<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Cloud Identity Model</title>
	<atom:link href="http://blog.talkingidentity.com/tag/cloud-identity-model/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Time To Put Your Thinking Caps On</title>
		<link>http://blog.talkingidentity.com/2011/07/time-to-put-your-thinking-caps-on.html</link>
		<comments>http://blog.talkingidentity.com/2011/07/time-to-put-your-thinking-caps-on.html#comments</comments>
		<pubDate>Tue, 12 Jul 2011 12:54:18 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Cat11]]></category>
		<category><![CDATA[Catalyst11]]></category>
		<category><![CDATA[CIS11]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[Cloud Identity Summit]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Federated Provisioning]]></category>
		<category><![CDATA[Gartner Catalyst Conference]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1251</guid>
		<description><![CDATA[Mike Neuenschwander has dubbed July as Identity Conference Month. And he should know, given that so many of his signature moments were on stage at the Catalyst conference that will be returning at the end of this month (July 26-29 in San Diego). Catalyst is always the most thought-provoking identity event of the year, but [...]]]></description>
			<content:encoded><![CDATA[<p>Mike Neuenschwander has dubbed July as <a href="http://bit.ly/noIEZA" target="_blank">Identity Conference Month</a>. And he should know, given that so many of his signature moments were on stage at the <a href="http://bit.ly/q3TjM1" target="_blank">Catalyst conference</a> that will be returning at the end of this month (July 26-29 in San Diego). Catalyst is always the most thought-provoking identity event of the year, but there is added intrigue this year, as a lot of us recurring *characters* are wondering what impact the Gartner takeover of the event (last years was still run by the Burton folk) will have on its ethos. I&#8217;ll be dropping in as always to learn, converse, incite and, of course, party.</p>
<p>The week before that, the <a href="http://bit.ly/n0zeMP" target="_blank">Cloud Identity Summit</a> (July 18-21) will once again be warming us up for Catalyst by hosting an impressive gathering of subject matter experts and thought leaders talking about the intertwined worlds of identity and the cloud. And this year, I&#8217;ll be there too, giving a talk on <strong>the future of identity provisioning</strong> (<em>July 20 at 12:00pm</em>). Following up on the talks I gave last year at <a href="http://bit.ly/d5aEZw">Gluecon</a> and at <a href="http://bit.ly/9xLC0N">Catalyst</a>, I&#8217;ll be bringing <a href="http://bit.ly/n28jdI" target="_blank">my cred as a provisioning expert</a> to bear in examining if identity provisioning even has a future in the pull-based future of identity (<em>spoiler alert: it does</em>), and what it might look like, given recent developments in the space and advancements in cloud architectures. In an unfortunate scheduling mishap, I will be going up against Pamela Dingle&#8217;s session on identity and mobility, which I would have loved to sit in on myself. I&#8217;m sure she&#8217;ll be peppering her session with cuteness in the form of cats or cuddly toys, so I&#8217;m going to have to up the game and incorporate something bad-ass into my session, like <em>Transformers</em> or <em>Angry Birds</em> (<em>Iron Man</em> was so <a href="http://bit.ly/9xLC0N">last year</a>). Pam, you&#8217;re going down <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Two weeks. Two great conferences. And me at both. So be there or be square!</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/cat11" rel="tag">Cat11</a>, <a href="http://blog.talkingidentity.com/tag/catalyst11" rel="tag">Catalyst11</a>, <a href="http://blog.talkingidentity.com/tag/cis11" rel="tag">CIS11</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-summit" rel="tag">Cloud Identity Summit</a>, <a href="http://blog.talkingidentity.com/tag/conference" rel="tag">Conference</a>, <a href="http://blog.talkingidentity.com/tag/federated-provisioning" rel="tag">Federated Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/gartner-catalyst-conference" rel="tag">Gartner Catalyst Conference</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/07/time-to-put-your-thinking-caps-on.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Building a Strong Foundation for Your Cloud with Identity Management</title>
		<link>http://blog.talkingidentity.com/2010/09/building-a-strong-foundation-for-your-cloud-with-identity-management.html</link>
		<comments>http://blog.talkingidentity.com/2010/09/building-a-strong-foundation-for-your-cloud-with-identity-management.html#comments</comments>
		<pubDate>Mon, 27 Sep 2010 06:01:44 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[The Cloud Identity Series]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[OOW10]]></category>
		<category><![CDATA[OpenWorld]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1045</guid>
		<description><![CDATA[That was the topic of my talk at OpenWorld this year. Fitting, I think, considering the emphasis that was put on Cloud Computing at OOW this year, starting with Larry&#8217;s opening keynote on Sunday. In my session, I talked about how, thanks in large part to the emergence of cloud computing, enterprises are moving towards [...]]]></description>
