The purpose of Identity management is to guard the data stored and accessed through applications from those that should and shouldn't have access. Where simple passwords are an inadequate authentication method, authorities have created IT infrastructures for more rigorous proof required to confirm the identity of the parties involved in the communication to validate the authenticity of the information being transferred.[1] In cryptography this takes the form of public key infrastructure (PKI) which establishes the respective identities of entities (like people and organizations). The trust, establishing the affirmed identity is established through a process of registration and issuance of certificates at and by a certificate authority (CA). Depending on the assurance level of the cipher key matching (binding), this may be carried out by an automated process or under human supervision. The PKI role that assures valid and correct registration is called a registration authority (RA). An RA is responsible for accepting requests for digital certificates and authenticating the entity making the request.[2] An entity must be uniquely identifiable within each CA domain on the basis of information about that entity. A third-party validation authority (VA) can provide this entity information on behalf of the CA. When a key is known to be compromised the problem can be fixed by revoking the certificate, but such a compromise is not easily detectable and can be a huge security breach as millions of web-browsers depend upon fixed VA trusts. The public's web browsers have to issue a security patch to revoke intermediary certificates issued by a compromised root certificate authority.[23] Some practical security vulnerabilities of X.509 certificates and known cases where keys were stolen from a major Certificate Authority listed below.

The stolen validation authority certificates challenged the trust of a few Internet important VAs, forcing organizations to switch off long-trusted keys and disrupting the trust in E-commerce for many. Many organizations that had adopted external trusts, re-internalized their security by registering their own VA/RA/CA keys - slowing their migration to the cloud and dependency upon on-premise access management. Competing standards also complicated PKI and although PKI vendors created a market, it is not the mid-1990s vision of uniformity, and ha grown slower than anticipated.[17] Several major vendors have gone out of business or been acquired by others. PKI has had the most success in government implementations; the largest PKI implementation to date is the Defense Information Systems Agency (DISA) PKI infrastructure for the Common Access Cards program. The set of roles, policies, and procedures needed to create, manage, distribute, use, store, and revoke digital certificates and manage public-key encryption is the province of Identity Access Governance (IAG). This governance of access can be gated by SAML and encryption, but requires a centralized Identity Access Management (IAM) framework to make it practical for organizations. The term UAM is now preferred because internalized infrastructure and external cloud infrastructures in the late 2010's require the reintegration of trust, now supporting B2B, B2C and hybrid public clouds .
