Attribute Aggregation and Federated Identity
N. Klingenstein · 2007
A principal sometimes needs to present a combination of attributes from multiple identities from distinct organizations to fully identify itself This problem is rarely encountered in non-federated identity transactions because services operate within the context of a single identity domain. Federated identity allows for data about one entity to be scattered across multiple identities throughout the distributed system. These data must be unified through attribute aggregation to fully identify an entity. In order to do so, the identities must be associated in some fashion, the user must have a session with a service, and the service must have all the information it needs to process the attributes it receives