<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Maarten Wegdam&#039;s Blog &#187; trust framework</title>
	<atom:link href="http://maarten.wegdam.name/tag/trust-framework/feed/" rel="self" type="application/rss+xml" />
	<link>http://maarten.wegdam.name</link>
	<description>A blog on identity, mobile, privacy, innovation, trust, middleware and more</description>
	<lastBuildDate>Wed, 25 Jan 2012 20:55:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='maarten.wegdam.name' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/919cf8ecf6f35b50e61434a17113f7ee?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Maarten Wegdam&#039;s Blog &#187; trust framework</title>
		<link>http://maarten.wegdam.name</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://maarten.wegdam.name/osd.xml" title="Maarten Wegdam&#039;s Blog" />
	<atom:link rel='hub' href='http://maarten.wegdam.name/?pushpress=hub'/>
		<item>
		<title>Looking back at 2011: what was new, and what could have been (IDentity.Next newsletter)</title>
		<link>http://maarten.wegdam.name/2011/12/21/looking-back-at-2011-what-was-new-and-what-could-have-been-identity-next-newsletter/</link>
		<comments>http://maarten.wegdam.name/2011/12/21/looking-back-at-2011-what-was-new-and-what-could-have-been-identity-next-newsletter/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 10:06:18 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=324</guid>
		<description><![CDATA[I wrote an article for the IDentity.Next newsletter that came out today (21 December 2011). It is here, and for convenience, also copied below. Looking back at 2011: what was new, and what could have been 18-12-2011 With 2011 almost over, the question IDentity.News had for me was to look back to 2011 what were new developments [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=324&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I wrote an article for the IDentity.Next newsletter that came out today (21 December 2011). It is <a href="http://www.identitynext.nl/news.php?id=39">here</a>, and for convenience, also copied below.</p>
<p><a href="http://maartenwegdam.files.wordpress.com/2011/12/1324209834_2011.jpg"><img class="aligncenter size-full wp-image-325" title="1324209834_2011" src="http://maartenwegdam.files.wordpress.com/2011/12/1324209834_2011.jpg?w=450" alt=""   /></a></p>
<h3>Looking back at 2011: what was new, and what could have been</h3>
<div><strong>18-12-2011</strong></div>
<p>With 2011 almost over, the question IDentity.News had for me was to look back to 2011 what were new developments in the area of digital identity. Since I&#8217;m in the business of innovation, looking forward is more in my DNA than looking back. And so a little out of my comfort zone, below three major new developments of 2011, and, also, three developments that did not happen in 2011.</p>
<p><strong>1. Trust frameworks</strong>- in the US (e.g. NSTIC, OIX), in NL (e.g. eHerkenning) and elsewhere trust frameworks as a way to ensure a fair and trusted ecosystem to provide identity-related services are catching on. Experience with large scale deployment is still limited though. I guess we just have to do and learn. And the alternative for trust frameworks (i.e. government issued identities) also stays popular (e.g., the new German ID card, the Dutch DigiD/eNIK).</p>
<p><strong>2. Cloud and identity-as-a-service</strong>– it seems impossible for a self-respecting event in the area of identity not to spend significant time on the combination of cloud and identity. And something similar seems to apply to identity experts J. There is also progress here; especially commercial offerings of identity-as-a-service have been progressing. On making the cloud identity-enabled, things have developed slower than I would have expected a year ago. Although I guess everyone (?) agrees that companies want to have centralized authentication, authorization and provisioning (efficiency, control etc), adoption of standards is still too limited, which is at least part of the reason this is going slow.</p>
<p><strong>3. DigiNotar </strong>(and other security fiasco&#8217;s in the identity area) – while a disaster for DigiNotar and potentially a huge disaster for an unknown number of Iranians, there is actually a bright side. It resulted in more attention at &#8216;higher levels in organizations&#8217; for information security and identity. And I&#8217;m sure many security consultants had sufficient work in second half of 2011. The downside of this attention is that I rather have digital identity associated with ‘enabling online services’ than with security risks.</p>
