Wednesday June 28, 2006
Alice and Bob - Crypto Rap
Reading Gudge's blog I came across this very funny crypto rap piece. It definitely reminds me of the numerous Alice and Bob discussions we've in the Technology Expert Group of Liberty Alliance
Posted at 02:28PM Jun 28, 2006 by Hubert Le Van Gong in Identity | Comments[0]
More on Liberty Alliance and User-Centric Identity.
Following my last entry on a taxonomy around the user-centric identity term, Paul and I discussed about the features I highlight and how they are relevant to our 3 terms: user centric, user controlled and consent. The table below is a stab at it:
|
User Consent |
User Controlled |
User Centric |
|
|---|---|---|---|
|
User consent (SAML req.) |
X |
||
|
Authentication Context |
X |
||
|
People Service |
X |
||
|
Interaction Service |
X |
X |
|
|
LECP/ECP |
X |
Two things to note there:
-
While the ID-WSF’s Interaction Service may not initially put the user between the requester and the provider it enables the provider to bring the user on the front row so it can ask for consent. It’s a PPEP (personal PEP) as Paul puts it.
-
There nothing in the user consent column (for now). I need to think a bit more about it.
Like I said, a work in progress...
All thoughts welcome!
Posted at 05:11PM Jun 21, 2006 by Hubert Le Van Gong in Identity | Comments[0]
A taxonomy on User-Centric Identity
Since Microsoft announced their work on InfoCard (or I guess I should say CardSpace now...) the term user-centric identity has been on many people’s blogs and as often happens with popular new terms the spectrum of its interpretations has widen. My esteemed Liberty partners Paul and Eve have blogged about a taxonomy that I think gives an excellent view on what we believe user-centric identity is and how it relates to the important notions of consent and control.
Not too long ago I gave a webcast on user-centric identity (along with John , see his excellent presentation on LECP ) and a prototype we have built that shows how Liberty‘s ID-WSF protocol do support user-centrism. Here is a first list of the technical aspects that supports this:
-
User consent ( SAML2.0 request)
-
Liberty Enabled Client/Proxy (aka. LECP - ID-FF )
-
Interaction Service ( ID-WSF2.0 )
-
People Service ( ID-WSF )
I’ll ad more to it as I think of them.
Posted at 11:00AM Jun 20, 2006 by Hubert Le Van Gong in Identity | Comments[0]
SAML v2.0 presentation.
Last summer Eve and I made some presentations for an internal workshop on Identity Management. One of the presentation I thought people were the most interested in was about SAML v2.0.
SAML (aka the universal solvent for identity) is a powerful combination of a token format (assertions that can be about authentication, attribute or authentication) and a set of protocols. It is a foundation for Liberty's work.
If you are interested in identity
management and want to learn more about SAML this presentation is a
MUST (in all modesty
).