Liberty Alliance urges standard for UK ID card plan
- 22 September, 2005 07:36
- Comments
As the U.K. government moves ahead with a national identification card plan, it should be based on open standards, the executive director of the Liberty Alliance said at a press briefing in London.
While the U.K. announced in May that it hopes to start issuing national ID cards by 2008, resolving broad issues of how citizens may interact with an increasingly Web-based government may be years away. However, companies are already speculating as to how the identity -- and security -- of people who access government information may be verified and managed.
Some private companies, such as General Motors and Fidelity Investments, have adopted a federated identity approach: the use of a single-source authentication entry point for customers. With a single user name and password, customers can pass to different Web sites without re-entering their information.
With government, as well, "you have to have a federated approach," said Donal O'Shea, executive director of the Liberty Alliance.
The Liberty Alliance Project, a consortium of companies and government organizations, creates standards for identity federation. Formed four years ago, the Liberty Alliance -- backed by IBM, Sun Microsystems and others -- has worked with the Organization for the Advancement of Structure Information Standards (OASIS) to develop SAML (Security Assertion Markup Language) for identity federation. A third organization, WS-Federation, backed by Microsoft, is also working on a federated identity standard.
The standard -- if any -- that is used by governments could have a strong impact on vendors vying for large-scale government IT infrastructure contracts.
The technology adopted by the U.K. government should be an open-source standard that will allow people to verify who they are across many organizations, O'Shea said. It should not make the "classic mistake" of not allowing for flexibility in databases that might be in use for up to 50 years for services yet to be envisioned, he said.
The adoption of standards for national ID cards could have implications for both the private and public sectors.
In July 2004, IBM signed a deal with France Telecom SA's mobile division for a single-sign on service for customers accessing different Web sites and mobile services using Liberty Alliance standards. Questions were raised in France as to whether hackers would be able to aggregate information stored across systems, O'Shea said. While nothing is impossible, O'Shea said "we were able to show them that's not the way it works."
Civil liberties and privacy rights questions remain among the public in regard to national ID cards, and whether people will trust and accept the concept of identity federation. "Ultimately, the right not to have information be used by anyone who wants to should be there," said Graham Kemp, head of the U.K. public sector for Sun.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
BYOD security: How to protect your business on the move
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
IT service management going social
-
PC users admit to pirating software - $US63 billion worth of it
-
Implementing Energy Efficient Data Centres
Electrical power usage is not a typical design criterion for data centers, nor is it effectively managed as an expense. This is true despite the fact that the electrical power costs over the life of a data center may exceed the costs of the electrical power system including the UPS, and also may exceed the cost of the IT equipment. Read on. -
High Availability with Oracle Database 11g Release 2
In this paper, we review the common causes of application downtime and discuss how technologies available in the Oracle Database can help avoid costly downtime and enable rapid recovery from unplanned failures and also minimize impact from planned outages. We also highlight new technologies introduced in Oracle Database 11g Release 2 that enable businesses to make their IT infrastructure even more robust and fault tolerant, maximize their return on investment on high availability infrastructure, and provide better quality of service to users. -
The Case for Real-Time Networking
CIOs are facing several powerful trends and inflection points that are defining the new IT landscape, including cloud computing, virtualization, the consumerization of IT, smart computing, and communications to collaboration. Taken individually, each one of these trends will have significant ripple effects throughout the planning and operations of IT network infrastructure. In aggregate, they will have an even more dramatic impact on the way that future network architectures need to be planned and designed. Read on.
-
Content Management Bible, 2nd Edition
-
Knoppix for Dummies
-
Iphone Fully Loaded, 3E
-
Software Engineering Member Package (4 Volume Set)
-
2005 Online Shopping Directory for Dummies
-
Data Modeler's Workbench
-
Professional Software Testing with Visual Studio 2005 Team System
-
Word 2010 All-In-One for Dummies®
-
Linux Timesaving Techniques for Dummies








Comments
Post new comment