Identifier Management

From MgmtWiki
Revision as of 20:38, 12 November 2019 by Tom (talk | contribs) (Other Approaches)

Jump to: navigation, search

Full Title or Meme

Identity Management (IdM) or Identity and Access Management (IAM) is a field of management in enterprises that is not clearly defined.

Context

  • Customer Relationship Management (CRM) has been an issue from the earliest days of tabulating machine deployment or earlier.
  • Vendor Relationship Management (VRM) has been proposed by Doc Searls[1] as the User managing their vendors.
  • The goal of this wiki is to give the user the same ability to manage identity as the web sites that they visit.

Problems

The term Identity Management is not well defined.

For example: According to Gartner, IGA solutions are tools that “manage digital identity and access rights across multiple systems.” They accomplish this by aggregating and correlating identity and access rights data that is distributed throughout the IT landscape, in order to enhance control over user access. This aggregated data serves as the basis for what Gartner considers the core IGA functions:

  • Identity Life Cycle and Entitlements Management
  • Access Requests
  • Workflow Orchestration
  • Fulfillment via Automated Provisioning and Service Tickets
  • Reporting and Analytics
  • Role and Policy Management
  • Auditing

The goal of both the user and the web site are basically the same: access to digital resources that should be under their control. In the vendor's case, it is content the user wants to see. In the user's case it is their personal information that the vendor wants to exploit. Each end has content that the other wants. It should be a natural thing for them to come to some agreement; except that the vendor has traditionally had more legal and technological expertise to tilt the playing field in their favor.

Solutions

  1. User or User Agent
  2. Identity Provider
  3. Attribute Provider
  4. Relying Party
  5. Intermediaries
  6. Credential Service Provider
  7. Registration Authorities
  • The distinction between the real-world User and the digital Entity User Agent often get confused and should be disambiguated in any serious discussion.
  • In the wiki items 2 and 3 are combined into IAP since the distinction between the two has become blurred.
  • Also the last two are less interesting and also hard to separate from other functions.

Self Issued Identifiers

Traditionally the internet issued identifiers only to machines and then those machines issued sub-identifiers to humans: for example the well known "mail-to:" scheme of human@machine.tld. Where a top level domain (tld) issued identifiers to machines (via the DNS) and those machines created email addresses for humans. For the Self-issued Identifier the human creates their own identifier, perhaps a GUID which they could them assign any attributes of interest to them and provide it to any web site of interest to them.

Other Approaches

  1. UNCITRAL UNITED NATIONS COMMISSION ON INTERNATIONAL TRADE LAW Working Group IV: Electronic Commerce WP 160 Draft Provisions on the Cross-border Recognition of Identity Management and Trust Services
  2. US FTC
  3. Underwriter's Labs Identity Management & Security
    Each day our world becomes more interconnected. Consumers and businesses are embracing the digitization of many aspects of our lives - our devices, payments, vehicles, homes. UL is dedicated to empowering trust in our transformation to an interconnected world. As the leading safety and security authority, we proactively work with businesses and governments to create standards and implement solutions that organizations and consumers can trust.
  4. Consumer Reports

References

  1. Doc Searls The Intention Economy: When Customers Take Charge (2012-04) ISBN 978-1422158524

Other Material