<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Kantara Initiative</title>
	<atom:link href="http://blog.talkingidentity.com/tag/kantara-initiative/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A Twittorial on Trust Frameworks</title>
		<link>http://blog.talkingidentity.com/2010/03/a-twittorial-on-trust-frameworks.html</link>
		<comments>http://blog.talkingidentity.com/2010/03/a-twittorial-on-trust-frameworks.html#comments</comments>
		<pubDate>Fri, 05 Mar 2010 17:57:41 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Brett McDowell]]></category>
		<category><![CDATA[ICAM]]></category>
		<category><![CDATA[Kantara Initiative]]></category>
		<category><![CDATA[Open Identity Exchange]]></category>
		<category><![CDATA[Paul Madsen]]></category>
		<category><![CDATA[Trust Frameworks]]></category>
		<category><![CDATA[User-Centric Identity]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=794</guid>
		<description><![CDATA[(Updated to reflect provisional status of OIX approval per this &#8211; thanks to Brett for telling me) I just got back home from the RSA Conference in San Francisco this week, where the topic of Trust was second only to all things Cloud. While sessions on Identity Management were few and far between, there was [...]]]></description>
			<content:encoded><![CDATA[<p><em><strong>(Updated to reflect provisional status of OIX approval per <a href="http://bit.ly/aAEZEs">this</a> &#8211; thanks to Brett for telling me)</strong></em></p>
<p>I just got back home from the RSA Conference in San Francisco this week, where the topic of <strong>Trust</strong> was second only to all things Cloud. While sessions on Identity Management were few and far between, there was lots of interesting news coming out of the conference (like <a href="http://bit.ly/cDxfRZ" target="_blank">the U-Prove announcement</a>). I <a href="http://twitter.com/NishantK/status/9930608994" target="_blank">tweeted about</a> the announcements that concern <em>Trust Frameworks</em>, a way for one site (Relying Party) to trust the identity, security, and privacy assertions/claims from a different site (Identity Provider) acting on behalf of a user.</p>
<p>The first announcement was on the <a href="http://bit.ly/deZYyF," target="_blank">launch of the <strong>Open Identity Exchange</strong></a><strong> (OIX)</strong>, a (yet another) non-profit organization (coming out of the <em>OpenID Foundation</em> and <em>Information Card Foundation</em>) that is dedicated to building trust in the exchange of        online identity credentials across public and private sectors. The second announcement was regarding the US Federal Government&#8217;s <strong><a href="http://www.idmanagement.gov/drilldown.cfm?action=icam" target="_new">Identity, Credential, and Access Management (ICAM)</a> Trust Framework Evaluation Team (TFET)</strong> provisionally approving both OIX and <strong>Kantara Initiative</strong> as a <em>Trust Framework Provider</em> to certify online identity management providers to U.S. federal standards for identity assurance (read more <a href="http://bit.ly/aAEZEs" target="_blank">here</a>).</p>
<p>Trying to digest all of this was a little difficult, so as I was stuck in traffic on my way home from the airport, I found myself riveted by a twitter exchange that was flying fast and furious between <a href="http://twitter.com/paulmadsen" target="_blank"><strong>Paul Madsen</strong></a> (everyone&#8217;s favorite source for biting identity musings) and <a href="http://twitter.com/brettmcdowell" target="_blank"><strong>Brett McDowell</strong></a> (till recently Executive Director of the <em>Kantara Initiative</em>, and now technology evangelist at <em>Paypal</em>, one of the first IdPs certified by OIX &#8211; so you can see he has unique insight). I have reproduced it here for everyone&#8217;s benefit (with their permission, of course).</p>
<blockquote>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
ICAM is one federation willing to deal with multiple trust frameworks. Will others?</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> ICAM isn&#8217;t actually dealing with multiple trust frameworks. It&#8217;s all just NIST SP800-63 w/ various means to prove you comply.</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> ICAM is &#8216;accepting&#8217;  OIX, KI-IAF, InCommon . To me those are all trust frameworks (ie certification programs)</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> ah, but what is a &#8220;trust framework&#8221;? The criteria for trust itself  (M04-04 &amp; 800-63) or the method for demonstrating compliance?</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> P.S., in the Kantara case, IAF has criteria as well, but it&#8217;s been &#8220;mapped&#8221; to prove comparability to US Federal requirements.</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