<p>There are also three developments that did not happen, but could have. I stay close to home for these.</p>
<p>What first comes to mind is that there is still no clarity on introduction of a Dutch electronic identity card (eNIK), although the responsible Minister of Internal Affairs promised parliament a proposal before the end of the year (still two weeks to go!).</p>
<p>What also did not happen in the Netherlands is the Dutch national electronic health record, instead the Dutch senate seems to prefer faxes, or maybe smoke signals. Not that the proposed law they stopped did not have its flaws from a privacy and authorization perspective. But the proposal could have been improved upon, and current practise is much worse in my opinion. Hopefully the Dutch national health record will continue in another form, there are signs it might.</p>
<p>The third development that did not happen is a breakthrough in a re-usable consumer identity solution on Dutch national or, even better, European or worldwide scale: we still have the same long list of username/passwords for every website that offers personalization.</p>
<p><em><strong>Maarten Wegdam </strong>(principal consultant Novay &#8211; IDentity.Next member panel)</em></p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity/'>identity</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/324/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=324&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/12/21/looking-back-at-2011-what-was-new-and-what-could-have-been-identity-next-newsletter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2011/12/1324209834_2011.jpg" medium="image">
			<media:title type="html">1324209834_2011</media:title>
		</media:content>
	</item>
		<item>
		<title>Digital identity in the Netherlands: DigiD for consumer-2-business?</title>
		<link>http://maarten.wegdam.name/2011/10/05/digital-identity-in-the-netherlands-digid-for-consumer-2-business/</link>
		<comments>http://maarten.wegdam.name/2011/10/05/digital-identity-in-the-netherlands-digid-for-consumer-2-business/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 18:01:47 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[business model]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[mobile-centric identity]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=279</guid>
		<description><![CDATA[On Tuesday 4 October we organised a Novay networking event called Tuesday Update, with digital identities as the subject. The main subject of discussion was the need for re-usable identities, and especially who should be the identity provider: government or private parties. This is a hot subject in the Netherlands, also because of the recent [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=279&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>On Tuesday 4 October we organised a Novay networking event called Tuesday Update, with digital identities as the subject. The main subject of discussion was the need for re-usable identities, and especially who should be the identity provider: government or private parties. This is a hot subject in the Netherlands, also because of the recent security incidents (<a href="http://maarten.wegdam.name/2011/09/06/hacks-will-happen-but-the-damage-can-be-less-diginotar/">DigiNotar</a>). Hein Aanstoot, director at <a href="http://www.sivi.org/">SIVI</a>, argued very well that the insurance sector increasingly needs a consumer-2-business identity solution, and would they be allowed to use the national citizin-2-government solution DigiD then this would help insurance companies a lot. This is however not allowed in the Netherlands, and Kees Keuzenkamp from the ministry of Internal Affairs explained the policy developments in this area (NL and EU), including the planned Dutch eID smartcard (called eNIK, <em>elektronische Nederlandse Identiteits Kaart</em>). Bottom-line (in my wording) is that the decision on eNIK will be taken end of this year (after which it goes to parlement) and that it is very unlikely that DigiD/eNIK can be used as a generic consumer-2-business identity solution. Hein Aanstoot also gave some insight into a new initiative with several large insurance companies to create a breakthrough in a re-usable identity for the insurance sector, I think it is good for these insurance companies that they do not make themselves (too) dependent on the government or others (banks). I also presented, and gave my perspectives on consumer-2-business identities, why this is so difficult (privacy, trust etc), the outcomes of our cidSafe project, my views on DigiD (and eHerkenning) and what the role of government should be (especially: solve it or be very clear you&#8217;re not going to do so). I also presented three innovations we are working on that we believe will increasingly become important: user control over their data, mobile-centric identity and context-enhanced authentication/authorization. My presentation is on <a href="http://www.slideshare.net/wegdam/digitale-identiteiten-vertrouwen-identity-providers-en-de-toekomst-novay-tuesday-update-4-oktober-2011">slideshare</a> (dutch!).