			<content:encoded><![CDATA[<p>That was the topic of my talk at OpenWorld this year. Fitting, I think, considering the emphasis that was put on Cloud Computing at OOW this year, starting with Larry&#8217;s opening keynote on Sunday.</p>
<p>In my session, I talked about how, thanks in large part to the emergence of cloud computing, enterprises are moving towards a borderless IT infrastructure that is going to change how security is done. The traditional mechanisms of security that are built on topology are going to have to be replaced by a security architecture built on the constant that can actually flow across domain boundaries &#8211; identity.</p>
<p>Yoda himself made an appearance to make the point.</p>
<p><img class="alignnone" title="Yoda on Identity-based Cloud Security" src="http://farm5.static.flickr.com/4126/5015994636_a2dd944377.jpg" alt="" width="500" height="375" /></p>
<p>My presentation was divided into a few parts:</p>
<ul>
<li>I revisited the issue of security in cloud computing, in particular highlighting specific areas that need to be addressed.</li>
<li>I talked about the foundational elements to building an identity-based security model for your cloud environment, and how to evolve that into a full-fledged platform for your cloud applications.</li>
<li>I also talked about the products and capabilities available in the Oracle Identity Management 11g suite, and some of our future plans aimed at specifically addressing the cloud.</li>
</ul>
<p>You can check out the presentation below (I hope to add the session audio to it at some point).</p>
<div id="__ss_5294105" style="width: 550px;"><object id="__sse5294105" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="550" height="460" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s317276-foundationforcloudusingidm-100926233432-phpapp01&amp;rel=0&amp;stripped_title=s317276-foundation-for-cloud-using-id-m&amp;userName=NishantKaushik" /><param name="name" value="__sse5294105" /><param name="allowfullscreen" value="true" /><embed id="__sse5294105" type="application/x-shockwave-flash" width="550" height="460" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s317276-foundationforcloudusingidm-100926233432-phpapp01&amp;rel=0&amp;stripped_title=s317276-foundation-for-cloud-using-id-m&amp;userName=NishantKaushik" name="__sse5294105" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/cloud-security" rel="tag">Cloud Security</a>, <a href="http://blog.talkingidentity.com/tag/oow10" rel="tag">OOW10</a>, <a href="http://blog.talkingidentity.com/tag/openworld" rel="tag">OpenWorld</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/09/building-a-strong-foundation-for-your-cloud-with-identity-management.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Identity Services should be like Vitamins, not Crack</title>
		<link>http://blog.talkingidentity.com/2010/08/identity-services-should-be-like-vitamins-not-crack.html</link>
		<comments>http://blog.talkingidentity.com/2010/08/identity-services-should-be-like-vitamins-not-crack.html#comments</comments>
		<pubDate>Thu, 12 Aug 2010 20:45:31 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1003</guid>
		<description><![CDATA[OK, so it&#8217;s a ridiculous title. But hear me out. Matt Flynn brought to my attention an article in which Dale Olds talks about the need for hosters (companies that provide the platform on which you deploy your Cloud/SaaS applications) to provide identity services (and as Matt points out, security services in general) as part [...]]]></description>
			<content:encoded><![CDATA[<p>OK, so it&#8217;s a ridiculous title. But hear me out.</p>
<p>Matt Flynn <a href="http://bit.ly/ab7V0e" target="_blank">brought to my attention</a> an <a href="http://bit.ly/bnVj4C" target="_blank">article in which Dale Olds talks</a> about the need for hosters (companies that provide the platform on which you deploy your Cloud/SaaS applications) to provide identity services (and as Matt points out, security services in general) as part of their offering.</p>
<p><em>&lt;Side Note&gt;No, I do not have a vendetta against Novell, though these last few blog posts may make it feel that way. I actually really like the Novell gang &#8211; Dale, Ben and Nick Nichols among others &#8211; and for the most part completely agree with their views on identity.&lt;/Side Note&gt;</em></p>
<p>Now, I am with Dale for the first half of the article. Developers of these cloud applications just want to focus on the business logic that is at the core of their service, and not have to worry about the plumbing items, which would include identity management. This is fundamental <strong>service-oriented security</strong> principles at play, and the survey Dale mentions reflects this (I would argue that even the one-third of SaaS vendors that said they want to handle identity themselves are either saying so because they don&#8217;t know what&#8217;s involved or are just not happy with what they are getting from the platform and embeddable components). A good set of identity services goes a long way in making applications agile and more acceptable/appealing to customers.</p>
<p>But then the article talks about hosters using identity services as a way to make their platform sticky, because if the platform owns the user accounts for the service, then the service will be hooked. I actually envision the opposite of that when I think of identity services in the platform &#8211; identity services making it possible for the SaaS vendor to switch between platforms easily. What is being described sounds like an Identity Provider, which is a business service, not a platform service.</p>
