<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Maarten Wegdam&#039;s Blog &#187; SAML</title>
	<atom:link href="http://maarten.wegdam.name/tag/saml/feed/" rel="self" type="application/rss+xml" />
	<link>http://maarten.wegdam.name</link>
	<description>A blog on identity, mobile, privacy, innovation, trust, middleware and more</description>
	<lastBuildDate>Wed, 25 Jan 2012 20:55:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='maarten.wegdam.name' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/919cf8ecf6f35b50e61434a17113f7ee?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Maarten Wegdam&#039;s Blog &#187; SAML</title>
		<link>http://maarten.wegdam.name</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://maarten.wegdam.name/osd.xml" title="Maarten Wegdam&#039;s Blog" />
	<atom:link rel='hub' href='http://maarten.wegdam.name/?pushpress=hub'/>
		<item>
		<title>No more Cardspace &#8230;</title>
		<link>http://maarten.wegdam.name/2011/02/16/no-more-cardspace/</link>
		<comments>http://maarten.wegdam.name/2011/02/16/no-more-cardspace/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 19:22:56 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[InfoCard]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[SAML]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=201</guid>
		<description><![CDATA[Microsoft announced yesterday that Cardspace 2.0 will not be shipping. Or to put this  more directly: that they&#8217;ve stopped with Cardspace. This is not a big surprise, uptake was very slow and Microsoft already showed signs of less-than-fully supporting Cardspace/InfoCards for a while now. Cardspace was IMHO a promising approach to some of the privacy, security and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=201&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Microsoft announced yesterday that Cardspace 2.0 will not be shipping. Or to put this  more directly: that they&#8217;ve stopped with Cardspace. This is not a big surprise, uptake was very slow and Microsoft already showed signs of less-than-fully supporting Cardspace/InfoCards for a while now.</p>
<p>Cardspace was IMHO a promising approach to some of the privacy, security and usability concerns for federated identity systems, but it lacked adoption. Part of the reason as Mike Jones puts it is <a href="http://self-issued.info/?p=458">it is not drop-dead simple to use</a>. Lack of user acceptance is  also <a href="http://maarten.wegdam.name/2010/03/11/user-centric-saml/">confirmed by the user study we did for SURFnet in 2009</a>, where users basically distrusted Cardspace. Other reasons I think are lack of an easy migration path from existing standards, and slower-than-hoped  update of identity federation in the consumer space in general.</p>
<p>Anyway, Microsoft stopping Cardspace will probably mean the end of the used InfoCard standard as well. This makes things clearer in the standards department, which a consolidation on basically OpenID (/OAuth) and SAML. And especially Facebook with a non-standard protocol to do similar things.  Not that standards are the most important, I agree with<a href="http://blogs.forrester.com/eve_maler/11-02-03-openid_successful_failures_and_new_federated_identity_options"> Eve Maler (now Forrester) when she states</a>:</p>
<blockquote><p>when it comes to lightweight consumer-scale federated identity, the specific protocol matters less for success than the user base, the nature of the data available about those users, and the tooling available for relying-party integration.</p></blockquote>
<p>Even though the protocol may not  be the biggest issue for a federated consumer identity solution, it is still not a trivial one. Especially the issue to have a web-based client (i.e. OpenID or SAML WebSSO) or an active client (Cardspace/InfoCard) is one that remains interesting because of the consequences for usability and security.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a>, <a href='http://maarten.wegdam.name/tag/infocard/'>InfoCard</a>, <a href='http://maarten.wegdam.name/tag/openid/'>OpenID</a>, <a href='http://maarten.wegdam.name/tag/saml/'>SAML</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/201/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=201&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/02/16/no-more-cardspace/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>
	</item>
		<item>
		<title>User consent pilot for SURFnet</title>
		<link>http://maarten.wegdam.name/2010/10/08/user-consent-pilot-for-surfnet/</link>
		<comments>http://maarten.wegdam.name/2010/10/08/user-consent-pilot-for-surfnet/#comments</comments>
		<pubDate>Fri, 08 Oct 2010 13:00:56 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SAML]]></category>
		<category><![CDATA[user centric identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=155</guid>
		<description><![CDATA[Together with my colleagues Ruud Janssen and Dirk-Jan van Dijk we have been working for SURFnet to help them if, and if so how, they should add a user consent feature to their SURFfederatie identity federation service. See also this previous post on user-centric SAML that describes what we did last year. We continued this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=155&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent.png"><a href="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent1.png"><img class="aligncenter size-full wp-image-157" title="timed-consent" src="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent1.png?w=450" alt=""   /></a></a></p>
<p>Together with my colleagues Ruud Janssen and Dirk-Jan van Dijk we have been working for SURFnet to help them if, and if so how, they should add a user consent feature to their <a href="http://www.surfnet.nl/nl/Thema/SURFfederatie/Pages/Default.aspx">SURFfederatie</a> identity federation service. See also this previous post on <a href="http://maarten.wegdam.name/2010/03/11/user-centric-saml/">user-centric SAML</a> that describes what we did last year. We continued this year, doing additional user studies, deciding on architectural issues, developing a prototype and doing a pilot. This pilot started two weeks ago J, see also a <a href="http://www.surfnet.nl/nl/nieuws/Pages/SURFfederatie-pilot%27Usercontrolledprivacy%27.aspx">SURFnet news item</a> (Dutch) on this. The pilot is with three of the bigger Dutch universities, and students/employees that go to the selected service providers will be asked to participate in the pilot. They go through the consent pages, and we bother them with two online surveys to get their feedback. It’s too early to predict the outcome, but the pilot itself seems be going well.</p>