</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/business-model/'>business model</a>, <a href='http://maarten.wegdam.name/tag/identity/'>identity</a>, <a href='http://maarten.wegdam.name/tag/mobile-centric-identity/'>mobile-centric identity</a>, <a href='http://maarten.wegdam.name/tag/privacy/'>privacy</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/279/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=279&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/10/05/digital-identity-in-the-netherlands-digid-for-consumer-2-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>
	</item>
		<item>
		<title>Government eID versus identity trust frameworks, at EIC</title>
		<link>http://maarten.wegdam.name/2011/05/13/government-eid-versus-identity-trust-frameworks-at-eic/</link>
		<comments>http://maarten.wegdam.name/2011/05/13/government-eid-versus-identity-trust-frameworks-at-eic/#comments</comments>
		<pubDate>Fri, 13 May 2011 07:34:03 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[business model]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=228</guid>
		<description><![CDATA[I spent most of this week in Munich, at Kuppinger Cole&#8217;s European Identity Conference. This had again a full program with presentations and panels on digital identity, GRC and, of course, cloud. Some personal high-lights were presentations and panels on: externalization of authorization (XACML 3.0 won an identity award) privacy (including personal clouds/datastores, Qiy won an identity award) [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=228&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I spent most of this week in Munich, at Kuppinger Cole&#8217;s<a href="http://www.id-conf.com/" target="_blank"> European Identity Conference</a>. This had again a full program with presentations and panels on digital identity, GRC and, of course, cloud. Some personal high-lights were presentations and panels on:</p>
<ul>
<li>externalization of authorization (XACML 3.0 won an identity award)</li>
<li>privacy (including personal clouds/datastores, Qiy won an identity award)</li>
<li>consumer identity/trust frameworks/OpenID (including an interesting presentation by Andrew Nash from Paypal). </li>
<li>and mostly the off-sessions discussions with leading people in the digital identity area</li>
</ul>
<p>I also had a presentation myself on consumer identity, and participated in panel. I presented my ideas on government issued consumer/citizin identities versus doing this through the market via an identity trust framework.</p>
<iframe src='http://www.slideshare.net/slideshow/embed_code/7940453' width='450' height='369'></iframe>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/business-model/'>business model</a>, <a href='http://maarten.wegdam.name/tag/identity/'>identity</a>, <a href='http://maarten.wegdam.name/tag/privacy/'>privacy</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/228/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=228&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/05/13/government-eid-versus-identity-trust-frameworks-at-eic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>
	</item>
		<item>
		<title>Internet identity solutions: 3, 3.5 or 4 parties?</title>
		<link>http://maarten.wegdam.name/2010/07/19/internet-identity-solutions-3-3-5-or-4-parties/</link>
		<comments>http://maarten.wegdam.name/2010/07/19/internet-identity-solutions-3-3-5-or-4-parties/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 20:06:04 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[business model]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=113</guid>