Components of a trust framework &#8211; policies, accreditation, certification, admin, metadata infrastructure, keg parties&#8230;.</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> if everybody agrees on 800 63 for the former, trust frameworks are distinguished by the latter</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> IAF/OITF (frameworks) differentiated by criteria, KI/OIX (.org&#8217;s who certify) differentiated by due diligence on applicant</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> thus KI (conditionally) approved for up to non-crypto LOA3 &#8230;</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> M04-04 &amp; SP800-63 is like the &#8220;spec&#8221;, IAF is like the SCR, and OIX is a registry of those asserting compliance to the spec</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> &#8220;non-crypto&#8221; is another misleading term/issue. It rules out &#8220;pure PKI&#8221; but not &#8220;signed&#8221; assertions (SAML) or claims (IMI)</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> but IAF is more than an extra level of policy detail on top of 800 63 criteria. And OIX is more than a registry</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> for KI to be approved for AL3 PKI &amp; AL4 in US Gov, it needs to cross-certify with the Federal Bridge</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> re: &#8220;but IAF is more than&#8221; and &#8220;OIX is more than&#8221; Paul, cut me some slack, this is Twitter, some nuances are going to be lost!</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> point was less about the &#8216;crypto&#8217; part, and more that diff frameworks may target different parts of &#8216;assurance space&#8217;</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> that&#8217;s why I avoid all subtleties &amp; nuances <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> I wouldn&#8217;t draw conclusions (or battle lines) regarding trust frameworks just yet. Remember the OIX RFI dialog w/KI is ongoing</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> as I complained to @<a rel="nofollow" href="http://twitter.com/ve7jtb">ve7jtb</a> , want to see matrix laying out components of a generic framework, specific instances mapped on</td>
</tr>
<tr>
<td><strong><a href="http://twitter.com/brettmcdowell">brettmcdowell</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/paulmadsen">paulmadsen</a> that sounded like a proposal not a complaint.  I accept your matrix proposal. Looking forward to reading it when you finish <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </td>
</tr>
</tbody>
</table>
</blockquote>
<p>And of course, Paul had to have the last word, and it was typically Madsen-istic.</p>
<blockquote>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td><strong><a href="http://twitter.com/paulmadsen">paulmadsen</a></strong><br />
@<a rel="nofollow" href="http://twitter.com/brettmcdowell">brettmcdowell</a> you know, my wife made that same interpretation 16 years ago. Must be more precise</td>
</tr>
</tbody>
</table>
</blockquote>
<p>Hopefully that exchange was illuminating, and gave you enough pointers to standards and topics that might help deepen your understanding of Trust Frameworks. It certainly has given me a lot to think about. While RSA may have been weak on identity related discussions, these announcements are likely to have a huge impact on the identity landscape going forward.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/brett-mcdowell" rel="tag">Brett McDowell</a>, <a href="http://blog.talkingidentity.com/tag/icam" rel="tag">ICAM</a>, <a href="http://blog.talkingidentity.com/tag/kantara-initiative" rel="tag">Kantara Initiative</a>, <a href="http://blog.talkingidentity.com/tag/open-identity-exchange" rel="tag">Open Identity Exchange</a>, <a href="http://blog.talkingidentity.com/tag/paul-madsen" rel="tag">Paul Madsen</a>, <a href="http://blog.talkingidentity.com/tag/trust-frameworks" rel="tag">Trust Frameworks</a>, <a href="http://blog.talkingidentity.com/tag/user-centric-identity" rel="tag">User-Centric Identity</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/03/a-twittorial-on-trust-frameworks.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Burton Catalyst 2009: The Twisted Web We Weave</title>
		<link>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-the-twisted-web-we-weave.html</link>
		<comments>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-the-twisted-web-we-weave.html#comments</comments>
		<pubDate>Wed, 05 Aug 2009 20:02:09 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Authorization]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Catalyst09]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[eBay]]></category>
