Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Saturday, January 5, 2008

Consent-centric Identity Management

An aspect I believe will have more and more relevance in the space of Identity Management is “Consent Management” i.e. the active management and enforcement of users’ consent when collecting, storing, accessing, processing and disclosing personal data.

This includes: the management of users’ preferences and users’ constraints on personal data, once this data has been disclosed; (potential) active involvement of users during the overall lifecycle of identity information; consent-driven identity lifecycle management. This includes aspects of privacy management, but it is wider that this – as it is about the overall process of handling identity information.

Given the current trends towards user-centric identity management, federation and “identity-aware devices”, people will increasingly realise how valuable their identities are (as an asset they should own) and demand more control and active involvement in their overall management.

This is opportunity for the IdM research community (and the industry) to contribute to this space.

--- NOTE: my original HP blog can be found here ---

No comments: