What Is SAML?
SAML, an abbreviation for "Security Assertion Markup Language," is an international standard widely used for exchanging authentication information as XML documents. Because it is used solely to pass authentication information, it is widely adopted in IDaaS (Identity as a Service: cloud-based ID and password management tools), single sign-on tools, and identity federation. The current version of SAML is Version 2.0, established in 2005 by OASIS, a nonprofit international consortium for the information and communications industry.
The Growing Need for SAML
SAML became especially important after cloud adoption in enterprises became widespread in the 2010s. As companies that had previously performed identity federation and single sign-on only within their own networks began using cloud services such as SaaS, IaaS, and PaaS, single sign-on came to be required not only for internal systems but also for cloud services. Given the nature of identity federation—exchanging only authentication information without accessing actual data—SAML gained attention as a standard protocol. Today, many IDaaS and single sign-on vendors support SAML.
Using SAML for Identity Federation
Let's take a concrete look at how SAML is used, using our own IDaaS product, "TrustLogin (formerly SKUID)," as an example.
On the left side of the diagram is the "service provider." This refers to providers of cloud-based services such as Office 365, G Suite, Salesforce.com, and Amazon Web Services (AWS), most of which support SAML authentication.
In the center of the diagram is the "user agent." This refers to the user actually performing identity federation, who typically logs in to the cloud service provided by the service provider through a browser.
Finally, on the right side of the diagram is the "identity service provider." You can think of this as the vendor that provides IDaaS or single sign-on. We provide "TrustLogin (formerly SKUID)" as our IDaaS service.
Reference: TrustLogin (formerly SKUID) introduction page https://trustlogin.com/lp/list/
The process begins when a user accesses the service provider's page via a browser add-on or dedicated page. After access, the service provider creates a SAML request and works with the identity service provider to authenticate the user. Once the user is authenticated, the identity service provider sends the response it created to the service provider (an ACS request), and the service provider verifies the response to grant the user access.
While this is what happens behind the scenes, as long as the identity service provider (IDaaS or single sign-on product) has been preconfigured, the user simply clicks the application they want to log in to from the product's screen, and single sign-on is achieved. From the user's perspective, single sign-on is achieved without needing to be aware of whether the system is an internal system or an external cloud service.
Consideration by Government Agencies
In 2007, the U.S. government introduced authentication using SAML 2.0 for the first time. Organizations currently using it include the "Federal E-Authentication Framework," the "Defense Information Systems Agency," the "U.S. Navy Identity Management System," and the "U.S. Environmental Protection Agency," among many others.
Japan has lagged behind the United States in this area, but efforts are underway. In 2015, the Ministry of Internal Affairs and Communications' Administrative Management Bureau published a study document titled "On Authentication Platforms." The document presents a proposal for a unified electronic authentication platform linked to the Basic Resident Register, with plans for private-sector websites to exchange authentication information via SAML with the government-built authentication platform to achieve seamless integration.
In addition, regarding the "Education Cloud Platform" (a system enabling access to educational content via the cloud), which the Ministry of Internal Affairs and Communications is separately planning, a 2017 report explicitly states that authentication via SAML or OpenID Connect is required.
Adoption in the Private Sector
SAML is already widely adopted in the private sector, particularly among IDaaS and single sign-on products, where its adoption is overwhelmingly common.
For companies that develop and operate cloud services (service providers), making their cloud services SAML-compatible means their services can be accessed through many identity federation services. SAML support has become essential for increasing user numbers and avoiding inconvenience for users.
For users (companies), adopting an IDaaS or single sign-on product to manage the growing number of IDs and passwords resulting from cloud adoption is desirable from the standpoint of improving both employee security and convenience.
Furthermore, for companies that develop and operate IDaaS or single sign-on products (identity service providers), identity federation services using SAML are themselves a business. IDaaS products are projected to grow at an average annual rate of 36.5% through 2021, and this rapid growth is also supported by the SAML standard. In this way, as cloud adoption continues to increase, the use of identity federation via SAML will also continue to grow.