<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>In Context</title>
	<atom:link href="http://www.incontextblog.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.incontextblog.com</link>
	<description></description>
	<lastBuildDate>Mon, 19 Jul 2010 21:00:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Violent agreement breaks out at Internet of Subjects Forum</title>
		<link>http://www.incontextblog.com/?p=614</link>
		<comments>http://www.incontextblog.com/?p=614#comments</comments>
		<pubDate>Mon, 19 Jul 2010 21:00:00 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Data Portability]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Personal Data Stores]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=614</guid>
		<description><![CDATA[On the morning of July 5th I had breakfast with Iain Henderson and David Alexander of Mydex. And then, within 5 minutes of walking in to the IoS meeting I met Serge, Sampo and Graham. Between meeting them on the one hand and the breakfast on the other I knew the whole trip was worthwhile. [...]]]></description>
			<content:encoded><![CDATA[<p>On the morning of July 5th I had breakfast with Iain Henderson and David Alexander of <a href="http://mydex.org/">Mydex</a>. And then, within 5 minutes of walking in to the IoS meeting I met Serge, Sampo and Graham. Between meeting them on the one hand and the breakfast on the other I knew the whole trip was worthwhile. It&#8217;s a great pleasure to spend time with people who share the vision of giving individuals more control over their own personal data. We all had a chance to share what we&#8217;re all learning about creating Personal Data Stores, VRM (TRM?), user managed identity, data portability, etc.</p>
<p>Check out <a href="http://www.iosf.org/">Internet of Subjects</a>. This is a new effort that deserves our support. I particularly like the fact that it&#8217;s not based in the (privacy-challenged) US. The effort is being indirectly supported by EU investments in <a href="http://www.tas3.eu/">TAS3</a>, a project that I&#8217;m only now learning about.</p>
<p>Here&#8217;s a quote from <a href="http://www.typepad.com/services/trackback/6a00d8342046f353ef0134853c2d18970c">Graham Sadd&#8217;s post</a> about the IoS meeting:</p>
<blockquote><p><a title="Ravet" href="http://fr.linkedin.com/in/sravet" target="_blank">Serge Ravet</a>, CEO of<a title="EIfEL" href="http://www.eife-l.org/" target="_blank"> EIfEL</a>, prefaced the <a title="epforum" href="http://www.epforum.eu/" target="_blank">Eifel  Learning Forum</a> with the inaugural <a title="IoS" href="http://www.iosf.org/" target="_blank">Internet of Subjects Forum</a> to an  international audience in London yesterday. The plenary  presentations were made by <a title="Kellomaki" href="http://symlabs.com/management-team" target="_blank">Sampo Kellomaki</a>, Chief Architect  at <a title="Symlabs" href="http://symlabs.com/company-overview" target="_blank">Symlabs</a>, <a title="Sadd" href="http://blog.grahamsadd.com/" target="_blank">Graham Sadd</a>, Founder &amp; CEO of <a title="Paoga" href="http://www.paoga.com/" target="_blank">PAOGA </a>(<a title="Sadd Interview" href="http://events.eife-l.org/events/2010/062010-3" target="_blank">read interview</a>) and <a title="Trevithick" href="http://en.wikipedia.org/wiki/Paul_Trevithick" target="_blank">Paul Trevithick</a> &#8211; Founder of <a title="Higgins" href="http://eclipse.org/higgins/" target="_blank">Higgins  Project</a> and CEO of <a title="Azigo" href="http://www.azigo.com/">Azigo</a>.</p>
<p><img class="alignnone" title="Internet of Subjects" src="http://paoga.typepad.com/.a/6a00d8342046f353ef0134853c1ebf970c-800wi" alt="" width="800" height="600" /></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=614</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cost vs. Security</title>
		<link>http://www.incontextblog.com/?p=611</link>
		<comments>http://www.incontextblog.com/?p=611#comments</comments>
		<pubDate>Tue, 22 Jun 2010 22:24:11 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Active clients]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=611</guid>
		<description><![CDATA[If you just look at authentication, and you ignore hardware-based  solutions and look at cost (where cost means the hard dollar cost per  user that an organziation will have to pay including help desk, user  education, systems integration, operating costs, fees, etc.) plotted  against the level of security required, my intuition [...]]]></description>
			<content:encoded><![CDATA[<p>If you just look at authentication, and you ignore hardware-based  solutions and look at cost (where cost means the hard dollar cost per  user that an organziation will have to pay including help desk, user  education, systems integration, operating costs, fees, etc.) plotted  against the level of security required, my intuition is that the  tradeoffs look roughly like this:</p>
<p><a href="../wp-content/uploads/2010/04/cost-v-security-v61.png"><img src="../wp-content/uploads/2010/04/cost-v-security-v61.png" alt="" width="538" height="368" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=611</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Thoughts on the state of identity</title>
		<link>http://www.incontextblog.com/?p=604</link>
		<comments>http://www.incontextblog.com/?p=604#comments</comments>
		<pubDate>Wed, 09 Jun 2010 21:04:17 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Active clients]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Selectors]]></category>
		<category><![CDATA[User Experience]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=604</guid>
		<description><![CDATA[I created these slides in response to a request 48 hours ago from Harry Halpin of the W3C&#8217;s social web experts group for a briefing on my views of the identity ecosystem.