<p>At ISSE 2010 I gave a presentation on the current status of this work, the presentation is on <a href="http://www.slideshare.net/wegdam/user-consent-for-consumer-identity-isse2010">slideshare</a>. In December we’ll finalize a report with the outcome of the pilot, after which it’s up to SURFnet to decide if they’ll add this feature to the SURFfederatie.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a>, <a href='http://maarten.wegdam.name/tag/openid/'>OpenID</a>, <a href='http://maarten.wegdam.name/tag/privacy/'>privacy</a>, <a href='http://maarten.wegdam.name/tag/saml/'>SAML</a>, <a href='http://maarten.wegdam.name/tag/user-centric-identity/'>user centric identity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/155/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=155&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2010/10/08/user-consent-pilot-for-surfnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent1.png" medium="image">
			<media:title type="html">timed-consent</media:title>
		</media:content>
	</item>
		<item>
		<title>User-centric SAML?</title>
		<link>http://maarten.wegdam.name/2010/03/11/user-centric-saml/</link>
		<comments>http://maarten.wegdam.name/2010/03/11/user-centric-saml/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 20:50:48 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[InfoCard]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SAML]]></category>
		<category><![CDATA[user centric identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=88</guid>
		<description><![CDATA[Let me first introduce user-centric identity (people who know this can skip to the second paragraph). Not so long ago OpenID en InfoCard where introduced as user centric identity standards, contrary to ‘old fashioned’ identity provider centric standard like SAML. Without going into details, user centricity boils down to providing user controlled privacy, i.e., providing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=88&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://maartenwegdam.files.wordpress.com/2010/03/consent-saml.png"><img class="aligncenter size-large wp-image-91" title="Example user consent in SAML WebSSO" src="http://maartenwegdam.files.wordpress.com/2010/03/consent-saml.png?w=614&#038;h=425" alt="" width="614" height="425" /></a></p>
<p>Let me first introduce user-centric identity (people who know this can skip to the second paragraph). Not so long ago OpenID en InfoCard where introduced as user centric identity standards, contrary to ‘old fashioned’ identity provider centric standard like SAML. Without going into details, user centricity boils down to providing user controlled privacy, i.e., providing informed consent. And I of course do not mean some legal disclaimer that you have to agree to as a user to be able to use some service. The idea to provide actual information on what information would be shared between an identity provider and a relying party, and asking the user for consent before sharing this. InfoCard inherently provides this, and does this with a piece of software on the client. OpenID provides this though a webpage.</p>
<p>We did a project for SURFnet, the Dutch NREN, to study if and if so how we could make their SURFfederatie (identity federation for higher education and research) provide user controlled privacy. The SURFfederation support different protocols, but is mainly SAML WebSSO based. We analyzed different options, focusing on providing user controlled privacy through InfoCards and doing this through SAML. The latter option is less used, but there are precedents, like <a href="http://www.switch.ch/aai/support/tools/uApprove.html">uApprove</a> (for Shibboleth) and the <a href="http://identitynetworks.wordpress.com/2009/03/09/ready-able-and-willing-federated-consent/">Consent module for SimpleSAMLphp</a>. Ignoring lots of details, SAML WebSSO works roughly the same as OpenID (by redirecting the browser from relying party to the identity provider, and back), and user controlled privacy can be implemented in a similar fashion for SAML WebSSO as for OpenID.</p>
<p>The choice between InfoCards and what I’ll call user-centric SAML is not a trivial one, both have advantages and disadvantages. And besides, it was not clear if the users (students and employees of universities etc) even want to be bothered with user controlled privacy. We figured that the best way forward researcher user centricity was to simple ask users what they want. We considered doing this through some large-scale survey, but decided that a small-scale but in-depth user study would provide more useful results. My colleague Ruud Janssen, an experienced user researcher, did this user study. Using mockups he asked users if they wanted control, and if so, if they prefer user-centric SAML or InfoCards. Although the number were too small to be statistically significant, there was a surprisingly clear consensus on what the users preferred: <em>user controlled privacy through user-centric SAML</em>. This thus also is what we recommended to SURFnet.</p>
<p>Although I expected that they would like the card-like user interface that InfoCard offers, the user we interviewed did not. We think this is mostly because they were unfamiliar with it, and therefore did not really trust it.</p>
<p>The research outcomes were written down in two reports: the <a href="http://www.surfnet.nl/Documents/indi-2009-09-014%20%28User%20controlled%20privacy%20voor%20de_SURFfederatie%20v1.1%29.pdf">first report</a> discusses the state-of-the-art, design guidelines for user-centric SAML and architectural analysis on using InfoCard vs user-centric SAML. The <a href="http://www.surfnet.nl/Documents/indi-2009-12-027%20%28User%20controlled%20privacy%20voor%20de%20SURFfederatie%20gebruikersstudie%29.pdf">second report</a> contains the outcomes of the user study. My apologies to non-Dutch speakers: both reports are in Dutch, as requested by our client.</p>
<p>We are continuing the research on user controlled privacy this year, focusing on the user interaction (prototyping, further user studies) and the architectural consequences of user-centric SAML for the SURFfederatie.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a>, <a href='http://maarten.wegdam.name/tag/infocard/'>InfoCard</a>, <a href='http://maarten.wegdam.name/tag/openid/'>OpenID</a>, <a href='http://maarten.wegdam.name/tag/privacy/'>privacy</a>, <a href='http://maarten.wegdam.name/tag/saml/'>SAML</a>, <a href='http://maarten.wegdam.name/tag/user-centric-identity/'>user centric identity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=88&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2010/03/11/user-centric-saml/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2010/03/consent-saml.png?w=1024" medium="image">
			<media:title type="html">Example user consent in SAML WebSSO</media:title>
		</media:content>
	</item>
	</channel>
</rss>
