<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Identity Assurance</title>
	<atom:link href="http://blog.talkingidentity.com/tag/identity-assurance/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Tue, 24 Aug 2010 17:16:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Executive IdM Session at OpenWorld: It&#8217;s All About Managing Risk</title>
		<link>http://blog.talkingidentity.com/2009/10/executive-idm-session-at-openworld-its-all-about-managing-risk.html</link>
		<comments>http://blog.talkingidentity.com/2009/10/executive-idm-session-at-openworld-its-all-about-managing-risk.html#comments</comments>
		<pubDate>Thu, 29 Oct 2009 18:13:24 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Identity Assurance]]></category>
		<category><![CDATA[Identity Controls]]></category>
		<category><![CDATA[OOW09]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=698</guid>
		<description><![CDATA[One of the things I did at OpenWorld this year was attend an Executive IdM Session that brought together folks from the IdM team and some of our best customers to share information and talk about the future direction of identity management at Oracle. It was an interesting gathering with lots of good discussion that [...]]]></description>
			<content:encoded><![CDATA[<p>One of the things I did at OpenWorld this year was attend an <strong>Executive IdM Session</strong> that brought together folks from the IdM team and some of our best customers to share information and talk about the future direction of identity management at Oracle. It was an interesting gathering with lots of good discussion that resulted in the session running well over its allotted time of 3 hours. As you can see from the picture below, it was a full room (what you don&#8217;t see is those of us who had to stand in the peanut gallery at the back of the room).</p>
<p><a href="http://img169.imageshack.us/my.php?image=nt6.jpg"><img class="alignnone" title="Executive IdM Session" src="http://img169.imageshack.us/img169/5779/nt6.jpg" alt="" width="640" height="480" /></a></p>
<p>The session had a nice flow to it, starting with a vendor presentation (Oracle, of course), followed by an analyst presentation (Bob Blakley and Lori Rowland from the Burton Group) and concluding with a customer presentation (our old friend Ramin Safai from Barclays Capital). Getting to discuss identity management from all points of view was quite a valuable exercise, and I gleaned lots of useful nuggets.</p>
<h3>Security Inside Out</h3>
<p><a href="http://www.oracle.com/security"><img class="alignright size-full wp-image-704" title="Security Inside Out" src="http://blog.talkingidentity.com/wp-content/uploads/2009/10/SecurityInsideOut.jpg" alt="Security Inside Out" width="200" height="102" /></a>Amit Jasuja (who heads up the Identity Management team at Oracle) kicked off the day by talking about &#8220;<strong>Security Inside Out</strong>&#8220;, Oracle&#8217;s new message on putting together a complete security practice by bringing together <em>Database Security</em>, <em>Identity Management</em> and <em>Information Rights Management</em>. Weaving all of these elements together allows an enterprise to get a complete handle on the nature of their security risk across all tiers &#8211; database, middleware and application &#8211; and in all contexts &#8211; data at rest or in motion, internal users vs. external users, and so on. This led to a lot of discussion on moving towards risk-based identity management, which can be more adaptive to an enterprise&#8217;s needs and allow identity management to be a business enabler, not a hindrance.</p>
<p><img class="alignleft size-full wp-image-709" title="breakglass" src="http://blog.talkingidentity.com/wp-content/uploads/2009/10/breakglass.jpg" alt="breakglass" width="200" height="107" />One of the concepts I particularly liked was using identity management to enable &#8220;<strong>Break The Glass</strong>&#8221; scenarios that allow for contextual security decisions. In such a scenario, a user who ordinarily does not have access is allowed to get access but with added controls (like heightened audit, approval and attestation) to address the unique, emergency-like situation that presents itself. Being able to adapt to sensitive contextual situations without sacrificing on security and compliance is a powerful message that resonates in the enterprise world. Another topic that proved fertile for conversation was for risk-based IdM to leverage One-Time Passwords delivered via SMS or over land-line phones in order to implement higher levels of identity assurance (LOA). As two-factor authentication goes, enterprises increasingly view this as an attractive way to increase levels of assurance without having to invest in tokens and biometrics.</p>