SWXG 2010.6.9 v2

If I&#8217;d had a bit more notice I should have added a discussion of the oStatus stack, XDI, RDF syndication and other [...]]]></description>
			<content:encoded><![CDATA[<p>I created these slides in response to a request 48 hours ago from Harry Halpin of the W3C&#8217;s social web experts group for a briefing on my views of the identity ecosystem.</p>
<div style="width: 425px;"><strong style="display: block; margin: 12px 0 4px;"><a title="SWXG 2010.6.9 v2" href="http://www.slideshare.net/ptrevithick/swxg-201069">SWXG 2010.6.9 v2</a></strong><object id="__sse4452859" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=swxg2010-6-9-100609094847-phpapp01&amp;stripped_title=swxg-201069" /><param name="name" value="__sse4452859" /><param name="allowfullscreen" value="true" /><embed id="__sse4452859" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=swxg2010-6-9-100609094847-phpapp01&amp;stripped_title=swxg-201069" name="__sse4452859" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<div style="width: 425px;"></div>
<p>If I&#8217;d had a bit more notice I should have added a discussion of the oStatus stack, XDI, RDF syndication and other things related to the pubsub of attributes. And VRM.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=604</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Internet of Subjects</title>
		<link>http://www.incontextblog.com/?p=597</link>
		<comments>http://www.incontextblog.com/?p=597#comments</comments>
		<pubDate>Thu, 06 May 2010 09:36:47 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Data Portability]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Higgins]]></category>
		<category><![CDATA[Personal Data Stores]]></category>
		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=597</guid>
		<description><![CDATA[Well, here&#8217;s a new organization, iosf.org, that I should have known about. I hope I can get to their event. It&#8217;s on July 5th and I have to be in Paris on the 6th for an Information Card workshop with FC2. Hmmm&#8230;should be possible.
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.incontextblog.com/wp-content/uploads/2010/05/ioslondon200.jpg" alt="" hspace="10" vspace="10" align="left" />Well, here&#8217;s a new organization,<a href="http://www.iosf.org/"> iosf.org</a>, that I should have known about. I hope I can get to their event. It&#8217;s on July 5th and I have to be in Paris on the 6th for an Information Card workshop with FC2. Hmmm&#8230;should be possible.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=597</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The end of the beginning</title>
		<link>http://www.incontextblog.com/?p=581</link>
		<comments>http://www.incontextblog.com/?p=581#comments</comments>
		<pubDate>Wed, 21 Apr 2010 17:35:11 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Selectors]]></category>
		<category><![CDATA[User Experience]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=581</guid>
		<description><![CDATA[The open identity landscape today is semi-organized chaos. At an organizational level is perceived of as Kantara vs. ICF vs. OIDF vs. OIX vs. Identity Commons vs. &#8230;. At a tech level it is perceived of as OpenID vs. I-Cards vs. SAML vs. passwords vs. OpenID vNext vs. Oauth vs. UMA vs&#8230;.  Some have buzz. [...]]]></description>
			<content:encoded><![CDATA[<p>The open identity landscape today is semi-organized chaos. At an organizational level is perceived of as Kantara vs. ICF vs. OIDF vs. OIX vs. Identity Commons vs. &#8230;. At a tech level it is perceived of as OpenID vs. I-Cards vs. SAML vs. passwords vs. OpenID vNext vs. Oauth vs. UMA vs&#8230;.  Some have buzz. Some have security. Some have maturity. There&#8217;s been lots of great work, and lots of progress. But all the same, <strong>we&#8217;re at an inflection point. </strong></p>
<p>What our experience with open tech has taught us is that no single approach can address all of the use cases, security levels, levels of convenience, etc.  The fact both OpenID and I-Cards are underway with next generation efforts that will introduce at least some <em>breaking</em> changes speaks for itself. And username/password isn&#8217;t going away either. Heterogeneity is here to stay.</p>
<p>Let me illustrate. If you just look at authentication, and you ignore hardware-based solutions and look at cost (where cost means the hard dollar cost per user that an organziation will have to pay including help desk, user education, systems integration, operating costs, fees, etc.) plotted against the level of security required, my intuition is that the tradeoffs look roughly like this:</p>
<p><a href="http://www.incontextblog.com/wp-content/uploads/2010/04/cost-v-security-v61.png"><img src="http://www.incontextblog.com/wp-content/uploads/2010/04/cost-v-security-v61.png" alt="" width="538" height="368" /></a></p>
<p>Or here&#8217;s another way to frame the issue. Different tech is suitable for different &#8220;volume&#8221; vs. long tail use cases:</p>
