[Identity Fundamentals](https://www.pingidentity.com/en/resources/identity-fundamentals.html)  

[Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-and-access-management.html) 

[Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai.html) 

[Key IAM Considerations to Support Agentic AI](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/key-iam-considerations.html) 

[AI Agent Classes and Use Cases](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/classes-and-use-cases.html) 

[IAM Best Practices for AI Agents](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html) 

[Reference Implementations and Patterns](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/reference-implementation-patterns.html) 

[Runtime Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/runtime-identity.html) 

[Headless Identity](https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/headless-identity.html) 

[B2B Identity and Access Management](https://www.pingidentity.com/en/resources/identity-fundamentals/b2b-identity.html) 

[Identity Providers and Service Providers](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-providers-service-providers.html) 

[Centralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management.html) 

[What is Centralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/what-is-centralized-identity-management.html) 

[How Does Centralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/how-does-centralized-identity-management-work.html) 

[Centralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards.html) 

[SAML](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/saml.html) 

[OAuth](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/oauth.html) 

[OpenID Connect (OIDC)](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/openid-connect.html) 

[Decentralized Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management.html) 

[What is Decentralized Identity Management?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/what-is-decentralized-identity-management.html) 

[How Does Decentralized Identity Management Work?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-does-decentralized-identity-management-work-.html) 

[How is Decentralized Identity Different?](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/how-is-decentralized-identity-different.html) 

[Decentralized Identity Standards](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/decentralized-identity-standards.html) 

[Common Terms](https://www.pingidentity.com/en/resources/identity-fundamentals/decentralized-identity-management/common-terms.html) 

[Zero Trust Security](https://www.pingidentity.com/en/resources/identity-fundamentals/zero-trust-security.html) 

[Orchestration](https://www.pingidentity.com/en/resources/identity-fundamentals/identity-orchestration.html) 

[Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication.html) 

[Single-factor, Two-factor, and Multi-factor Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-factor-two-factor-multi-factor-authentication.html) 

[Passwordless Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication.html) 

[FIDO Authentication: WebAuthn, FIDO2 & CTAP2 Explained](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/passwordless-authentication/fido.html) 

[Risk-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/risk-based-authentication.html) 

[Certificate-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/certificate-authentication.html) 

[Token-based Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/token-based-authentication.html) 

[Single Sign-On (SSO)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html) 

[Federated Identity Management](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/federated-identity-management.html) 

[Continuous Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/continuous-authentication.html) 

[CHAP Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/chap-authentication.html) 

[Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization.html) 

[What Is Adaptive Access Control? RBAC vs. Adaptive](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/authorization-methods.html) 

[User and Account Provisioning](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/user-account-provisioning.html) 

[Single Sign-on with a Directory](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/sso-directory.html) 

[Dynamic Authorization](https://www.pingidentity.com/en/resources/identity-fundamentals/authorization/dynamic-authorization.html) 

[Protocols](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols.html) 

[LDAP](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ldap.html) 

[SCIM](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/scim.html) 

[WebAuthn](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/webauthn.html) 

[Kerberos](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/kerberos.html) 

[WS-Trust](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ws-trust.html) 

[Verification](https://www.pingidentity.com/en/resources/identity-fundamentals/verification.html) 

[Shared Device Authentication](https://www.pingidentity.com/en/resources/identity-fundamentals/shared-device-authentication.html) 

Expand All | Collapse All 

# Authentication and Authorization Protocols

Sometimes confused with an [authentication “standard,”](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards.html) an authentication protocol is a set of specific rules and procedures that all entities must agree to use before communicating. The protocol language must be followed step by step by each party so that the requesting entity can safely authenticate the receiving entity and vice versa. There are many authentication protocols available to enterprises today. This article highlights Kerberos, Lightweight Directory Application Protocol (LDAP), and WS-Trust.

## [Kerberos](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/kerberos.html)

Kerberos was built to support both authentication and authorization so that once a user is authenticated, they’re also authorized. Used for [single-sign on (SSO)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-sign-on.html) by many enterprises, the Kerberos protocol doesn’t send passwords over the network for authentication. Instead, it uses strong, time-limited secret-key cryptography, multiple secret keys, and a third-party service to authenticate client-server applications and user identities.

Kerberos may be complicated on the backend, but it offers an almost frictionless experience on the front end. The user simply signs into one device and is automatically authenticated to access network resources and many third-party applications that they were previously authorized to use. Kerberos streamlines daily work so that employees can focus on the task at hand instead of continually signing into the systems and resources they need.

## [Lightweight Directory Access Protocol (LDAP)](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ldap.html)

LDAP was originally created to provide secure authentication sessions for enterprise employees. It employs strong encoding rules that prevent users from creating weak passwords. An LDAP authentication session begins when a user (client) connects to an LDAP server that houses user data that was previously entered by administrators. Once connected, the two entities can exchange data.

LDAP is used in a network’s active directory to store data in a hierarchical fashion so users can find information they need quickly. When a user queries an LDAP database for a specific object, LDAP walks down the directory tree to find the object the user requested. All permissions are contained in the separate domains in the hierarchy, so authentication can be allowed or denied at this stage without having to go back to the general network administrator.

## [WS-Trust](https://www.pingidentity.com/en/resources/identity-fundamentals/authentication-authorization-protocols/ws-trust.html)

The WS-Trust protocol is used to establish and manage trust relationships between two or more applications or devices. Organizations can use the WS-Trust protocol to define the basic messaging framework for secure machine-to-machine messaging. WS-Trust can issue, renew, and validate security tokens. Specifically, the protocol uses a Security Token Service (STS) to perform operations on security tokens.

On the web service client side, WS-Trust allows STS to convert a local security token into a standard [Security Assertion Markup Language (SAML)](https://www.pingidentity.com/en/resources/identity-fundamentals/centralized-identity-management/authentication-authorization-standards/saml.html) security token, which contains the identity of the user. On the web service provider side, the STS is used to validate those incoming security tokens and can also generate a new local token that can be consumed by other applications. The main role of WS-Trust is to function as a request-response message pair with the help of the STS.

Start Today

Contact Sales

[sales@pingidentity.com](mailto:sales@pingidentity.com)

See how Ping can help you deliver secure employee, partner, and customer experiences in a rapidly evolving digital world.