<h3>Complete Security</h3>
<p>The Burton Group team talked about the state of identity management in the market today, especially emerging trends and hot-button topics. Lori validated <a href="http://bit.ly/2S0Ren">my observation</a> that cloud computing is going to have a huge impact on the future of identity management, and gave a nice shout out to <a href="http://bit.ly/3AqANC">my OpenWorld session</a> on the topic. One of the interesting takeaways from their talk was this point that Bob made about achieving <strong>complete security</strong>: An enterprise needs to have <em>preventive controls</em> that allow business to be conducted as usual but flush the bad guys into the open, where <em>detective controls</em> can identify them and their activities, which would then allow <em>responsive controls</em> (aka the cops) to take action.</p>
<h3>Down In The Trenches</h3>
<p>Ramin then gave a customers perspective on implementing identity management &#8211; from &#8220;down in the trenches&#8221;, as he called it. There were a lot of good lessons in his talk &#8211; about scoping the project correctly and dividing it into small, achievable mini projects that demonstrate ROI, about the processes and architecture they put in place to ensure success of the project, and some of the achievements they had with their IdM implementation, especially when Barclays acquired Lehman Brothers. One of the major points made in the room during discussion was that security within the enterprise needs to be driven top down by an &#8220;Executive Governance Board&#8221; in order to achieve  consistency and completeness. It cannot be done piecemeal at the IT level.</p>
<p>I love taking part in sessions like these, as it is great to be able to hear so many different perspectives. And thanks to Greg Belanger from the Apollo Group for giving me a shout out during the analyst discussion on Oracle&#8217;s differentiators in the identity management area. The point he was making about Oracle demonstrating vision in IdM is an important one that we are very serious about here, and I am glad to be a small part of that.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/identity-assurance" rel="tag">Identity Assurance</a>, <a href="http://blog.talkingidentity.com/tag/identity-controls" rel="tag">Identity Controls</a>, <a href="http://blog.talkingidentity.com/tag/oow09" rel="tag">OOW09</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bbodytext%3DOne%2520of%2520the%2520things%2520I%2520did%2520at%2520OpenWorld%2520this%2520year%2520was%2520attend%2520an%2520Executive%2520IdM%2520Session%2520that%2520brought%2520together%2520folks%2520from%2520the%2520IdM%2520team%2520and%2520some%2520of%2520our%2520best%2520customers%2520to%2520share%2520information%2520and%2520talk%2520about%2520the%2520future%2520direction%2520of%2520identity%2520management%2520at%2520Oracle.';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Bt%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bannotation%3DOne%2520of%2520the%2520things%2520I%2520did%2520at%2520OpenWorld%2520this%2520year%2520was%2520attend%2520an%2520Executive%2520IdM%2520Session%2520that%2520brought%2520together%2520folks%2520from%2520the%2520IdM%2520team%2520and%2520some%2520of%2520our%2520best%2520customers%2520to%2520share%2520information%2520and%2520talk%2520about%2520the%2520future%2520direction%2520of%2520identity%2520management%2520at%2520Oracle.';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bnotes%3DOne%2520of%2520the%2520things%2520I%2520did%2520at%2520OpenWorld%2520this%2520year%2520was%2520attend%2520an%2520Executive%2520IdM%2520Session%2520that%2520brought%2520together%2520folks%2520from%2520the%2520IdM%2520team%2520and%2520some%2520of%2520our%2520best%2520customers%2520to%2520share%2520information%2520and%2520talk%2520about%2520the%2520future%2520direction%2520of%2520identity%2520management%2520at%2520Oracle.';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Bh%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%2520Executive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/10/executive-idm-session-at-openworld-its-all-about-managing-risk.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The changing face of Password Management</title>