<p><a href="http://www.incontextblog.com/wp-content/uploads/2010/04/long-tail-v2.png"><img class="alignnone size-full wp-image-591" title="long tail v2" src="http://www.incontextblog.com/wp-content/uploads/2010/04/long-tail-v2.png" alt="" width="560" height="395" /></a></p>
<p>If you need a third perspective, consider certification and the need for trust frameworks. The OIDF and ICF both jointly created the OIX organization to meet this (clearly cross-protocol) need. Yet there is still confusion about how this relates to Kantara&#8217;s IAF. Clearly certification and trust frameworks cut across the existing lines. Every technology needs a certification listing service. Every technology needs interoperability testing.</p>
<p>Based on just these examples of cross-cutting realities, I contend that most of the non-profits as we know them have outlived their usefulness <em>in their current form</em>:<em><br />
</em></p>
<ul>
<li><strong>High overhead.</strong> Each spends money duplicating the resources, executive directors, infrastructure, etc. The result is that less work gets done promoting, say, OpenID, than it could otherwise.</li>
<li><strong>Lack of coherent messaging. </strong>In the enterprise market, for example, the louder each non-profit shouts the more the buyers sit on the fence and say &#8220;let&#8217;s wait and see which cat emerges from the bag.&#8221;</li>
<li><strong>Poor and inconsistent UX</strong>. The user experiences of each isn&#8217;t great. Try putting two or three together and the result is nonsensical.</li>
<li><strong>Not enough focus on relying parties</strong>. Relying parties are who adopt this stuff. We need clear messaging and we need great enabling libraries and services. After all, Janrain can only do so much!</li>
</ul>
<p><strong>The next step is consolidation</strong></p>
<p>Creating a new consolidated non-profit for open identity that would combine existing groups and thereby create something quite different and new is an obvious and unoriginal idea. The question, as ever, is one of timing. Is now the moment? Kantara tried to pull this off a couple years ago, but that was too early. As my fellow board members on the ICF can attest, my sense of timing on this topic is too hurried. But all the same I can&#8217;t shake the feeling that now is the time to try to make some kind of progress. So I continue to have private conversations with friends and colleagues.</p>
<p>To protect the innocent I won&#8217;t name names, but I get generally supportive reactions. A recent plum was, &#8220;Good idea Paul, we&#8217;ll sit on the sidelines and watch you run around getting arrows in your back; we might even pull one out for you.&#8221;  For the moment and the record, I&#8217;m doing this without being duly authorized by Identity Commons, ICF, Kantara, or any other board I sit on.</p>
<p>Beyond reducing duplication and waste the most compelling argument for NewCo (what Bob Blakley might call IDTBD 2.0) is that we have no place to work on critical projects including:</p>
<ul>
<li><strong>Cross protocol analytic framework </strong>(and common messaging). We need an analytic framework that helps RPs decide what open technology is right for what use case, cost target, LOA, etc. For example, I think we need a project team put together that takes my sketch of cost vs. security and calibrates it to actual &#8220;all in&#8221; costs and security levels by studying real world deployments. Let&#8217;s move away from the religious wars over whose tech is better.</li>
<li><strong>A consistent UX</strong> across technologies. The Kantara ULX group is doing good work but lives in a silo beside the OIDF&#8217;s efforts.</li>
<li>A set of <strong>cross-protocol RP libraries</strong> and enabling technologies.</li>
<li><strong>R&amp;D on active clients</strong>. A consensus has emerged. An active client has to build on, and work with OpenID (and other protocols) and not compete with it(them). I think an active client must also be a password manager. An active client must be optional; things should work without it and work &#8220;better with&#8221; it. The ICF is supposed to support active clients, yet work on OpenID v.Next goes on at the OIDF. This makes no sense to either organization.</li>
</ul>
<p>Lastly, from a marketing point of view a startling amount of energy would be created by consolidating several websites into one. Of course true alignment will take years, but the perception of alignment even if we just start at the top would be powerful.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=581</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Apps and Personal Data Stores</title>
		<link>http://www.incontextblog.com/?p=504</link>
		<comments>http://www.incontextblog.com/?p=504#comments</comments>
		<pubDate>Mon, 22 Mar 2010 01:25:39 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Azigo]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Higgins]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[Selectors]]></category>
