SlideShare a Scribd company logo
Opening Up User-Centric Identity Nate Klingenstein [email_address] Internet2 Shibboleth Project Royal College of Physicians Eduserv Symposium 2009 21 st  May, 2009: London
Identity is Totally Forked Federated identity has diverged Enterprise-centric User-centric Nothing matters but users and applications Is divergence desirable, feasible, neither? “When you come to a fork in the road, take it” – Yogi Berra
Enterprise-Centric Federated Identity Enterprise asserts identity data on behalf of an individual for which it is authoritative Attributes Identity Trust relationships and integrated applications defined by the enterprise Federations SAML is the primary protocol
User-Centric Federated Identity Self-asserted or unverified User-mediated trust establishment Opens up worlds of apps OpenID Yahoo ID, MyspaceID, Google Friend Connect Twitter?, and maybe your provider here Facebook Connect Federated identity’s largest success by far
Universities and Identity Both services and identities The natural “home” for some user data Courses, majors, titles, affiliations, grades, HR Identity-proofing? Also a home to applications Many outside applications federated today Some are low-risk, consumer-oriented
Students, Identity, and School Services how many email accounts do they have that parents don't know about- do they use same password 4 all #socialmedia ? #teens “ They don't use email so it's more a matter of which ones they forgot about. They often forget their passwords so I would guess that they don't use the same password consistently. Of course, they also share certain passwords with their closest "trusted" friends so that gets messy really fast. And they change it when there's a breakup.” Do they really care about/use school library websites? “ Nope, they don't. All but Twitter [which they don’t use] are categorized as school tools and are only used when absolutely necessary and Google won't suffice.” http://www.zephoria.org/thoughts/archives/2009/05/16/answers_to_ques.html
Natural Pressures Economy Discovery Trust and Ease of Use Users, developers, administrators We’re lazy
Economic Pressures User data is extremely valuable To both IdP/OP and SP/RP User data is extremely expensive Password resets, vetting, aging, etc. Network externalities Security externalities Save now, maybe pay later: easy choice?
Discovery Pressures Users are Lazy Interface Work is Hard Pull-downs?  Text boxes?  Buttons?  Client code? Buttons are winning http://google-code-updates.blogspot.com/2009/05/google-openid-api-taking-next-steps.html Social bookmarking syndrome Browsers ready to enter the fray?  Whither Cardspace?
Trust Pressures Administrator-mediated trust mediation is slow and arduous Federations help; could help more in a different world Consent-based trust is faster, gives users control Will they use it responsibly?  Do they care?  Do we care?  Does it depend?
What to do? Reunification of federated identity? Protocols Discovery Trust Attributes Ne’er the two shall meet?
Protocols World’s most ridiculous fight But there’s bad blood and high stakes Most protocols can solve most problems Hacks, revisions, kludges Identity sources should support many protocols and apps should be agnostic Deployed base is large
Discovery If we don’t come up with something good, buttons win E-mail? Auto-complete with institutional name? Client software?  Cardspace, Mozilla? Remember the economic pressures A few providers would also win
Trust One size will never fit all Many different user preferences Many different application needs Many different legal requirements The answer must be flexible enough Federations, consent, reputation systems, roots, authorities…
Attributes Attributes cannot be divorced from the asserting/attesting entity Natural sources of authority exist Legal name, course enrollment, music preferences Aggregation happens out-of-band today Must be automated for tomorrow Levels of Assurance
Would a Lack of Unification be Bad? User confusion, particularly with discovery or client software Data duplication, distribution Additional deployment and software complexity -- maybe Nothing new here…
Will Unification Happen? Dunno Probably some, particularly aggregation Probably not all We should endeavor to ensure that the outcome is deliberate and sufficient Cooperation Economic pressures

