RWS Architecture article

Federated Authentication

Federated Authentication is the product-neutral architecture building block for federated identity, authentication, and token brokering. It states what DC 3.0 needs from this capab

  1. Typeabb
  2. Statuscandidate
  3. Domainsecurity
On this page
  1. ABB Federated Authentication
  2. Summary
  3. Capabilities
  4. Constraints
  5. Service Description
  6. Roadmaps
  7. Landing Zones
  8. Interfaces
  9. Dependencies
  10. EIRA Alignment
  11. Available SBB's

ABB Federated Authentication

Summary

Federated Authentication is the product-neutral architecture building block for federated identity, authentication, and token brokering. It states what DC 3.0 needs from this capability before a concrete SBB, product, or operating model is selected.

Capabilities

  • Provides federated identity, authentication, and token brokering.
  • Defines the functional, technical, security, and quality expectations that SBBs must satisfy.
  • Keeps service ownership, interfaces, and consumption boundaries visible before product selection.
  • Enables traceability from architecture intent to implementation, operational evidence, and consuming services.

Constraints

  • The resulting SBB must fit the identity and access management ownership model and document the support, lifecycle, and service-management boundary.
  • Security, privacy, logging, evidence, and compliance controls must be explicit enough to assess BIO2-aligned implementation where applicable.
  • Authentication flows must support least privilege, MFA where required, auditability, and lifecycle management.
  • SBBs must not create standalone identities where federation is required.

Service Description

This ABB offers a federation service that connects DC 3.0 services to approved identity providers and standard authentication protocols. It is consumed by solution architects, platform teams, and service owners as the capability contract for selecting and shaping SBBs.

The service description remains implementation-neutral: product selection, hosting pattern, detailed runbooks, and service levels belong in the mapped SBB and related ADRs.

Roadmaps

  • Baseline: confirm scope, service ownership, constraints, and acceptance criteria for Federated Authentication.
  • MVP: validate the mapped SBB implementation and record the selected support and lifecycle model.
  • Next: add measurable service levels, evidence requirements, and roadmap dependencies once the SBB is selected.

Landing Zones

  • Private cloud and central DC 3.0 landing zone for core infrastructure and platform services.
  • Government cloud or external cloud landing zones only when the SBB documents the required control set, connectivity model, and data classification fit.

Interfaces

  • OIDC, OAuth2, SAML, LDAP, SCIM, and token interfaces as applicable.
  • Application, platform, and administrative authentication integrations.
  • Audit and policy interfaces.

Dependencies

  • Depends on identity-governance-and-administration for a supporting capability or integration boundary.
  • Depends on public-key-infrastructure for a supporting capability or integration boundary.
  • Implemented by keycloak as currently mapped SBB traceability.
  • Consuming ABB and SBB dependencies must be recorded as links when solution design identifies concrete upstream or downstream use.

EIRA Alignment

Available SBB's

  • keycloak - Keycloak is a candidate solution building block for the translated DC 3.0 ABB model. It remains candidate until the responsible architects confirm service ownership, support model, and acceptance criteria.