SlideShare a Scribd company logo
OpenID a katalyst for EU e-id [email_address]
As an ID expert we like to present this problem
For 25 years nobody really cares! Double digit growth eCommerce PKI Smartcards as a beer coaster Infocard not shipped Self asserted username-passwords is fine Employees bypass security systems to do their real work
eID the right tool at the right time?
Different use-cases, or just a different market approach towards a consumer accepted e-ID?
Additional trends that confirm a need for a different approach Password fatigue Mobile first Socialisation of the web Cloud – Services Integration
Registration fatigue ‘ GBA’
Consumers create single sign-on
A new identity console
Your digital identity on the social web 500M+ 175M+
Sharing your data under consent between services (oauth)
OpenID, one single digital identity for consumers? OpenID is a successful multichannel protocol to enable consumers and merchants to share identities Consumers do not understand OpenID as their single identity  Identity providers want to promote their brand and competitive advantage Re-use exiting accounts, like Google, Facebook, Hyves, LinkedIn More on OpenID situation 2011 “OpenID Swot ”
The Evolution of Open Identity  OpenID User must understand and remember URL Each OpenID Provider has different URL syntax This worked  “OK” on tech-focused blogs, wikis, discussion groups, etc. but not well with broader audiences and applications Yahoo buttons, Google Friend Connect, Facebook Connect, ID Selector Content Provider Advisory Committee meeting in NYC First UX Summit at Yahoo Major OPs improving workflow User only needs to click on icon for preferred identity account Second UX Summit at Facebook Graphical interface of major Identity Providers, including proprietary solutions from  Facebook, MySpace, & Microsoft 2007 2008-2009 2010
2011 Challenges/Priorities OpenID foundation Challenge: Improve the OpenID  “product” Finalize and implement OpenID ABC Outreach to other identity protocols  (UX, Attributes, Consent) Challenge: Globalize OpenID Adoption Worldwide OpenID summits will improve specifications and adoption OIDF leaders organize, sponsor and speak at global identity events, OpenID summits Challenge: Build momentum and expand outreach Collaborate with related standards bodies and organizations Extend content curator program Challenge: Keep OpenID free and IPR protected Extend trademark protections globally
Working Group Current specification OpenID 2.0 used successfully in different use cases (also enterprise) New Spec in progress “OpenID ABC” Almost certainly not final branding! Spec work occurring in “Artifact Binding” working group Incorporates submissions to former “OpenID Connect” working group Points of departure Mobile phones and other limited platforms “ Facebook Connect” style functionality for easy registration Easier deployment than OpenID 2.0
The OpenID ABC product  Artifact Binding UserInfo Endpoint Simple RPs Higher LoA Session Management Unregistered Clients OAuth 2 Integration Use of JWTs Single Logout
Protocol workgroup participants Key working group participants: Nat Sakimura – Nippon Research Institute – Japan John Bradley – Independent – Chile Breno de Medeiros – Google – US Paul Tarjan – Facebook – US Axel Nennker – Deutsche Telekom – Germany Kick Willemse – Independent – Netherlands Tony Nadalin – Microsoft – US Mike Jones – Microsoft – US By no means an exhaustive list! OpenID specs developed via an open process All free to participate
Discussion & Resources Artifact Binding Working Group Wiki Page http://wiki.openid.net/w/page/12995134/Artifact-Binding Artifact Binding Mailing List http://lists.openid.net/mailman/listinfo/openid-specs-ab
Specification Structure OpenID AB spec contains in two parts Core – abstract specification Binding – OAuth 2 based binding JSON Web Token (JWT) spec with signing Next version will add encryption Other specs like UMA are looking to adopt it Discovery a separate spec Will refer to OAuth 2.0 specs once finished
Spec Progress Current status Core – 70% done Bindings – 75% done  (pending OAuth 2.0 completion) Discovery – 80% (working from SWD) JWT – 90% done for tokens and signature Encryption remains to be specified OAuth 2.0 – 95% Target:  Complete drafts by Internet Identity Workshop (IIW) in May, Final IIW in November 2011
Visit our summits for updates and discussions http://Wiki.openid.net January 18 Completed  OpenID Policy Summit hosted and sponsored by OIX in Washington DC  March 8 Completed  OpenID Retail Summit hosted by PayPal in San Jose  May 2 12-5 PM  OpenID Security Summit co-hosted by Symantec/Google in Mountain View  May 10 8-12 AM   OpenID Technology Summit at EIC co-sponsored by Google and Microsoft in Munich  TBD TBD OpenID Asia/Pacific Technology Summit hosted by NRI in Tokyo  July 19 8-12 AM   OpenID Enterprise Summit hosted by Ping Identity in Keystone, Colorado Oct 10 TBD  OpenID Technology Summit at RSA Conference co-hosted by Microsoft and Google in London November 12-5 PM OpenID Social Media Summit November hosted by FaceBook in Palo Alto
So what about trust levels?  OpenID is not a trustscheme Do you really need a trust level or may self assertion, pre-registration or IDP whitelisting work for you?  Local trust schemes, country specific US-Gov Profile  OpenID ICAM profile Stork E-ID  and  ISO/IEC 29115 International movement towards trustschemes that make it possible to re-use existing identities, both private and public
The trust framework paradox? Identity = A collection of multiple attributes or claims about a person or system Name E-mail Date of Birth Profession Address  Why do we want to define Levels of Assurance (LOA) on  a single Identity Level and not attribute level?
Mapping attribute schemes is an important condition for LOA’s A datamodel for personal data SEMIC  (EU) Attribute Exchange, Sreg in OpenID Open Social – Portable Contacts Social network specific Country specific
Trust scheme on attribute level A first scheme for e-mail by Google within OIX OpenID Summit certification list/ Google RP   Possible methods of verification Self asserted Proof of Possesion Authentic Register Certificate of origin
Interested in helping shape the future of internet identity? OIDF Company/Organizational Membership Share experience and concenrs with important identity players like Google, Paypal, Microsoft, FaceBook, Ping, Deutsche Telekom  Inclusion in OpenID Foundation press releases and industry events Corporate logo displayed on the OpenID Foundation website and materials OpenID Summits fees waived for all employees Propose and lead OpenID technical and marketing work groups Vote on ratification of OpenID specifications and recommendations OIDF Individual Membership Vote on OpenID workgroups, specifications, and community board members Use the OpenID Foundation Member logo and signature on your blog, email, website, apps Influence the technical development of OpenID technology and adoption Free pass to all OpenID Summits and discounts to conferences on internet identity Students and Professional Courtesy options available on request.

