Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity

    Federated Single Sign-On Shifts GM into High Gear

    Written by

    Anne Chen
    Published February 21, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      When General Motors Corp.s employee portal forced workers to endure a traffic jam of user names and passwords, the company turned to federated single sign-on to put employees in the drivers seat.

      By employing specifications from the Liberty Alliance Project to let workers submit one user name and password to access benefits, GM made access to the portal much easier. The process gave reluctant users a new incentive to use the portal.

      The program has succeeded, said John Jackson, GMs director of software technology. “There has been universal sentiment that federated single sign-on at GM will be well-received by our ultimate customers,” Jackson said. “Our human resources group believes that federation provides a high value in employee-facing applications and services—so much that we did not calculate return on investment for this project.”

      The Liberty Alliance Project, established in 2001, has more than 150 members. (GM is a founding member.) It focuses on the development and deployment of open, federated network identification specifications.

      /zimages/2/28571.gifClick here to read an interview with the Liberty Alliances Michael Barrett.

      “General Motors joined Liberty Alliance because we believed it was important for the industry to have some choice in the technology that was used,” Jackson said. “We never believed that a single provider—regardless of whether [it was] the federal government, Microsoft [Corp.] or a large bank—would be able to serve the entire Internet. It was important to us that multiple identity providers exist in the Internet.”

      In a 2003 poll conducted by the Liberty Alliance, nearly 60 percent of founders and sponsor-level members said they planned to implement the groups Version 1.1 specification that year. GMs use of alliance specifications to federate its employee portals was among those implementations.

      /zimages/2/28571.gifRead about the groups Version 2.0 spec here.

      GM is the worlds largest vehicle manufacturer, employing more than 326,000 people worldwide. The Detroit-based company has one of the worlds largest employee portals—MySocrates—serving more than 190,000 hourly and salaried workers in the United States. MySocrates supports more than 32,000 concurrent users and gets more than 3 million hits per hour, Jackson said.

      MySocrates offers a single point of access to hundreds of internal GM Web sites. The portal lets employees customize their experience by providing access to personal information such as health care and retirement benefits. GM outsources many of the HR services that employees use—such as its 401(k) program and expense reporting—to third-party providers.

      Before GM implemented federated identity, it wasnt easy for employees to get information they needed. When users accessed any of GMs third-party providers via MySocrates, they had to pass through a firewall and authenticate to each third-party service they wanted to access.

      IT managers at GM wanted to make access more seamless and efficient for employees, but they understood that many users would be reluctant to use the same profile and password for both their health care provider and their 401(k) provider. By using federation, Jackson concluded, employees could control their own profiles and access levels.

      Next page: Pilot program.

      Page Two

      In 2003, the company launched a pilot project that integrated various internal and external systems. The proof-of-concept requirements included validating the ID-FF 1.1 specification and building a model production environment using firewalls and proxies as well as the Internet.

      GM, along with Workscape Inc., the Framingham, Mass., company that manages MySocrates, worked with GMs 401(k) provider on the federation project. Because MySocrates was built using Sun Microsystems Inc.s Sun ONE Portal Server, GM and Workscape decided to use Suns Java System Access manager, which supports Liberty Alliances ID-FF specification. Sun is another founding member of the alliance.

      The pilot enables users to log on to MySocrates and choose whether to opt in to federated single sign-on. Users who opt in authenticate just once to the portal, then can access their 401(k) information and other data without having to reauthenticate. To provide a seamless interface between MySocrates and the 401(k) providers Web site, GM chose to use JSP (JavaServer Pages) technology.

      Jackson said federating identity for the portal was easier, in part, because GM used the publicly available Liberty Alliance specification.

      “Since youre both going through a publicly available specification, youre both talking the same language as youre doing so, which simplifies the issues,” Jackson said. “It also abstracts the simplification of our site to your site—regardless of the identity solution youre using.”

      GM is fully deploying federated SSO for 70,000 users of its employee portal. While Jackson estimated the technology should take no longer than two months to deploy, he said legal and business issues may cause the project to take as much as one year to complete. For example, GM still needs to work out what will happen if something goes wrong during authentication.

      “There are issues around the business that still need to be resolved,” Jackson said. “But these issues are not limited to General Motors. They affect any company trying to federate identity.”

      GM is looking at other services it wants to enable using Liberty Alliance federation. Because the automaker has systematically outsourced business processes, Jackson said it makes sense for it to federate with as many third-party providers as possible.

      GM units have built systems using a standard set of products, but each has its own solution, such as a portal for the engineering division and another for manufacturing. Because of this, Jackson said, federation may also be handy internally. “General Motors is a big business to run globally,” he said. “Rather than try to build one large infrastructure for the entire company, it may make more sense to federate.”

      Senior Writer Anne Chen can be reached at [email protected].

      Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Anne Chen
      Anne Chen
      As a senior writer for eWEEK Labs, Anne writes articles pertaining to IT professionals and the best practices for technology implementation. Anne covers the deployment issues and the business drivers related to technologies including databases, wireless, security and network operating systems. Anne joined eWeek in 1999 as a writer for eWeek's eBiz Strategies section before moving over to Labs in 2001. Prior to eWeek, she covered business and technology at the San Jose Mercury News and at the Contra Costa Times.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×