• Speaking
  • Downloads
  • About Talking Identity
  • About Me

Project Concordia Has Its Work Cut Out For It

  • Posted on:June 27, 2007
  • Posted in:Insight IdM
  • Posted by:Nishant Kaushik
2

I attended the Project Concordia workshop yesterday, ahead of the Catalyst conference. I mentioned the project in a blog post last week; it has the worthy goal of trying to initiate efforts that make sense of the competing standards and methodologies that exist in the identity world. I found myself enjoying the kind of lively discussion that makes you glad to be part of such a dynamic community. Built around 5 use case presentations done by organizations deploying identity solutions today, the goal of the workshop was to identify the protocol interoperability challenges that these implementations are facing and what needs to be done to solve it.

The use cases presented by AOL, Boeing, Govt. of British Columbia, GM and US-GSA were quite detailed and very articulate with regards to the challenges being faced in their deployments. Since the discussion was one of standards and protocols, the discussions focused primarily on the authentication and federation pieces in the identity management puzzle (as those standards are the most evolved in the identity space).

Some common themes emerged in the discussions:

  • Usability of the authentication process was identified as an area that is greatly lacking, and potentially needs some work by the standards bodies. The whole idea is to make the life of the end-user easier. Users shouldn’t have to worry about which credential they need to use, but should still have a choice of which credential they want to use.
  • Seemingly at opposite ends of the spectrum, incorporation of the device into the authentication process (reliance on OS authentication) and independence from the device (for portability of identity across laptops, cellphones and kiosks) were identified as being key requirements
  • Setting up federations still requires too much investment and time, preventing it from being a scalable solution to the single identity problem
  • In the context of single sign-on across web applications, the topics of session timeouts and global logout generated much discussion
  • Standards are being unevenly implemented by vendors. All cover the basic aspects of the spec, but none implement the whole spec, usually on edge features, which causes confusion, surprises and incompatibility.
  • Everyone agreed that the non-technology aspects of federation are more complex than the technical aspects

The AOL use case was very interesting as it was the only one that was purely in the consumer space, and discussed the role their OpenID strategy plays in it. The others had more of an enterprise feel to them. At the same time, enterprises like Boeing and GM stated that they were actively trying to figure out where OpenID would fit into their business model. GM and Boeing both talked to the issues of deploying federation with 1000s of partners, and for a mobile workforce in manufacturing environments where issues of presence and entitlement management are key. The Govt. of British Columbia presented an interesting challenge of creating a federation with both large and small “organizations”, where organizations is a loose term that not only covers businesses but also small proprietorships like doctors offices, where the opportunity to deploy complex software does not exist.

The use case presentations engendered some lively discussions that were both entertaining and thought-provoking. Mike Beach of Boeing (never one to shy away from creating controversy) questioned the need for interoperability, postulating that maybe convergence of the standards is better. That is the essence of the challenge that Project Concordia faces – how to come up with an elegant, usable solution out of the morass of standards that different interests have thrown into the ring.

Be Sociable, Share!

Tags: Application-Centric IdMAuthentication ManagementBurton Catalyst ConferenceBurtonGroupCatalyst07Project Concordia
  • http://ejnorman.blogspot.com Eric Norman

    I don’t view the Concordia project as trying to arrive at a “solution”. I view it as providing guidance along directions toward a goal. And I do think this difference reflects a mindset that’s more than semantic BS.

  • Nishant Kaushik

    Well, anything that helps eliminate any problems is a solution, right :)
    But I take your point. I think one of the challenges that Project Concordia faces is clearly defining what will come out of the efforts of the group. Obviously the aim is not to come up with even more standards. But identifying where various standards/protocols need to work together towards a solution, without actually specifying what that solution is, is going to be an interesting challenge. Personally, I feel that the outcome of the project will be recommendations on what needs to be done, which is the beginning of a solution outline.

Recent Posts

The Conundrum of 2FA meets the Enigma that is PAM
"It's a mystery. Broken into a jigsaw puzzle. Wrapped in a conun...
The Dilemma of the OAuth Token Collector
'Tis the season to be hacked, I guess. Twitter joined a bunch of...
Why 2013 will be 'The Year of the SCUID'
I'm just now coming back to earth from the high I've been on sin...
The IDaaS Powered World
Last week I was in Colorado for the Defrag and Blur conferences....
What Happens When Telco's Declare SMS 'Unsafe'?
If you've been following Authentication related discussions, you...

Recent Comments

Bob Pinheiro on
The Conundrum of 2FA meets the Enigma that is PAM
7 weeks ago

NishantKaushik on
The IDaaS Powered World
7 weeks ago

Nikolaj Ivancic on
The IDaaS Powered World
15 weeks ago

on
The Dilemma of the OAuth Token Collector
18 weeks ago

on
The Dilemma of the OAuth Token Collector
18 weeks ago

Tags

Application-Centric IdM Burton Catalyst Conference Cloud Computing Cloud Identity Model Facebook Federated Provisioning Identity Governance Identity Governance Framework Identity in Social Networking Identity Management Identity Services IGF OpenID Oracle Identity Management Oracle Identity Manager Oracle OpenWorld Oracle_IDM Password Management Personal Identity Management Privacy Provisioning Risk Management Role Management Service-Oriented Security User-Centric Identity

Connect

Twitter Follow @NishantK

LinkedIn Connect on LinkedIn

Slideshare View Nishant's Presentations

About Me nishantkaushik.com

Categories

  • Ask Dr. K (11)
  • Identity Services (36)
  • Identropy IDaaS (2)
  • Insight IdM (124)
  • Oracle Identity Management (61)
  • Personal Identity Management (32)
  • The Cloud Identity Series (17)
  • Tips & Techniques (4)
  • User-Centric Identity (24)

Archives

  • ► 2013 (3)
    • April (1)
    • February (1)
    • January (1)
  • ► 2012 (13)
    • November (2)
    • August (3)
    • July (2)
    • June (2)
    • May (1)
    • February (3)
  • ► 2011 (29)
    • December (1)
    • November (1)
    • October (1)
    • September (2)
    • August (3)
    • July (4)
    • June (5)
    • May (3)
    • April (4)
    • February (2)
    • January (3)
  • ► 2010 (33)
    • December (1)
    • October (1)
    • September (4)
    • August (5)
    • July (6)
    • June (4)
    • May (3)
    • April (2)
    • March (3)
    • February (2)
    • January (2)
  • ► 2009 (24)
    • December (1)
    • November (1)
    • October (3)
    • September (3)
    • August (4)
    • July (2)
    • June (2)
    • May (3)
    • April (1)
    • February (2)
    • January (2)
  • ► 2008 (44)
    • December (1)
    • October (4)
    • September (4)
    • August (8)
    • July (11)
    • June (4)
    • May (2)
    • April (2)
    • March (3)
    • February (3)
    • January (2)
  • ► 2007 (56)
    • December (3)
    • November (5)
    • October (6)
    • September (5)
    • August (8)
    • July (5)
    • June (9)
    • May (3)
    • April (2)
    • March (5)
    • February (5)
  • ► 2006 (33)
    • December (4)
    • November (2)
    • October (6)
    • September (1)
    • August (2)
    • July (3)
    • June (5)
    • May (3)
    • April (2)
    • March (5)

Disclaimer

Talking Identity is my exploration of the world of Identity Management. The views expressed on this blog are my own and do not necessarily reflect the views of Identropy (doesn't mean I'm not trying hard to mold them in my own image).

Copyright © 2005-2013 Nishant Kaushik. All Rights Reserved.