Network World
Saturday, November 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

Relationships and Trust

Bob Blakley is partly right when he says "It's the relationships, stupid." But then he proposed that we stop talking about "trust" when what we really mean is cryptography . . . Huh?

In the IAM world, relationships with an identity are used to assist in authentication. Think of the "regular customer" scenario. Reputation can be considered as part of the risk/trust relationship to determine what accesses you have or are permitted to do in a session, but it is not an identity or a credential. It's just a part of the level of confidence. Check the terminology in this dictionary: http://identityaccessman.blogspot.com/

Identity does not have a context as such; but the authentication of an identity does. The same identity in a different context does not usually get the same authorizations, because their assurance level (risk/trust) is usually different. We can, should, and often do use Assurance Levels to predetermine the amount of risk / degree of trust we are prepared to accept for any given transaction.
That is, the transactional relationship varies. The regular customer can be trusted if they do the same thing every time, but should not be trusted to do something different on the same basis. The relying party is the one taking the risk. Refer to http://identityaccessman3.blogspot.com/ for an explanation of assurance frameworks.

Dave, the minimal data necessary to satisfy a need for data which could be used as an identifier is all that's needed if there is only one assurance level (which is not usually the case, except for some of the simpler OpenId transactions). And it's clearly not the case where there is the need to "step-up" the credential strength (not the identity) when attempting to transacting a more risky transaction.
"Stop thinking of our vendors, clients, partners, employees and customers in terms of risks to be assessed." I don't think so, Bob.

"Relationship is the context which protects the security and the privacy of identity information"? I don't think so, Bob, unless you simply mean a "legal" relationship.

As for Cryptography, it's a relatively trusted method of keeping shared secrets private, usually in a message. Encryption of an identity 'claim' simply increases the level of confidence in the data. But when we use the word "trust", Bob, almost all of us don't mean "cryptography".

Allan Milgate

Click to read the article this is in response to.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: