FAQ. What is OIX? Who is leading OIX?

Similar documents
Increasing Trust through Standards & Conformity Assessment for Identity

Pan-Canadian Trust Framework Overview

Digital Identity Innovation Canada s Opportunity to Lead the World. Digital ID and Authentication Council of Canada Pre-Budget Submission

ITI Comment Submission to USTR Negotiating Objectives for a U.S.-Japan Trade Agreement

APEC Internet and Digital Economy Roadmap

National Association of State Chief Information Officers (NASCIO) 2003 Recognition Award Nomination

WFEO STANDING COMMITTEE ON ENGINEERING FOR INNOVATIVE TECHNOLOGY (WFEO-CEIT) STRATEGIC PLAN ( )

Brief to the. Senate Standing Committee on Social Affairs, Science and Technology. Dr. Eliot A. Phillipson President and CEO

Introduction. digitalsupercluster.ca

Summary Remarks By David A. Olive. WITSA Public Policy Chairman. November 3, 2009

RECOMMENDATIONS. COMMISSION RECOMMENDATION (EU) 2018/790 of 25 April 2018 on access to and preservation of scientific information

A Behind-the-Scenes Look Into the Technology Driving the Testing Industry Castle Worldwide

Decentralized Protocol for Self-Sovereign Identities with Embedded Compliance

CANADIAN LEADERSHIP TASKFORCE ON INDUSTRY GROWTH

The Value of Membership.

SMB/5835/SBP. TC13 Scope

GOING GLOBAL ONBOARD Fall 2017 LOND N CALLING

ABOUT THE MINISTERIAL PROGRAMME

twitter.com/twc_rp Research Announcement

Membership. Founder Member $100,000. Contributing Member $100,000. Influencing Member 25,000. Analyst Member 5,000

Hamburg, 25 March nd International Science 2.0 Conference Keynote. (does not represent an official point of view of the EC)

FastTrack Achievements

Consumer Identity World Europe 2017 Pre-conference Workshop

Applied Research APPLIED KNOWLEDGE INNOVATIVE RESEARCH PROVEN RESULTS. nscc.ca/appliedresearch

November 4, appear before you today on behalf of CTIA The Wireless Association and the

ICSU World Data System Strategic Plan Trusted Data Services for Global Science

Technology Plan

A New Platform for escience and data research into the European Ecosystem.

IP Commercialization Trends Income or Impact. Trieste, September 29 and 30, 2016

Buenos Aires Action Plan

Independent Communications Authority of South Africa Pinmill Farm, 164 Katherine Street, Sandton Private Bag X10002, Sandton, 2146

What is a collection in digital libraries?

THESIS PRESENTATION. Gabriele Goebel-Heise 5617A011-4

Structuring Global International Cooperation in Space Exploration

The Association s high-level visit to Hong Kong in April 2018

New forms of scholarly communication Lunch e-research methods and case studies

TECHNOLOGY INNOVATION LEGISLATION HIGHLIGHTS

Before the FEDERAL COMMUNICATIONS COMMISSION Washington, DC ) ) ) ) ) ) ) ) ) ) ) PETITION FOR ETC DESIGNATION OF HUGHES NETWORK SYSTEMS, LLC

Digital Transformation in Thailand: Policy and Institutional Reform

250 Introduction to Applied Programming Fall. 3(2-2) Creation of software that responds to user input. Introduces

«INTERNAL AUDITORS AND AUDIT COMMITTEES» Key Elements for sound Corporate Governance

Interoperable systems that are trusted and secure

The 45 Adopted Recommendations under the WIPO Development Agenda

The Collaboration Imperative: Universities and Industry as Partners in the 21 st Century Knowledge Economy

DEFENSE AUTOMOTIVE TECHNOLOGIES CONSORTIUM (DATC) WORKSHOP OCTOBER 12, 2017

COMMISSION RECOMMENDATION. of on access to and preservation of scientific information. {SWD(2012) 221 final} {SWD(2012) 222 final}

