100 likes | 248 Vues
Identity Assurance Expert Group (IAEG). Goal: to foster adoption of identity assurance services, and uniformity and interoperability amongst identity service providers by promulgating o verarching values Public SIG exists alongside to solicit and encourage broad public participation.
E N D
Identity Assurance Expert Group (IAEG) • Goal: to foster adoption of identity assurance services, and uniformity and interoperability amongst identity service providers by promulgating overarching values • Public SIG exists alongside to solicit and encourage broad public participation
IAEG Key Activity: Identity Assurance Framework • GUIDANCE (vs. policy) on what Federation members should consider and have policies for • 1.0 focused on IdPs/CSPs; Future phases to consider RPs & Federation Operators • Enable Federations to map their policies, practices and technologies to each other and ensure comparable trust levels • HARMONIZED, BEST-OF-BREEDindustry identity assurance approaches • Re-use contributions from other sources (EAP, US E-Auth Federation, T-Scheme, TSCP, others) • Build upon accepted industry standards • NEUTRAL, COMPREHENSIVE &GLOBAL • Cover all aspects of identity assurance: risk classification and assurance levels, service assessment criteria for organizations, credential management & identity proofing; business rules and certification models
Liberty IAF: The Picture Liberty Alliance Identity Assurance Framework Federation 1 Federation 2 Federation 3 Federation 4
Upcoming Activities • IAF in draft review • (http://www.projectliberty.org/liberty/content/download/3736/24651/file/liberty-identity-assurance-framework-v1.0.pdf) • Public webcasts: • March 5, 8 am PT,Credential Management Service Assessment Criteria • March 12, 8 am PT, Identity Proofing Service Assessment Criteria • March 26, 8 am PT, Certification/Accreditation Business Rules • Public input welcome: https://maa.projectliberty.org/id/idf-feedback.html • Panel Session, RSA Conference, SF, April 9, 9:10 am • Pre-Conference workshop, TowerGroup Conference, Boston, May 28 • Panel Session, Gartner Identity and Access Summit, London, June 23-25 • Panel Session, Burton Catalyst Conference, San Diego, June 23-25 • Others, TBD
Why was Liberty Alliance Formed? • Foster the ubiquitous, interoperable, privacy-respecting, identity layer (holistic identity management): • Liberty represents all constituencies toward this objective • (vendors, enterprise, government, consumers, universities, SME’s, etc.) • Must be an open, collaborative system vs. single vendor strategy • Identity is important & complex. We must come together OR: • industry will become more fractured • governments will intervene • Develop privacy-compliant practices to exchange identity information • Develop standards-based model to … • Interoperate in heterogeneous environments • Avoid proprietary vendor lock-in • Provide flexible foundation for future growth • Scale to the WWW • Deliver consumer & enterprise confidence that security, privacy and data integrity will be maintained
More than Technology Technology Standards and Guidelines Business and Privacy Guidelines Assurance An Ecosystem of Interoperable Products & Services An Ecosystem of Interoperable Products & Services Identity Assurance Framework & Assessors
The Liberty Process - Market Centric • By … • Listening to the Market • Collaborating with other relevant groups • Documenting the requirements • Developing specifications and frameworks to meet the needs • Certify the products & assessors • Continuous evolution and improvement
Identity Assurance Roadmap • Phase One of Certification Program for CSPs/IDPs, ratified in Identity Assurance Framework v1.0 FINAL (Q2 2008) • Launch Accreditation Program to enable the Certification model and spur the market (Q2 2008) • Scope and define Phases 2 and 3 for Federation Operators and Relying Parties (begins Q3 2008)
Getting Involved with Identity Assurance • Liberty Alliance Identity Assurance Expert Group (formal membership in Liberty Alliance is required) http://www.projectliberty.org/liberty/membership/become_a_member • Identity Assurance Special Interest Group (formal membership in Liberty Alliance is not required) http://wiki.projectliberty.org/index.php/IASIG • Identity Assurance Framework for Review and Comment http://www.projectliberty.org/liberty/content/download/3736/24651/file/liberty-identity-assurance-framework-v1.0.pdf