<p>What the platform should provide, and what most enterprise customers would want, is an <a href="http://bit.ly/cpDs9R">Identity Hub</a> service, as opposed to an Identity Store service. This allows the customer of the SaaS application to plug it into their enterprise identity store (usually a corporate LDAP system, but it could also be their Salesforce user store) and also accept incoming identities over the wire, while still freeing the SaaS vendor from having to manage identities. In this model, the stickiness for the hoster comes not from owning the user accounts, but from the QoS of the identity services they are providing to their customers (the SaaS vendors and their delegated customers). It also doesn&#8217;t force a SaaS vendor to be married to one platform.</p>
<p>Now, I am going to be a little presumptuous here. Having spent some time with Dale, and knowing his past work, I think that he believes in the view I am taking as well. The article seems to be discussing the topic of identity services from a particular angle, which is that there is currently a market opportunity for hosters to leverage the lack of good (non-enterprise) Identity Providers to make their platforms more sticky. It is absolutely true that platforms can (and are actively seeking  to) make themselves sticky by owning the accounts; Dale points out that  this is exactly what Google did by leveraging GMail as the gateway drug  (see, I told you the metaphor works). But as Google seeks to penetrate  the enterprise market deeper, even they are recognizing the need to  support federated identities as a necessary step for viability. (<strong>UPDATE</strong>: An <a href="http://bit.ly/cXkSmU" target="_blank">old blog post</a> of Dale&#8217;s actually clarifies this, and in essence agrees with the view point I am stating here &#8211; exactly as I thought he would <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  )</p>
<p>Bob Blakley has long mused about what business models would make Identity Oracle&#8217;s viable. And the simple truth is that  platform players like Google or Force.com <em>that can leverage an identity-rich business service that they also have</em> are ideally suited to be trusted Identity Providers. But while a big platform player can certainly be a good Identity Provider, not all hosters should need to be Identity Providers to be successful. Instead, standards based identity services would be a great asset for hosters that want to be sticky (by being the best platform to deploy on) without having to take on the onerous task of being an Identity Provider (which has its own challenges) or passing on those responsibilities to their customers (which is what mostly happens today). And it would be an asset for SaaS vendors that want to have the freedom of choice that we all crave, and that want to be able to work with their customers identity infrastructure. As Dale says in the article:</p>
<blockquote><p>You see, people can move an application from one host to another without  much trouble.</p></blockquote>
<p>Now, isn&#8217;t that a good thing, and something that we should be aiming for?</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/saas" rel="tag">SaaS</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/08/identity-services-should-be-like-vitamins-not-crack.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Can OAuth do what SPML hasn&#8217;t?</title>
		<link>http://blog.talkingidentity.com/2009/11/can-oauth-do-what-spml-hasnt.html</link>
		<comments>http://blog.talkingidentity.com/2009/11/can-oauth-do-what-spml-hasnt.html#comments</comments>
		<pubDate>Tue, 24 Nov 2009 21:52:03 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[The Cloud Identity Series]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[Federated Provisioning]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[SPML]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=720</guid>
		<description><![CDATA[I spent an interesting week at HQ last week, trying to deal with some of the craziness that occurs every time a major release is on its way. But far more interesting were all the identity management conversations I engaged in during the course of the week &#8211; in hallways, over meals and especially over [...]]]></description>
			<content:encoded><![CDATA[<p>I spent an interesting week at HQ last week, trying to deal with some of the craziness that occurs every time a major release is on its way. But far more interesting were all the identity management conversations I engaged in during the course of the week &#8211; in hallways, over meals and especially over drinks. Suffice to say that it was a very thought provoking week. I wanted to use this forum to expand on a conversation that started in one venue, and then spilled over into the Twitterverse.</p>
<p>One of the topics that has been fodder for some animated discussion has been the <a href="http://blog.talkingidentity.com/tag/federated-provisioning" target="_blank">topic of federated provisioning</a>. As the cloud has brought federated authentication back into focus, it has also shone a light on the need for federated provisioning to power cloud identity. After a very interesting discussion that I had with some folks who are looking at identity in the cloud, <a href="http://twitter.com/NishantK/status/5806488992" target="_blank">I posed the following question</a> on Twitter:</p>