		<category><![CDATA[VRM]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=504</guid>
		<description><![CDATA[This post presents an architecture comprised of apps, a dashboard, and a personal data store (PDS) that can be implemented by multiple developers, hosted by multiple operators over an open, personal data network and whose goal is to give users more control over their own identity (personal data, profiles, preferences, affiliations, and relationships). It is [...]]]></description>
			<content:encoded><![CDATA[<p>This post presents an architecture comprised of apps, a dashboard, and a personal data store (PDS) that can be implemented by multiple developers, hosted by multiple operators over an open, personal data network and whose goal is to give users more control over their own identity (personal data, profiles, preferences, affiliations, and relationships). It is in support of aspirations that have been widely reported by others and called variously <a href="http://cyber.law.harvard.edu/projectvrm/Main_Page">VRM</a>, <a href="http://dataportability.org/">data portability</a>, user-centric identity, the Data Web, <a href="http://ojphi.org/htbin/cgiwrap/bin/ojs/index.php/fm/article/viewArticle/1068">Augmented Social Network (2003)</a>, and so on.</p>
<p><a href="http://www.incontextblog.com/wp-content/uploads/2010/03/tla-2.0.101.png"><img class="alignnone size-full wp-image-576" title="top level architecture (12)" src="http://www.incontextblog.com/wp-content/uploads/2010/03/tla-2.0.101.png" alt="" width="813" height="571" /></a></p>
<p>I&#8217;ve annotated the diagram above with little &#8220;H&#8221; and &#8220;A&#8221; markers so you can see specifically the areas that Higgins and Azigo are working on respectively. Lots of other folks are also working on other parts of the picture too, of course.</p>
<p><strong>Apps</strong></p>
<p>Apps are of course the most important kind of component since they are what the end user sees and appreciates. Apps gain access to the user&#8217;s data by making calls (e.g. <em>getAttribute</em>)  to an API exposed by the <em>PDS Client</em>. Architecturally, we&#8217;ve seen the need to support both conventional kinds of apps: web, mobile (iPhone, Android, etc.), and desktop, as well as a more unusual kind of app, I&#8217;ll call a <em>Javascript app</em>.  In this latter case Javascript is fetched from a web service (e.g. from <a href="http://www.kynetx.com/">Kynetx</a> KNS) injected locally into your browser by a browser extension. This same browser extension exposes the same PDS Client API to this Javascript program.<br />
<strong> </strong></p>
<p><strong>Dashboard</strong></p>
<p>The dashboard is an admin GUI app for your personal data. It is an occasional-use tool that provides: (a) a control panel to manage the permissioning policies that control which of your attributes are shared with whom (including so-called &#8220;selector&#8221; functionality to approve the release of your info)  (b) a dashboard GUI to see and manage all of your identity data attributes (including profile data, credentials, friends lists, etc.) whether stored in your own PDS or managed by others (c) a place to directly enter self-asserted attributes (d) an embedded app marketplace (e) a canvas area where apps can extend the UI to add their own admin interfaces (f) a place to import &amp; manage your i-cards and OpenID OP relationships.</p>
<blockquote><p>ASIDE: <em>Dashboard</em> is a new word I&#8217;m trying  out. The reality is that this piece of software is a bit of a swiss army  knife where each blade/tool is called something different. A few examples: Microsoft  calls the aspect that pops up to give notice and consent to release a set  of attributes an <em>identity selector</em>. Inside Google they call  identity-related client add-ons to a browser an <em>active client</em>. The &#8220;show  me all of my stuff&#8221; aspect does sound like a <em>dashboard</em>. On the other hand, the  permissioning aspect is something Eve would call a <em>relationship manager</em> (or I  think she would). And I think Bob Blakley would too.</p></blockquote>
<p>The dashboard combines aspects of earlier client efforts. In 2006-2007 we saw Information Card Selectors like <a href="http://en.wikipedia.org/wiki/Windows_CardSpace">Windows  CardSpace</a> as well as the Higgins selectors provide an interface to view and manage multiple digital identities displayed as visual cards, as well as provide notice and consent to the release of your selected digital identity. In 2009 Azigo augmented the selector concept support for  Kynetx apps in <a href="http://azigo.com/">Azigo</a> (along with cross-platform and card roaming support). Prototypes shown by Microsoft (e.g. <a href="http://self-issued.info/?p=235">OpenID Active Client</a>) and Higgins at IIW in 2009 added OpenID support thus demonstrating multi-protocol support. <a href="http://mozillalabs.com/blog/2010/03/account-manager/">Mozilla  Lab&#8217;s Account Manager</a> is doing some great work in this area. The Higgins project is working on a next-generation client as part of the <a href="http://wiki.eclipse.org/Active_Client_Overview">Higgins 2.0 Active Client</a> expected in 2011.</p>
