I was reading an interesting article today from Aviation Week on airport security screening. Of course we all have heard about, and large numbers of us have complained about, the recent changes at the airport. We jockey lines to try and avoid the full body scanners and possible pat-downs. I know most people are not doing this to avoid security but to avoid embarrassment or at least perceived embarrassment. This article made me think more about identity and traveling and some of the work that is being done today to improve identity and authorization decisions within the government sector.
We all have heard that air travel is a privilege - one generated out of the convenience of time. I can go anywhere without having to fly - it just may take a lot longer. In that vein I begin to wonder if people are ready to accept the need for better identity assurance at a security screening checkpoint to make traveling easier and maybe safer. What if we had a card based credential that allowed a user to scan the credential prior to entering a metal detector? The credential would ideally carry the same level of assurance of any ICAO travel document and could be issued by a nation, such as a passport, or could be issued by the private sector. The traveller would scan their card immediately before entering the metal detector. While the traveller is passing through the scanning device an automated check of the credential would allow personnel to know if the credential presented was valid and combined with the visual check of the card would allow match of person to the credential. Using this combination could increase the level of assurance of identity of the traveller. If the credential does not properly validate then some additional screening could be performed.
If we take it one step further we could incorporate some of the work being done in the government with Backend Attribute Exchange, aka BAE, which would allow the system to reach back to the credential issuer or potentially a National Travel Blacklist, to see if there are any reasons to further screen the individual. These checks could be performed in seconds, the time it takes for a person to step through a metal detector and make it through the security area.
Of course in such a idealized system one would need to consider the issues of privacy and the need to ensure tracking information is not being maintained in the system. Integrity and availability of the system would be critical to ensure minimized additional screening. For the frequent, trusted, traveler this may mean a faster and easier trip through security at the airport and could provide a basis for a system that adds to the security environment for all air passengers.
Something to think about.
- Posted using BlogPress from my iPad
Some personal thoughts on improving security for users of online services.
Wednesday, February 9, 2011
Sunday, February 6, 2011
Mixed Messages
The beginning of this past week I was getting on a plane to head to the left coast when I saw, what I thought was, a good piece on Headline News on the National Strategy for Trusted Identity in Cyberspace aka NSTIC. It was a quick overview but they seemed to have gotten the message right - that it was an effort to get industry to improve the capabilities for online identity. The idea around NSTIC is that the government and industry would work together to define/refine standards to ensure that it was not a set of stovepipe identity solutions that could not interoperate; work together so that the systems would be secure; and to, in the process, protect privacy as appropriate.
I was somewhat encouraged - mainstream media had seemed to actually understand the effort .... and then a few hours later I saw the headline Why You Should Trust Apple More Than the U.S. Commerce Dept. With Your Universal Online ID
POP goes the bubble. Here we have someone writing for Fast Company proposing a corporately patented idea as the right approach. Now we know that as the standards evolve there will be patent issues and, as in the past, I expect them to be resolved for the greater good, but this article seems to suggest that Commerce is going to hold your identity and everything is in the governments control. This is not the vision of NSTIC that I see, or anyone that I know and work with sees.
If you want a vision of what NSTIC is look no further than the US Government employee ID, the PIV card. Here a standard was developed for internal government use. It had technical and policy aspects and required the use of Government run or Government contracted identity providers. But then industry realized that the technical specifications of the card provided a good base for non-governmental people. What happened next - well government and industry worked on refining the standard for non-governmental work. The identity issuers were now private industry. The card issuers we now private industry. The only thing the government did to stay involved was to crate a test program around the standard that would ensure that the credential could be trusted ... and PIV-I was born.
This is what NSTIC envisions - a public-private partnership where good standards are made better through joint discussion; testing programs are put in place to ensure that products and services meet a set of standards and private industry provides these products and services to the masses.
How hard is that to understand? I hope Fast Company spends some time researching so they can criticize where it is deserved.
