advising on IT-business alignment
IT-business alignment about us blog our services articles & reports resources your profile exposure
blog
blog
Tuesday, June 20, 2006

Lots happening in world of identity management

The last couple of weeks have seen a lot of activity in identity management land. Last week saw Burton Group's Catalyst Conference, which is always one of the key events in the identity management calendar. Although I wasn't able to be there it has been admirably covered by Sun's Mark Dixon and Digital ID World's Eric Norlin and Phil Becker (here, here, here, here, here and here). The conference also saw a meeting of the Identity Gang, briefly summarised by Kaliya Hamlin aka Identity Woman here. The discussions continue this week at the Berkman Center for Internet & Society with the Identity Mashup Conference.

With all this activity, it is not surprising that there has been a fair amount of news, but I wanted to call out a couple of announcements that caught my eye. Both relate to user-centric identity, which as I discuss in our recent report on identity management is a separate world from identity management behind the firewall but:
As more and more of the interactions with businesses are performed digitally, individuals will want to use a single identity with multiple organisations. They will want to manage their identity and control how that identity is used and how much information is exposed, dependent on the context of the interaction.
For organisations operating in a "business-to-consumer" context, it is important to pay close attention to ongoing developments and how enterprise identity management vendors plan to coexist.

Although neither announcement specifically calls out bridging these two worlds, they are both associated with ensuring a consistent desktop experience for individuals (and one which is applicable whether or not the individual is behind a corporate firewall) as they are authenticated by a variety of identity providers. This doesn't span the divide but it is an important plank in that bridge.

Following on from the Higgins Project and Bandit, yesterday saw the announcement of another, to my mind complementary, open source user-centric identity project: the Heraldry Identity Project proposal within the Apache Software Foundation. This is welcome news, given the objectives of bringing the world of lightweight URL/XRI-based identities to the desktop by combining the Yadis identity service discovery protocol with the OpenID single sign-on authentication protocol and developing a common desktop component. Being a user of LID (which is interoperable with OpenID and Yadis) and the VeriSign (whose David Recordon proposed the Heraldry project to Apache) Personal Identity Provider, I have first-hand experience of the need to hide the underlying mechanics and provide individuals with a consistent desktop experience - it is meant to be user-centric after all. What I find particularly encouraging is the desire to exploit OSIS, the potential open source implementation of Microsoft's CardSpace (formerly InfoCard), since this promises to ensure a consistent experience for individuals, irrespective of their desktop platform. Obviously, it is still very early stages for both Heraldry and OSIS (not least because the intellectual property issues need to ironed out!) but this is a good start.

The second announcement - or more correctly news story - concerns Microsoft's plans to release a software development kit for the Windows Live ID service. Windows Live ID is the reincarnation of Passport, fulfilling the same authentication role for Microsoft's Live services as Passport did for the MSN services. Live ID goes beyond Passport, though, acknowledging the importance of federation and the need to work with CardSpace. With the SDK it will be possible for application developers to use the Live ID service within rich client applications, thereby allowing individuals who are already users of Live Messenger/Mail/Search ... to be authenticated without having a new set of user credentials. The sheer number of individuals using the various Live Services, together with Microsoft's foothold in the developer community, suggests that Live ID will become a significant identity provider.

Microsoft also plans to provide an SDK for service providers, the Relying Party Suite (RPS), to allow them to use the Live ID service. Given the past failure of Hailstorm, primarily because Microsoft had naively assumed that service providers would be prepared to relinquish control of their valuable customer data, I am not so sure that this SDK will prove as attractive.
Comments:
Neil:

Thank you for linking to my blog.

Regards,

Mark
 
Post a Comment

<< Home


Burn this feed
Burn this feed!

Creative Commons License
This work is licensed under a Creative Commons License.

Blog home

Previous posts

Finally, a new MWD podcast episode - SOA 2.0, and ...
SOA 2.0: The Petition
Getting to the heart of persistent identity manage...
Microsoft's acquisition of Softricity
SOA 2.0? Stop the madness
New podcast episode: interview with prominent ente...
Yowzah - open source management in the enterprise
"Software development is dead": can you smell some...
Web 2.0, "Web as place" and the value of networks
Novell and identity management: from a long-tailed...

Blog archive

March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
July 2008
August 2008
September 2008
October 2008
November 2008
December 2008
January 2009
February 2009
March 2009
April 2009
May 2009
June 2009
July 2009

Blogroll

Andrew McAfee
Andy Updegrove
Bob Sutor
Dare Obasanjo
Dave Orchard
Digital Identity
Don Box
Fred Chong's WebBlog
Inside Architecture
Irving Wladawsky-Berger
James Governor
Jon Udell
Kim Cameron
Nicholas Carr
Planet Identity
Radovan Janecek
Sandy Kemsley
Service Architecture - SOA
Todd Biske: Outside the Box

Powered by Blogger

Weblog Commenting and Trackback by HaloScan.com

Enter your email address to subscribe to updates:

Delivered by FeedBurner