The U.S firm McGohan Brabender, located on Ohio, manage the Wellvibe service, a medical website of detection and monitoring focus on workers.This website needed to use the form service of health risk evaluation from Wellsource.

Scenario

At the initial scenario, McGohan Brabender had to send a set of users to Wellsource to inform about the users who have got granted access to use the form service of health risk evaluation.

This model has disadvantages for McGohan Brabender and for its users because of the technical and operational problems related to the constant actualization dispatch of the valid users list besides the fact of the users having a new user and password.

McGohan Brabender contacted with PRiSE to carry out the adaptation of the Wellbive website, in order to use the SAML 2 interface given by Wellsource. Thus, it wouldn't be necessary to send the list of valid users but allow access to the evaluation form health risks due to the SAML 2 assertion provided by Wellvibe at the access.

End Scenario

The deployed solution was to install simpleSAMLphp. It would be configured as an identity provider who understand SAML 2 and connected with Wellvibe. The SAML 2 assertion dispatch represents the user's digital identity and it's realized through the HTTP POST binding. This assertion contains the user identification and its attributtes in order to allow the Wellvibe security framework evaluate them and show the corresponding form if it's fulfill all the conditions.

To stablish the trust relationship among Wellvibe and Wellsource with SAML 2 assertions, they will have to exchange their public keys in order to prove the origin of the assertions through digital signing.