<blockquote><p>Had an interesting discussion this morning on how OAuth could be to federated provisioning what OpenID is to federated SSO. Any takers?</p></blockquote>
<h3>The Thesis</h3>
<p>Federated provisioning is about creating an account with appropriate privileges in underlying systems on the <em>Relying Party</em> side when triggered by an authentication event (user comes to the <em>RP</em> service from the <em>Identity Provider</em>, or <em>IdP</em>, side). Further, the authentication token being presented to the <em>RP</em> does not contain sufficient claims (attributes, etc) for the systems on the <em>RP</em> side to create the necessary account (there are other scenarios, of course, but this is the common one I am trying to address). Consequently, we have a need for the <em>RP</em> to get provisioned with data from the <em>IdP</em> side.</p>
<p>Now in my post &#8220;<a href="http://blog.talkingidentity.com/2009/02/the_thing_about_federated_prov.html" target="_blank">The Thing About Federated Provisioning</a>&#8220;, I pointed out that there are challenges in doing all of this just-in-time. Enterprises often resort to out-of-band pre-provisioning of accounts across the domain boundaries, which is where SPML proves to be adequate. But the demand for JIT mechanisms still exists. The cloud exacerbates this problem greatly, because pre-provisioning is pretty much impossible when you move up to the scale and loose coupling of the cloud. And the nature of SPML requires that extensive integration be done before the connection between the RP and the IdP can go live.</p>
<p><a href="http://oauth.net/"><img class="alignright" title="OAuth" src="http://hueniverse.com/wp-content/uploads/2009/09/OAuth-Shine-300x298.png" alt="" width="193" height="191" /></a>And this is where I believe <strong>OAuth</strong> could play a role. OpenID is already viewed as a lightweight solution for enabling federated authentication, with attribute exchange supporting the simpler data transport scenarios. We could now augment this flow by adding an <em>OAuth-based data provisioning</em> mechanism that allows a <em>Provisioning Service </em>on the <em>RP</em> side to connect back to a <em>Provisioning Service </em>on the <em>IdP</em> side and retrieve the data it needs to create the underlying accounts. Being based on OAuth, this would require far less integration than the SPML based approach would.</p>
<p>Mapping the concepts, the <em>RPs Provisioning Service</em> becomes the <em>OAuth Consumer</em>, while the <em>IdPs Provisioning Service</em> becomes the <em>OAuth Service Provider</em>. The interactions are outlined in the diagram below (greatly simplified for the purposes of this discussion).</p>
<p><img class="aligncenter size-full wp-image-726" title="OAuth for Fed-Prov" src="http://blog.talkingidentity.com/wp-content/uploads/2009/11/OAuth-for-Fed-Prov.jpg" alt="OAuth for Fed-Prov" width="500" height="312" /></p>
<h3>The Challenge</h3>
<p>But when you look at the actors involved in OAuth, you run into one problem &#8211; OAuth was defined with users in mind, not enterprises. So you find the User as part of the protocol, but nothing that would allow the Enterprise to have a say in the exchange. And this raises an interesting challenge.</p>
<p>Just like there are security issues to resolve in the OpenID protocol for it to satisfy enterprise requirements, there are policy challenges that would need to be resolved in the OAuth exchange as well. Connecting the services only requires that the user in the flow provide their assent, but if OAuth were to step in as a federated provisioning protocol, it would require some way for the enterprise to inject (fine-grained) business policy into the exchange. And what if approval workflow needs to enter the picture?</p>
<p>One thought would be to introduce an <a href="http://www.openliberty.org/wiki/index.php/IGF_Introduction" target="_blank">IGF</a> style declarative policy mechanism that would allow the services on each side of the exchange to declare intent and policy, thereby allowing some automated decision making that ensures that security and business policies are honored by the exchange. Because when you are talking about fed-prov, a one-size-fits-all construct will be a non-starter.</p>
<p>My posting on twitter did generate some good feedback from folks like <a href="http://twitter.com/xmlgrrl" target="_blank">Eve Maler</a> and <a href="http://twitter.com/itickr" target="_blank">Ashish Jain</a>. I am interested to get people&#8217;s thoughts on the viability of this idea, and whether you think adding OAuth to provisioning systems would be part of the move to enabling enterprise identity management systems for the cloud.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/federated-provisioning" rel="tag">Federated Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/oauth" rel="tag">OAuth</a>, <a href="http://blog.talkingidentity.com/tag/spml" rel="tag">SPML</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/11/can-oauth-do-what-spml-hasnt.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Screencast of my OpenWorld Session on &#8220;IdM and the Cloud&#8221;</title>