		<description><![CDATA[When scaling an internet identity solutions (or identity federation or trust frameworks) to many relying parties and identity providers, one is bound to run into scalability issues. I’m not referring to the amount of users, or logins/transactions, but to the relationships that need to be formed between the identity providers and the relying parties. To [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=113&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>When scaling an internet identity solutions (or identity federation or trust frameworks) to many relying parties and identity providers, one is bound to run into scalability issues. I’m not referring to the amount of users, or logins/transactions, but to the relationships that need to be formed between the identity providers and the relying parties. To make things complex, there are technical issues related to this, and organizational issues. I simplify this here to four issues: the technical issues have to do with finding the necessary meta-information (URLs etc), and with protocol translations (not relevant for all scenario’s). The organizational issues have to do with trust (who is part of the federation/trust framework etc) and business aspects. The business aspect is related to business model: in lot’s of business models someone, typically the relying party, is paying another, typically the identity provider. For example, imagine a trust framework in which 100s of relying parties would use 10s of identity providers, and needing a contract between them. This quickly becomes a combinational explosion that does not scale without some form of automation or intermediate party.</p>
<p>Different internet identity solutions address, or do not address, these issues in different ways. In this blog post I write down my current thinking on this subject, hoping for input from others. The alternative architectures I found are:</p>
<ol>
<li><em>A single IdP</em> – avoid the issue altogether. This kind of monopolist identity provider is however not an option in many cases.</li>
<li><em>Centralized meta-information</em> – centralize the meta-information, this obviously addresses the technical issues, and can also help with the trust issue since this list can serve as a whitelist. (This list does not have to be physically centralized, and can also be a list-of-list etc). It does not help with the business aspects, or protocol translations.</li>
<li><em>Hub</em> – one central component managed by a (very) trusted party that can basically address all four issues mentioned above, but does become a more-or-less monopolist, as used by for example <a href="http://www.surffederatie.nl">SURFfederatie</a>.</li>
<li><em>Broker</em> – similar to the hub architecture, but there is more than one hub (allowing competition between them), as used by for example <a href="http://maarten.wegdam.name/2010/04/20/network-approach-to-e-identification-erecogition/">eHerkenning (eRecognition)</a>.</li>
</ol>
<p>The figure below depicts the four alternatives, with examples (biased to the Netherlands). The numbers indicate the amount of connections from the perspective of the source of the arrow.</p>
<p><a href="http://maartenwegdam.files.wordpress.com/2010/07/3-3-5-4-party-model.png"><img class="aligncenter size-full wp-image-114" title="3-3.5-4-party-model" src="http://maartenwegdam.files.wordpress.com/2010/07/3-3-5-4-party-model.png?w=450" alt=""   /></a></p>
<p>There are three major arguments that came to my mind while looking into the architectural alternatives (ignoring the single-IdP architecture):</p>
<ul>
<li>Standards compliant – What is interesting is that most (or all?) identity federation standards basically assume the world consists of three type of parties: users, relying parties (aka service providers) and identity providers, and have no concept of meta-data repository, hub (3.5 ? parties) or brokers (4 parties). Going into details is too much for this blog post, but I found that staying standard conformant can clash with the hub and broker architectures, or extensions to the standards are needed that may make it difficult to use COTS federation software (including for the meta-information architecture).</li>
<li>“Justifyable Parties” – in accordance with Kim Cameron’s Laws of Identity nr 3, there have to be good reasons to add parties, especially when they are in the protocol flow and have access to privacy sensitive information or/and are a security risk. For hub and broker architectures, this can be a difficult trade-off.</li>
<li>Security – related to both arguments above, but end-to-end security can and I think often is broken when introducing a hub or broker. The hub/broker thus needs to be trusted to an extend that for certain scenario’s is not desirable.</li>
</ul>
<p>A major benefit of a hub or broker model is that should be easier for relying parties to hook up to the federation, both technically (there only need to connect to a single hub or broker), and organizationally (they trust the hub/broker to keep track of who is trusted, they only need to have a single contract contrary to many for each identity provider).</p>