- Posted using BlogPress from my iPad
I was somewhat encouraged - mainstream media had seemed to actually understand the effort .... and then a few hours later I saw the headline Why You Should Trust Apple More Than the U.S. Commerce Dept. With Your Universal Online ID
POP goes the bubble. Here we have someone writing for Fast Company proposing a corporately patented idea as the right approach. Now we know that as the standards evolve there will be patent issues and, as in the past, I expect them to be resolved for the greater good, but this article seems to suggest that Commerce is going to hold your identity and everything is in the governments control. This is not the vision of NSTIC that I see, or anyone that I know and work with sees.
If you want a vision of what NSTIC is look no further than the US Government employee ID, the PIV card. Here a standard was developed for internal government use. It had technical and policy aspects and required the use of Government run or Government contracted identity providers. But then industry realized that the technical specifications of the card provided a good base for non-governmental people. What happened next - well government and industry worked on refining the standard for non-governmental work. The identity issuers were now private industry. The card issuers we now private industry. The only thing the government did to stay involved was to crate a test program around the standard that would ensure that the credential could be trusted ... and PIV-I was born.
This is what NSTIC envisions - a public-private partnership where good standards are made better through joint discussion; testing programs are put in place to ensure that products and services meet a set of standards and private industry provides these products and services to the masses.
How hard is that to understand? I hope Fast Company spends some time researching so they can criticize where it is deserved.
- Posted using BlogPress from my iPad
Location:the stratosphere
Friday, January 28, 2011
Moving ahead with reduced identities
I had lunch last week with an old colleague. During the lunch we had a good chat on NSTIC. One of the points she brought up was the education aspect - the fact that to most people this whole cyber security thing is very foreign and that there are many things that exist today that people do not realize bring additional trust to what they do online.
I have been thinking about that for a while. Especially in relation to the work that I have been doing on what effectively is credential re-use. She was correct in that most people do not know to look for the green bar in the browser indicating the extra diligence to validate the site. I think that it is a case of people not knowing why it is there and what it brings. But I also think the same is true of identity re-use. I think people do it today and do not realize it.
Now I do not mean just the re-use of drivers licenses, Social Security numbers and the such but of online identities. I started to think about my own environment. I use my Google identity to use many things today - the normal Gmail, Calendar etc but also using it to log onto other applications on my iPad, laptop and Android phone. I use my OpenID to access ToodleDo and other sites and many applications that I use leverage SAML, Oauth and OpenID to allow me to take advantage of credential re-use. Of course in a lot of these cases I also see Facebook and Twitter options for login so I have to imagine that people are using these rather than create yet another account.
I think the strength and advantage of NSTIC is the possibility that in a few years I will be able to do all my online functions using a small set of identities. I may always have that Yahoo mail address so getting rid of all but one is unlikely but if I can get to 3 that would be great. And at that point I hope I will be able to do what I do today with my OpenID identity and use functions like CallVerifID when the transaction calls for that level of additional authentication.
So yes there is possibility - and now we just need to decide which we need to do first - get infrastructure available or get people educated as to what they can do today as a staring point.
Some things for thought .... I hope.
- Posted using BlogPress from my iPad
I have been thinking about that for a while. Especially in relation to the work that I have been doing on what effectively is credential re-use. She was correct in that most people do not know to look for the green bar in the browser indicating the extra diligence to validate the site. I think that it is a case of people not knowing why it is there and what it brings. But I also think the same is true of identity re-use. I think people do it today and do not realize it.
Now I do not mean just the re-use of drivers licenses, Social Security numbers and the such but of online identities. I started to think about my own environment. I use my Google identity to use many things today - the normal Gmail, Calendar etc but also using it to log onto other applications on my iPad, laptop and Android phone. I use my OpenID to access ToodleDo and other sites and many applications that I use leverage SAML, Oauth and OpenID to allow me to take advantage of credential re-use. Of course in a lot of these cases I also see Facebook and Twitter options for login so I have to imagine that people are using these rather than create yet another account.