		<link>http://blog.talkingidentity.com/2008/10/the_changing_face_of_password.html</link>
		<comments>http://blog.talkingidentity.com/2008/10/the_changing_face_of_password.html#comments</comments>
		<pubDate>Thu, 09 Oct 2008 22:36:15 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Personal Identity Management]]></category>
		<category><![CDATA[User-Centric Identity]]></category>
		<category><![CDATA[Identity Assurance]]></category>
		<category><![CDATA[Password Management]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=134</guid>
		<description><![CDATA[A college student was arraigned on Wednesday for allegedly breaking into Gov. Sarah Palin&#8217;s private e-mail account last month. Political leanings aside, I  read the news article with great interest for the inherent security implications. Reading it, this line jumped out at me:
The F.B.I. said that the younger Mr. Kernell allegedly hacked into the account [...]]]></description>
			<content:encoded><![CDATA[<p>A college student was arraigned on Wednesday for allegedly breaking into Gov. Sarah Palin&#8217;s private e-mail account last month. Political leanings aside, I  read the <a href="http://thecaucus.blogs.nytimes.com/2008/10/08/indictment-handed-down-in-palin-hacking-case/?ref=technology" target="_blank">news article</a> with great interest for the inherent security implications. Reading it, this line jumped out at me:</p>
<blockquote><p>The F.B.I. said that the younger Mr. Kernell allegedly hacked into the account in mid-September by resetting Gov. Palin’s password.</p></blockquote>
<p>I obviously don&#8217;t know the specifics of how the F.B.I. says the password was reset. But for the sake of our discussion, let&#8217;s <span style="text-decoration: underline;">assume</span> that the email system relied on a typical challenge response mechanism (currently the norm in most free email systems). The hacker obviously didn&#8217;t know the password, but was able to reset the password to something of his/her choosing by successfully answering the challenge questions. In the age of Google, how hard is it to find out the the first school, the first car, the mother&#8217;s maiden name or the pets name of a famous public personality like Sarah Palin?</p>
<p>As <strong>Bob Blakely</strong> likes to point out, there are no secrets any more therefore any system that relies on secrets is inherently flawed.</p>
<p>In a completely separate conversation, a colleague of mine sent me the following thought:</p>
<blockquote><p>All the banks and merchants I do business with online have been increasing their level of security, especially with password complexity requirements.  Historically I have limited all my passwords down to 3 based on the type of site so I had no need to write them down.  Now because of all the different password complexity requirements, especially the password history requirement, I can no longer do that&#8230;. so I&#8217;m now forced to write them down <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>In some sick way, more security by merchants is now leading to worse security for me, the user.  I&#8217;m forced back to the sticky note.</p></blockquote>
<h3>From the Good News/Bad News Department</h3>
<p>The <strong>bad news</strong> in all this is that we seem to be going through a phase where additional mechanisms introduced to <span style="text-decoration: underline;">secure the systems in a user-friendly manner</span> have actually <em>exacerbated</em> the problem because they rely on flawed assumptions. The above issues are clear illustrations of this. The mechanisms deployed (challenge response, password complexity requirements) would have been fine on their own for the system they are meant to protect. But these solutions did not anticipate how they would be impacted by the reality of their users online environment. The aggregation of multiple such systems for a user actually ends up degrading the effectiveness of these solutions, to the point where they end up becoming liabilities instead.</p>
<p>The <strong>good news</strong> is that new technologies and solutions are emerging that (hopefully) will address these problems. OpenID and Information Cards aim to rid us of the multiple password problem by promising a world of reduced sign-on built on trust. Identity assurance technologies (like the ones in Oracle&#8217;s <strong>Identity Assurance Partner Alliance</strong>) provide safer, more reliable means to verify the interacting parties identity than traditional challenge response mechanisms, thus preventing the kind of attacks described above.</p>