More Related Content

PPT
Carroll
PDF
URMA Conference 2009
PPT
ADEA Dallas 2008
PDF
Demystifying WCAG 2.0: An Intro to Web, Office, InDesign, & PDF Accessibility
PPT
Chapter 11
PPT
Hello, My Name Is Host Name Endgrain Rad Kaminsky
PPTX
When the DOJ/OCR Makes a Visit: Lessons Learned in Resolving Complaints About...
PPT
Social Media Policy
Carroll
URMA Conference 2009
ADEA Dallas 2008
Demystifying WCAG 2.0: An Intro to Web, Office, InDesign, & PDF Accessibility
Chapter 11
Hello, My Name Is Host Name Endgrain Rad Kaminsky
When the DOJ/OCR Makes a Visit: Lessons Learned in Resolving Complaints About...
Social Media Policy

What's hot (10)

PPT
Yammerat db andrew camacho
PPT
Accessibility Workshop
PPT
The Business of Blogging
PPT
Web 2.0: Making Email a Useful Web App
PPT
Unit 5
PPT
Researcher@Leeds Lp
PPTX
Web 1.0, 2.0 & 3.0
PPT
Knowledge Sharing over social networking systems
PDF
Web evolution,Walfram Aplha
PPT
“Library 2.0: Balancing the Risks and Benefits to Maximise the Dividends”
Yammerat db andrew camacho
Accessibility Workshop
The Business of Blogging
Web 2.0: Making Email a Useful Web App
Unit 5
Researcher@Leeds Lp
Web 1.0, 2.0 & 3.0
Knowledge Sharing over social networking systems
Web evolution,Walfram Aplha
“Library 2.0: Balancing the Risks and Benefits to Maximise the Dividends”
Ad

Viewers also liked (9)

ODP
User-Centric Identity
PPTX
Identity and Consumer Economics Common Assessment
PDF
Consumer Identity: a Dutch Perspective on Benefits, Issues and Next Steps (EI...
PPT
User consent for consumer identity (@ISSE2010)
PDF
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
PDF
White Paper: The Evolution of Consumer Identity: 10 Predictions for 2015
PPT
User & Mobile Centric Identity
PDF
User Centric Digital Identity, Talk for Computer Science and Telecommunicatio...
PDF
50 data principles for loosely coupled identity management v1 0
User-Centric Identity
Identity and Consumer Economics Common Assessment
Consumer Identity: a Dutch Perspective on Benefits, Issues and Next Steps (EI...
User consent for consumer identity (@ISSE2010)
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
White Paper: The Evolution of Consumer Identity: 10 Predictions for 2015
User & Mobile Centric Identity
User Centric Digital Identity, Talk for Computer Science and Telecommunicatio...
50 data principles for loosely coupled identity management v1 0
Ad

Similar to Opening Up User-Centric Identity (20)

PPT
Tony Nadalin' presentation at eComm 2008
PPTX
Campus Consortium EdTalks Featuring Clemson University
PDF
Real World Identity Managment
PPT
Identity federation & user centric identity
PPTX
Identity and User Access Management.pptx
PPTX
FAM - a triumph of technology over usability - Andy Powell
PDF
Identity 101: Boot Camp for Identity North 2016
PPTX
Trust and identity
ODP
Web 2.0 Core Concepts, Applications, and Implications
PPT
Identity 2.0 and User-Centric Identity
PDF
Trusting External Identity Providers for Global Research Collaborations
PPT
Edugate Futures
PPTX
Identity Management for Web Application Developers
PDF
CIS14: Authentication: Who are You? You are What You Eat
PDF
CIS14: Authentication: Who are You? You are What You Eat
PPT
Federated Access Management 102
ODP
Shibboleth Guided Tour Webinar
PDF
My Identiverse: The Evolution of Digital Identity and Openness
PPSX
Improving the User Experience
PPT
Federated Futures (Nicole Harris)
Tony Nadalin' presentation at eComm 2008
Campus Consortium EdTalks Featuring Clemson University
Real World Identity Managment
Identity federation & user centric identity
Identity and User Access Management.pptx
FAM - a triumph of technology over usability - Andy Powell
Identity 101: Boot Camp for Identity North 2016
Trust and identity
Web 2.0 Core Concepts, Applications, and Implications
Identity 2.0 and User-Centric Identity
Trusting External Identity Providers for Global Research Collaborations
Edugate Futures
Identity Management for Web Application Developers
CIS14: Authentication: Who are You? You are What You Eat
CIS14: Authentication: Who are You? You are What You Eat
Federated Access Management 102
Shibboleth Guided Tour Webinar
My Identiverse: The Evolution of Digital Identity and Openness
Improving the User Experience
Federated Futures (Nicole Harris)