I think the strength and advantage of NSTIC is the possibility that in a few years I will be able to do all my online functions using a small set of identities. I may always have that Yahoo mail address so getting rid of all but one is unlikely but if I can get to 3 that would be great. And at that point I hope I will be able to do what I do today with my OpenID identity and use functions like CallVerifID when the transaction calls for that level of additional authentication.
So yes there is possibility - and now we just need to decide which we need to do first - get infrastructure available or get people educated as to what they can do today as a staring point.
Some things for thought .... I hope.
- Posted using BlogPress from my iPad
Monday, November 1, 2010
Continuing the Thought
It has been a while since I started this thought but it is not a case that I felt it was a bad thought but more a case that I wanted to let it stew for a while.
In the past few weeks I have seen and heard lots of discussion in regards to attributes so I thought that this renewal of my thought process would be appropriate now.
The last point of discussion here was the thought that we do need to be able to share data to better identify the rights that someone has within an application or transaction. You will note that I use these words, "rights", "application" and "transaction" loosely and this is quite intentional as I believe the fundamental idea spreads across a broad spectrum of transactions.
When we talk about sharing of data, used to identify users, there needs to be agreement as to how we identify the data that is shared. In today's space this has been accomplished through broad agreement on data dictionaries. Sometimes this is based around specific industries while other times it is based nationally. One of the realizations that has come out of working in this area has been that these specific dictionaries can restrict the use of the technologies to a narrow band of the actual user community. While a financial sector has very specific needs to communicate within its sector it has become recognized that the same community has large interaction with other parties where their "standard" data dictionary is not necessarily understood.
Now it is easy in this case to say that maybe a global dictionary is needed or to rely on a national level dictionary that is driven by government standards or by existing best practices. The issue here has always been one of broad agreement and thereby practically implementable solutions. Generally speaking, the broader the agreement, the less practical it is in terms of it's use.
So let's think about how this has worked in other technical areas. DNS is a good example whereby translation is handled through a set of distributed capabilities. Could this idea also be used with a data dictionary service? Let's think of a "centralized" service that translates attribute schema elements between defined data dictionaries. There is no need to share actual data but a method to ensure that "name" is understood as one party communicates to another.
There are of course lots of specific implementation needs to surround this but I would first like to start the discussion to see if it is a needed model before we get to the specifics of things like, knowing who we are dealing with; protecting any sensitive transaction sets; and modeling an implementation to see what is needed from a management and operational perspective to ensure viability and usefulness.
Your thoughts on this are appreciated.
- Posted using BlogPress from my iPad
In the past few weeks I have seen and heard lots of discussion in regards to attributes so I thought that this renewal of my thought process would be appropriate now.
The last point of discussion here was the thought that we do need to be able to share data to better identify the rights that someone has within an application or transaction. You will note that I use these words, "rights", "application" and "transaction" loosely and this is quite intentional as I believe the fundamental idea spreads across a broad spectrum of transactions.
When we talk about sharing of data, used to identify users, there needs to be agreement as to how we identify the data that is shared. In today's space this has been accomplished through broad agreement on data dictionaries. Sometimes this is based around specific industries while other times it is based nationally. One of the realizations that has come out of working in this area has been that these specific dictionaries can restrict the use of the technologies to a narrow band of the actual user community. While a financial sector has very specific needs to communicate within its sector it has become recognized that the same community has large interaction with other parties where their "standard" data dictionary is not necessarily understood.
Now it is easy in this case to say that maybe a global dictionary is needed or to rely on a national level dictionary that is driven by government standards or by existing best practices. The issue here has always been one of broad agreement and thereby practically implementable solutions. Generally speaking, the broader the agreement, the less practical it is in terms of it's use.
So let's think about how this has worked in other technical areas. DNS is a good example whereby translation is handled through a set of distributed capabilities. Could this idea also be used with a data dictionary service? Let's think of a "centralized" service that translates attribute schema elements between defined data dictionaries. There is no need to share actual data but a method to ensure that "name" is understood as one party communicates to another.
