Securing the Backbone of the Internet: How Arelion Built an Independent Identity Foundation with Curity | Curity Identity Server
Securing the Backbone of the Internet: How Arelion Built an Independent Identity Foundation
Logo Securing the Backbone of the Internet: How Arelion Built an Independent Identity Foundation

Securing the Backbone of the Internet: How Arelion Built an Independent Identity Foundation

Arelion is a leading light in global connectivity services. They’ve been keeping the world connected since 1993 and today their global IP backbone, AS1299, is ranked number one in the world. Arelion's network spans Europe, North America and Asia with 77,000 km of optical fiber and 1,700 MPLS endpoints.

When you operate at the very core of global internet connectivity - carrying traffic for thousands of operators, content providers and enterprises, reaching billions of end users - a compromised or failed authentication event can cost a lot.

Arelion, one of the world’s largest Tier 1 internet providers, understood this clearly when it set out to build its own independent IT foundation following its 2021 divestment from Telia Company. Choosing the right identity and access management solution was a strategic decision about control, security and long-term competitive resilience.

Arelion chose Curity.

We operate at the very core of internet connectivity. Our customers are measured in thousands, but the impact of our services reaches billions of users.” - Per-Axel Felth, Head of IT Architecture, Arelion

Two Years to Build Independence

Following its divestment, Arelion had two years to establish a fully independent IT landscape. Identity was among the most critical components to get right.

The requirements were straightforward: self-hosted deployment, deep flexibility for custom use cases, integration with on-premise user repositories, strict adherence to open standards like OAuth and OpenID Connect and support for specific flows.

Choosing a SaaS identity provider would have meant accepting someone else’s architectural constraints, vendor upgrade schedules and limited control over the token issuance, structure of claims and enforcing permissions.

“We wanted to keep control and make sure we could cover all our use cases” said Per-Axel “With SaaS services, you often don’t get the flexibility we needed. Having a self-hosted solution gave us that confidence”.

Curity delivered what the alternatives couldn’t: an enterprise-grade identity platform built on open standards with the deployment control Arelion needed to build an independent foundation for its business.

Curity vs SaaS

Requirement Curity Typical SaaS IAM
Self-hosted deployment X
On-premise data store integration X
Full OAuth flow flexibility Partial
Token Intelligence X
Rolling upgrades Vendor-managed
Kubernetes production ready Not applicable
Open standards

Curity - One Platform for Customers, APIs and Internal Systems

Rather than treating customer authentication and API security as separate domains requiring separate vendors, Arelion built a single, unified identity layer on Curity - one platform serving every integration point in the business.

The customer portal uses different identity flows to support users, APIs, and partner integrations. User authentication runs on the OAuth 2.0 authorization code flow, while internal and external APIs are protected using JWT bearer tokens and client credentials. Server-to-server communication runs on assertion flows and partner integrations are handled through federated identity.

Production Performance: Reliability at Backbone Scale

For Arelion’s customers - major global enterprises, operators and digital infrastructure providers - even a brief authentication failure carries significant operational and reputational consequences. In production, Curity has delivered precisely the stability the business requires.

Rolling upgrades are performed without customer impact, on Arelion’s terms, so that version changes introduce no downtime. The team emphasizes that the environment is stable, performant and operationally predictable - all these are critical for a company whose own value proposition to its customers rests on exactly these qualities.

Kubernetes at Scale: From Early Adopter to Production Ready

Arelion deployed Curity on AWS EKS - and both parties are honest about this learning curve. Curity’s Kubernetes support was not yet where it needed to be and Arelion found itself in early-adopter territory. Through the great collaboration, Arelion worked closely with Curity’s support to adapt their own deployment model and push the platform forward. Working through the hard problems together was worth it: today, the EKS environment is stable and the team runs version changes smoothly.

Toward More Granular, Risk-Adaptive Security

Arelion’s identity program continues to evolve. The next phase is focused on moving away from uniform security controls toward a risk-adaptive model, where token lifetimes, authentication strength and permission scope are dynamically tied to the privilege level of the action being performed. The team is leveraging the token intelligence capabilities of the Curity Identity Server by developing differentiated token lifetimes and also investigating stronger second-factor requirements for high-risk operations.

Compliance requirements are also becoming increasingly central, reinforcing the business case for a robust, adaptable identity foundation that Curity offers.

Identity as Competitive Infrastructure

For Arelion, the Curity platform is not a standalone security tool but rather a part of the critical infrastructure that makes the business possible - the foundation on which customer trust, API security and operational reliability are built.

From post-divestment urgency to stable, scalable production, Arelion’s journey is a case study in treating identity as a strategic asset rather than a compliance cost. The flexibility to customize token issuance, the control that comes with self-hosted deployment and the open standards architecture that enables future integrations - these are the characteristics that make the Curity Identity Server the right choice for organizations that require full control, flexibility and trust in their identity infrastructure.

