Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Liberty Alliance urges standard for UK ID card plan

In a UK conference, the Liberty Alliance urges UK national ID cards to be based on open standards.

As the U.K. government moves ahead with a national identification card plan, it should be based on open standards, the executive director of the Liberty Alliance said at a press briefing in London.

While the U.K. announced in May that it hopes to start issuing national ID cards by 2008, resolving broad issues of how citizens may interact with an increasingly Web-based government may be years away. However, companies are already speculating as to how the identity -- and security -- of people who access government information may be verified and managed.

Some private companies, such as General Motors and Fidelity Investments, have adopted a federated identity approach: the use of a single-source authentication entry point for customers. With a single user name and password, customers can pass to different Web sites without re-entering their information.

With government, as well, "you have to have a federated approach," said Donal O'Shea, executive director of the Liberty Alliance.

The Liberty Alliance Project, a consortium of companies and government organizations, creates standards for identity federation. Formed four years ago, the Liberty Alliance -- backed by IBM, Sun Microsystems and others -- has worked with the Organization for the Advancement of Structure Information Standards (OASIS) to develop SAML (Security Assertion Markup Language) for identity federation. A third organization, WS-Federation, backed by Microsoft, is also working on a federated identity standard.

The standard -- if any -- that is used by governments could have a strong impact on vendors vying for large-scale government IT infrastructure contracts.

The technology adopted by the U.K. government should be an open-source standard that will allow people to verify who they are across many organizations, O'Shea said. It should not make the "classic mistake" of not allowing for flexibility in databases that might be in use for up to 50 years for services yet to be envisioned, he said.

The adoption of standards for national ID cards could have implications for both the private and public sectors.

In July 2004, IBM signed a deal with France Telecom SA's mobile division for a single-sign on service for customers accessing different Web sites and mobile services using Liberty Alliance standards. Questions were raised in France as to whether hackers would be able to aggregate information stored across systems, O'Shea said. While nothing is impossible, O'Shea said "we were able to show them that's not the way it works."

Civil liberties and privacy rights questions remain among the public in regard to national ID cards, and whether people will trust and accept the concept of identity federation. "Ultimately, the right not to have information be used by anyone who wants to should be there," said Graham Kemp, head of the U.K. public sector for Sun.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Fidelity Investments, France Telecom, General Motors, IBM, Liberty Alliance, Microsoft, Sun Microsystems

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Implementing Energy Efficient Data Centres
    Electrical power usage is not a typical design criterion for data centers, nor is it effectively managed as an expense. This is true despite the fact that the electrical power costs over the life of a data center may exceed the costs of the electrical power system including the UPS, and also may exceed the cost of the IT equipment. Read on.
    Learn more »
  • High Availability with Oracle Database 11g Release 2
    In this paper, we review the common causes of application downtime and discuss how technologies available in the Oracle Database can help avoid costly downtime and enable rapid recovery from unplanned failures and also minimize impact from planned outages. We also highlight new technologies introduced in Oracle Database 11g Release 2 that enable businesses to make their IT infrastructure even more robust and fault tolerant, maximize their return on investment on high availability infrastructure, and provide better quality of service to users.
    Learn more »
  • The Case for Real-Time Networking
    CIOs are facing several powerful trends and inflection points that are defining the new IT landscape, including cloud computing, virtualization, the consumerization of IT, smart computing, and communications to collaboration. Taken individually, each one of these trends will have significant ripple effects throughout the planning and operations of IT network infrastructure. In aggregate, they will have an even more dramatic impact on the way that future network architectures need to be planned and designed. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments