<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>identity graphs Archives - IDPro</title>
	<atom:link href="https://idpro.org/tag/identity-graphs/feed/" rel="self" type="application/rss+xml" />
	<link>https://idpro.org/tag/identity-graphs/</link>
	<description>The Professional Organization for Digital Identity Management</description>
	<lastBuildDate>Thu, 28 Oct 2021 16:58:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://idpro.org/wp-content/uploads/2023/07/cropped-idpro_stickerA-circle-100-32x32.jpg</url>
	<title>identity graphs Archives - IDPro</title>
	<link>https://idpro.org/tag/identity-graphs/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Case for Identity Graphs</title>
		<link>https://idpro.org/the-case-for-identity-graphs/</link>
					<comments>https://idpro.org/the-case-for-identity-graphs/#respond</comments>
		
		<dc:creator><![CDATA[VTM Web Services]]></dc:creator>
		<pubDate>Thu, 28 Oct 2021 15:32:04 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[access management]]></category>
		<category><![CDATA[B2B]]></category>
		<category><![CDATA[B2B2C]]></category>
		<category><![CDATA[B2C]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[data complexity]]></category>
		<category><![CDATA[graph databases]]></category>
		<category><![CDATA[iam]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity graphs]]></category>
		<category><![CDATA[identity relationship management]]></category>
		<category><![CDATA[internet traffic]]></category>
		<category><![CDATA[IRM]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[multi-joins]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=1319</guid>

					<description><![CDATA[<p>by Alex Babeanu, Identity Solutions Architect — Nulli The Golden Age We can trace the field of Identity and Access [&#8230;]</p>
<p>The post <a href="https://idpro.org/the-case-for-identity-graphs/">The Case for Identity Graphs</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>by Alex Babeanu, Identity Solutions Architect  —  Nulli</p>



<h3 class="wp-block-heading">The Golden Age</h3>



<p>We can trace the field of Identity and Access Management (IAM) back to the creation of the password by <a href="https://en.wikipedia.org/wiki/Fernando_J._Corbat%C3%B3">Fernando Corbato</a> in <strong>1961</strong>. We’ve had to manage user accounts ever since.</p>



<p>Because of these user accounts, two further inventions have shaped IAM since that milestone:</p>



<ul class="wp-block-list"><li>The creation of Relational Algebra ( <a href="https://en.wikipedia.org/wiki/Edgar_F._Codd">Edgar F Codd</a>, “<a href="https://www.seas.upenn.edu/~zives/03f/cis550/codd.pdf"><em>A Relational Model of Data for Large Shared Data Banks</em></a>”, <strong>1970</strong>). Which led to the creation of the first SQL-based Relational Database System, <a href="https://en.wikipedia.org/wiki/Oracle_Database">Oracle v.2</a> in <strong>1979</strong>;</li><li>The creation and eventual approval of the <a href="https://en.wikipedia.org/wiki/X.500#:~:text=500%20series%20was%20developed%20by,was%20approved%20first%20in%201988.">X.500</a> set of standards in <strong>1988.</strong></li></ul>



<p>These 3 inventions are still ubiquitous—33 years after the creation of the last one. Nothing new has really happened since. We still store and manage Digital Identities in Directories and/or SQL databases, and we’ve done this since <a href="https://en.wikipedia.org/wiki/Epoch_(computing)">Epoch</a>.</p>



<p>However, the challenges of the hyperconnected modern era have shown massive cracks in these old foundations…and some companies have started to notice (I have names).</p>



<h3 class="wp-block-heading">The Problem with Modern Identity</h3>



<h4 class="wp-block-heading">Volume</h4>



<p>We live in a very different world today than during that famed epoch. <a href="https://www.thalesgroup.com/en/markets/digital-identity-and-security/government/identity/digital-identity-services/trends">4.6 billion users had access to the internet as of the end of 2020</a>, 50% of all internet traffic now goes through mobile devices, there are close to <a href="https://findstack.com/internet-of-things-statistics/">36 Billion installed/live IoT devices this year around the world</a>, and that number keeps growing.</p>



<p>Figure 1 below best summarizes this trend: the total volume of data created worldwide since 2010 and projected up to 2024.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img fetchpriority="high" decoding="async" width="552" height="382" src="https://idpro.org/wp-content/uploads/2021/10/Graphic1.png" alt="" class="wp-image-1320" srcset="https://idpro.org/wp-content/uploads/2021/10/Graphic1.png 552w, https://idpro.org/wp-content/uploads/2021/10/Graphic1-300x208.png 300w" sizes="(max-width: 552px) 100vw, 552px" /></figure></div>



<p>The thing to note is that before 2010, the total amount of data stored worldwide<strong> </strong>was negligible when compared to the amount in use today.</p>



<h4 class="wp-block-heading">Complexity</h4>



<p>But data volumes are not just humongous nowadays, data has also become exceedingly complex. For instance, the Observatory of Economic Complexity (<a href="https://oec.world/en/resources/about">OEC</a>) publishes data visualizations of the complexity of worldwide economic exchanges.&nbsp; Figure 2 below represents an example of the data they make available:</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img decoding="async" width="636" height="461" src="https://idpro.org/wp-content/uploads/2021/10/Graphic2.png" alt="" class="wp-image-1321" srcset="https://idpro.org/wp-content/uploads/2021/10/Graphic2.png 636w, https://idpro.org/wp-content/uploads/2021/10/Graphic2-300x217.png 300w" sizes="(max-width: 636px) 100vw, 636px" /></figure></div>