<p><strong>Personal Data Store</strong></p>
<p>A PDS is a web service that works on your behalf, giving you more control over your own personal data whether it is stored in the PDS or managed elsewhere. PDS stores <em>local</em> attributes in blinded form so that only the user has the decryption key&#8211;not the PDS service provider. The PDS is an idea that has been underdevelopment for years. For some background see <a href="http://blog.joeandrieu.com/2007/07/26/vrm-and-personal-datastores/">Joe  Andrieu</a>, <a href="http://blog.joeandrieu.com/2007/06/14/vrm-the-user-as-point-of-integration/">Joe  again</a>, and <a href="http://informationanswers.com/?p=506">Iain Henderson</a>. As part of Higgins 2.0 the <a href="http://wiki.eclipse.org/Personal_Data_Store_2.0">PDS</a> is being developed. Another interesting PDS development project is <a href="http://themineproject.org/">Mine</a>!</p>
<p><strong>PDS Client </strong></p>
<p>The PDS Client has no UI, but provides an API for apps that wish to read/write  attributes from the PDS. Here are some of its functions:</p>
<ul>
<li>Maintains (and syncs to the PDS and other clients) the user’s &#8221;permissions&#8221;–the decisions that the user has make as to who (what app or relying party) has access to what attributes. For example, the first time a new app/RP asks for a certain set of attributes, the PDS Client will trigger the PDS Dashboard to present the policy decision to the user. The next time this same request happens, the PDS Client remembers the grant and usually doesn’t have to bother the user about it this time.</li>
<li>Maintains a local copy of some or all of the person’s personal data stored in the remote PDS</li>
<li>Maintains an OAuth WRAP access token that it gets by authenticating itself to an external authentication service. It passes this token along in XDI messages to the remote PDS service.</li>
<li>Can be configured to encrypt attribute values before they are sent over the wire (e.g. in XDI messages) to the remote PDS</li>
<li>Contains a local Security Token Service (STS) that allows it to create and sign SAML (for example) tokens for self-asserted attributes.</li>
<li>Contains an STS client to support remote IdP/STSes managed by external parties (e.g. to support managed i-cards).</li>
<li>Performs cross-context schema mapping.</li>
</ul>
<p>The Higgins 2.0 <a href="http://wiki.eclipse.org/PDS_Client_2.0">PDS Client</a> is packaged as either a C++  or Java code library or as a separate  operating system process (e.g. on  Windows it is a Windows Service).</p>
<p><strong> </strong></p>
<p><strong>Network Protocol</strong></p>
<p><a href="http://www.equalsdrummond.name/">Drummond Reed</a> with his <a href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xdi">OASIS  XDI</a> and OASIS XRI work was first to my knowledge to define an open <em>data web</em>. A few years later Tim published his <a href="http://www.w3.org/DesignIssues/LinkedData.html">Linked Data</a> paper. We&#8217;re starting to see implementations of Linked Data so now the Semweb  folks also have a data web. Both of these approaches are important.</p>
<p>An open community is starting to form around the XDI that is focused on PDS-related use cases and create might be called a <em>profile</em> of XDI in this area. The community is leveraging XDI&#8217;s existing strengths in the areas of identity management integration, security, access control, data sharing and versioning, as well as extending them where needed in order to meet the PDS-related requirements.</p>
<p>This focus probably provides a critical time-to-adoption advantage over the Linked Data effort in this PDS area. Since the objective is interoperability (i.e. an interoperable ecosystem of PDSes and apps over a common protocol) assembling a community focused on this area would seem to be the fasted way to get there. Linked Data (like &#8220;vanilla&#8221; XDI) has a much broader link-all-the-worlds-data-together mission and lacks direct support for many of the PDS-related requirements. As a consequence RDF developers (including Higgins) define ad-hoc extensions to RDF to make it support the PDS use cases that are only interoperable within their own developer community.</p>
<p><strong>PDS Schema</strong></p>
<p>The Higgins PDS uses its own <em>internal</em> schema called the <a href="http://wiki.eclipse.org/Persona_Data_Model_2.0">Persona</a> data model. This is not  to say that the PDS architecture imposes a single ontology on its  clients. Quite the opposite. Every attribute call (e.g. getAttribute)  may request attributes in any vocabulary. As I&#8217;ve mentioned in my <a href="../?p=463">schema mapping post</a>, we follow the philosophy of mapping into and out from the  internal schema.</p>
<p><strong>Authorization Manager</strong> <strong>(AM)</strong></p>
