<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Maarten Wegdam&#039;s Blog &#187; user centric identity</title>
	<atom:link href="http://maarten.wegdam.name/tag/user-centric-identity/feed/" rel="self" type="application/rss+xml" />
	<link>http://maarten.wegdam.name</link>
	<description>A blog on identity, mobile, privacy, innovation, trust, middleware and more</description>
	<lastBuildDate>Wed, 25 Jan 2012 20:55:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='maarten.wegdam.name' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/919cf8ecf6f35b50e61434a17113f7ee?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Maarten Wegdam&#039;s Blog &#187; user centric identity</title>
		<link>http://maarten.wegdam.name</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://maarten.wegdam.name/osd.xml" title="Maarten Wegdam&#039;s Blog" />
	<atom:link rel='hub' href='http://maarten.wegdam.name/?pushpress=hub'/>
		<item>
		<title>Mobile-centric identity in the IDentity.Next newsletter</title>
		<link>http://maarten.wegdam.name/2011/04/05/mobile-centric-identity-in-the-identity-next-newsletter/</link>
		<comments>http://maarten.wegdam.name/2011/04/05/mobile-centric-identity-in-the-identity-next-newsletter/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 18:40:26 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[mobile-centric identity]]></category>
		<category><![CDATA[user centric identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=225</guid>
		<description><![CDATA[Below a contribution I wrote for the IDentity.Next newsletter  (I&#8217;m on the expert panel) on mobile-centric identity, see also http://www.identitynext.nl/news.php?id=22.  Mobile phone &#8211; the remote control of our (digital) identity? 29-03-2011 For most people the mobile (smart) phone is the most personal device they have. You carry it with you almost always, you rarely let [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=225&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Below a contribution I wrote for the IDentity.Next newsletter  (I&#8217;m on the expert panel) on mobile-centric identity, see also <a href="http://www.identitynext.nl/news.php?id=22">http://www.identitynext.nl/news.php?id=22</a>. </p>
<h3>Mobile phone &#8211; the remote control of our (digital) identity?</h3>
<div><img title="Mobile phone - the remote control of our (digital) identity?" src="http://www.identitynext.nl/images/1301428699_airremote-cool-iphone-remote-control-app-150608.jpg" alt="Mobile phone - the remote control of our (digital) identity?" width="150" /></div>
<p><strong>29-03-2011</strong></p>
<p>For most people the mobile (smart) phone is the most personal device they have. You carry it with you almost always, you rarely let others use it and you notice it is gone very quickly. Combine this with the smart phone becoming a mature and popular channel to online services, and you realize the importance of your mobile phone for your digital identity. The term user centric identity was (or still is) quite popular the last few years, going further I’m a strong believer in mobile centric identity: the mobile phone as the central component to control your digital identity.</p>
<p> I distinguish three ways in which this is happening:</p>
<p>1.     <em>The mobile phone as authentication device</em>– this is already happening and is progressing, especially one-time-passwords over SMS are pretty common. But also apps for Android or iPhone with one-time-password generators, or <a href="http://maarten.wegdam.name/2010/01/08/mobile-pki-and-mobile-centric-identity/" target="_blank">Mobile PKI</a> which exploits the SIM card for more security.</p>
<p>2.     <em>Authentication for the mobile channel</em>– this is still a struggle, even more than identity on the ‘fixed’ internet. Typing passwords is a huge hassle on mobile phones, and providing these to random and barely trusted mobile apps is not a good idea (for example a third party mobile banking app). Common stronger authentication means like smartcards-with-readers or one-time-password tokens  are not really an option since no one wants to carry additional devices with them. Also identity federation standards like <a href="http://en.wikipedia.org/wiki/Security_Assertion_Markup_Language" target="_blank">SAML WebSSO</a> and <a href="http://openid.net/" target="_blank">OpenID</a> are not really suitable for mobile phones. We’ve been using <a href="http://oauth.net/" target="_blank">oAuth</a> for mobile Apps, which may not be the final solution but is a step into the right direction if ‘medium’ security is good enough.</p>