<p>So better days are coming. The real challenge ahead of us is getting all involved parties (consumers, online enterprises, vendors) educated on how these solutions can be used to make our online lives more secure.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/identity-assurance" rel="tag">Identity Assurance</a>, <a href="http://blog.talkingidentity.com/tag/password-management" rel="tag">Password Management</a>, <a href="http://blog.talkingidentity.com/tag/user-centric-identity" rel="tag">User-Centric Identity</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DThe%2520changing%2520face%2520of%2520Password%2520Management%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%26amp%3Btitle%3DThe%2520changing%2520face%2520of%2520Password%2520Management%26amp%3Bbodytext%3DA%2520college%2520student%2520was%2520arraigned%2520on%2520Wednesday%2520for%2520allegedly%2520breaking%2520into%2520Gov.%2520Sarah%2520Palin%2527s%2520private%2520e-mail%2520account%2520last%2520month.%2520Political%2520leanings%2520aside%252C%2520I%25C2%25A0%2520read%2520the%2520news%2520article%2520with%2520great%2520interest%2520for%2520the%2520inherent%2520security%2520implications.%2520Reading%2520it%252C';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%26amp%3Bt%3DThe%2520changing%2520face%2520of%2520Password%2520Management';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%26amp%3Btitle%3DThe%2520changing%2520face%2520of%2520Password%2520Management';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%26amp%3Btitle%3DThe%2520changing%2520face%2520of%2520Password%2520Management%26amp%3Bannotation%3DA%2520college%2520student%2520was%2520arraigned%2520on%2520Wednesday%2520for%2520allegedly%2520breaking%2520into%2520Gov.%2520Sarah%2520Palin%2527s%2520private%2520e-mail%2520account%2520last%2520month.%2520Political%2520leanings%2520aside%252C%2520I%25C2%25A0%2520read%2520the%2520news%2520article%2520with%2520great%2520interest%2520for%2520the%2520inherent%2520security%2520implications.%2520Reading%2520it%252C';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%26amp%3Btitle%3DThe%2520changing%2520face%2520of%2520Password%2520Management%26amp%3Bnotes%3DA%2520college%2520student%2520was%2520arraigned%2520on%2520Wednesday%2520for%2520allegedly%2520breaking%2520into%2520Gov.%2520Sarah%2520Palin%2527s%2520private%2520e-mail%2520account%2520last%2520month.%2520Political%2520leanings%2520aside%252C%2520I%25C2%25A0%2520read%2520the%2520news%2520article%2520with%2520great%2520interest%2520for%2520the%2520inherent%2520security%2520implications.%2520Reading%2520it%252C';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%26amp%3Btitle%3DThe%2520changing%2520face%2520of%2520Password%2520Management';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%26amp%3Bh%3DThe%2520changing%2520face%2520of%2520Password%2520Management';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DThe%2520changing%2520face%2520of%2520Password%2520Management%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html%2520The%2520changing%2520face%2520of%2520Password%2520Management';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DThe%2520changing%2520face%2520of%2520Password%2520Management%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fthe_changing_face_of_password.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/10/the_changing_face_of_password.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dissecting all the buzz about Identity Assurance</title>
		<link>http://blog.talkingidentity.com/2008/10/dissecting_all_the_buzz_about.html</link>
		<comments>http://blog.talkingidentity.com/2008/10/dissecting_all_the_buzz_about.html#comments</comments>
		<pubDate>Tue, 07 Oct 2008 22:19:57 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Digital ID World]]></category>
		<category><![CDATA[Identity Assurance]]></category>
		<category><![CDATA[Identity Assurance Framework]]></category>
		<category><![CDATA[Identity Assurance Partner Alliance]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=133</guid>