WORLD LIBRARY AND INFORMATION CONGRESS: 72ND IFLA GENERAL CONFERENCE AND COUNCIL August 2006, Seoul, Korea

DEVELOPMENT OF SCIENCE, TECNOLOGY, AND INNOVATION IN UKRAINE Oleg Khymenko

Start A Successful Business Expert Advice To Take Your Startup From Idea To Empire Inc Magazine

GROUP OF SENIOR OFFICIALS ON GLOBAL RESEARCH INFRASTRUCTURES

SEEING BEYOND TECHNOLOGY:

National Perpetual Access & Digital Preservation CRKN & Scholars Portal

Digital Built Britain David Philp Digital Built Britain (DBB): BIM Working Group

JTC1 Smart Ci,es workshop. Welcome!

INTEL INNOVATION GENERATION

Designing for an Internet of Humans

CPE/CSC 580: Intelligent Agents

Section 1: Internet Governance Principles

USEFUL TOOLS IN IMPLEMENTING MIGRATORY BIRD CONSERVATION BY THE DOD

CACI INTERNATIONAL INC /DE/

Marine Renewable-energy Application

LIBER s role in supporting European Research Libraries. Wouter Schallier Executive Director

European Nuclear Education Network Association

The Eco-Patent Commons

At its meeting on 18 May 2016, the Permanent Representatives Committee noted the unanimous agreement on the above conclusions.

Robert Bond Partner, Commercial/IP/IT

Digital transformation in the Catalan public administrations

EMPOWERING THE GAMES COMMUNITY.

GUIDELINES FOR THE APPLICATION FOR PUBLIC RADIOCOMMUNICATIONS SERVICE (PRS) LICENCES

Testimony of Professor Lance J. Hoffman Computer Science Department The George Washington University Washington, D.C. Before the

WIPO Development Agenda

Kryptonite Authorized Seller Program

Tony Vanchieri, Luke Sebby and Gary Dooley

Global Alzheimer s Association Interactive Network. Imagine GAAIN

Advancing Health and Prosperity. A Brief to the Advisory Panel on Healthcare Innovation

Dynamic Spectrum Alliance response to consultation on the ACMA Five-year spectrum outlook

ICT : Internet of Things and Platforms for Connected Smart Objects

NETWORK MANAGERS FORUM. Your invitation to attend the MONDAY 6 MARCH PM PM New Zealand

Towards a French Creative Industry RALLYING, ACCELERATING, TRANSFORMING

TABLE OF CONTENTS OUR MISSION OUR MEMBERS OUR PLAN C_TEC S PRIORITIES WORDSMITH + BLACKSMITH

Issues and Challenges in Ecosystems of Federated Embedded Systems

The Riga Declaration on e-skills A call to action on digital skills and job creation in Europe

MEDIA AND INFORMATION

THE GSMA PRESENTS MINISTERIAL PROGRAMME

European Charter for Access to Research Infrastructures - DRAFT

[Definitions of terms that are underlined are found at the end of this document.]

)XWXUH FKDOOHQJHV IRU WKH WRXULVP VHFWRU

Privacy Policy SOP-031

1 Canada needs mining. 2 Canada s competitive advantage. 3 Challenges to the industry. 4 Collaboration and engagement

Digital Financial Solutions to Advance Women s Economic Participation

I. THE RELATIONSHIP BETWEEN NATIONAL AND CHAPTERS

e-research Team A view of access management from Europe Introduction

STRATEGIC ACTIVITIES AND PRIORITIES

PRODUCT INFORMATION FORM (PIF TM )

A Malaysian Technical Cooperation Programme (MTCP) ISLAMIC MARKETS PROGRAMME. Strengthening the Wellbeing of Societies

Conclusions concerning various issues related to the development of the European Research Area

UN-GGIM Future Trends in Geospatial Information Management 1

REPORT ON THE INTERNATIONAL CONFERENCE MEMORY OF THE WORLD IN THE DIGITAL AGE: DIGITIZATION AND PRESERVATION OUTLINE

Chapter 1 Company Highlights

ATTRIBUTE EXCHANGE NETWORKS: NEW INFRASTRUCTURE FOR DIGITAL BUSINESS

Transcription:

