<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Brett McDowell</title>
	<atom:link href="http://blog.talkingidentity.com/tag/brett-mcdowell/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A Twittorial on Trust Frameworks</title>
		<link>http://blog.talkingidentity.com/2010/03/a-twittorial-on-trust-frameworks.html</link>
		<comments>http://blog.talkingidentity.com/2010/03/a-twittorial-on-trust-frameworks.html#comments</comments>
		<pubDate>Fri, 05 Mar 2010 17:57:41 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Brett McDowell]]></category>
		<category><![CDATA[ICAM]]></category>
		<category><![CDATA[Kantara Initiative]]></category>
		<category><![CDATA[Open Identity Exchange]]></category>
		<category><![CDATA[Paul Madsen]]></category>
		<category><![CDATA[Trust Frameworks]]></category>
		<category><![CDATA[User-Centric Identity]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=794</guid>
		<description><![CDATA[(Updated to reflect provisional status of OIX approval per this &#8211; thanks to Brett for telling me) I just got back home from the RSA Conference in San Francisco this week, where the topic of Trust was second only to all things Cloud. While sessions on Identity Management were few and far between, there was [...]]]></description>
			<content:encoded><![CDATA[<p><em><strong>(Updated to reflect provisional status of OIX approval per <a href="http://bit.ly/aAEZEs">this</a> &#8211; thanks to Brett for telling me)</strong></em></p>
<p>I just got back home from the RSA Conference in San Francisco this week, where the topic of <strong>Trust</strong> was second only to all things Cloud. While sessions on Identity Management were few and far between, there was lots of interesting news coming out of the conference (like <a href="http://bit.ly/cDxfRZ" target="_blank">the U-Prove announcement</a>). I <a href="http://twitter.com/NishantK/status/9930608994" target="_blank">tweeted about</a> the announcements that concern <em>Trust Frameworks</em>, a way for one site (Relying Party) to trust the identity, security, and privacy assertions/claims from a different site (Identity Provider) acting on behalf of a user.</p>
<p>The first announcement was on the <a href="http://bit.ly/deZYyF," target="_blank">launch of the <strong>Open Identity Exchange</strong></a><strong> (OIX)</strong>, a (yet another) non-profit organization (coming out of the <em>OpenID Foundation</em> and <em>Information Card Foundation</em>) that is dedicated to building trust in the exchange of        online identity credentials across public and private sectors. The second announcement was regarding the US Federal Government&#8217;s <strong><a href="http://www.idmanagement.gov/drilldown.cfm?action=icam" target="_new">Identity, Credential, and Access Management (ICAM)</a> Trust Framework Evaluation Team (TFET)</strong> provisionally approving both OIX and <strong>Kantara Initiative</strong> as a <em>Trust Framework Provider</em> to certify online identity management providers to U.S. federal standards for identity assurance (read more <a href="http://bit.ly/aAEZEs" target="_blank">here</a>).</p>
<p>Trying to digest all of this was a little difficult, so as I was stuck in traffic on my way home from the airport, I found myself riveted by a twitter exchange that was flying fast and furious between <a href="http://twitter.com/paulmadsen" target="_blank"><strong>Paul Madsen</strong></a> (everyone&#8217;s favorite source for biting identity musings) and <a href="http://twitter.com/brettmcdowell" target="_blank"><strong>Brett McDowell</strong></a> (till recently Executive Director of the <em>Kantara Initiative</em>, and now technology evangelist at <em>Paypal</em>, one of the first IdPs certified by OIX &#8211; so you can see he has unique insight). I have reproduced it here for everyone&#8217;s benefit (with their permission, of course).</p>
<blockquote>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
ICAM is one federation willing to deal with multiple trust frameworks. Will others?</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> ICAM isn&#8217;t actually dealing with multiple trust frameworks. It&#8217;s all just NIST SP800-63 w/ various means to prove you comply.</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> ICAM is &#8216;accepting&#8217;  OIX, KI-IAF, InCommon . To me those are all trust frameworks (ie certification programs)</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> ah, but what is a &#8220;trust framework&#8221;? The criteria for trust itself  (M04-04 &amp; 800-63) or the method for demonstrating compliance?</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> P.S., in the Kantara case, IAF has criteria as well, but it&#8217;s been &#8220;mapped&#8221; to prove comparability to US Federal requirements.</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
Components of a trust framework &#8211; policies, accreditation, certification, admin, metadata infrastructure, keg parties&#8230;.</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> if everybody agrees on 800 63 for the former, trust frameworks are distinguished by the latter</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> IAF/OITF (frameworks) differentiated by criteria, KI/OIX (.org&#8217;s who certify) differentiated by due diligence on applicant</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> thus KI (conditionally) approved for up to non-crypto LOA3 &#8230;</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> M04-04 &amp; SP800-63 is like the &#8220;spec&#8221;, IAF is like the SCR, and OIX is a registry of those asserting compliance to the spec</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> &#8220;non-crypto&#8221; is another misleading term/issue. It rules out &#8220;pure PKI&#8221; but not &#8220;signed&#8221; assertions (SAML) or claims (IMI)</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> but IAF is more than an extra level of policy detail on top of 800 63 criteria. And OIX is more than a registry</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> for KI to be approved for AL3 PKI &amp; AL4 in US Gov, it needs to cross-certify with the Federal Bridge</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> re: &#8220;but IAF is more than&#8221; and &#8220;OIX is more than&#8221; Paul, cut me some slack, this is Twitter, some nuances are going to be lost!</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> point was less about the &#8216;crypto&#8217; part, and more that diff frameworks may target different parts of &#8216;assurance space&#8217;</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> that&#8217;s why I avoid all subtleties &amp; nuances <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> I wouldn&#8217;t draw conclusions (or battle lines) regarding trust frameworks just yet. Remember the OIX RFI dialog w/KI is ongoing</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> as I complained to @<a rel="nofollow" href="http://twitter.com/ve7jtb">ve7jtb</a> , want to see matrix laying out components of a generic framework, specific instances mapped on</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> that sounded like a proposal not a complaint.  I accept your matrix proposal. Looking forward to reading it when you finish <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </td>
</tr>
</tbody>
</table>
</blockquote>
<p>And of course, Paul had to have the last word, and it was typically Madsen-istic.</p>
<blockquote>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> you know, my wife made that same interpretation 16 years ago. Must be more precise</td>
</tr>
</tbody>
</table>
</blockquote>
<p>Hopefully that exchange was illuminating, and gave you enough pointers to standards and topics that might help deepen your understanding of Trust Frameworks. It certainly has given me a lot to think about. While RSA may have been weak on identity related discussions, these announcements are likely to have a huge impact on the identity landscape going forward.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/brett-mcdowell" rel="tag">Brett McDowell</a>, <a href="http://blog.talkingidentity.com/tag/icam" rel="tag">ICAM</a>, <a href="http://blog.talkingidentity.com/tag/kantara-initiative" rel="tag">Kantara Initiative</a>, <a href="http://blog.talkingidentity.com/tag/open-identity-exchange" rel="tag">Open Identity Exchange</a>, <a href="http://blog.talkingidentity.com/tag/paul-madsen" rel="tag">Paul Madsen</a>, <a href="http://blog.talkingidentity.com/tag/trust-frameworks" rel="tag">Trust Frameworks</a>, <a href="http://blog.talkingidentity.com/tag/user-centric-identity" rel="tag">User-Centric Identity</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/03/a-twittorial-on-trust-frameworks.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