There are of course lots of specific implementation needs to surround this but I would first like to start the discussion to see if it is a needed model before we get to the specifics of things like, knowing who we are dealing with; protecting any sensitive transaction sets; and modeling an implementation to see what is needed from a management and operational perspective to ensure viability and usefulness.
Your thoughts on this are appreciated.
- Posted using BlogPress from my iPad
Friday, October 29, 2010
The dangers of blogging ....
I love my iPad. It was not something that I needed but when my fiancée, now my wife, gave it to me for my birthday I was excited. Was this a neat new toy or could it be more than that? Could it be a useful business tool? Well so far it has certainly become a valuable addition to the business tools I have - and it is still a neat new toy that was great to have on our honeymoon.
All that being said my iPad and the associated apps have come with some extra learning. Grabbing a tall coffee here at my local coffee shop I re-read some of my past posts and saw the glaring typos. Why did I not catch them? Well some of them were not typos in the purist sense as the words were spelt correctly - they were just words that did not belong in that context.
Lesson learned - re-read my posts before I post them. If I miss things I hope you all will catch me.
Cheers
- Posted using BlogPress from my iPad
- Posted using BlogPress from my iPad
All that being said my iPad and the associated apps have come with some extra learning. Grabbing a tall coffee here at my local coffee shop I re-read some of my past posts and saw the glaring typos. Why did I not catch them? Well some of them were not typos in the purist sense as the words were spelt correctly - they were just words that did not belong in that context.
Lesson learned - re-read my posts before I post them. If I miss things I hope you all will catch me.
Cheers
- Posted using BlogPress from my iPad
Location:The dangers of coffee shop blogging
- Posted using BlogPress from my iPad
Thursday, October 7, 2010
Identity & Attributes
A couple of days ago I was in Alexandria having a whiteboard session on attribute exchange. I truly believe that people in a room will solve more problems than people on conference calls etc... I know that great ideas can be shared via blogs and e-mail but when it comes to hashing through the real issues I believe a piece of paper and face time are invaluable.
However that was not my original point when I started writing this. When i was in Alexandria I was leaving to get in my car and I spied this ....

I know it is a car and I know you will wonder what it has to do with identity .... but this car is a great analogy. When one first looks at it, if you know nothing about cars of the 20's and 30's you may think "cool car" but when you look at the front and you see a Bugatti symbol your mind may change. But does the initial view tell the true story? Is this a 1930's Bugatti? Well to truly know we need to be able to validate attributes of the car. The extent of what we validate is based on what our intent is. If we are the casual observer and it is just a "cool car" then the initial look is fine - we really do not care if it is a Bugatti. If you are a car nut then you may check the shape of the grill and the suspension to see if it matches the 30s Bugatti since you may want to be able to tell your friends "I saw this cool 30s Bugatti today". However if you are considering buying this car then you will really want to look at its attributes - engine and chassis numbers, papers of ownership and purchase, repair records etc.
Online transactions are no different. If I am commenting on yesterdays no-hitter on Yahoo! Sports then few people care if I know anything about baseball at all. When I buy my signed Halliday card on eBay then the buyer wants a higher level of assurance that he is going to get paid and will do a check of my credit card before shipping or will wait till the check clears. If I am going to proceed to online voting then the checks should be much more extensive.
We have always done all of these additional checks if a non-online transaction value is considered high - why would we not want to make sure that the same is done online. For those that think that those checks invade their rights I think the answer is simple - do commerce as you did it 10 years ago. For me I am hoping I can get to a point where I have one identity that I can use to provide selectable levels of trust so I can blog in the morning and buy Treasury bonds at night and not have to use 10 different identities to do it but will not have to expose any more data than I feel is needed.
And I will keep working to see that this idea is usable for all ....
.... cu
- Posted using BlogPress from my iPad
However that was not my original point when I started writing this. When i was in Alexandria I was leaving to get in my car and I spied this ....