FAQ What is OIX? The Open Identity Exchange (OIX) is a non-profit corporation serving as an independent, neutral provider of certification trust frameworks for open identity technologies. Who is leading OIX? The founding Board of Directors includes Kennie Kwong, Lead Member of Technical Staff, AT&T; Ron Carpinella, VP Identity, Equifax; Eric Sachs, Product Manager for GoogleSecurity, Google; Andrew Nash, Senior Director of Identity Services, PayPal; Nico Popp, Vice President of Innovation, Verisign; and Peter Tibbett, Vice President of Technology and Innovation; Verizon. The Chairman of the OIX Board of Directors is Don Thibeau, who currently serves as the Executive Director of the OpenID Foundation. The Acting Executive Director of OIX is John Ehrig. Why is OIX being launched? Just as certain activities in the physical world driving a car, flying in an airplane, applying for a mortgage require identity credentials, so do certain activities in the digital world. However until recently digital identity credentials were largely confined to closed systems that served a defined population of known users, such as a single website, or a corporate or university network. The rise of the Internet and the Web interconnecting millions of different websites and systems demands new digital identity solutions like OpenID and Information Cards that open up closed systems to qualified users from anywhere on the Internet. What problem is OIX solving? Open identity technologies reduce the friction of using the Web, much like credit cards reduce the friction of paying for goods and services. However, they also introduce a new problem: who do you trust? In other words, how does a relying party know it can trust credentials from an identity service provider without knowing if that provider s security, privacy, and operational policies are strong enough to protect the relying party s interests? This is not a technology problem. It is a business, legal, and social problem that must be solved with policy-based solutions like OIX. What is an identity provider? 1

An identity provider is the website or service providing a security credential on behalf of the user. What is a relying party? A relying party is the website or service that requires a security credential from the user. What is a trust framework? In digital identity systems, a trust framework is a certification program that enables a relying party to trust the identity, security, and privacy assurances from an identity provider. Is OIX following an open market model approach? Yes, the key challenge to providing identity assurance at Internet scale is removing the need for direct trust agreements between identity providers and relying parties. To solve this problem, the open identity community, led by members of the OpenID Foundation and Information Card Foundation, developed the Open Identity Trust Framework (OITF) model [http://openidentityexchange.org/sites/default/files/the-open-identity-trustframework-model-2010-03.pdf]. This model breaks apart centralized control of certification into separate functions in order to create an open competitive market for each function. What are the benefits of an open market model for identity assurance? Open market models reward good market behavior in a virtuous cycle. Having trust frameworks, trust framework providers, identity providers, relying parties, and assessors competing directly with each other for business means: More choice for users and websites about the policies that will apply to their interactions. Market pricing for services throughout the open identity infrastructure. Economies of scale as service standardization lowers costs for all parties. Diversity from head to foot of the "long tail", which is especially important to preserve the diversity of contexts and policies necessary for a healthy online ecosystem. What Open Identity Trust Frameworks are OIX now servicing? The US General Services Administration (GSA) and the Identity, Credential, and Access Management Committee (ICAM) has approved OIX as the first trust framework provider to the US government. This permits OIX to issue certifications for the US ICAM LOA 1 trust framework [http://openidentityexchange.org/trust-frameworks/us-government-icam] to identity providers who are assessed to meet its identity, security, and privacy requirements. The National Institute of Health (NIH) is the first US federal agency to 2

