The Challenges of Third Party Credentials & Why a Trusted Identity Registry is Needed: Current...

Post on 10-May-2015

189 views 0 download

Tags:

description

Don Thibeau, Chairman & President of the Open Identity Exchange discusses the challenges of third party credentials in a Breakout Session at the 2014 IRM Summit in Phoenix, Arizona.

transcript

A Registry for Online Trust

Building OIXnet

Don Thibeau Chairman & President

A Registry for Online Trust

Early Maps of Emerging Ecosystems

Markets grow when there is trust between stakeholders, making transactions

reliable and repeatable

Trusted identity systems need leverage

How do we leverage trusted identity systems?

Listings leverage identity data

Directories automate discovery

Exchanges grow markets

Registries build trust

Even dogs have registries!

There is no registry for trusted identity systems.

is building

An online registry of trusted identity systems

enables federation

increases the volume and velocity of trusted transactions

accelerates market growth.

Registries drive unique value.

What’s the value of a registry for identity systems?

WE ARE HERE

Early Impact on Emerging Ecosystems ü  It’s early in the registry adoption process…

ü  Now is the time to shape and steer smarter

federation growth

ü  By doing so, we help everybody

TIME

TRU

STED

TRA

NSA

CTIO

NS

OIXnet Value

Disclosure Discovery •  Trustworthiness

across registered identity systems

•  Compliance across registered identity systems rules

•  Equivalency across registered identity systems rules

Centralized •  Visibility,

transparency and understandability builds trust

•  Information needed to be trusted

•  Information needed to be registered

•  Market driven

•  Interoperability of registered identity systems

•  Registrants’ policies, certifications, end-points are easier to find and be found

Information Needed “To Be Trusted”

Registrants’ business, legal and technical federation requirements

Information Needed “To Be Registered”

OIX verification of registrant information ensures credibility

ACCES

S LA

YER

GOVER

NANCE

LAYER

Manual/Automated Platforms

Discovery at high volumes and high velocities

Building OIXnet

Accelerating Self-Certification and Federation

ü  Focusing on near-term, low cost, agile use-cases (e.g. OpenID Connect, Account Chooser, etc.)

ü  Investing in legal research focused on liability in the OIXnet registry model

Adapting Registry Models for OIXnet

ü  CA Browser Forum Membership Information

ü  FICAM TFS Approved Identity Services

ü  U.S.-EU & U.S.-Swiss Safe Harbor Frameworks

Piloting* Registry Technical Infrastructure

ü  Testing machine-to-machine discovery

ü  Partnering with 3rd parties on development

WHO BENEFITS? HOW?

IDPs, APs, and RPs ü  Access complete business, legal and technical requirements ü  Market driven convergence of requirements over time ü  Leverage safe harbor-type models for risk mitigation

COIs and TFPs ü  Greater visibility into other COIs’ and TFPs’ requirements ü  Greater ability to identify federation opportunities

OIX Members ü  Early influence on OIXnet governance and operations ü  Greater insight into market dynamics and policy needs

Pilots ü  Greater visibility into global pilot requirements ü  Greater ability to identify interoperability opportunities

All Stakeholders ü  Complete visibility into registrants’ requirements ü  Greater visibility of global market opportunities ü  Greater understandability of policy across registries

OIXnet Partners

Why OIX?

ü  Non-profit

ü Multi-sector

ü  Technology & business

model agnostic

ü  Experience

ü Global

ü  Industry leadership

Early Maps of Emerging Ecosystems

Don Thibeau Chairman & President

don.thibeau@openidentityexchange.org

Join OIX’s work to build trust in internet identity. Shape the future of trusted transactions online.