Title: Advances in Digital Identity
1Advances in Digital Identity
- Steve PlankIdentity Architect
2Identity
no consistency
Naming
DNS
Connectivity
IP
3taught users
type
usernames passwords
web page
4what is identity?
5attributes givenName sn preferredName planky date
OfBirth 170685! over18 true over21 true over6
5 false image
steve plank
6 self asserted
what claims i make about myself
verifiable
what claims another party makes about me
7elvis presley
only 1 of them is real
probably
8 trust
make these
claims
9SECURITY TOKEN
steve plank over 18 over 21 under 65 image
10security token service
give it something
DIFFERENT SECURITY TOKEN
Username Password
Biometric Signature
Certificate
Secret
11identity metasystem
12participants
subject
relying party (website)
13identity provider
identity provider
relying party
relying party
security tokenservice
WS-
security token service
WS-
identity selector
14identity selector
15human integration
consistent experience across contexts
16(No Transcript)
17cards
18login with self issued card
user
relying party (website)
19select self issued card
user
relying party (website)
20create token from card
user
relying party (website)
21sign, encrypt send token
user
relying party (website)
22login with managed card
user
relying party (website)
23select managed card
user
relying party (website)
24request security token
user
authNX509, kerb, SC, U/pwd
relying party (website)
25request security token response
user
sign, encrypt send
relying party (website)
26ltbodygt ltform id"form1" method"post"
action"login.aspx"gt ltdivgt ltbutton
type"submit"gt Click here to sign in with
your Information Card lt/buttongt ltobject
type"application/x-informationcard"
name"xmlToken"gt ltparam name"tokenType"
value"urnoasisnamestcSAML1.0assertion"
/gt ltparam name"issuer
value"http//schemas.xmlsoap.org/ws/2005/05/iden
tity/issuer/self" /gt ltparam
name"requiredClaims" value"
http//schemas.xmlsoap.org/ws/2005/05/identity/cla
ims/givenname http//schemas.xmlsoap.org/w
s/2005/05/identity/claims/surname
http//schemas.xmlsoap.org/ws/2005/05/identity/cla
ims/emailaddress http//schemas.xmlsoap.or
g/ws/2005/05/identity/claims/
privatepersonalidentifier /gt
lt/objectgt lt/divgt lt/frmgt lt/bodygt
27xmlToken (signed encrypted)
token decrypter
relying party (website)
xmlToken (plaintext)
claims extractor
ppid
456
user database
first name
last name
index into DB
email
456
phone
28demo
29roadmap
- Built into Windows Vista
- Available for Windows XP Windows Server 2003
- Betas CTPs available fromhttp//msdn.microsoft
.com/windowsvista/getthebeta - RTM 2nd half 2006
- More Information Samples at http/cardspace.netf
x3.com
30review
- identity layer
- phishing, phraud
- human integration
- consistent experience across contexts
- ip
- rp
- user
- identity selector
Presentation style mercilessly stolen off
Lawrence Lessig, BBC News 24 and Dick Hardt