move into production status to accept OpenID and Information Card credential issued by OIX-certified identity providers. Are there any identity providers certified for US ICAM? Yes. Google, PayPal, and Equifax are the first three OIX members to be certified for as identity providers [http://openidentityexchange.org/certified-providers] at US ICAM LOA 1 (level of assurance 1). Verizon and VeriSign are currently in the certification process. Are other governments adopting the trust framework model? Canada, the UK, and France (FC2 consortium) all have projects investigating the use of open identity technologies and trust frameworks. What other types of trust frameworks is OIX anticipating to serve? Trust frameworks can be developed by any online community that needs to assure trust across diverse members. An example is the U.S. Public Broadcasting System (PBS) affiliate network. In addition to increasing audience involvement and integrating television and online content, PBS would like to build subscriber relationships, streamline donations, and help safeguard children from predators when they visit web sites for popular PBS children s television shows such as Sesame Street, Arthur, and Curious George. PBS could do this with a Public Media Trust Framework [http://openidentityexchange.org/trust-frameworks/pbs-public-media]. Will trust frameworks only come from governments and non-profits? No. Trust communities can also be entirely private. For example, the Line Information Database (LIDB) Forum, a group of telecommunications companies with decades of experience implementing technical interoperability standards for phone system interchange, is investigating developing a trust framework for privacy-protected sharing of subscriber data. Another example is the Online Computer Library Center (OCLC) which wants to develop a cooperative trust framework for libraries and their users. An OCLC trust framework will broaden online access to library materials, essentially creating a virtual online library card. How will OIX benefit consumers? Consumers of identity management services (either from identity providers or relying parties) will benefit first from the increased adoption of open identity technologies from certified providers -- for example the availability of OpenID and Information Cards to use at US federal government websites. They will also benefit from the standardized identity, security, and privacy policies that OIX trust frameworks will propagate. Lastly, 3

the OIX Listing Service will permit consumers to compare the technical and policy standards of various identity providers and relying parties, helping advance competition and increase quality throughout the industry. Who should join OIX? All organizations engaged in the digital identity market who want to become certified identity providers, relying parties, or assessors. In addition OIX welcomes governments, professional associations, non-profit networks, and other communities who want to develop their own trust frameworks. What are the top benefits of OIX membership? The top benefits exclusively available to OIX members are: 1. The ability to be certified to the US ICAM trust framework requirements, thereby gaining access to the US government market. 2. Signify that your organization is a leader in digital identity assurance through use of the OIX Certified brand. 3. Gain access to a worldwide network of leading organizations and individuals in the digital identity assurance industry. 4. "Early mover" engagement with new and evolving public and private trust frameworks, including the ability to participate in OIX advisory committees and working groups developing these frameworks. 5. Achieve a level playing field with the biggest players in the market. 6. Influence the strategy, direction and policies of OIX. How can I join OIX? Joining is easy, simply follow these instructions [http://openidentityexchange.org/join]. How much does it cost to become a member and get certified? OIX s two tiered member program Executive and General (with a special pricing plan for government, academic and non-profit organizations) - encourages organizations of all sizes to participate, collaborate, and contribute to the success of our shared mission. Each tier has auditing, participation and/or leadership benefits commensurate with financial contribution. See the complete fee schedule [http://openidentityexchange.org/join]. Where can I get more information? For more information please contact help@openidentityexchange.org What is the OpenID Foundation? 4

The OpenID Foundation (OIDF) [http://www.openid.net/] was formed in June 2007 to help promote, protect, and enable the OpenID technologies and community. The OIDF does not dictate the technical direction of OpenID; instead it will help enable and protect whatever is created by the community. OpenID is a Web registration and single sign-on protocol that lets users register and login to OpenID-enabled websites using their own choice of OpenID identifier. With OpenID, a user can operate their own OpenID service (such as on their blog), or they can use the services of a third-party OpenID provider (most major Web portals, such as AOL, Google, and Yahoo, now offer OpenID service). What is the Information Card Foundation? The Information Card Foundation (ICF) [http://www.informationcard.net/] is non-profit community of individuals and companies working together to evolve the Information Card ecosystem. Information Cards are a new approach to Internet-scale digital identity in which all of a user s identities, whether self-created or from third party identity providers are uniformly represented as visual cards in a software application called a card selector. The cards themselves may be stored on the same computer as the card selector, or on a mobile device, or in the cloud. Cards may be exchanged with websites using a variety of protocols and formats. All card selectors support at least the IMI protocol developed by the OASIS IMI TC, however Information Cards are now being adapted to other protocols as well (including OpenID). 5