<p>3.     <em>Control your privacy on your mobile phone </em>– I, and many with me, believe that sharing personal data can make our lives easier, but that the user should be in control of this. A single point of control for this is the way to go, for example determine in a central place who should get access to my new home address, and my location updates. This starts at basic consent functionality when using external identities (e.g., OpenID), but goes all the way to <a href="http://personaldataecosystem.org/" target="_blank">Personal Data Ecosystem</a>, Vendor <a href="http://blogs.law.harvard.edu/vrm/" target="_blank">Relationship Management</a> and <a href="http://kantarainitiative.org/confluence/display/uma/Home" target="_blank">User Managed Access ambitions</a>. The mobile could be the trusted device to control this. This is far from reality nowadays.</p>
<p>A major risk for the success and speed in which mobile centric identity will come to be is if we are successful in keeping the mobile phone secure enough for this. This has not been a major issue yet, but for sure requires attention (for example, <a href="http://www.enisa.europa.eu/act/application-security/smartphone-security-1/top-ten-risks/top-ten-smartphone-risks" target="_blank">ENISA report</a> or <a href="http://www.kuppingercole.com/report/mk_toptrends07032011" target="_blank">KuppingerCole Top Trends 2011</a>). Solutions that are part of the operating system and/or exploit trusted hardware like the SIM card may prove most successful.</p>
<p>Related to identity is always payment, and although slower than expected the signs are good that NFC technology (for mobile payments) will get a significant penetration to mobile phones the coming years. Also, at least in the Netherlands, <a href="http://www.nfctimes.com/news/dutch-banks-and-telcos-move-forward-m-payment-project" target="_blank">banks and mobile operators have joint forces</a> to make mobile payment possible. Your mobile phone may very well replace both the coins and the bank/smartcards that are now in your wallet. It will be interesting to see how, how fast and who will profit from this!</p>
<p><em><strong><a href="http://www.linkedin.com/in/wegdam" target="_blank">Maarten Wegdam</a> (principal researcher at Novay &#8211; member of IDentity.Next expert panel)</strong></em></p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/mobile/'>mobile</a>, <a href='http://maarten.wegdam.name/tag/mobile-centric-identity/'>mobile-centric identity</a>, <a href='http://maarten.wegdam.name/tag/user-centric-identity/'>user centric identity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/225/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=225&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/04/05/mobile-centric-identity-in-the-identity-next-newsletter/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://www.identitynext.nl/images/1301428699_airremote-cool-iphone-remote-control-app-150608.jpg" medium="image">
			<media:title type="html">Mobile phone - the remote control of our (digital) identity?</media:title>
		</media:content>
	</item>
		<item>
		<title>User consent pilot for SURFnet</title>
		<link>http://maarten.wegdam.name/2010/10/08/user-consent-pilot-for-surfnet/</link>
		<comments>http://maarten.wegdam.name/2010/10/08/user-consent-pilot-for-surfnet/#comments</comments>
		<pubDate>Fri, 08 Oct 2010 13:00:56 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SAML]]></category>
		<category><![CDATA[user centric identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=155</guid>
		<description><![CDATA[Together with my colleagues Ruud Janssen and Dirk-Jan van Dijk we have been working for SURFnet to help them if, and if so how, they should add a user consent feature to their SURFfederatie identity federation service. See also this previous post on user-centric SAML that describes what we did last year. We continued this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=155&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent.png"><a href="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent1.png"><img class="aligncenter size-full wp-image-157" title="timed-consent" src="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent1.png?w=450" alt=""   /></a></a></p>
<p>Together with my colleagues Ruud Janssen and Dirk-Jan van Dijk we have been working for SURFnet to help them if, and if so how, they should add a user consent feature to their <a href="http://www.surfnet.nl/nl/Thema/SURFfederatie/Pages/Default.aspx">SURFfederatie</a> identity federation service. See also this previous post on <a href="http://maarten.wegdam.name/2010/03/11/user-centric-saml/">user-centric SAML</a> that describes what we did last year. We continued this year, doing additional user studies, deciding on architectural issues, developing a prototype and doing a pilot. This pilot started two weeks ago J, see also a <a href="http://www.surfnet.nl/nl/nieuws/Pages/SURFfederatie-pilot%27Usercontrolledprivacy%27.aspx">SURFnet news item</a> (Dutch) on this. The pilot is with three of the bigger Dutch universities, and students/employees that go to the selected service providers will be asked to participate in the pilot. They go through the consent pages, and we bother them with two online surveys to get their feedback. It’s too early to predict the outcome, but the pilot itself seems be going well.</p>
