Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163
Showing posts with label concent-centric identity management. Show all posts
Showing posts with label concent-centric identity management. Show all posts

Wednesday, June 11, 2008

Article: “50 Ways to Take Back Control of Your Personal Data”

Have a look at this very interesting article, called “50 Ways to Take Back Control of Your Personal Data”, by InsideCRM providing a useful list of tips and “common sense” (but quite often forgotten …) ways to protect your personal data, maintaining degrees of control on it and reduce your risk exposure to identity thefts, financial losses and other crimes.

These tips are organised by categories, in terms of:
  • Web Privacy
  • Credit and Finance
  • General Privacy
  • Cell Phones and Online Phone Services
  • Rules to follow to Protect Your Privacy
  • Tools and tips

--- NOTE: my original HP blog can be found here ---

Sunday, February 3, 2008

Are Legal Obstacles Delaying Federated Identity Management?

This is a key point made in Thomas J. Smedinghoff’s article, titled “Legal Obstacles Delaying Federated Identity Management”:

“Without some type of a legal framework to address these issues, however, a federated identity model will likely not scale. At least in the case of economically significant transactions, the risks to each of the parties of such unresolved issues are simply too great to justify reliance on the federated process. These questions, and others like them, are the legal land mines that stand in the way of a viable federated identity management infrastructure.”

The issues mentioned above are about: Identification Process, Personal Information, Scope of Assertion, Use of Assertion and Liability.

I agree that having a proper legal framework in place can help. I would argue, though, that proper “identity assurance” must also be put in place in the context of federated identity management, as discussed in a HPL Technical Report.

--- NOTE: my original HP blog can be found here ---

Saturday, January 5, 2008

Consent-centric Identity Management

An aspect I believe will have more and more relevance in the space of Identity Management is “Consent Management” i.e. the active management and enforcement of users’ consent when collecting, storing, accessing, processing and disclosing personal data.

This includes: the management of users’ preferences and users’ constraints on personal data, once this data has been disclosed; (potential) active involvement of users during the overall lifecycle of identity information; consent-driven identity lifecycle management. This includes aspects of privacy management, but it is wider that this – as it is about the overall process of handling identity information.

Given the current trends towards user-centric identity management, federation and “identity-aware devices”, people will increasingly realise how valuable their identities are (as an asset they should own) and demand more control and active involvement in their overall management.

This is opportunity for the IdM research community (and the industry) to contribute to this space.

--- NOTE: my original HP blog can be found here ---