Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Microsoft says Credentica acquisition will help users protect privacy

Technology will be added to CardSpace, Microsoft’s Web services bus
By John Fontana , Network World , 03/07/2008

Microsoft's acquisition of privacy vendor Credentica signals another step in the company’s effort to ensure that users don’t lose control of their personal data.

Credentica develops technology called U-Prove that uses cryptography and multiparty privacy features to facilitate “minimal disclosure” so a user can reveal only the bits of information about themselves they want to while protecting their privacy.

Terms of the acquisition announced Thursday were not disclosed.

But Microsoft’s Identity Architect Kim Cameron could hardly hide his pleasure at landing the U-Prove technology, which he said on his blog is “equivalent in the privacy world of RSA in the security space.”

Cameroni has almost single-handedly rescued Microsoft from its identity gaffe of years ago when it launched Passport, which called for Microsoft to store user’s personal data. Cameron was the driving force behind Microsoft’s new CardSpace technology and claims-based architecture, which flips the Passport concept on its head and makes users gatekeepers of their own personal information.

Cameron told Network World, “customers want authorization without putting their personal information in jeopardy. In many online interactions, there is a need to verify people’s identities. Today we have to give too much personal information, and it increases our risk of online identity theft or misuse of our personal information.”

Cameron said the Credentica acquisition is an important step in developing Microsoft’s Identity Metasystem concept, a framework for connecting identity systems via Web services based protocols and client, server and middleware technologies.
He said the U-Prove technology could be applied in many areas, including anonymous age or membership verification for online communities or social networks.

“If a student is issued a U-Prove token by a school and the student uses the token to apply for access at an age-controlled Web site, the only information the site obtains from the student is the fact that the token has not been tampered with and the student is under or over a certain age. The site does not obtain the exact age, name, address, etc. of the student,” he said.

The technology also could be used to access government services without those individual services being able to link the user data they collect to create a user profile.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (1)
Login
Forgot your account info?

Microsoft buys Credentica to boost ID mgtBy Microsoft Subnet on March 10, 2008, 1:41 pmToken vendor Credentica could help Microsoft take a giant step in the right direction toward better consumer privacy. Microsoft doesn't have enough respect by...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.