We present the concept and design of Dynamic Automa
ted Metadata Exchange (DAME) in
Security Assertion Markup Language (SAML) based use
r authentication and authorization
infrastructures. This approach solves the real-worl
d limitations in scalability of pre-exchanged
metadata in SAML-based federations and inter-federa
tions. The user initiates the metadata
exchange on demand, therefore reducing the size of
the exchanged metadata compared to
traditional metadata aggregation. In order to speci
fy and discuss the necessary changes to
identity federation architectures, we apply the Mun
ich Network Management (MNM) service
model to Federated Identity Management via a truste
d third party (TTP); an overview of all
components and interactions is created. Based on th
is model, the management architecture of
the TTP with its basic management functionalities i
s designed. This management architecture
includes further functionality for automated manage
ment of entities and dynamic federations.