More Related Content

PPTX
Higgins active clients and personal data stores v2
PDF
Verifiable Credentials in Self-Sovereign Identity (SSI)
PDF
Identity is Changing: The Rise of Self-Sovereign Identity Infrastructure usin...
PDF
Why The Web Needs Decentralized Identifiers (DIDs) — Even if Google, Apple, a...
PDF
Getting Started With Self-Sovereign Identity (SSI) | Evernym Webinar
PPTX
Verifiable Credentials & Legal Entity Identifiers (LEIs) | Evernym & GLEIF
PDF
Decentralized Identifiers (DIDs): The Fundamental Building Block of Self-Sove...
PDF
The Shift from Federated to Decentralized Identity
Higgins active clients and personal data stores v2
Verifiable Credentials in Self-Sovereign Identity (SSI)
Identity is Changing: The Rise of Self-Sovereign Identity Infrastructure usin...
Why The Web Needs Decentralized Identifiers (DIDs) — Even if Google, Apple, a...
Getting Started With Self-Sovereign Identity (SSI) | Evernym Webinar
Verifiable Credentials & Legal Entity Identifiers (LEIs) | Evernym & GLEIF
Decentralized Identifiers (DIDs): The Fundamental Building Block of Self-Sove...
The Shift from Federated to Decentralized Identity