Per-Axel Felth

Having a flexible identity platform gives us confidence when discussing new solutions. We know we have a strong foundation that can support future use cases

Per-Axel Felth - Head of IT Architecture

Read More Customer Stories

Ziklo (Volvofinans) Bank has evolved identity and access management across all digital services
Ziklo (Volvofinans) Bank has evolved identity and access management across all digital services

Ziklo (Volvofinans) Bank has evolved identity and access management across all digital services

Read Story
The Curity Identity Server allowed Dun & Bradstreet to unify their many different services and meet their unique requirements
The Curity Identity Server allowed Dun & Bradstreet to unify their many different services and meet their unique requirements

The Curity Identity Server allowed Dun & Bradstreet to unify their many different services and meet their unique requirements

Read Story
SproutLoud leveraged API integrations using the Curity Identity Server, allowing them to create a common identity platform
SproutLoud leveraged API integrations using the Curity Identity Server, allowing them to create a common identity platform

SproutLoud leveraged API integrations using the Curity Identity Server, allowing them to create a common identity platform

Read Story
Seamless and modern authentication for Scandic Hotels guests powered by the Curity Identity Server
Seamless and modern authentication for Scandic Hotels guests powered by the Curity Identity Server

Seamless and modern authentication for Scandic Hotels guests powered by the Curity Identity Server

Read Story
Santander strengthens API security with the Curity Identity Server
Santander strengthens API security with the Curity Identity Server

Santander strengthens API security with the Curity Identity Server

Read Story
Poppulo achieves their API-first strategy with the Curity Identity Server
Poppulo achieves their API-first strategy with the Curity Identity Server

Poppulo achieves their API-first strategy with the Curity Identity Server

Read Story
PayEx established a secure and flexible IAM system allowing for easier customer integrations
PayEx established a secure and flexible IAM system allowing for easier customer integrations

PayEx established a secure and flexible IAM system allowing for easier customer integrations

Read Story
Nowcom improved login security with the Curity Identity Server
Nowcom improved login security with the Curity Identity Server

Nowcom improved login security with the Curity Identity Server

Read Story
Maersk Customs Services created ‘one truth’ for identity and data sharing with the Curity Identity Server
Maersk Customs Services created ‘one truth’ for identity and data sharing with the Curity Identity Server

Maersk Customs Services created ‘one truth’ for identity and data sharing with the Curity Identity Server

Read Story
Ikano Bank streamlined identity management in multiple countries with the Curity Identity Server
Ikano Bank streamlined identity management in multiple countries with the Curity Identity Server

Ikano Bank streamlined identity management in multiple countries with the Curity Identity Server

Read Story
If Insurance built a secure, scalable identity platform powering partners, customers and AI
If Insurance built a secure, scalable identity platform powering partners, customers and AI

If Insurance built a secure, scalable identity platform powering partners, customers and AI

Read Story
How Skandia Scaled Digital Banking with Curity
How Skandia Scaled Digital Banking with Curity

How Skandia Scaled Digital Banking with Curity

Read Story
How ATG moved to a microservice architecture with the Curity Identity Server
How ATG moved to a microservice architecture with the Curity Identity Server

How ATG moved to a microservice architecture with the Curity Identity Server

Read Story
HealthHero future-proofs its virtual healthcare services with the Curity Identity Server
HealthHero future-proofs its virtual healthcare services with the Curity Identity Server

HealthHero future-proofs its virtual healthcare services with the Curity Identity Server

Read Story
Entercard complies with banking regulations and secures its microservices with the Curity Identity Server
Entercard complies with banking regulations and secures its microservices with the Curity Identity Server

Entercard complies with banking regulations and secures its microservices with the Curity Identity Server

Read Story
E.ON’s seamless transition to modern identity management with the Curity Identity Server
E.ON’s seamless transition to modern identity management with the Curity Identity Server

E.ON’s seamless transition to modern identity management with the Curity Identity Server

Read Story
Curity helped dmTECH secure online sales and provide smooth login UX for dm-drogerie markt digital services
Curity helped dmTECH secure online sales and provide smooth login UX for dm-drogerie markt digital services

Curity helped dmTECH secure online sales and provide smooth login UX for dm-drogerie markt digital services

Read Story
Curity enabled easier ways of logging in, leading to an increased usage of Tele2 services
Curity enabled easier ways of logging in, leading to an increased usage of Tele2 services

Curity enabled easier ways of logging in, leading to an increased usage of Tele2 services

Read Story
Curity enabled PagerDuty to deploy in different regions and enhance service availability
Curity enabled PagerDuty to deploy in different regions and enhance service availability

Curity enabled PagerDuty to deploy in different regions and enhance service availability

Read Story
Bjorn Lunden unifies authentication and accelerates growth with Curity and Elastx
Bjorn Lunden unifies authentication and accelerates growth with Curity and Elastx

Bjorn Lunden unifies authentication and accelerates growth with Curity and Elastx

Read Story
Bankdata modernizes identity infrastructure with the Curity Identity Server
Bankdata modernizes identity infrastructure with the Curity Identity Server

Bankdata modernizes identity infrastructure with the Curity Identity Server

Read Story
Arion Banki now has a standards-based identity platform and robust Open Banking protection
Arion Banki now has a standards-based identity platform and robust Open Banking protection

Arion Banki now has a standards-based identity platform and robust Open Banking protection

Read Story

Next steps

Ready for the Next Generation of IAM?

Build secure, flexible identity solutions that keep pace with innovation. Start today.