advising on IT-business alignment
IT-business alignment about us blog our services articles & reports resources your profile exposure
blog
blog
Friday, October 28, 2005

"Loosely Coupled" reinvents Passport

The Loosely Coupled blog authored by Phil Wainewright published an entry on Identity as a service yesterday.

What Phil says here makes a lot of sense:

One of the things that's becoming evident as organizations deploy service-oriented architectures is that identity management (access control, user authorizations) has to be implemented as a service. Anything else rapidly becomes too unwieldy to maintain and manage as the number of discrete application services increases.

What's true within a single enterprise infrastructure surely holds true even more in the WorldWide Web. But at the moment, each separate service provider (Google, Amazon.com, eBay, Yahoo!, etc) either has their own identity management stack — if not several — or else it has none at all (eg, every site that publishes an RSS feed).


It's true, there is a need for an open, interoperable, vendor-independent infrastructure for delivering identity which puts the user in control. This is the objective of Kim Cameron's 7 laws of identity and the identity metasystem - basically to do for identity what TCP/IP did for networking.

But then he goes on:

That's why identity as a service is the killer app. Not as a service offered in its own right to individuals, but as a service to websites and providers that have no workable identity management infrastructure of their own to offer their users. Restricting access on a named-user basis to individual URLs — RSS feeds, screencasts, PDF files or web service URIs — is the key that would enable such sites to realize value from those assets. At present it's not a viable option because of the cost and/or hassle of maintaining their own secure identity management system. But if the site owner could sign up to a third-party identity service, and have an embedded sign-up process that meant the service provider would take care of allocating rights to the user profile and then authorizing access to the relevant URLs — perhaps with options to measure or limit usage over a certain period — it opens up a whole new world of possibilities. Make it cheap enough — no more than a dollar a month per ID — and at a stroke the fabled thousand flowers would bloom as businesses found new ways to monetize information flows and online services by restricting them to named users, whether they be employees, customers or even other websites and service aggregators.


Hmmm - Phil, haven't you just invented Passport? ;-)

The challenge isn't really about technology - it's about trust (which is something that Microsoft fell over with Passport and "Hailstorm"). Who is going to be trusted by the various stakeholders to actually manage identities? Government? (The UK identity card furore would suggest otherwise.) Financial services companies? (The identity theft furore around credit card data is not a good sign.) Lastly - any such solution would ultimately require co-operation between such service providers since no one organisation is big enough.


Burn this feed
Burn this feed!

Creative Commons License
This work is licensed under a Creative Commons License.

Blog home

Previous posts

Plumtree becomes AquaLogic User Interaction
Service notification
Stoking the Sun database fire
Sun and Google collaboration: oh well, you can dre...
Google + Sun = a fundamental shift or NC redux?
A great identity management resource
Microsoft and JBoss co-operate: commercial realiti...
Office productivity suites finally got interesting...
SAP venture funding bears fruit
Microsoft's WWF Smackdown

Blog archive

March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
July 2008
August 2008
September 2008
October 2008
November 2008
December 2008
January 2009
February 2009
March 2009
April 2009
May 2009
June 2009
July 2009

Blogroll

Andrew McAfee
Andy Updegrove
Bob Sutor
Dare Obasanjo
Dave Orchard
Digital Identity
Don Box
Fred Chong's WebBlog
Inside Architecture
Irving Wladawsky-Berger
James Governor
Jon Udell
Kim Cameron
Nicholas Carr
Planet Identity
Radovan Janecek
Sandy Kemsley
Service Architecture - SOA
Todd Biske: Outside the Box

Powered by Blogger

Weblog Commenting and Trackback by HaloScan.com

Enter your email address to subscribe to updates:

Delivered by FeedBurner