Switch edu-ID implements an identity federation. It purpose is to promote cooperation between universities in Switzerland and with university-related partners. Switch edu-ID provides a digital identity to university members (students, staff and teachers) and also to users without university affiliation like university guests, alumni, further education students, private library users, or event participants. With a Switch edu-ID identity a user may access any service in the federation, under the condtion that the service provider allows the use by defining appropriate access rules.

New participants in the federation are admitted by the Swiss universities and by Switch. The main criterion for admission is the creation of added value for the Swiss university community.

The Switch edu-ID user directory contains the user-managed attributes, as well as affiliation attributes that indicate with which universities the user is currently affiliated with. When a new user is registered at a university, an organisational account is created and linked to the edu-ID. The organisational identity management (IdM) system notifies the edu-ID service, which updates the affiliation attributes. The notification and attribute exchange between organisation and edu-ID either uses provisioning via Affiliation API (or push interface), or the Attribute Provider API (or pull interface). Likewise, the affiliations are updated when a user leaves a university.
To access a service provider, a user authenticates at the central Switch edu-ID IdP. The user managed attributes and the affiliation attributes from all organisations where the user is currently affiliated with are collected. The attributes are then filtered and reduced to the needs of the service and the set of permitted attributes as defined by the university. Finally, with the user’s consent, the attributes are delivered to the service.
A user who has left a university and who has no further current affiliation with another university keeps the personal, user managed part of a Switch edu-ID identity. Although many services will require users with a current affiliation with a university, an increasing number of services will be open to people who are neither student nor university staff.
According to the federation architecture definitions, edu-ID implements a hybrid architecture.

Switch edu-ID is a full-mesh architecture
Switch edu-ID is a hub-and-spoke architecture