprises operating at scale have, following success with IoT, built analytic, operations management and software development capabilities – ranging from autonomous vehicles to manageable robotics installations. They have embraced these capabilities as if they were Silicon Valley startups. As a result, many firms employ new business models that place enormous impor...
SYS-CON Events announced today that TidalScale will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale is the leading provider of Software-Defined Servers that bring flexibility to modern data centers by right-sizing servers on the fly to fit any data set or workload. TidalScale’s award-winning inverse hypervisor technology combines multiple commodity servers (including their ass...
As popularity of the smart home is growing and continues to go mainstream, technological factors play a greater role. The IoT protocol houses the interoperability battery consumption, security, and configuration of a smart home device, and it can be difficult for companies to choose the right kind for their product. For both DIY and professionally installed smart homes, developers need to consider each of these elements for their product to be successful in the market and current smart homes.
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, will lead you through the exciting evolution of the cloud. He'll look at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering ...
As hybrid cloud becomes the de-facto standard mode of operation for most enterprises, new challenges arise on how to efficiently and economically share data across environments. In his session at 21st Cloud Expo, Dr. Allon Cohen, VP of Product at Elastifile, will explore new techniques and best practices that help enterprise IT benefit from the advantages of hybrid cloud environments by enabling data availability for both legacy enterprise and cloud-native mission critical applications. By rev...
SYS-CON Events announced today that NetApp has been named “Bronze Sponsor” of SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. NetApp is the data authority for hybrid cloud. NetApp provides a full range of hybrid cloud data services that simplify management of applications and data across cloud and on-premises environments to accelerate digital transformation. Together with their partners, NetApp emp...
SYS-CON Events announced today that Dasher Technologies will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Dasher Technologies, Inc. ® is a premier IT solution provider that delivers expert technical resources along with trusted account executives to architect and deliver complete IT solutions and services to help our clients execute their goals, plans and objectives. Since 1999, we'v...
SYS-CON Events announced today that TidalScale, a leading provider of systems and services, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale has been involved in shaping the computing landscape. They've designed, developed and deployed some of the most important and successful systems and services in the history of the computing industry - internet, Ethernet, operating s...
SYS-CON Events announced today that Massive Networks, that helps your business operate seamlessly with fast, reliable, and secure internet and network solutions, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. As a premier telecommunications provider, Massive Networks is headquartered out of Louisville, Colorado. With years of experience under their belt, their team of...
Widespread fragmentation is stalling the growth of the IIoT and making it difficult for partners to work together. The number of software platforms, apps, hardware and connectivity standards is creating paralysis among businesses that are afraid of being locked into a solution. EdgeX Foundry is unifying the community around a common IoT edge framework and an ecosystem of interoperable components.
Join IBM November 1 at 21st Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA, and learn how IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Cognitive analysis impacts today’s systems with unparalleled ability that were previously available only to manned, back-end operations. Thanks to cloud processing, IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Imagine a robot vacuum that becomes your personal assistant tha...
Infoblox delivers Actionable Network Intelligence to enterprise, government, and service provider customers around the world. They are the industry leader in DNS, DHCP, and IP address management, the category known as DDI. We empower thousands of organizations to control and secure their networks from the core-enabling them to increase efficiency and visibility, improve customer service, and meet compliance requirements.