More from Eduserv Foundation (16)

PPT
User-centric Research
PPT
Experiences in federated access control for UK e-Science
PPT
News from the new coffeehouses
PPT
Virtual World Watch - summary of Second Life Snapshots
PPT
Sausages, coffee, chicken and the web: Establishing new trust metrics for sch...
PPT
Universities and social networking: making sense out of nonsense
PPT
Web 2.0: Managing the Risks
PPT
BBC 2.0 Years On
PPT
How Web 2.0 changed the Guardian
PPT
UKOLN Blogs and Social Networks workshop - all presentations
PDF
OpenIDand User-Centric Identity: It’s All About Me
PPT
OpenID and eLearning
PPT
Virtual worlds in context
PPT
Holyrood Park: a virtual campus for Edinburgh
PPT
Second Nature - Nature Publishing Group In Second Life
PPT
SEAL - Second Environment, Advanced Learning
User-centric Research
Experiences in federated access control for UK e-Science
News from the new coffeehouses
Virtual World Watch - summary of Second Life Snapshots
Sausages, coffee, chicken and the web: Establishing new trust metrics for sch...
Universities and social networking: making sense out of nonsense
Web 2.0: Managing the Risks
BBC 2.0 Years On
How Web 2.0 changed the Guardian
UKOLN Blogs and Social Networks workshop - all presentations
OpenIDand User-Centric Identity: It’s All About Me
OpenID and eLearning
Virtual worlds in context
Holyrood Park: a virtual campus for Edinburgh
Second Nature - Nature Publishing Group In Second Life
SEAL - Second Environment, Advanced Learning

Recently uploaded (20)

PPTX
Cell Types and Its function , kingdom of life
PPTX
PPH.pptx obstetrics and gynecology in nursing
PDF
Microbial disease of the cardiovascular and lymphatic systems
PPTX
Introduction to Child Health Nursing – Unit I | Child Health Nursing I | B.Sc...
PDF
2.FourierTransform-ShortQuestionswithAnswers.pdf
PDF
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
PDF
Complications of Minimal Access Surgery at WLH
PPTX
Week 4 Term 3 Study Techniques revisited.pptx
PDF
Supply Chain Operations Speaking Notes -ICLT Program
PDF
STATICS OF THE RIGID BODIES Hibbelers.pdf
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PDF
Business Ethics Teaching Materials for college
PPTX
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
PDF
Pre independence Education in Inndia.pdf
PDF
Mark Klimek Lecture Notes_240423 revision books _173037.pdf
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
PDF
Classroom Observation Tools for Teachers
PPTX
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
PPTX
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
PDF
Module 4: Burden of Disease Tutorial Slides S2 2025
Cell Types and Its function , kingdom of life
PPH.pptx obstetrics and gynecology in nursing
Microbial disease of the cardiovascular and lymphatic systems
Introduction to Child Health Nursing – Unit I | Child Health Nursing I | B.Sc...
2.FourierTransform-ShortQuestionswithAnswers.pdf
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
Complications of Minimal Access Surgery at WLH
Week 4 Term 3 Study Techniques revisited.pptx
Supply Chain Operations Speaking Notes -ICLT Program
STATICS OF THE RIGID BODIES Hibbelers.pdf
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
Business Ethics Teaching Materials for college
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
Pre independence Education in Inndia.pdf
Mark Klimek Lecture Notes_240423 revision books _173037.pdf
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
Classroom Observation Tools for Teachers
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
Module 4: Burden of Disease Tutorial Slides S2 2025