<p>At ISSE 2010 I gave a presentation on the current status of this work, the presentation is on <a href="http://www.slideshare.net/wegdam/user-consent-for-consumer-identity-isse2010">slideshare</a>. In December we’ll finalize a report with the outcome of the pilot, after which it’s up to SURFnet to decide if they’ll add this feature to the SURFfederatie.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a>, <a href='http://maarten.wegdam.name/tag/openid/'>OpenID</a>, <a href='http://maarten.wegdam.name/tag/privacy/'>privacy</a>, <a href='http://maarten.wegdam.name/tag/saml/'>SAML</a>, <a href='http://maarten.wegdam.name/tag/user-centric-identity/'>user centric identity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/155/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=155&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2010/10/08/user-consent-pilot-for-surfnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2010/10/timed-consent1.png" medium="image">
			<media:title type="html">timed-consent</media:title>
		</media:content>
	</item>
		<item>
		<title>User-centric SAML?</title>
		<link>http://maarten.wegdam.name/2010/03/11/user-centric-saml/</link>
		<comments>http://maarten.wegdam.name/2010/03/11/user-centric-saml/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 20:50:48 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[InfoCard]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SAML]]></category>
		<category><![CDATA[user centric identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=88</guid>
		<description><![CDATA[Let me first introduce user-centric identity (people who know this can skip to the second paragraph). Not so long ago OpenID en InfoCard where introduced as user centric identity standards, contrary to ‘old fashioned’ identity provider centric standard like SAML. Without going into details, user centricity boils down to providing user controlled privacy, i.e., providing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=88&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://maartenwegdam.files.wordpress.com/2010/03/consent-saml.png"><img class="aligncenter size-large wp-image-91" title="Example user consent in SAML WebSSO" src="http://maartenwegdam.files.wordpress.com/2010/03/consent-saml.png?w=614&#038;h=425" alt="" width="614" height="425" /></a></p>
<p>Let me first introduce user-centric identity (people who know this can skip to the second paragraph). Not so long ago OpenID en InfoCard where introduced as user centric identity standards, contrary to ‘old fashioned’ identity provider centric standard like SAML. Without going into details, user centricity boils down to providing user controlled privacy, i.e., providing informed consent. And I of course do not mean some legal disclaimer that you have to agree to as a user to be able to use some service. The idea to provide actual information on what information would be shared between an identity provider and a relying party, and asking the user for consent before sharing this. InfoCard inherently provides this, and does this with a piece of software on the client. OpenID provides this though a webpage.</p>
<p>We did a project for SURFnet, the Dutch NREN, to study if and if so how we could make their SURFfederatie (identity federation for higher education and research) provide user controlled privacy. The SURFfederation support different protocols, but is mainly SAML WebSSO based. We analyzed different options, focusing on providing user controlled privacy through InfoCards and doing this through SAML. The latter option is less used, but there are precedents, like <a href="http://www.switch.ch/aai/support/tools/uApprove.html">uApprove</a> (for Shibboleth) and the <a href="http://identitynetworks.wordpress.com/2009/03/09/ready-able-and-willing-federated-consent/">Consent module for SimpleSAMLphp</a>. Ignoring lots of details, SAML WebSSO works roughly the same as OpenID (by redirecting the browser from relying party to the identity provider, and back), and user controlled privacy can be implemented in a similar fashion for SAML WebSSO as for OpenID.</p>
<p>The choice between InfoCards and what I’ll call user-centric SAML is not a trivial one, both have advantages and disadvantages. And besides, it was not clear if the users (students and employees of universities etc) even want to be bothered with user controlled privacy. We figured that the best way forward researcher user centricity was to simple ask users what they want. We considered doing this through some large-scale survey, but decided that a small-scale but in-depth user study would provide more useful results. My colleague Ruud Janssen, an experienced user researcher, did this user study. Using mockups he asked users if they wanted control, and if so, if they prefer user-centric SAML or InfoCards. Although the number were too small to be statistically significant, there was a surprisingly clear consensus on what the users preferred: <em>user controlled privacy through user-centric SAML</em>. This thus also is what we recommended to SURFnet.</p>
