Identity Broker is a generic industry term and not part of any Standard
A Identity Broker or Identity Correlation service maps Identity Attributes, including unique identifiers, across multiple Identity Provider (IDP) to the Digital Subject.
Often a Identity Broker is incorporated within the Identity Provider (IDP) service.
As an intermediary service, the Identity Broker is responsible to create a trust relationship with Identity Provider (IDP)s in order to use the Digital Identitys to access services exposed by Service Providers.
From an user perspective, an Identity Broker provides an user-centric and centralized way to manage Digital Identitys across different Security Domains or realms, where an existing Digital Identitys can be linked with into one Digital Subject as a Federated Identity from different Identity Provider (IDP)s or even created based on the identity information obtained from the various Digital Identitys.
Identity Broker are usually Security Token Service providers that can translate Tokens between different identity tokens from one standard format to another or to the proprietary session cookie formats used by many WAM systems.
Often various Authentication Agents would be installed on an Identity Broker machine allowing Cross-platform Authentication.
Often the Identity Broker would:
The Native Applications Working Group is defining a profile of OpenID Connect (OIDC) that will enable a standardized cross-app Single Sign-On experience model for native mobile applications on both consumer-centric and enterprise applications.
Acxiom Corporation, Google, Facebook are a few of the many Internet or Database Marketing Organizations that provide these type of services.