<p>There is indeed a relationship between textiles fabricated in China and chemicals produced in Europe. Not a “1-hop” relationship mind-you—not at all. Instead, you have to follow certain paths of products and subproducts, of interconnected partnerships and data exchanges to get from one to the other. It’s not just 1-1 or 1-N relationships anymore. No, it’s more like 1-N-N-&#8230;-N-1 these days.<br></p>



<p>Complexity arises as soon as several actors interact and start exchanging data. Complexity increases further when one starts to ponder the ways in which to protect the access to all that shared information. A good case-in-point here is the new <strong>B2B2C</strong> business model. We currently lack a truly holistic view of all the actors and resources involved in such systems.</p>



<h3 class="wp-block-heading">Graphs</h3>



<p>At this point, we have to stop and ponder the reasons why Relational Databases and LDAP Directories have been, and still are, ubiquitous in IAM. The reason is simple: both can capture the relationships that link entities together—to some extent at least.</p>



<p>LDAP Directories can only represent hierarchies (parent/child relationships). This in itself is very limiting, as the only way to relate any 2 objects to each-other is to create a common parent. This quickly leads to an unmanageable explosion in the number of such parents as the number of arbitrary relationships increases—exactly the cause of the infamous RBAC Role Explosion.</p>



<p>At least SQL Databases support all kinds of relationships. Nevertheless, they can’t cope with the sheer number of relationships that must be modelled. As mentioned above, we now have to deal with many 1-N-N-&#8230;-N-1 relationships. And as we know, joining huge tables (remember the Billions of Identities we need to manage today?) together, or with themselves (the infamous “friends-of-friends” query), many times over can bring the most advanced SQL databases to their knees pretty fast.</p>



<p>Not so for Graph Databases!</p>



<p>Graphs are simple diagrams made of Nodes and Relationships (arrows) that can actually model any data at all.</p>



<p>Figure 3 below is a simple Identity Graph example that depicts the relationships between 2 Identities (a User and a Client) and a Company (“Walstuff”):</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img decoding="async" width="620" height="427" src="https://idpro.org/wp-content/uploads/2021/10/Graphic3.png" alt="" class="wp-image-1322" srcset="https://idpro.org/wp-content/uploads/2021/10/Graphic3.png 620w, https://idpro.org/wp-content/uploads/2021/10/Graphic3-300x207.png 300w" sizes="(max-width: 620px) 100vw, 620px" /></figure></div>



<p>A great value-added of Graphs is that they are easily readable in plain natural language, and readable by pretty much anyone. For instance, just follow the arrows in the graph above to “read the data” in plain English.</p>



<p>Representing data as Graphs actually solves all the problems inherent to the legacy tools we’ve been using for so long. </p>



<p>In particular:</p>



<h4 class="wp-block-heading">Multi-Joins</h4>



<p>Querying a Graph for an Access request for example boils down to finding a path, or set of paths, between a subject identity and the resource it tries to access. A path in the graph has the same length no matter how many other billions of nodes are stored in the database. The time it takes to process a path query is the same, regardless of the amount of data in the graph. Compare this to SQL joins.&nbsp;</p>



<h4 class="wp-block-heading">Data Complexity</h4>



<p>This is better shown.&nbsp;</p>



<p>Figure 4 below is still a simple Graph. To the Graph of Figure 3 above, we’ve now added a <strong>B2B2C </strong>partner (“InstantShop”), as well as their flagship Web App “OnlineOrders” and only 1 of their users. The result is still readable in plain English—just follow the arrows.</p>



<p>Now the clients of our Walstuff supermarket can also buy their products online through their OnlineOrders app. Same products, same clients, different channel. Note that employees from both sides should be able to support this new system.</p>



<p>Who can access what in such a model?</p>



<p>Please note that this is just an example and doesn’t reflect any actual IAM system.&nbsp;</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="649" height="642" src="https://idpro.org/wp-content/uploads/2021/10/Graphic4.png" alt="" class="wp-image-1323" srcset="https://idpro.org/wp-content/uploads/2021/10/Graphic4.png 649w, https://idpro.org/wp-content/uploads/2021/10/Graphic4-300x297.png 300w" sizes="auto, (max-width: 649px) 100vw, 649px" /></figure></div>



<p>Ok, now try to model that in LDAP (and please email me if you find a good solution).</p>



<h3 class="wp-block-heading">Conclusion</h3>



<p>It is time for a paradigm shift in IAM. Given the challenges we face nowadays, we need data stores that can truly manage relationships, ones where relationships are true first class citizens, which can represent any arbitrary type of relationship. It is time to switch to <strong>Identity Relationship Management</strong> (IRM)!&nbsp;</p>



<p>In the fully distributed and Identity-centric world of tomorrow, full of Distributed Identities, Consents, and Verifiable Claims, the only real way to make sense of Identities and their Entitlements is to consider them along with their relationships, in context—their context graphs.</p>
<p>The post <a href="https://idpro.org/the-case-for-identity-graphs/">The Case for Identity Graphs</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://idpro.org/the-case-for-identity-graphs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk

Served from: idpro.org @ 2026-04-01 14:28:35 by W3 Total Cache
-->