Identity Metasystem

Identity Metasystem

The Identity Metasystem is an interoperable architecture for digital identity that enables people to have and employ a collection of digital identities based on multiple underlying technologies, implementations, and providers. Using this approach, customers can continue to use their existing identity infrastructure investments, choose the identity technology that works best for them, and more easily migrate from old technologies to new technologies without sacrificing interoperability with others. The Identity Metasystem is based upon the principles in [http://msdn2.microsoft.com/en-us/library/ms996456.aspx The Laws of Identity] .

Identity Metasystem Architecture

Roles within the Identity Metasystem

Different parties participate in the metasystem in different ways. The three roles within the metasystem are:
* Identity Providers, which issue digital identities. For example, credit card providers might issue identities enabling payment, businesses might issue identities to their customers, governments might issue identities to citizens, and individuals might use self-issued identities in contexts like signing on to web sites.
* Relying Parties, which require identities. For example, a web site or online service that utilizes identities offered by other parties.
* Subjects, which are the individuals and other entities about whom claims are made. Examples of subjects include end users, companies, and organizations.In many cases, the participants in the metasystem play more than one role, and often all three.

Components of the Identity Metasystem

There are five key components to the Identity Metasystem:
* A way to represent identities using claims. Claims are carried in security tokens, as per WS-Security.
* A means for identity providers, relying parties, and subjects to negotiate. Dynamically negotiating the claims to be delivered and the security token format used enables the Identity Metasystem to carry any format of token and any kinds of claims needed for a digital identity interaction. Negotiation occurs using WS-SecurityPolicy statements exchanged using WS-MetadataExchange.
* An encapsulating protocol to obtain claims and requirements. The WS-Trust and WS-Federation protocols are used to carry requests for security tokens and responses containing those tokens.
* A means to bridge technology and organizational boundaries using claims transformation. Security Token Services (STSs) as defined in WS-Trust are used to transform claim contents and formats.
* A consistent user experience across multiple contexts, technologies, and operators. This is achieved via Identity Selector client software such as Windows CardSpace representing digital identities owned by users as visual Information Cards.

Interoperability and Licensing

The protocols needed to build Identity Metasystem components can be used by anyone for any purpose with no licensing cost and interoperable implementations can be built using only publicly-available documentation. Patent promises have been issued by [http://www.microsoft.com/interop/osp/ Microsoft] , [http://www-03.ibm.com/linux/opensource/ispinfo.shtml IBM] , and others ensuring that the protocols underlying the Identity Metasystem can be freely used by all.

Several interoperability testing events for Identity Metasystem components have been sponsored by [http://osis.netmesh.org/ OSIS] and the [http://www.burtongroup.com/ Burton Group] , the most recent of which was the [http://identityblog.burtongroup.com/bgidps/2007/10/osis-user-centr.html Interop at the October 2007 European Catalyst Conference in Barcelona] . These events are helping to ensure that the different software components being built by the numerous Identity Metasystem participants work well together.

In his report on the [http://identityblog.burtongroup.com/bgidps/2007/08/recapping-the-c.html Interop at the June 2007 Catalyst Conference in San Francisco] , analyst Bob Blakley wrote:

The interop event was a milestone in the maturation of user-centric identity technology. Prior to the event, there were some specifications, one commercial product, and a number of open-source projects. After the event, it can accurately be said that there is a running identity metasystem.

ee also

* Information Card
* Identity Selector
* WS-Security
* WS-Trust
* WS-MetadataExchange
* WS-SecurityPolicy
* WS-Federation
* Windows CardSpace
* Higgins trust framework

References

* [http://msdn2.microsoft.com/en-us/library/ms996422.aspx Microsoft's Vision for an Identity Metasystem] , Michael B. Jones, May 2005.
* [http://msdn2.microsoft.com/en-us/library/ms996456.aspx The Laws of Identity] , Kim Cameron, May 2005.
* [http://research.microsoft.com/~mbj/papers/Identity_Metasystem_Design_Rationale.pdf Design Rationale behind the Identity Metasystem Architecture] , Kim Cameron and Michael B. Jones, January 2006.
* [http://www.ipc.on.ca/images/Resources/up-7laws_whitepaper.pdf 7 Laws of Identity: The Case for Privacy-Embedded Laws of Identity in the Digital Age] , Ann Cavoukian, Information and Privacy Commissioner of Ontario, October 2006.

External links

* [http://identityblog.burtongroup.com/bgidps/2007/08/recapping-the-c.html Burton Group report on OSIS June 2007 User-Centric Identity Interop at Catalyst in San Francisco] , August 2007.
* [http://identityblog.burtongroup.com/bgidps/2007/10/osis-user-centr.html Burton Group report on OSIS October 2007 User-Centric Identity Interop at Catalyst in Barcelona] , October 2007.
* [http://www.bandit-project.org/index.php/DigitalMe DigitalMe Identity Selector]
* [http://www.microsoft.com/interop/osp/ Microsoft Open Specification Promise] , May 2007.
* [http://www-03.ibm.com/linux/opensource/ispinfo.shtml IBM Interoperability Specifications Pledge] , July 2007.


Wikimedia Foundation. 2010.

Игры ⚽ Нужно решить контрольную?

Look at other dictionaries:

  • Identity — may refer to:Philosophy* Identity (philosophy), the sameness of two things * Identity theory of mind, in the philosophy of mind, holds that the mind is identical to the brain * Personal identity (philosophy) * Identity (social science) * Identity …   Wikipedia

  • Identity 2.0 — Identity 2.0, also called digital identity, is the anticipated revolution of identity verification on the internet using emerging user centric technologies such as Information Cards or OpenID. Identity 2.0 stems from the Web 2.0 theory of the… …   Wikipedia

  • Identity Selector — An Identity Selector is a platform service for user centric identity management that: * Provides a consistent user experience for authentication (and in some cases other kinds of interactions) with a Relying Party (also known as a Service… …   Wikipedia

  • Federated identity — In information technology, federated identity has two general meanings: * The virtual reunion, or assembled identity , of a person s user information (or ), stored across multiple distinct identity management systems. Data is joined together by… …   Wikipedia

  • Information Card — Information Cards are personal digital identities that people can use online. Visually, each Information Card has a card shaped picture and a card name associated with it that enable people to organize their digital identities and to easily… …   Wikipedia

  • Windows CardSpace — (codenamed InfoCard), is Microsoft s client software for the Identity Metasystem. CardSpace is an instance of a class of identity client software called an Identity Selector. CardSpace stores references to users digital identities for them,… …   Wikipedia

  • Carte d'information — Carte d informations Cartes d informations telles qu affichées sous DigitalMe Les cartes d informations (ou Information Cards) sont des identités numériques que tous et chacun peuvent utiliser en ligne. Visuellement, chaque carte d information se …   Wikipédia en Français

  • Carte d'informations — Cartes d informations telles qu affichées sous DigitalMe Les cartes d informations (ou Information Cards) sont des identités numériques que tous et chacun peuvent utiliser en ligne. Visuellement, chaque carte d information se présente sous la… …   Wikipédia en Français

  • Cartes d'informations — Carte d informations Cartes d informations telles qu affichées sous DigitalMe Les cartes d informations (ou Information Cards) sont des identités numériques que tous et chacun peuvent utiliser en ligne. Visuellement, chaque carte d information se …   Wikipédia en Français

  • Information Card — Carte d informations Cartes d informations telles qu affichées sous DigitalMe Les cartes d informations (ou Information Cards) sont des identités numériques que tous et chacun peuvent utiliser en ligne. Visuellement, chaque carte d information se …   Wikipédia en Français

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”