<p>The AM provides the &#8220;back end&#8221; authorization manager for access  control  of attributes managed by data services other than your own PDS.  The Higgins project has been tracking the promising <a href="http://kantarainitiative.org/confluence/display/uma/Home">UMA    Authorization Manager</a> effort that <a href="http://www.xmlgrrl.com/blog/">Eve Maler</a> and others have been developing.</p>
<p><strong>Kynetx KNS</strong></p>
<p>KNS is a web service that serves up compiled Javascript apps for injection into browsers. The app developer uses the Kynetx AppBuilder tool to create apps. Each app is packaged as an information card. The developer puts this app on their website for folks to download and install. If you click on it and already have a PDS Dashboard the new app gets installed in about one second. If you click on it an you don&#8217;t already have a PDS Dashboard, then you download an installation package that includes a Dashboard (with the app pre-installed inside it).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=504</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>ICF input to NS-SOT</title>
		<link>http://www.incontextblog.com/?p=498</link>
		<comments>http://www.incontextblog.com/?p=498#comments</comments>
		<pubDate>Sun, 21 Mar 2010 22:13:08 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Public Policy]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=498</guid>
		<description><![CDATA[At RSA Ely Kahn (Director of Cybersecurity Policy at National Security Staff) and some of his contractors/staff met with members of the ICF board as well as with members of the OIDF and OIX boards. During the meeting the foundations were asked to respond to a questionnaire that was designed inform the &#8220;National Strategy for [...]]]></description>
			<content:encoded><![CDATA[<p>At RSA Ely Kahn (Director of Cybersecurity Policy at National Security Staff) and some of his contractors/staff met with members of the ICF board as well as with members of the OIDF and OIX boards. During the meeting the foundations were asked to respond to a questionnaire that was designed inform the &#8220;National Strategy for Secure Online Transactions&#8221; (NS-SOT) &#8211;a name chosen to sidestep the big brother alarm raised whenever words like <em>identity management</em> are used by the feds. He mentioned that Obama would be announcing this strategy in June.</p>
<p>Instead of answering the questionnaire the ICF board decided to write and send this <a href="http://www.incontextblog.com/wp-content/uploads/2010/03/icf-ns-sot-response-final.pdf">NS-SOT ICF Response</a> to Ely. Ely is one of the good guys, so I&#8217;m glad to spend time on this sort of thing. The jist of the paper is that relatively small, short term (not FY12 !) investment in turning a few Federal agencies into buyers of federated/externalized identities would jump-start an entire ecosystem. It would be particularly good for i-cards and OpenID.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=498</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>PPID Interoperability</title>
		<link>http://www.incontextblog.com/?p=488</link>
		<comments>http://www.incontextblog.com/?p=488#comments</comments>
		<pubDate>Mon, 22 Feb 2010 21:14:04 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Information Cards]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=488</guid>
		<description><![CDATA[This post is an attempt to summarize in one place some interoperability issues related to IMI PPID computation that we&#8217;ve run into as we get ready for RSA next week.
Specifications
There are two specifications of how to compute the PPID:

ISIP 1.0
IMI 1.0 (same as ISIP 1.5 submission). A clarification was added as described here: (see  Changes [...]]]></description>
			<content:encoded><![CDATA[<p>This post is an attempt to summarize in one place some interoperability issues related to IMI PPID computation that we&#8217;ve run into as we get ready for RSA next week.</p>
<p><strong>Specifications</strong></p>
<p>There are two specifications of how to compute the PPID:</p>
<ol>
<li>ISIP 1.0</li>
<li>IMI 1.0 (same as ISIP 1.5 submission). A clarification was added as described <a href="http://www.oasis-open.org/committees/document.php?document_id=29512&amp;wg_abbrev=imi">here</a>: (see  <em>Changes Made in ISIP V1.5</em> on page 72). It says: &#8220;To provide a migration path from non-EV to EV certs, the RP PPID Seed for a non-EV cert containing the same OLSC values is the same as for an EV cert, resulting in the same PPID&#8221;</li>
</ol>
<p>In addition, <a href="http://support.microsoft.com/kb/969419">here’s a very detailed article about this calculation</a>, with example values. <a href="http://self-issued.info/?p=80">Mike</a> suggests that anyone wanting to debug their implementation might want to check its calculations against these known-good values.</p>
<p><strong>CardSpace Versions</strong></p>
<ol>
<li>.Net 3.0 version: implements ISIP 1.0 according to <a href="http://self-issued.info/?p=80">Mike</a></li>
<li>.Net 3.5 version: implements IMI 1.0 according to <a href="http://self-issued.info/?p=80">Mike</a></li>
