openid and-usercentric-identity-its-all-about-me-1199787052835912-2

33
Joint Information Systems Committee OpenID and User-Centric Identity: It’s All About Me Nicole Harris, JISC Executive

Upload: nicole-harris

Post on 15-Jun-2015

298 views

Category:

Business


4 download

TRANSCRIPT

Page 1: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

OpenID and User-Centric Identity: It’s All About MeNicole Harris, JISC Executive

Page 2: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

An Apology

Today, I will be saying very little about OpenID

Page 3: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

What are we talking about?

Identity 2.0??

Page 4: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

“in Identity 2.0, usage of identity more closely resembles today's offline identity systems, but with the advantages of a digital medium. As with a driver's license, the issuer provides the user with a certified document containing claims. The user can then choose to show this information

when the situation requires.”

Burton Group

Page 5: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

What are we talking about?

The multiple identity problem?

Page 6: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Multiple Identities

Page 7: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Page 8: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Page 9: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Page 10: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Page 11: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Approaches to managing multiple affiliations

and lots more……

Page 12: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Identity 2.0 Is Too Ill-Defined for Imminent Deployment

Gartner, 9th August 2006

Page 13: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

We are talking about…

What services are users accessing?

Who is responsible?

Page 14: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Access and Identity Within the UK

Service Provider Credentials

Single Central Identity Provider

Devolved A

uthentication

User C

entric Identity??

Page 15: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Managing Identity or..

Page 16: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Managing Resource Access

Page 17: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

What’s the difference?

Page 18: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

It’s All About Me

Page 19: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

What is my Identity? Personal Information

27th April 1977 [email protected]

Victoria

07734 058308

Page 20: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

What is my Identity? Stuff I like

Page 21: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

What is my Identity? Stuff I am Allowed to do

Page 22: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Disconnecting Identity from Resources

Page 23: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Can I manage my own identity?

Page 24: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Can I manage my own identity?

Page 25: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Can I manage my own identity?

Page 26: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Redefining the institutional role as identity provider and service provider for students

Page 27: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

The role of the broker

Page 28: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Direct Relationship between User-Institution-Resource

Page 29: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

No Direct Relationship Between User-Institution-Resource

Page 30: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Questions

When is it better for the institution to physically host the resource for an end-user? Institution provided blogs, wikis, google video etc.?

When is it better for the institution to manage an identity for the end-user? (registration / revocation).

When is it better for the institution to verify identity for service providers? (authentication)

When is it better for the institution to broker access to resources for the end-user (authorisation process)? Can this be disaggregated from all service providers?

Do we have the infrastructure to allow institutions to broker access against a user-managed identity?

Where will this be important?

Who benefits, and where?

Page 31: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

So, OpenID?

Important role to play in providing the infrastructure to allow us to move forward.

Better than e-mail verification.

Role for institutions as an OpenIDprovider?

Links to ‘policy-lite’ approaches.

Single digital identity very important.

Great for people without an identity provider.

Page 32: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

What is JISC Doing?

Full review of access and identity management against the Information Environment.

Identity Project: reporting soon. Focus on current landscape within institutions.

OpenID / external identity provision study to be commissioned.

Identity Metasystems study to be commissioned.

Personalisation study.

E-Portfolio work: ULN??

Importance of links to repositories work.

Users and Innovation Programme.

Page 33: Openid and-usercentric-identity-its-all-about-me-1199787052835912-2

Joint Information Systems Committee

Contacts

[email protected]

[email protected]

www.jisc.ac.uk