What's hot (9)

PDF
Meet Evernym's SSI Platform
PPTX
An Expert Panel on Safe Credentials
PDF
Learning 2.0 and OpenID
PPTX
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
PDF
Explaining SSI to C-suite executives, and anyone else for that matter
PDF
The State of Digital Identity Wallets – Darrell O’Donnell
PDF
Global Logic Ukraine Introduction Ver28 Jan2011
PDF
Global Logic Ukraine Introduction Ver28 Jan2011
PDF
Blockchain for Education: Lifelong Learning Passport. Wolfgang Gräther & others
Meet Evernym's SSI Platform
An Expert Panel on Safe Credentials
Learning 2.0 and OpenID
Gluu founder and ceo, mike schwartz, to host open id connect 1.0 session at r...
Explaining SSI to C-suite executives, and anyone else for that matter
The State of Digital Identity Wallets – Darrell O’Donnell
Global Logic Ukraine Introduction Ver28 Jan2011
Global Logic Ukraine Introduction Ver28 Jan2011
Blockchain for Education: Lifelong Learning Passport. Wolfgang Gräther & others
Ad

Similar to OpenID Progress EEMA Conference (20)

PPTX
SWXG 2010.6.9 v2
PPT
A .net developer experiences with web2.0 and social media
PPT
Identity_and_Access_Management_Overview.ppt
PDF
Review on OpenID Authentication Framework
PPT
Clearvale Overview En 2010 01 07
PPT
Clearvale Hlo En 2010 01 18
PPTX
Enterprise2.0 achiving the vision
PDF
Introduction To Open Web Protocols
ODP
Shibboleth Guided Tour Webinar
PPT
VSLive! Dallas Keynote
PPTX
Fyronic seminar-engage-slideshare
PPTX
OpenID SWOT analysis 2011
PDF
Introduction to FIDO Alliance
PPT
Identity Federation on JBossAS
PPTX
Fyronic seminar-software factorymeeting-sls
PPTX
Modernizing the Student Journey with Ethos Identity
ODP
Web 2.0 Core Concepts, Applications, and Implications
PPT
Enterprise 20 Summary
PPT
Openid - an identity system for the open Web
PPT
Clearvale Overview October 2010
SWXG 2010.6.9 v2
A .net developer experiences with web2.0 and social media
Identity_and_Access_Management_Overview.ppt
Review on OpenID Authentication Framework
Clearvale Overview En 2010 01 07
Clearvale Hlo En 2010 01 18
Enterprise2.0 achiving the vision
Introduction To Open Web Protocols
Shibboleth Guided Tour Webinar
VSLive! Dallas Keynote
Fyronic seminar-engage-slideshare
OpenID SWOT analysis 2011
Introduction to FIDO Alliance
Identity Federation on JBossAS
Fyronic seminar-software factorymeeting-sls
Modernizing the Student Journey with Ethos Identity
Web 2.0 Core Concepts, Applications, and Implications
Enterprise 20 Summary
Openid - an identity system for the open Web
Clearvale Overview October 2010
Ad

More from evidos (9)

PPTX
Hoe weet ik wie digitaal getekend heeft?
PPT
Why Relying Party´s should implement OpenID
PDF
Ontwikkelen open id na 2009 openid_meetup_15sept_2010
PPTX
Ontwikkelen open id na 2009 openid_meetup_15sept_2010
PPTX
OpenID binnen de Rijksoverheid
PPTX
Hyves Open Id
PPTX
Mobile Authentication on the Internet
PPTX
Open Id Security ITsec
PPTX
ConsumentenID
Hoe weet ik wie digitaal getekend heeft?
Why Relying Party´s should implement OpenID
Ontwikkelen open id na 2009 openid_meetup_15sept_2010
Ontwikkelen open id na 2009 openid_meetup_15sept_2010
OpenID binnen de Rijksoverheid
Hyves Open Id
Mobile Authentication on the Internet
Open Id Security ITsec
ConsumentenID