<p>Although I expected that they would like the card-like user interface that InfoCard offers, the user we interviewed did not. We think this is mostly because they were unfamiliar with it, and therefore did not really trust it.</p>
<p>The research outcomes were written down in two reports: the <a href="http://www.surfnet.nl/Documents/indi-2009-09-014%20%28User%20controlled%20privacy%20voor%20de_SURFfederatie%20v1.1%29.pdf">first report</a> discusses the state-of-the-art, design guidelines for user-centric SAML and architectural analysis on using InfoCard vs user-centric SAML. The <a href="http://www.surfnet.nl/Documents/indi-2009-12-027%20%28User%20controlled%20privacy%20voor%20de%20SURFfederatie%20gebruikersstudie%29.pdf">second report</a> contains the outcomes of the user study. My apologies to non-Dutch speakers: both reports are in Dutch, as requested by our client.</p>
<p>We are continuing the research on user controlled privacy this year, focusing on the user interaction (prototyping, further user studies) and the architectural consequences of user-centric SAML for the SURFfederatie.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a>, <a href='http://maarten.wegdam.name/tag/infocard/'>InfoCard</a>, <a href='http://maarten.wegdam.name/tag/openid/'>OpenID</a>, <a href='http://maarten.wegdam.name/tag/privacy/'>privacy</a>, <a href='http://maarten.wegdam.name/tag/saml/'>SAML</a>, <a href='http://maarten.wegdam.name/tag/user-centric-identity/'>user centric identity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=88&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2010/03/11/user-centric-saml/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2010/03/consent-saml.png?w=1024" medium="image">
			<media:title type="html">Example user consent in SAML WebSSO</media:title>
		</media:content>
	</item>
		<item>
		<title>Tuesday Update event on (consumer) identity</title>
		<link>http://maarten.wegdam.name/2009/12/04/tuesday-update-event-on-consumer-identity/</link>
		<comments>http://maarten.wegdam.name/2009/12/04/tuesday-update-event-on-consumer-identity/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 22:56:40 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[user centric identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=61</guid>
		<description><![CDATA[My employer organizes networking events called Tuesday Update by Novay. The theme this time was identity, and more specifically consumer identity (consumer2business). We had an audience that was a very good mix of business people (financial industry, some media, some operators), government, &#8216;identity industry&#8217; and people who more generally are involved with innovation. It was [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=61&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://maartenwegdam.files.wordpress.com/2009/12/picture11.png"><img class="alignnone size-medium wp-image-66" title="Wordle" src="http://maartenwegdam.files.wordpress.com/2009/12/picture11.png?w=300&#038;h=153" alt="" width="300" height="153" /></a></p>
<p>My employer organizes networking events called Tuesday Update by Novay. The theme this time was identity, and more specifically consumer identity (consumer2business). We had an audience that was a very good mix of business people (financial industry, some media, some operators), government, &#8216;identity industry&#8217; and people who more generally are involved with innovation. It was an interesting and lively event!</p>
<p>We invited Frank Leyman from FEDICT to give a talk on the Belgian eID, and it&#8217;s usage for consumer identity. FEDICT is the Belgian government organization responsible for the eID card. The Belgian government eID can, contrary to the Netherlands, be used by private businesses, and they appear to be ahead of the Netherlands in this area (e.g., an actual eID card &#8230;). This made it a very interesting case, and Frank explained the different functionalities very well. See <a href="https://doc.novay.nl/dsweb/Get/Document-108439/200912%20-%20FEDICT%20-%20Frank%20Leyman%20-%20beligische%20eID%20-%20Tuesday%20update.pdf">here</a> for his slides.</p>
