Techniques are provided for dynamically establishing and managing
authentication and trust relationships. An identity service acquires and
evaluates contracts associated with relationships between principals. The
contracts permit the identity service to assemble authentication
information, aggregated attributes, and aggregated policies which will
drive and define the various relationships. That assembled information is
consumed by the principals during interactions with one another and
constrains those interactions. In some embodiments, the constraints are
dynamically modified during on-going interactions between the principals.