Recently uploaded (20)

PDF
KodekX | Application Modernization Development
PDF
Empathic Computing: Creating Shared Understanding
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Electronic commerce courselecture one. Pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Machine learning based COVID-19 study performance prediction
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Modernizing your data center with Dell and AMD
KodekX | Application Modernization Development
Empathic Computing: Creating Shared Understanding
“AI and Expert System Decision Support & Business Intelligence Systems”
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Chapter 3 Spatial Domain Image Processing.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
Digital-Transformation-Roadmap-for-Companies.pptx
Electronic commerce courselecture one. Pdf
Network Security Unit 5.pdf for BCA BBA.
Machine learning based COVID-19 study performance prediction
NewMind AI Monthly Chronicles - July 2025
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Unlocking AI with Model Context Protocol (MCP)
20250228 LYD VKU AI Blended-Learning.pptx
Encapsulation_ Review paper, used for researhc scholars
Modernizing your data center with Dell and AMD

OpenID Progress EEMA Conference

  • 1. OpenID a katalyst for EU e-id [email_address]
  • 2. As an ID expert we like to present this problem
  • 3. For 25 years nobody really cares! Double digit growth eCommerce PKI Smartcards as a beer coaster Infocard not shipped Self asserted username-passwords is fine Employees bypass security systems to do their real work
  • 4. eID the right tool at the right time?
  • 5. Different use-cases, or just a different market approach towards a consumer accepted e-ID?
  • 6. Additional trends that confirm a need for a different approach Password fatigue Mobile first Socialisation of the web Cloud – Services Integration
  • 9. A new identity console
  • 10. Your digital identity on the social web 500M+ 175M+
  • 11. Sharing your data under consent between services (oauth)
  • 12. OpenID, one single digital identity for consumers? OpenID is a successful multichannel protocol to enable consumers and merchants to share identities Consumers do not understand OpenID as their single identity Identity providers want to promote their brand and competitive advantage Re-use exiting accounts, like Google, Facebook, Hyves, LinkedIn More on OpenID situation 2011 “OpenID Swot ”
  • 13. The Evolution of Open Identity OpenID User must understand and remember URL Each OpenID Provider has different URL syntax This worked “OK” on tech-focused blogs, wikis, discussion groups, etc. but not well with broader audiences and applications Yahoo buttons, Google Friend Connect, Facebook Connect, ID Selector Content Provider Advisory Committee meeting in NYC First UX Summit at Yahoo Major OPs improving workflow User only needs to click on icon for preferred identity account Second UX Summit at Facebook Graphical interface of major Identity Providers, including proprietary solutions from Facebook, MySpace, & Microsoft 2007 2008-2009 2010
  • 14. 2011 Challenges/Priorities OpenID foundation Challenge: Improve the OpenID “product” Finalize and implement OpenID ABC Outreach to other identity protocols (UX, Attributes, Consent) Challenge: Globalize OpenID Adoption Worldwide OpenID summits will improve specifications and adoption OIDF leaders organize, sponsor and speak at global identity events, OpenID summits Challenge: Build momentum and expand outreach Collaborate with related standards bodies and organizations Extend content curator program Challenge: Keep OpenID free and IPR protected Extend trademark protections globally
  • 15. Working Group Current specification OpenID 2.0 used successfully in different use cases (also enterprise) New Spec in progress “OpenID ABC” Almost certainly not final branding! Spec work occurring in “Artifact Binding” working group Incorporates submissions to former “OpenID Connect” working group Points of departure Mobile phones and other limited platforms “ Facebook Connect” style functionality for easy registration Easier deployment than OpenID 2.0
  • 16. The OpenID ABC product Artifact Binding UserInfo Endpoint Simple RPs Higher LoA Session Management Unregistered Clients OAuth 2 Integration Use of JWTs Single Logout