		<link>http://blog.talkingidentity.com/2009/10/screencast-of-my-openworld-session-on-idm-and-the-cloud.html</link>
		<comments>http://blog.talkingidentity.com/2009/10/screencast-of-my-openworld-session-on-idm-and-the-cloud.html#comments</comments>
		<pubDate>Fri, 16 Oct 2009 19:20:21 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[OOW09]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>
		<category><![CDATA[Oracle_IDM]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=682</guid>
		<description><![CDATA[On Monday, I presented at Oracle OpenWorld on the topic of &#8220;Identity Management and the Cloud: Stormy Days Ahead?&#8220;. The title proved to be a little too prescient, because the weather in San Francisco was pretty nasty. And as you can imagine, the number of jokes made about this became all to predictable. Unfortunate coincidences [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.oracle.com/us/openworld/index.htm"><img class="alignright" title="Oracle OpenWorld 2009" src="http://oracleimg.com/admin/images/oow09/ocom_oowsf09_reg_banner.gif" alt="" width="185" height="125" /></a>On Monday, I presented at Oracle OpenWorld on the topic of &#8220;<strong>Identity Management and the Cloud: Stormy Days Ahead?</strong>&#8220;. The title proved to be a little too prescient, because the weather in San Francisco was pretty nasty. And as you can imagine, the number of jokes made about this became all to predictable.</p>
<p>Unfortunate coincidences on the title aside, the overall response to my session was quite positive, especially from folks whose opinions I really respect like <a href="http://bit.ly/3iVPOq" target="_blank">Bob Blakley</a> and Lori Rowland from the Burton Group. There was general agreement that widespread adoption of Cloud Computing is going to be a major disruption on the existing evolutionary path that Identity Management has been following. And adoption of the Identity Services model is a major component to readying IdM for the Cloud.</p>
<p>Check out the screencast (slides with audio of the session) of my session below. Registered attendees of OpenWorld can download the presentation itself and the MP3 audio recording of the session from <a href="http://bit.ly/1OgIvs" target="_blank">OpenWorld On-Demand</a> (just login with the Username and Password you created during your OOW registration).</p>
<div id="__ss_2222693" style="width: 425px; text-align: left;"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" title="IdM And The Cloud: Stormy Days Ahead?" href="http://bit.ly/bRO1u">IdM And The Cloud: Stormy Days Ahead?</a><object style="margin:0px" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s309525-idmandthecloudstormydaysahead-091014121834-phpapp02&amp;rel=0&amp;stripped_title=idm-and-the-cloud-stormy-days-ahead" /><param name="allowfullscreen" value="true" /><embed style="margin:0px" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s309525-idmandthecloudstormydaysahead-091014121834-phpapp02&amp;rel=0&amp;stripped_title=idm-and-the-cloud-stormy-days-ahead" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://bit.ly/eYtlC">Nishant Kaushik</a>.</div>
</div>
<p>The audio includes the questions that were asked of me, and turns out that the questions didn&#8217;t record well and I forgot to repeat them. Hopefully my answers are cogent enough that you get an idea of what questions were asked. I did want to follow up here on this blog post a few of those answers:</p>
<ul>
<li>A question came up regarding the licensing terms for Oracle IdM products when they are being used in a cloud environment (specifically, by organizations that are going to be Cloud Providers of Identity Services). The biggest challenge for such organizations is that they cannot accurately estimate the number of users, or other such variables licensing is typically based on, beforehand, which creates uncertainty for them as to the cost they will have to bear. After the session, I confirmed with our PM team that there is special licensing available for ISVs. Talk to your Oracle sales rep about this if interested.</li>
<li>Another question came up regarding the impact of all this on standards like SPML. I believe my answer covered my opinion on the greater emphasis the cloud identity model will put on the evolution of these standards, especially SPML, which has been languishing. Follow up conversations with some of the original architects of the SPML standard and others involved in standards efforts brought up that the communities responsible for these standards are looking at this very hard and are gearing up efforts to address this. So stay tuned for more on that.</li>
<li>A question was asked regarding Just-In-Time Deprovisioning of access to cloud-based assets. This is something <a href="http://bit.ly/4lX6Wr">I discussed quite a bit in a blog conversation</a> with folks like <a href="http://www.tuesdaynight.org/2009/02/05/will-the-real-federated-provisioning-please-stand-up.html">Ian Glazer</a> and <a href="http://eternallyoptimistic.com/2009/02/05/federated-de-provisioning/">Pam Dingle</a> a while back. So check out that <a href="http://bit.ly/4lX6Wr">post</a> and the related thread.</li>
</ul>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/oow09" rel="tag">OOW09</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/10/screencast-of-my-openworld-session-on-idm-and-the-cloud.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