		<description><![CDATA[ One of the big buzzwords this past month or so has been &#8220;Identity Assurance&#8220;. Liberty Alliance made a big push for the Identity Assurance Framework (IAF)at DIDW last month, conducting a number of sessions/workshops introducing it to the masses. Our old friend Frank Villavicencio, who is a co-chair of the IAEG, was a star [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.talkingidentity.com/wp-content/uploads/2008/10/idtheft_thumb.gif"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 0px 0px 5px; border-right-width: 0px" src="http://blog.talkingidentity.com/wp-content/uploads/2008/10/idtheft_thumb.gif" border="0" alt="idtheft" width="295" height="320" align="right" /></a> One of the big buzzwords this past month or so has been &#8220;<strong>Identity Assurance</strong>&#8220;. Liberty Alliance made a big push for the <strong>Identity Assurance Framework</strong> (IAF)at DIDW last month, conducting a number of sessions/workshops <a href="http://www.projectliberty.org/strategic_initiatives/identity_assurance" target="_blank">introducing it</a> to the masses. Our old friend Frank Villavicencio, who is a co-chair of the IAEG, was a star at the show, even collecting a Liberty Alliance IDDY award. At OpenWorld, Oracle <a href="http://www.oracle.com/us/corporate/press/017473_EN?rssid=rss_ocom_pr" target="_blank">announced</a> the formation of the <strong>Oracle Identity Assurance Partner Alliance</strong>, an initiative focused on extending our identity and access management offerings with comprehensive and proactive identity fraud prevention solutions from strategic partners (you can read the <a href="http://www.oracle.com/us/corporate/press/017473_EN?rssid=rss_ocom_pr" target="_blank">press release</a> for details).</p>
<p>So what exactly is Identity Assurance? Simplistically, <strong>Identity Assurance</strong> is the ability to determine, with some level of certainty, that the person (identity) presenting themselves in an identity transaction is who they are claiming to be. The level of certainty one can have about the presented identity is what is referred to as the &#8220;Assurance Level&#8221;. <strong>Identity Proofing</strong> is another term that is used in this context (and that <a href="http://blogs.oracle.com/talkingidentity/2007/08/interesting_eweek_article_on_i.html" target="_blank">I have used in the past</a>), though it is more commonly associated with the verification of ones real world identity during the registration process.</p>
<p>So what are these two initiatives, and how are they related?</p>
<h3>Identity Assurance Framework &#8211; Think TRUSTe for IdPs</h3>
<p>The <strong>IAF</strong> is coming at the Identity Assurance discussion purely from the authentication angle, especially within federation contexts. It is based, in part, on the <a href="http://eap.projectliberty.org/docs/Trust_Framework_010605_final.pdf">Electronic Authentication Partnership Trust Framework</a> and the <a href="http://www.cio.gov/eauthentication/documents/CAF.pdf">US E-Authentication Federation Credential Assessment Framework</a>, initiatives designed for the sole purpose of enabling interoperability among electronic authentication systems. As such, it attempts to define a trust framework around the quality of claims issued by an IdP based on language, business rules, assessment criteria and certifications.</p>
<p>The IAF has published a standard set of <em>assurance levels</em> regarding the authentication of the user (Level 1 means low assurance, Level 2 means medium assurance, and so on. As of today, there are only 4 levels of assurance, Level 4 being the highest level). When a digital token is issued, it states the level of assurance at which the user was authenticated &#8211; Level 1 through Level 4.</p>
<p>The IAF defines a <em>certification process</em> through which an independent auditor assesses whether the issuers interpretation of Level 1-4 meets a <em>standard assessment criteria</em> established by IAF. So one issuer may have used a RSA SecureID token in combination with Username-Password to issue a Level 2 token, while a second issuer may have used a biometric challenge in addition to a UserID-PIN to issue a Level 2 token. The RP receiving the token from both issuers simply knows that both tokens are Level 2, and doesn&#8217;t know/need to know what the actual mechanics were, simply that an audit process certified that the mechanism for generating the token meets the criteria laid out by Liberty IAF.</p>
<p>The IAF is NOT defining any technology or standard protocols. In this sense, the IAF is trying to set up something analogous to the way TRUSTe verifies and asserts through their web seal that an eCommerce site is trustworthy.</p>
<h3>Oracle Identity Assurance Partner Alliance &#8211; Tools of the Assurance Trade</h3>