		<category><![CDATA[Kantara Initiative]]></category>
		<category><![CDATA[Oracle_IDM]]></category>
		<category><![CDATA[Project Concordia]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=581</guid>
		<description><![CDATA[I&#8217;m finally settling back into work after a wonderful week out in sunny San Diego at Burton Group&#8216;s annual Catalyst Conference. And it wasn&#8217;t just the weather outside that was wonderful. Inside you could find some thought-provoking sessions, inspiring discussions and great people. It&#8217;s given me way too much to blog about, and I hope [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m finally settling back into work after a wonderful week out in sunny San Diego at <strong>Burton Group</strong>&#8216;s annual <strong>Catalyst Conference</strong>. And it wasn&#8217;t just the weather outside that was wonderful. Inside you could find some thought-provoking sessions, inspiring discussions and great people. It&#8217;s given me way too much to blog about, and I hope to be able to put some of it out here. But if you are interested, I have captured <a href="http://blog.talkingidentity.com/downloads/my-catalyst-2009-tweet-stream">my tweet stream from the conference</a> (since Twitter search only goes back a few days), though it can be rough reading. But as Dave Kearns <a href="http://vquill.com/2009/07/dearth-of-blogging.html" target="_blank">tried to remind us tweeters</a>, we shouldn&#8217;t forget the value of a well written blog post (or two).</p>
<h3>The SIG Meetings</h3>
<p>For me, the conference was divided into two parts. Monday and Tuesday I attended a few SIG meetings on topics that were varied yet highly interconnected. Monday was a meeting of the Concordia Workshop, which is now a <a href="http://kantarainitiative.org/confluence/display/concordia/Home" target="_blank">discussion group</a> under the new Kantara Initiative. The focus of the meeting was <em><strong>Use Cases driving Identity in Enterprise 2.0: The Consumerization of IT</strong></em>. The ever intrepid Eve Maler has <a href="http://projectconcordia.org/index.php/Catalyst_pre-conference_workshop_agenda#Agenda" target="_blank">posted materials from the day</a> to the Concordia site, so you can check them out yourself. While the individual discussions covered all manner of areas, the connecting thread throughout was <strong>Authorization</strong>. There was a morning discussion where a panel talked about the progress made in the authorization space, from the <a href="http://lists.oasis-open.org/archives/xacml/200907/msg00019.html" target="_blank">XACML API contributed to the TC</a> by Oracle and Cisco, to the emergence of AuthZ as the critical service in the identity services reference architecture being developed in the Burton Group ISWG (which I have been participating in and writing about). <a href="http://twitter.com/MikeG514" target="_blank">Mike Gotta</a> and Alice Wang gave an excellent talk on the emerging concerns regarding social tools in the enterprise, and a lot of those concerns again boil down to authorization issues, in this case regarding data and information. Eve talked about <a href="http://www.xmlgrrl.com/blog/categories/protectserve/" target="_blank">her work on the ProtectServe protocol</a> that enables authorized data sharing from a user perspective. And the day finished with a talk on Levels of Assurance, a critical piece in allowing for partners to make informed authorization decisions.</p>
<p>Tuesday started with a meeting on <em><strong>Cloud Computing Security and Identity Management</strong></em>. As readers of my blog/twitter know, I have been saying for a while that cloud computing is going to have a major impact on the identity management business, in much the same way that compliance concerns did a few years ago. It is probably a sign of the immaturity of the market that the discussion was focused on describing the challenges to be solved rather than any solutions.</p>
<p>The meeting included a deep dive presentation by Liam Lynch, Ebay&#8217;s Chief Security Strategist, on how the auction giant tackles their internal cloud computing needs. There were a few points made during his presentation that I found interesting:</p>
<ul>
<li>eBay is into cloud computing as a provider, not a consumer, since they allow 3rd party developers to create their own auction sites on eBay infrastructure using a development kit called eBox</li>
<li>As such, eBay feels that security considerations have to be made inherent in cloud architecture as they cannot rely on these 3rd party developers to not make mistakes</li>