<p>We also invited <a href="http://www.yme.nl/">Yme Bosma </a>from Hyves to present the Hyves view on identity. Hyves is the by-far-largest Dutch social network, and Hyves is, as its US/international counterparts, becoming an Identity Provider for low-trust identity. Think OpenID, oAuth etc. Hyves is, with some limitations, also a relying party. What&#8217;s especially interesting to me is that Yme is quite straightforward on their business case (my wording): we provide more value to our users, and it&#8217;s easy to do, so we do it. See <a href="http://docs.google.com/a/yme.nl/present/view?id=dg22g52h_10c29qhvdj">http://docs.google.com/a/yme.nl/present/view?id=dg22g52h_10c29qhvdj</a> for his slides.</p>
<p>I also gave a presentation, discussing among other business models, market entry en privacy aspects. And I advocated user centric identity, and our personal buzzword: mobile centric identity. I also briefly discussed our high-trust consumer identity for the Netherlands project proposal, and the OpenID.nl+ initiative (by ECP-EPN) which I&#8217;m becoming more involved in (as project manager for the proof-of-concept). See <a href="http://www.slideshare.net/wegdam/consumer-identity-tuesday-update-on-1-december-2009">http://www.slideshare.net/wegdam/consumer-identity-tuesday-update-on-1-december-2009</a> for my slides (the first few slides have some Dutch, but don&#8217;t worry, you can easily skip those).</p>
<br />Posted in Uncategorized Tagged: identity, identity federation, OpenID, user centric identity <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/61/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=61&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2009/12/04/tuesday-update-event-on-consumer-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2009/12/picture11.png?w=300" medium="image">
			<media:title type="html">Wordle</media:title>
		</media:content>
	</item>
		<item>
		<title>Presentations on Id Fed, user centric and mobile centric identity</title>
		<link>http://maarten.wegdam.name/2009/10/22/presentations-on-id-fed-user-centric-and-mobile-centric-identity/</link>
		<comments>http://maarten.wegdam.name/2009/10/22/presentations-on-id-fed-user-centric-and-mobile-centric-identity/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 17:13:43 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity federation]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[user centric identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=51</guid>
		<description><![CDATA[I gave two presentation recently that I&#8217;ll share in this post. They were for quite different audiences, and in different countries, but both in the area of identity federation, user centric identity and mobile centric identity. The first presentation was at the Dutch Identity 2009 event, which was co-located with ISSE 2009 this year. This took place [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=51&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I gave two presentation recently that I&#8217;ll share in this post. They were for quite different audiences, and in different countries, but both in the area of identity federation, user centric identity and mobile centric identity.</p>
<p>The first presentation was at the Dutch <a href="http://www.iir.nl/ict/it_security/event/identity_isse_2009/">Identity 2009 event</a>, which was co-located with ISSE 2009 this year. This took place in Schevingen (The Hague), on 6-7 October 2009.  I presented my views on trend in identity federation, and user centric identity. Among others, I argued that SAML is just as user centric than OpenID, or at least, can and should be&#8230;<br />
<iframe src='http://www.slideshare.net/slideshow/embed_code/2211095' width='450' height='369'></iframe></p>
<p>Highlights on Identity/ISSE 2009 for me were the presentations by <a href="http://identity-des.com/">Don Schmidt </a>(Microsoft), who talked about claim-based identity, and a presentation on the Norwegian BankID, which discussed the status of the Norwegian collaboration between banks to provide identity services to public and private sector.</p>
<p>The second presentation was at the <a href="http://www.eid-epass.org/">National eID &amp; ePassport conference</a>, which is taking place as I type this (22-23 October 2009), in Lisbon. It was organized by among others Multicert, who invited me to talk about and discuss mobile centric identity. It was an audience not very familiar with user centric identity, so I first introduced this. I then argued that this implies mobile centric identity, and that using the mobile phone is only the first step towards mobile centric identity.<br />
<iframe src='http://www.slideshare.net/slideshow/embed_code/2321405' width='450' height='369'></iframe></p>
<br />Posted in Uncategorized Tagged: identity, identity federation, mobile, user centric identity <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/51/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=51&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2009/10/22/presentations-on-id-fed-user-centric-and-mobile-centric-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>
	</item>
	</channel>
</rss>
