kantara trust frameworks 2016 05-08

26
Trust Frameworks Explained (in 20 minutes or less) Andrew Hughes [email protected] KantaraInitiative.org

Upload: andrew-hughes

Post on 24-Jan-2017

228 views

Category:

Internet


2 download

TRANSCRIPT

Page 1: Kantara trust frameworks 2016 05-08

Trust Frameworks Explained (in 20 minutes or less)

Andrew Hughes [email protected]

KantaraInitiative.org

Page 2: Kantara trust frameworks 2016 05-08

About the Kantara Initiative

2

Page 3: Kantara trust frameworks 2016 05-08

What is Kantara? Non-profit founded in 2009. Comprises 60+ Leading Organizations, hundreds of Participants,

Enterprise & Governments. Connects the best of business, Government, Research & Education. Develops Innovations and Programs developing trustworthy on-line

experiences.

Page 4: Kantara trust frameworks 2016 05-08

Do you recognize our members?

Page 5: Kantara trust frameworks 2016 05-08

Kantara’s Values Trust

Operating Accreditation, Approval & Certification programs Privacy

Developing privacy respecting solutions. Security

Developing high security solutions and practices Community

Bridging technology and policy requirements

Page 6: Kantara trust frameworks 2016 05-08

WHAT IS A DIGITAL TRUST FRAMEWORK?

Explaining Digital Trust Frameworks in 20 minutes or less

Page 7: Kantara trust frameworks 2016 05-08

Fun and Exciting!

Page 8: Kantara trust frameworks 2016 05-08

What is a Digital Identity Trust Framework?

“Digital Identity”• Identity: A reference or designation used to

distinguish a unique and particular individual, organization or device.

• Trusted Digital Identity: ‘a trusted electronic representation of who I am.’

“Framework”• Digital Identity Trust Frameworks define

the ‘rules of the road’ for interactions between organizations when handling identity, authentication and authorization. Often, these Frameworks form the basis of agreements and contracts.

Page 9: Kantara trust frameworks 2016 05-08

Free provincial flags for Canada Day!

Page 10: Kantara trust frameworks 2016 05-08

Resident?

Alice

Page 11: Kantara trust frameworks 2016 05-08

Apply & Authorize information release

Ask Alice to Get Proof

Tell Telco to Give Proof

A=5 years

Page 12: Kantara trust frameworks 2016 05-08

Alice gets a free flag!

Page 13: Kantara trust frameworks 2016 05-08

Why does this work? Festival and a group of Telcos both comply with a Digital Trust

Framework

• UMA protocol is used to make it possible for Alice to authorize electronic information release from one org to another

Page 14: Kantara trust frameworks 2016 05-08

Did it work before? Kinda

Previously, Festival had to contract with every Telco and configure themselves differently for each one

Festival had to keep track of new Telcos Festival had to adapt to meet each Telco’s technical

requirement Festival had to agree to different terms & lawyer fees

were rising

Page 15: Kantara trust frameworks 2016 05-08

A reason for a framework?

To make negotiating agreements easier

Page 16: Kantara trust frameworks 2016 05-08

How?

Framework

Contracts and Agreements

StandardsRegulationsLaws

Framework Profile

Page 17: Kantara trust frameworks 2016 05-08

Contracts The program negotiates contracts with every

information source Policies, business processes, standards, operating

practices, formats

OR The program requires conformance to Trust

Framework Profile Negotiation burden lowered

Page 18: Kantara trust frameworks 2016 05-08

Some Details

Page 19: Kantara trust frameworks 2016 05-08

Digital Trust Framework Elements

Roles & Responsibilities

Page 20: Kantara trust frameworks 2016 05-08

Digital Trust Framework Elements

Business functions & Expected Processes

Page 21: Kantara trust frameworks 2016 05-08

Digital Trust Framework Elements

Processes & Criteria (proof of ‘sameness’ and ‘equivalency’)

Page 22: Kantara trust frameworks 2016 05-08

Digital Trust Framework Elements

Library of Profiles

Page 23: Kantara trust frameworks 2016 05-08

Tools and Rules Technical protocols Software / servers Cryptography Communication

protocols Standards

Policies for proof of

identity; ‘Levels’ of certainty

Privacy policy Operations practices Designated authorities

Page 24: Kantara trust frameworks 2016 05-08

The Future Possibilities Model contract clauses Automation for contracts Addition of new roles, responsibilities, business

functions Build a library of framework profiles

Page 25: Kantara trust frameworks 2016 05-08

Now what?Join us in innovating and verifying trusted identity solutions for the world Kantara Initiative members include global experts from industry and

government in the fields: Identity assurance Privacy Security Policy Information systems assessment

Join. Innovate. Trust. Visit.:

KantaraInitiative.org

Page 26: Kantara trust frameworks 2016 05-08

Join. Innovate. Trust.General Inquiries: [email protected]

[email protected]@Wunderlich.ca