<p>Oracle <strong>IAPA</strong> aims at extending Oracle’s Identity Management Suite with partner technologies that offer capabilities such as identity proofing, internet geolocation, multi-factor authentication, out-of-band authentication, endpoint security and secure remote access. As such, its charter is pretty broad in combating identity fraud and providing context-aware security, and this encompasses identity assurance.</p>
<p>The solutions in the IAPA can provide the underlying mechanism by which an IdP can support the main tenet in the IAF, wherein an assertion can be trusted (at varying levels of assurance) to really belong to the entity represented. The IAPA steps in as a way for Oracle IAM to leverage technologies that enhance an authentication process with additional &#8220;challenges&#8221; that up-level the authentication assurance to the appropriate level &#8211; whether it be by using a biometric challenge, a voice challenge, a knowledge challenge based on external data aggregators, etc. So Oracle IAM + IAPA is positioned nicely to be the execution/implementation arm of an IdPs IAF compliance efforts.</p>
<h3>Looking To Tie Them Together</h3>
<p>One thing I will be exploring is the possibility of having the IAPA stack go through the Liberty IAF audit process. Then any customer deploying Oracle Access Management in conjunction with one of our partners would immediately know the IAF assurance levels of the authentication tokens being issued. Conversely, a customer that is targeting being able to issue credentials of certain assurance levels will be able to identify the solutions that will meet their need.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/digital-id-world" rel="tag">Digital ID World</a>, <a href="http://blog.talkingidentity.com/tag/identity-assurance" rel="tag">Identity Assurance</a>, <a href="http://blog.talkingidentity.com/tag/identity-assurance-framework" rel="tag">Identity Assurance Framework</a>, <a href="http://blog.talkingidentity.com/tag/identity-assurance-partner-alliance" rel="tag">Identity Assurance Partner Alliance</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%26amp%3Btitle%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance%26amp%3Bbodytext%3D%2520One%2520of%2520the%2520big%2520buzzwords%2520this%2520past%2520month%2520or%2520so%2520has%2520been%2520%2522Identity%2520Assurance%2522.%2520Liberty%2520Alliance%2520made%2520a%2520big%2520push%2520for%2520the%2520Identity%2520Assurance%2520Framework%2520%2528IAF%2529at%2520DIDW%2520last%2520month%252C%2520conducting%2520a%2520number%2520of%2520sessions%252Fworkshops%2520introducing%2520it%2520to%2520the%2520masses.%2520Our%2520';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%26amp%3Bt%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%26amp%3Btitle%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%26amp%3Btitle%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance%26amp%3Bannotation%3D%2520One%2520of%2520the%2520big%2520buzzwords%2520this%2520past%2520month%2520or%2520so%2520has%2520been%2520%2522Identity%2520Assurance%2522.%2520Liberty%2520Alliance%2520made%2520a%2520big%2520push%2520for%2520the%2520Identity%2520Assurance%2520Framework%2520%2528IAF%2529at%2520DIDW%2520last%2520month%252C%2520conducting%2520a%2520number%2520of%2520sessions%252Fworkshops%2520introducing%2520it%2520to%2520the%2520masses.%2520Our%2520';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%26amp%3Btitle%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance%26amp%3Bnotes%3D%2520One%2520of%2520the%2520big%2520buzzwords%2520this%2520past%2520month%2520or%2520so%2520has%2520been%2520%2522Identity%2520Assurance%2522.%2520Liberty%2520Alliance%2520made%2520a%2520big%2520push%2520for%2520the%2520Identity%2520Assurance%2520Framework%2520%2528IAF%2529at%2520DIDW%2520last%2520month%252C%2520conducting%2520a%2520number%2520of%2520sessions%252Fworkshops%2520introducing%2520it%2520to%2520the%2520masses.%2520Our%2520';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%26amp%3Btitle%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%26amp%3Bh%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html%2520Dissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DDissecting%2520all%2520the%2520buzz%2520about%2520Identity%2520Assurance%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fdissecting_all_the_buzz_about.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/10/dissecting_all_the_buzz_about.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
