don thibeau, executive director, openid foundation (oidf) drummond reed, executive director,...

21
Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

Upload: robert-preston

Post on 18-Jan-2018

220 views

Category:

Documents


0 download

DESCRIPTION

3 Most are closed ◦Visa, MasterCard, AMEX credit card networks ◦Phone networks ◦ATM networks Some are open ◦Political, social, religious organizations Some are explicit (legal agreements) Some are implicit (social contracts)

TRANSCRIPT

Page 1: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

Don Thibeau,Executive Director, OpenID Foundation (OIDF)

Drummond Reed,Executive Director, Information Card Foundation (ICF)

Page 2: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

2

BackgroundThe Open Identity FrameworkHow the OIF will drive adoptionNext steps

Page 3: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

3

Most are closed◦ Visa, MasterCard, AMEX credit card networks◦ Phone networks◦ ATM networks

Some are open◦ Political, social, religious organizations

Some are explicit (legal agreements)Some are implicit (social contracts)

Page 4: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

4

In April, the U.S. government asked the OIDF and ICF to create a trust framework for OpenID and Information Cards◦ This would enable U.S. government websites to begin

accepting OpenID and Information Card credentialsGSA ICAM relying party requirements:

◦ Open (not just US citizens)◦ Explicit (legal documentation of certification to NIST

levels of assurance)◦ Internet scale

Page 5: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

5

See the first set of deliverables at IDmanagement.gov◦ Identity Scheme Adoption Process (ISAP)◦ Trust Framework Provider Adoption Process (TFPAP)

Two open identity scheme profiles completed under the ISAP process

Page 6: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

6

OpenID LOA 1 profile is now implemented across tens of millions of OpenID accounts◦ Test/pilot infrastructure built◦ Multiple IdP implementations tested◦ Pilot customer (National Institute of Health) with test site

IMI Information Cards 1.0 profile covers LOA 1, 2, and non-PKI 3

Page 7: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

7

How to best implement the profilesHow to best implement the trust framework

IdentityProviders

(IdPs)RelyingParties(RPs)

Policy interop

Technical interop

Page 8: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

8

In August, OIDF and ICF published a joint white paper saying an open, Internet-scale approach to trust frameworks must be:◦ Open to any trust framework authority◦ Open to all IdPs and RPs◦ Open to any qualified assessor/auditor◦ Open to any qualified certification process (including self-

certification)◦ Open to evolution and adaptation to market forces

Page 9: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

9

An open Internet-scale trust framework must also:◦ Offer both Levels of Assurance (LOA) for IdPs and Levels

of Protection (LOP) for RPs◦ Provide a means for dealing with liability◦ Provide a simple, useful, scalable listing service◦ Be open and transparent in its dealings, use public

documents written in plain language, and provide frequent reports on all activities

Page 10: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

10

The following slide shows the basic design reflecting the OIF principles

It illustrates the relationships between the four parties connected by OIF legal agreements◦ The OIF TFP itself◦ Auditors/assessors◦ Identity providers◦ Relying parties

Page 11: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

Trust framework agreementsOptional direct agreements

IdentityProviders

(IdPs)RelyingParties(RPs)

Users

Trust Framework Provider(the Open Identity Framework)

auditors/assessors

trust framework authorities

Page 12: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

12

The OIF design explicitly supports at two levels of interoperability◦ Technical certification listings drive adoption before the

trust layer is required◦ Policy certification listings drives adoption where explicit

trust is requiredSelf-certification and third-party certification is

supported at both layersTechnical and policy requirements (“profiles”) can

be reused at both layers

Page 13: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

IdentityProviders

(IdPs)RelyingParties(RPs)

Trust Framework Provider(the Open Identity Framework)

auditors/assessors

trust framework authorities

Technical CertificationListings

Technical InteropRequirements

Page 14: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

IdentityProviders

(IdPs)RelyingParties(RPs)

Trust Framework Provider(the Open Identity Framework)

auditors/assessors

trust framework authorities

Technical CertificationListings

Policy CertificationListings

Policy InteropRequirements

Page 15: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

EfficiencyOpenness/TransparencyCredibility/AccountabilityUser experience

15

Page 16: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

The OIF makes it easy for anyone of any size to ensure technical or policy interop with their choice of profiles

Eliminates the n-squared problem of multi-lateral interop testing or trust agreements◦ Quickly become unwieldy for even a small number of

IdPs and RPsGrows the market for everyone

◦ The “network effect for trust”

16

Page 17: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

17

Properly implemented, the OITF provides an open, transparent process for trusted identity transactions◦ Both within and between communities

Helps protect participants from collusion or anti-trust concerns

Anticipates cross-border data protection issues

Page 18: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

18

Each participant (policy authority, IdP, RP, assessor/auditor) reinforces the credibility of the entire model

Mutual accountability of all participantsEnhanced by government participation

◦ Gov’ts serve as the initial “trust anchors”

Page 19: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

19

Increased interoperability of Internet identity across websites

More consistent ceremony leads to lower login or transaction abandonment at RPs

Consistent trust mark raises user confidence

Page 20: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

20

Cost efficiency◦ Lower legal, design, and operations costs◦ Lower overhead for assessors/auditors, IdPs, and RPs

who need certificationProcess efficiency

◦ Single entity for negotiation of MOAs with policy authorities

Effectiveness◦ 1+1=3

Page 21: Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)

21

Please contact either foundation with questions or comments

[email protected]@informationcard.net

Let us know if your organization is interested