THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

28
A Registry for Online Trust Don Thibeau Chairman & President

description

DON THIBEAU, Chairman & President, The Open Identity Exchange (OIX), at the European IRM Summit 2014.

Transcript of THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Page 1: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

A Registry for Online TrustDon Thibeau

Chairman & President

Page 2: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Four Problems Plague Trusted Transactions

… “Four Horsemen of the Identity Apocalypse”

Page 3: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

• Governance systems that are transparent in the service of trusted transactions in the “zero-trust” internet ecosystem

• Liability is the legal enforcement and assignment of the duties of all actors in an identity system for the protection of all stakeholders

• Certification options that are responsive to the speed, scale and dynamism of the internet

• Adoption of a community of interest’s business, legal and technical interoperability requirements

… “Four Horsemen of the Identity Apocalypse”

Page 4: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Page 5: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Markets grow when there is trust between stakeholders, making transactions reliable and repeatable

Page 6: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Trusted identity systems need leverage

Page 7: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

How do we leverage trusted identity systems?

Page 8: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Listings leverage identity data

Page 9: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Directories automate discovery

Page 10: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Exchanges grow markets

Page 11: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Registries build trust

Page 12: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Even dogs have registries!

Page 13: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

There is no registry for trusted identity systems.

Page 14: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

is building

Page 15: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Registries build trust

Page 16: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

enable interoperability

Page 17: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

increase the volume and velocity of trusted transactions

Page 18: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

And accelerate market growth

Page 19: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

How does it work?

Page 20: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Page 21: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

OIXnet Pilot

Symantec providing a secure, trusted, scalable platform for conformance testing, self-certification and registration.

OIX announces the pilot of the OIXnet registry and the the first self-certifications of OpenID Connect.

Google, Microsoft, Ping Identity and salesforce to be the first to self-certify to the OpenID Connect standard and to be registered at the OIXnet pilot

Page 22: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Pilot Registration Flow

Registration Requirements

FAQ&

Terms of Service

Approve?

Registration Approval Package

YES

Registration Denial

NO

Page 23: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

Information Needed “To Be Trusted”

COI’s are solely responsible for business, legal and technical

requirements

Information Needed “To Be Registered”

OIX is solely responsible for business, legal and technical

requirements

AC

CES

SLA

YER

GO

VER

NA

NC

ELA

YER

Manual/Automated Discovery

Pilot Phase: Listing Service -- Future: Automated Discovery

Page 24: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Building OIXnet

Testing Self-Certification and Registration Focusing on near-term, low cost, agile use-cases e.g. OpenID

Connect

Investing in legal research focused on liability in the OIXnet registry

model

Adapting Registry Models for OIXnet CA Browser Forum

Cloud Security Alliance Star Registry

U.S.-EU Safe Harbor

IDESG Trust Framework and Trustmark Committee

Liberty Alliance Project

Piloting Registry Business, Legal and Technical MechanismsPartnering with COI’s and e.g. OpenID Foundation and others

Partnering with industry, government and academic leaders

Page 25: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

…“Four Horsemen of the Identity Apocalypse”

• Governance: the full transparency of all COI and OIX business, legal and technical requirements builds trust

• Liability: COI + OIXnet TOS agreements clearly assign and enforce all duties of all actors in an identity system

• Certification: self certification + registration responds to the speed, scale and dynamism of internet identity

• Adoption: OIXnet removes friction and speeds the discovery of a COI’s business, legal and technical requirements

… “Four Horsemen of the Identity Apocalypse”

Page 26: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Why OIX?

Page 27: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Global Cross-Sector Leadership

Data Aggregators

Enterprise

Technology

Consulting Services

Banking

Government

Telcos

Page 28: THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

© by Open Identity Exchange, 2014

A Registry for Online Trust

Join OIX’s work to build trust in internet identity. Shape the future of trusted transactions online.

Don ThibeauChairman| Open Identity Exchange

[email protected]