70 likes | 79 Views
Explore the importance of identity transfer protocols as vehicles for data transfer while not determining the nature of individual identities. Discover how widely assertable digital identities hold more value and the inevitability of interconnectivity. This practical and legal discussion highlights the market's need for prompt action.
E N D
Just Identity • Identity transfer protocols are just vehicles for data transfer • Must not determine the nature of an individual identity • Digital identities are more valuable as they are more widely assertable • Inter-{change|operability|connection} is unavoidable • Practical • Legal • Market • The sooner we react the better
A Few Use Cases (From just those with SAML in common) • InfoCard • The obvious usability cases • IdP/AA resolver • OpenID • Attribute query bootstrapping • Aggregating user control • OAuth • Access to non-web resources • Initial enrollment • RADIUS • Authentication in non-web environments • Leveraged authorization • X.509 • Derived personal certificates • PKI-based attribute authorities
EMC2/Mobility/GN3… • Discussions ongoing on back-channels for network access in TF-Mobility • Interconnecting InfoCard and eduroam • The identity hubs in SIR, WAYF.DK,… • The Beyond WebSSO work-item in TF-EMC2 • Kerberos • Dynamic LDAP • SAML ECP • DAMe and its successor(s) • Specific tasks inside GN3 JRA3T2 • Originally, on “user centric identity” • Play with the technology and explore the policies
…Concordia… • A global initiative to driveinteroperability among identityprotocols • Originated inside Liberty • Looking far beyond • Driven by use cases • Several collected • Some demonstrated • Proposal of an Identity Metasystem http://www.projectconcordia.org/
…And REFEDS? • Collaboration models and requirements • Hubs, gateways, credential services,… • Identifier assessment • Cross-border cases • Trust • Does PMA style make sense here? • LoAs • Protocols and transitivity • Procedures and common semantics • External (big) providers • Reciprocity