<li>eBay uses contextual behavior and reputation, including biometric analysis, as the underpinnings of its identity management strategy. Reputation and behavior analysis generate (over time) dynamic identity claims that then get used in access control decisions</li>
<li>eBay found RBAC to be a bad match for their performance requirements, and shifted to a claims-based model for authorization. In this model, claims are attached to the data object being accessed itself (sort of a next-generation ACL). The access then compares the claims the actor has at runtime with these to make an authorization decision.</li>
<li>Liam made the point that managing access through roles was a bad model for them, which is why they went claims-based. I understand the performance concerns that arise when evaluating RBAC at runtime, but for managing the grants of access, nothing beats a role-based model. So I was a little surprised by his statement. When I dug deeper, it turned out that they simply replaced RBAC with Organization-based AC, and not because of performance reasons but because of compliance reasons since the org change has approval attached while the role change did not. So it wasn&#8217;t really an issue with RBAC, just the implementation they had in-house.</li>
<li>Liam pointed out that a move to the cloud can be an opportunity to fix broken internal processes, since the cloud will amplify any issues you may have</li>
</ul>
<p>The meeting also had Nils Puhlmann, co-founder of the <a href="http://www.cloudsecurityalliance.org/" target="_blank"><strong>Cloud Security Alliance</strong></a>, speaking to the participants on the need to come up with a practical security checklist that all Cloud Service Providers could be measured against, so that enterprise customers can make accurate assessments of the risk with using a particular CSP. He called for greater vendor involvement and focus on the cloud, since the cost dynamics of the cloud make adoption inevitable. And that CSPs need to be more transparent about their security controls and policies.</p>
<p>Later that afternoon I attended the next meeting of the <em><strong>Identity Services Working Group</strong></em> that I&#8217;ve been participating in. There were a lot of new folks in the audience, so it was a good opportunity to recruit new blood into the effort. As Kevin Kampman presented the work that had been done previously on the Authentication service and laid out the effort lying ahead on the Authorization service, we got into highly spirited, and productive, discussions on the nature of the services architecture. One of the points made repeatedly (and which was echoed later in the week during the sessions) was the terminology issue that plagues the identity community, in this case around words like Policy (vs. policy). There was a strong sentiment from the group that policy management needs to be made part of the overall framework for it to work properly. And there was also a strong push from the group to try and condense the best of the prior efforts at defining AuthZ services into our vision.</p>
<p>While on the surface all of these SIGs were on different topics, I found them to be highly intertwined. Identity concerns in cloud computing are tied in directly to the need for an identity services architecture that allows cloud services to leverage enterprise identity (and therefore security) apparatus, thus reducing risk for the enterprise and providing compliance with both internal and regulatory controls. And Enteprise 2.0 is mostly about the intrusion of  cloud-based services like social media into the enterprise environment (or the extrusion of the enterprise into commercialized IT services, depending on how you want to look at it), where concerns about consistency of identity and controls are foremost in the minds of CIOs and CISOs everywhere. So while the discussion is still somewhat fragmented (as it probably should be at this time), I look forward to all of this coming together nicely in the future (maybe even at a future Catalyst conference).</p>
<p>I think I need to do a better job breaking these posts into smaller, more readable chunks. My next post(s) will focus on the sessions themselves.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/authorization" rel="tag">Authorization</a>, <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/catalyst09" rel="tag">Catalyst09</a>, <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/ebay" rel="tag">eBay</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/kantara-initiative" rel="tag">Kantara Initiative</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a>, <a href="http://blog.talkingidentity.com/tag/project-concordia" rel="tag">Project Concordia</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-the-twisted-web-we-weave.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