Opening Up User-Centric Identity

  • 1. Opening Up User-Centric Identity Nate Klingenstein [email_address] Internet2 Shibboleth Project Royal College of Physicians Eduserv Symposium 2009 21 st May, 2009: London
  • 2. Identity is Totally Forked Federated identity has diverged Enterprise-centric User-centric Nothing matters but users and applications Is divergence desirable, feasible, neither? “When you come to a fork in the road, take it” – Yogi Berra
  • 3. Enterprise-Centric Federated Identity Enterprise asserts identity data on behalf of an individual for which it is authoritative Attributes Identity Trust relationships and integrated applications defined by the enterprise Federations SAML is the primary protocol
  • 4. User-Centric Federated Identity Self-asserted or unverified User-mediated trust establishment Opens up worlds of apps OpenID Yahoo ID, MyspaceID, Google Friend Connect Twitter?, and maybe your provider here Facebook Connect Federated identity’s largest success by far
  • 5. Universities and Identity Both services and identities The natural “home” for some user data Courses, majors, titles, affiliations, grades, HR Identity-proofing? Also a home to applications Many outside applications federated today Some are low-risk, consumer-oriented
  • 6. Students, Identity, and School Services how many email accounts do they have that parents don't know about- do they use same password 4 all #socialmedia ? #teens “ They don't use email so it's more a matter of which ones they forgot about. They often forget their passwords so I would guess that they don't use the same password consistently. Of course, they also share certain passwords with their closest "trusted" friends so that gets messy really fast. And they change it when there's a breakup.” Do they really care about/use school library websites? “ Nope, they don't. All but Twitter [which they don’t use] are categorized as school tools and are only used when absolutely necessary and Google won't suffice.” http://www.zephoria.org/thoughts/archives/2009/05/16/answers_to_ques.html
  • 7. Natural Pressures Economy Discovery Trust and Ease of Use Users, developers, administrators We’re lazy
  • 8. Economic Pressures User data is extremely valuable To both IdP/OP and SP/RP User data is extremely expensive Password resets, vetting, aging, etc. Network externalities Security externalities Save now, maybe pay later: easy choice?
  • 9. Discovery Pressures Users are Lazy Interface Work is Hard Pull-downs? Text boxes? Buttons? Client code? Buttons are winning http://google-code-updates.blogspot.com/2009/05/google-openid-api-taking-next-steps.html Social bookmarking syndrome Browsers ready to enter the fray? Whither Cardspace?
  • 10. Trust Pressures Administrator-mediated trust mediation is slow and arduous Federations help; could help more in a different world Consent-based trust is faster, gives users control Will they use it responsibly? Do they care? Do we care? Does it depend?
  • 11. What to do? Reunification of federated identity? Protocols Discovery Trust Attributes Ne’er the two shall meet?
  • 12. Protocols World’s most ridiculous fight But there’s bad blood and high stakes Most protocols can solve most problems Hacks, revisions, kludges Identity sources should support many protocols and apps should be agnostic Deployed base is large
  • 13. Discovery If we don’t come up with something good, buttons win E-mail? Auto-complete with institutional name? Client software? Cardspace, Mozilla? Remember the economic pressures A few providers would also win
  • 14. Trust One size will never fit all Many different user preferences Many different application needs Many different legal requirements The answer must be flexible enough Federations, consent, reputation systems, roots, authorities…
  • 15. Attributes Attributes cannot be divorced from the asserting/attesting entity Natural sources of authority exist Legal name, course enrollment, music preferences Aggregation happens out-of-band today Must be automated for tomorrow Levels of Assurance
  • 16. Would a Lack of Unification be Bad? User confusion, particularly with discovery or client software Data duplication, distribution Additional deployment and software complexity -- maybe Nothing new here…
  • 17. Will Unification Happen? Dunno Probably some, particularly aggregation Probably not all We should endeavor to ensure that the outcome is deliberate and sufficient Cooperation Economic pressures