<p>Disclaimer: the above thinking is work-in-progress, and I’m struggling with simplicity vs accuracy …</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/business-model/'>business model</a>, <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=113&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2010/07/19/internet-identity-solutions-3-3-5-or-4-parties/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2010/07/3-3-5-4-party-model.png" medium="image">
			<media:title type="html">3-3.5-4-party-model</media:title>
		</media:content>
	</item>
		<item>
		<title>Network Approach to E-identification (eRecognition)</title>
		<link>http://maarten.wegdam.name/2010/04/20/network-approach-to-e-identification-erecogition/</link>
		<comments>http://maarten.wegdam.name/2010/04/20/network-approach-to-e-identification-erecogition/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 13:34:00 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=103</guid>
		<description><![CDATA[Recently the Dutch company Innopay published, on behalf of the Ministerie of Economic Affairs, a report called A Network Approach to E-identification (http://www.innopay.com/index.php/plain/newsletters/04_2010_e_identity_as_a_two_sided_market_the_business_case_will_drive_adoption_not_the_technology). This is an interesting report that gives some background and motivation for the Dutch eRecognition program which works on a trust framework, of scheme, for business-2-government identity. Together with Paul Oude Luttighuis, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=103&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently the Dutch company Innopay published, on behalf of the Ministerie of Economic Affairs, a report called <em>A  Network Approach to E-identification</em> (<a href="http://www.innopay.com/index.php/plain/newsletters/04_2010_e_identity_as_a_two_sided_market_the_business_case_will_drive_adoption_not_the_technology"><span style="text-decoration:underline;">http://www.innopay.com/index.php/plain/newsletters/04_2010_e_identity_as_a_two_sided_market_the_business_case_will_drive_adoption_not_the_technology</span></a>). This is an interesting report that gives some background and motivation for the Dutch eRecognition program which works on a trust framework, of scheme, for business-2-government identity. Together with Paul Oude Luttighuis, a colleague and interoperability expert, we wrote a short reaction. This reaction is below, but in Dutch &#8230; For non-Dutch speakers, among others we discuss:</p>
<ul>
<li>We support the choice for a network model (or trust framework or scheme)</li>
<li>The report advocates the use of a four party model, as is  used in the financial world, contrary to the probably more common  three-party model (user, identity provider, relying party).</li>
<li>We discuss the risk that new parties trying to enter this market are prevented from doing so by the parties already active in it.</li>
<li>We discuss the opportunity to have mutual authentication, i.e., the service provider could also authenticate to the user.</li>
<li>We discuss semantic issues, and pseudonyms.</li>
</ul>
<p><em>What follows is the Dutch text (feel free to experiment with Google Translate &#8230;).</em></p>
<p><strong>Wie bent u om mijn klant te zijn?</strong></p>
<p>Recent publiceerde het bedrijf Innopay  op verzoek van het Ministerie van Economische Zaken hun rapport <em>A  Network Approach to E-identification</em> (<a href="http://www.innopay.com/index.php/plain/newsletters/04_2010_e_identity_as_a_two_sided_market_the_business_case_will_drive_adoption_not_the_technology"><span style="text-decoration:underline;">http://www.innopay.com/index.php/plain/newsletters/04_2010_e_identity_as_a_two_sided_market_the_business_case_will_drive_adoption_not_the_technology</span></a>)  .  Dit belangwekkende rapport bespreekt het gedachte­goed ach­ter  hui­dige e-identity-ontwikkelingen bij de Nederlandse overheid. Paul Oude  Luttighuis ( Enterprise Interopera­bility expert bij Novay) en Maarten  Wegdam (Identity Management expert bij Novay) rea­geren.</p>
<p>============================</p>
<p>Het stuk bepleit een  <strong>netwerkbenadering</strong>. Die gaat uit van interoperabiliteit tussen  concurrenten, gevat in een expliciete en goed beheerde set van afspra­ken (door  het stuk een scheme genoemd), in plaats van een centrale voor­ziening. Als  concept is dat niet nieuw, maar in het e-over­heids­veld is inderdaad de  “centrale voorziening” vaak het leidende concept. Door in het netwerk rollen te  onderscheiden wordt er niet alleen gekoppeld, maar ook ont­koppeld: de rollen  krijgen de kans zich in hun eigen dyna­miek te ontwik­kelen. Zo’n model kan  daarom soepeler groeien dan een centrale-voorzie­ning-model, zolang de rollen  goed gekozen zijn en er voorzieningen zijn om te inno­veren op de koppelvlakken  tus­sen de rollen.</p>