<li>.Net 3.5 SP1 version: (i) implements IMI 1.0a for token of p-card (ii) implements both ISIP 1.0, and IMI 1.0 to find a p-card that matches the PPID credentials of a &#8220;backed&#8221; m-card.</li>
<li>.Net 3.5 SP2 version: same as #3 above</li>
<li>CardSpace 2.0 beta version: same as #3 above</li>
</ol>
<p><strong>Azigo Versions</strong></p>
<ul>
<li>2.0.0.35 &#8211;&gt; 2.0.0.40 versions: implement IMI 1.0</li>
</ul>
<p><strong>Higgins STS</strong></p>
<ul>
<li>Higgins 1.1 STS implements IMI 1.0</li>
</ul>
<p><strong>Avoco Versions</strong></p>
<ul>
<li>It appears to use different PPID-related logic than CardSpace WRT to finding a matching p-card against the PPID of a backed m-card.</li>
</ul>
<p><strong>Known Incompatibilities (bugs):</strong></p>
<ol>
<li><a href="http://eternallyoptimistic.com/">Pam</a> reported: You can&#8217;t export a p-card backed m-card from Azigo 2.0.0.35 and import into .Net 3.5 SP1 version of CardSpace.</li>
<li>Paul Battersby of Avoco reported: 1) An Azigo Managed card backed by a CardSpace Personal card using a crds imported from CardSpace. 2) An Azigo Managed card backed by an Azigo Personal card using a crds imported from Azigo Desktop selector. In the first case the PPID matches (i.e. the PPID calculated by the selector matches the PPID stored in the managed card). The algorithm uses a Relying Party Id generated from |O=”*.azigo.net”|L=””|S=””|C=””|. The second scenario fails. However, if I force the code to use a Relying Party Id generated from the public key of the certificate then the PPID matches. This is rather strange as the certificates in the Managed cards from both scenarios are exactly the same and the public key should only be used if the certificate is not valid or the Organizational units are empty.</li>
<li>JohnB recently pointed out that Azigo 2.0.0.40 and CardSpace .Net 3.5 SP2 generate different (and thus incompatible) PPID values on p-cards for the PayPal site (site with an EV cert)</li>
</ol>
<p>The first two above are caused by the same set of inter-related issues. The root cause is an inability to validate the certificate of cardpres.azigo.net and as a result Azigo computes the wrong PPID for this site. We thought that we could fix this by including then entire certificate chain in the .crd. We did this today, but there are other related issues and we need another 2 days to deploy a new version of our hosted i-card service (service.azigo.com)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=488</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Schema Mapping Session at IIW</title>
		<link>http://www.incontextblog.com/?p=463</link>
		<comments>http://www.incontextblog.com/?p=463#comments</comments>
		<pubDate>Mon, 09 Nov 2009 21:48:01 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Data Portability]]></category>
		<category><![CDATA[Higgins]]></category>
		<category><![CDATA[Ontologies]]></category>
		<category><![CDATA[Semantic Web]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=463</guid>
		<description><![CDATA[I led a session about schema mapping at IIW last week. The basic idea is this. Rather than trying to get the world to agree to a single schema for attributes (e.g. OpenID AX, ICF Schema Catalog, Plaxo Portable Contacts, etc., etc., &#8230;you know the old saw that the great thing about standard is that [...]]]></description>
			<content:encoded><![CDATA[<p>I led a session about schema mapping at IIW last week. The basic idea is this. Rather than trying to get the world to agree to a single schema for attributes (e.g. OpenID AX, ICF Schema Catalog, Plaxo Portable Contacts, etc., etc., &#8230;you know the old saw that the great thing about standard is that there are so many of them (like 75!)) we just let the natural authorities for attributes mint their own URIs.</p>
<p>And while we&#8217;re being lazy, we just sit back and watch as these schema-creators evangelize their particular schema as far and as wide as they wish to. Today the only way an IdP can talk to an RP is if both know how to speak a common schema. This is true regardless of protocol or transport. It is as true of SAML tokens as OpenID attributes.</p>
<p>Its all a form of tight coupling. And tight coupling requires a lot of effort. You know what they say &#8220;consensus is harder than code.&#8221; Experience shows that the richer the schema the higher the costs to get everyone on board, the longer the process takes, and the narrower the diffusion/adoption. These economic realities drive the creation of more and newer schemas in each sub-ecosystem, even when common schemas could theoretically be agreed to.</p>
<p>But if we can&#8217;t all agree to the &#8220;one schema to rule them all&#8221; aren&#8217;t we doomed to a Tower of Babel?</p>
<p><img src="http://www.incontextblog.com/wp-content/uploads/2009/11/babel1.png" alt="" hspace="10" vspace="10" align="left" /></p>
