Skip Links

Network World

  • Social Web 
  • Email 
  • Close

What is 'user-centric' identity?

'User-centric' identity vs. 'enterprise-centric'
Security: Identity Management Alert By Dave Kearns , Network World , 07/10/2006
Kearns
Sign up for this newsletter now!

The term "user-centric" identity is getting bandied about a lot these days. It's generally understood to be a different way of expressing the entire identity transaction as opposed to what might be called the "enterprise-centric" approach traditionally used within provisioning, federation and even simplified sign-on situations. There is still much confusion as to exactly what steps are necessary to make the transaction truly user-centric, though.

Unfortunately, when most people outside the identity field look at the two supposedly opposed organizational methods they simply don't understand what all the fuss is about as both methods revolve around the identity of people, the users. There's also nothing that mandates that either method is solely concerned with the identity of people; both can (and are) extended to the identity of things, concepts, protocols and more.

So where's the difference?

Sxip CEO Dick Hardt recently posted a note about this and I was taken with his second definition: "The user has a consistent user experience. That does not mean that all users have the same user experience, but that a specific user is using the same identity agent over and over for each identity transaction, similar to the interfaces we all see for saving and printing files regardless of the application. Currently each SP [service provider] provides its own user interface which means the user is learning a new interface, sometime for onetime use (e.g. site registration). By separating the identity component from the rest of the application, the user also has more certainty on who the SP is which helps resolve phishing."

In the enterprise system, the user probably does have a consistent experience because the enterprise is using a single interface to provide enterprise simplified sign-on (ESSO). This satisfies Hardt's definition because it takes the multiplicity of sign-on interactions that are present in a non-ESSO environment and reduces them to a single one that is always the same for the user.

Outside of the enterprise, the user is being presented with as many, if not more, types of dialogs as there are services that need authentication. That's not a friendly experience, and it isn't user centric.

Perhaps Microsoft's Card Space (formerly InfoCard and now generically called iCard) can set a standard for the interface as Windows has done for file and print dialogs. That would be an excellent legacy for Bill Gates to leave as he retires from active service.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

I think he should demand that at least one network engineer be on the jury. Very few other people would...- Anonymous

Join the Discussion