<p>Specifiek kiest het stuk  voor een zogenoemd <strong>vier-partijenmodel</strong>, waarin twee hoofdrollen,  in dit ge­val de eind­gebruiker en de dienstverlener, elk worden be­diend door  een ondersteunende rol aan hun zijde. In dit geval is dat de  authentica­tieprovider, die de eindgebruiker voorziet van  authenticatie­middelen, en de zoge­naamde rou­ting service, die de  dienstverleners toegang biedt tot het netwerk. De kernafspraak in dit netwerk is  dan dat alle authenticatieproviders ver­bon­den zijn met alle routing services.  Deze we­derzijds gedwongen winkelnering vraagt wel om maatregelen tegen het  oneigen­lijk weren van nieuwe toetreders tot het netwerk.</p>
<p>Een ander voordeel van het  vier-partijenmodel is dat eindgebruiker en dienstverlener via één partij  toe­gang krijgen tot het hele netwerk. Natuurlijk moeten zij dan wel het hele  net­werk ver­trouwen en, in­direct, de au­thenticatieproviders en routing  services daarbinnen. Overigens is ook een decentraal drie-partijenmodel  denk­baar. Sterker nog, gang­bare identity-fede­ratiestandaarden gaan daarvan  uit en niet van een vier-partijenmodel. Sommige identity-federaties, zoals de  SURFfedera­tie, hebben wel een vierde rol, maar centraliseren deze.</p>
<p>Overigens, het geschetste  vier-partijenmodel is asymmetrisch. Bij authenticatie is sprake van twee  hoofdrol­len: de partij wiens identiteit wordt vast­gesteld en de par­tij die  die vaststelling ontvangt. In het stuk worden de­ze rollen geïdentificeerd met  respec­tievelijk de eind­ge­bruiker en de dienstverle­ner. Dat ziet over het  hoofd dat in een transactie ook de eindgebruiker behoefte kan hebben aan  zekerheid over de identiteit van de dienstverlener. Is het netwerk niet ook  daarvoor te gebruiken?</p>
<p>Een andere adder onder het  gras is dat het besproken netwerkmodel weliswaar functioneel decen­traal is,  maar <strong>semantisch</strong> wel degelijk cen­traal. Elke eindgebrui­ker die  het netwerk als zodanig kent, heeft namelijk maar één identiteit in dat netwerk.  Anders kunnen niet alle authenticatie­midde­len worden geaccep­teerd door alle  dienstverleners. Dat brengt privacy-issues met zich mee, die niet door het stuk  worden bespro­ken. De voor de hand liggende manier om hier­mee om te gaan is om  één per­soon meerdere “eindgebruikers” te kun­nen laten spelen, door middel van  pseudo­niemen. Dit is gebrui­ke­lijk in modern denken over elektroni­sche  identiteit. Het stuk maakt echter niet duidelijk of het afsprakenstelsel dit  gaat toe­staan en hoe wordt geborgd dat pseudoniemen niet toch worden  ge­combineerd in een omvattender persoonsidentiteit.</p>
<p>Daarnaast heeft een  eventuele centralisatie van het identiteitsbegrip ook informatiekundige  gevolgen. In rela­tie met een school is een persoon leerling of student, in  relatie met een vereni­ging is hij lid, in zijn relatie met een bank is hij  bankklant. Dat kunnen écht andere rela­ties zijn, die dus een andere iden­titeit  vragen. Denk bijvoor­beeld aan een gezinslidmaat­schap van een vereniging, of  aan één persoon die ver­schil­lende relaties heeft met één dienstver­le­ner, in  verschillende hoedanig­heden.</p>
<p>Deze semantische kwestie  wordt alleen maar groter als dit afsprakenstelsel wordt uitgebreid richting  eindge­bruikers die <strong>namens hun organisatie</strong> optreden, zoals het  stuk aan het eind suggereert. Zo zou ook een organisa­tie-an-sich kunnen worden  geauthen­ticeerd. Echter, of zo’n optreden wer­kelijk námens een organisatie is,  kan van veel dingen afhangen: van een expliciete autorisatie, van de precieze  ge­bruikte dienst, van het tijdstip, van de locatie of van de situatie (denk  bijvoorbeeld aan noodgevallen). Deze semantische variëteit dreigt veel  complexiteit in het netwerk brengen. Het zal in elk geval niet de bedoeling zijn  deze genuanceerde autorisatie onmogelijk te maken, nemen we aan.</p>
<p>Tot slot, het stuk claimt  dat zo een centralistische machtspositie wordt voorkomen. Moch­ten deze  net­werken echter suc­cesvol blij­ken, zullen zij vanzelf een oligopolie of  monopolie vestigen en de keuzevrijheid toch weer be­perken. Daarom moet het  beheer van het afsprakenstelsel zorgvuldig en voldoende open worden  vormgege­ven.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity/'>identity</a>, <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/103/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=103&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2010/04/20/network-approach-to-e-identification-erecogition/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>
	</item>
	</channel>
</rss>