<p>Not entirely. There is another possible route to interoperability. Mapping. Instead of creating N*N mappings between each schema we create 2N mappings into and out from a common, rich, granualr, and horribly complicated schema (that nobody would use <em>directly</em>).</p>
<p>We use a mechanical process (think web service, library, etc.) that maps an <em>input</em> schema into a rich, intermediate schema, and from there to an <em>output</em> schema. This schema mapping process, being both algorithmic and data driven, can live at the RP, in the cloud, or at the IdP, depending on the need.</p>
<p>I will now describe one way to do this schema mapping. I have a personal bias towards declarative approaches that involve rich data and simple algorithms. The mapping rules that I&#8217;m about to describe can themselves be described as data with embedded names of a few simple functions. So that&#8217;s the design approach. Here are the details.</p>
<p>Every input attribute must come from some known namespace (schema name). A set of mapping rules must have already been created; one for each attribute in the input schema. The rule for the specific input attribute is then looked up and applied to transform this input attribute into its equivalent attribute(s) in the internal, intermediate data model (schema). To create the output attribute(s) the process is reversed. The target namespace (schema name) must be known, and a set of mapping rules must have been created for it. The output process takes the attribute in the internal data model, looks up the mapping rule for it and uses this rule to generate the output attribute.</p>
<p>This approach was discussed a lot on the second day of the recent <a href="http://middleware.internet2.edu/tao-of-attributes/">Tao of Attributes workshop</a>, and a some similar thinking was discussed a couple years ago regarding a Common Dictionary Service (CDS) on the <a href="http://identityschemas.org">IdentitySchemas.org</a> list at Identity Commons</p>
<p>The Higgins project is starting work on an open source <a href="http://wiki.eclipse.org/Persona_Data_Model_1.1#UML_Class_Diagram">Persona Data Model</a> that could serve as a common internal schema. A schema that nobody would actually use per se, but useful to map into and out from. We&#8217;re also experimenting with declarative mapping rules.</p>
<p>A quick aside:</p>
<blockquote><p>The straw that broke the camel&#8217;s back for me happened recently. In the ICF&#8217;s Schema Working Group, we created a super-lightweight, email-based process to simply list whatever attribute/claim URIs that any party reasonably suggested they wanted. <a href="http://wiki.informationcard.net/index.php/Claim_Catalog">Here&#8217;s the catalog</a> we created. When Equifax wanted an &#8220;I&#8217;m over 18&#8243; URI we swung into action and minted http://schemas.informationcard.net/@ics/age-18-or-over/2008-11. Cool.</p></blockquote>
<blockquote><p>Then the ICF and OpenID foundations start working together with the GSA and other parts of the Federal government. There&#8217;s a need for a &#8220;Level of Assurance&#8221; 1 claim. No problem. We created http://schemas.informationcard.net/@ics/icam-assurance-level-1/2009-06. Trouble is, when the GSA&#8217;s profile for IMI Infocards was published the URI started with http://idmanagement.gov.</p>
<p>Why? Who knows. That&#8217;s what they wanted. And since (sadly) in SAML there are no sub-namespaces allowed with the URI namespace, one URI is as good as another since all must be treated as an opaque string. So it&#8217;s hard to push back on the &#8220;customer&#8221; and tell them that the attribute should really start off http://schemas.informationcard.net&#8230;  They think that the LOA 1 URI is theirs. To make a separate URI and thus define another schema over such a trifling matter, was all the convincing that I needed to rethink things.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=463</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>OpenID Summit &amp; IIW IX Presentations</title>
		<link>http://www.incontextblog.com/?p=456</link>
		<comments>http://www.incontextblog.com/?p=456#comments</comments>
		<pubDate>Wed, 04 Nov 2009 07:19:45 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Higgins]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[Selectors]]></category>
		<category><![CDATA[User Experience]]></category>

		<guid isPermaLink="false">http://www.incontextblog.com/?p=456</guid>
		<description><![CDATA[
Kantara ULX WG &#8211; a quick intro to what we&#8217;re trying to do
Relationship cards &#8211; newbie intro

]]></description>
			<content:encoded><![CDATA[<ul>
<li><a href="http://www.incontextblog.com/wp-content/uploads/2009/11/ULX-at-OpenID-Summit-Nov-2-2009.pdf">Kantara ULX WG</a> &#8211; a quick intro to what we&#8217;re trying to do</li>
<li><a href="http://www.incontextblog.com/wp-content/uploads/2009/11/Relationship-Cards-IIW-Nov-3-2009.pdf">Relationship cards</a> &#8211; newbie intro</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.incontextblog.com/?feed=rss2&amp;p=456</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