  • 17. Protocol workgroup participants Key working group participants: Nat Sakimura – Nippon Research Institute – Japan John Bradley – Independent – Chile Breno de Medeiros – Google – US Paul Tarjan – Facebook – US Axel Nennker – Deutsche Telekom – Germany Kick Willemse – Independent – Netherlands Tony Nadalin – Microsoft – US Mike Jones – Microsoft – US By no means an exhaustive list! OpenID specs developed via an open process All free to participate
  • 18. Discussion & Resources Artifact Binding Working Group Wiki Page http://wiki.openid.net/w/page/12995134/Artifact-Binding Artifact Binding Mailing List http://lists.openid.net/mailman/listinfo/openid-specs-ab
  • 19. Specification Structure OpenID AB spec contains in two parts Core – abstract specification Binding – OAuth 2 based binding JSON Web Token (JWT) spec with signing Next version will add encryption Other specs like UMA are looking to adopt it Discovery a separate spec Will refer to OAuth 2.0 specs once finished
  • 20. Spec Progress Current status Core – 70% done Bindings – 75% done (pending OAuth 2.0 completion) Discovery – 80% (working from SWD) JWT – 90% done for tokens and signature Encryption remains to be specified OAuth 2.0 – 95% Target: Complete drafts by Internet Identity Workshop (IIW) in May, Final IIW in November 2011
  • 21. Visit our summits for updates and discussions http://Wiki.openid.net January 18 Completed OpenID Policy Summit hosted and sponsored by OIX in Washington DC March 8 Completed OpenID Retail Summit hosted by PayPal in San Jose May 2 12-5 PM OpenID Security Summit co-hosted by Symantec/Google in Mountain View May 10 8-12 AM  OpenID Technology Summit at EIC co-sponsored by Google and Microsoft in Munich TBD TBD OpenID Asia/Pacific Technology Summit hosted by NRI in Tokyo July 19 8-12 AM  OpenID Enterprise Summit hosted by Ping Identity in Keystone, Colorado Oct 10 TBD OpenID Technology Summit at RSA Conference co-hosted by Microsoft and Google in London November 12-5 PM OpenID Social Media Summit November hosted by FaceBook in Palo Alto
  • 22. So what about trust levels? OpenID is not a trustscheme Do you really need a trust level or may self assertion, pre-registration or IDP whitelisting work for you? Local trust schemes, country specific US-Gov Profile OpenID ICAM profile Stork E-ID and ISO/IEC 29115 International movement towards trustschemes that make it possible to re-use existing identities, both private and public
  • 23. The trust framework paradox? Identity = A collection of multiple attributes or claims about a person or system Name E-mail Date of Birth Profession Address Why do we want to define Levels of Assurance (LOA) on a single Identity Level and not attribute level?
  • 24. Mapping attribute schemes is an important condition for LOA’s A datamodel for personal data SEMIC (EU) Attribute Exchange, Sreg in OpenID Open Social – Portable Contacts Social network specific Country specific
  • 25. Trust scheme on attribute level A first scheme for e-mail by Google within OIX OpenID Summit certification list/ Google RP Possible methods of verification Self asserted Proof of Possesion Authentic Register Certificate of origin
  • 26. Interested in helping shape the future of internet identity? OIDF Company/Organizational Membership Share experience and concenrs with important identity players like Google, Paypal, Microsoft, FaceBook, Ping, Deutsche Telekom Inclusion in OpenID Foundation press releases and industry events Corporate logo displayed on the OpenID Foundation website and materials OpenID Summits fees waived for all employees Propose and lead OpenID technical and marketing work groups Vote on ratification of OpenID specifications and recommendations OIDF Individual Membership Vote on OpenID workgroups, specifications, and community board members Use the OpenID Foundation Member logo and signature on your blog, email, website, apps Influence the technical development of OpenID technology and adoption Free pass to all OpenID Summits and discounts to conferences on internet identity Students and Professional Courtesy options available on request.

Editor's Notes

  • #27: Don's version (Nov 19)