I know it is a car and I know you will wonder what it has to do with identity .... but this car is a great analogy. When one first looks at it, if you know nothing about cars of the 20's and 30's you may think "cool car" but when you look at the front and you see a Bugatti symbol your mind may change. But does the initial view tell the true story? Is this a 1930's Bugatti? Well to truly know we need to be able to validate attributes of the car. The extent of what we validate is based on what our intent is. If we are the casual observer and it is just a "cool car" then the initial look is fine - we really do not care if it is a Bugatti. If you are a car nut then you may check the shape of the grill and the suspension to see if it matches the 30s Bugatti since you may want to be able to tell your friends "I saw this cool 30s Bugatti today". However if you are considering buying this car then you will really want to look at its attributes - engine and chassis numbers, papers of ownership and purchase, repair records etc.
Online transactions are no different. If I am commenting on yesterdays no-hitter on Yahoo! Sports then few people care if I know anything about baseball at all. When I buy my signed Halliday card on eBay then the buyer wants a higher level of assurance that he is going to get paid and will do a check of my credit card before shipping or will wait till the check clears. If I am going to proceed to online voting then the checks should be much more extensive.
We have always done all of these additional checks if a non-online transaction value is considered high - why would we not want to make sure that the same is done online. For those that think that those checks invade their rights I think the answer is simple - do commerce as you did it 10 years ago. For me I am hoping I can get to a point where I have one identity that I can use to provide selectable levels of trust so I can blog in the morning and buy Treasury bonds at night and not have to use 10 different identities to do it but will not have to expose any more data than I feel is needed.
And I will keep working to see that this idea is usable for all ....
.... cu
- Posted using BlogPress from my iPad
Thursday, September 16, 2010
How do we share information?
When we start talking about identity one of the first things in our minds is how we authenticate people. Today we do this many different ways in many different situations - uniforms and badges on police officers, UPS workers in UPS trucks, drivers licenses, passports, Yahoo! mail ids and on and on. Each of these ways of authenticating people is valid, depending on the situation of course.
In the digital world authentication and authorization take on a different scope. Once we authenticate a user, at some level of assurance, we need to determine what rights and privileges that the entity has within the system or transaction. To do this we must determine some other information about the user - some set of attributes. This is where the conversation gets interesting.
When we begin to discuss attributes the first thing we see is an issue with the definition of what an attribute is versus what ones identity is. Some would argue that outside of a biometric that everything is an attribute as it is asserted by someone else. Others would argue that fundamental data sets created by authoritative sources assert identity and are therefore identity assurances, the level of which can be determined by looking at practice of issuance. So as you can see we start the discussion with a range of opinions on what we should even be including in the bucket.
The next challenge in the discussion then becomes how do we understand the differences in attribute descriptors and use. In some cultures ones last name is in fact stated as the first name and exists as such in records. The range of these "discrepancies" within an environment can be extensive and as that environment grows, think globally, it becomes even a greater challenge.
This is not a new discussion but in my next post I will talk about some of the existing approaches and propose an additional idea.
- Posted using BlogPress from my iPad
In the digital world authentication and authorization take on a different scope. Once we authenticate a user, at some level of assurance, we need to determine what rights and privileges that the entity has within the system or transaction. To do this we must determine some other information about the user - some set of attributes. This is where the conversation gets interesting.
When we begin to discuss attributes the first thing we see is an issue with the definition of what an attribute is versus what ones identity is. Some would argue that outside of a biometric that everything is an attribute as it is asserted by someone else. Others would argue that fundamental data sets created by authoritative sources assert identity and are therefore identity assurances, the level of which can be determined by looking at practice of issuance. So as you can see we start the discussion with a range of opinions on what we should even be including in the bucket.
The next challenge in the discussion then becomes how do we understand the differences in attribute descriptors and use. In some cultures ones last name is in fact stated as the first name and exists as such in records. The range of these "discrepancies" within an environment can be extensive and as that environment grows, think globally, it becomes even a greater challenge.
This is not a new discussion but in my next post I will talk about some of the existing approaches and propose an additional idea.
- Posted using BlogPress from my iPad
Subscribe to:
Posts (Atom)