Oracle launches open identity protection project

Oracle, working with other technology vendors, has launched an open framework initiative to develop software to protect identity-related employee, customer and partner information, the company said Wednesday.

Oracle is inviting technology vendors and customers to review plans for the Identity Governance Framework (IGF) and contribute to key draft specifications, the company said in a news release. Five technology vendors, including CA, Sun and Novell, have reviewed a draft of the framework and plan to work with Oracle to develop full specifications, Oracle said.

The project, based on XML, comes as security vendors look for ways to help businesses and government agencies avoid adding to a series of security breaches during the past two years. Oracle rolled out a piece of its own identity-management software suite, called Oracle Identity Manager 10g R3, in May.

IGF will be designed to protect identity information as it flows across several applications, the company said. Identity-related information is often embedded in numerous applications across organizations, placing the information at risk and creating potential privacy violations, Oracle said.

The goal of IGF will be to establish a standard way of defining organizationwide policies to share sensitive personal information securely among applications, Oracle said.

Oracle understands the challenges its customers face in trying to manage and secure identity-related information and knows that it is increasingly important to establish policies regarding such information, Hasan Rizvi, Oracle's vice president of identity management and security products, said in a statement.

Vendors and customers can currently review four components of IGF:

-- Client Attribute Requirement Markup Language (CARML), an XML-based declarative contract defined by application developers that informs deployment managers and service providers about the attribute-use requirements of an application;

-- Attribute Authority Policy Markup Language (AAPML), a set of policy rules regarding the use of identity-related information from an identity source that allow these sources to specify constraints on use of provided data by applications;

-- CARML, an application programming interface that makes it easier for developers to write applications that consume and use identity-related data in a way that conforms to policies set around the use of such information;

-- Identity Service, a policy-secured service for accessing identity-related data from multiple identity sources.

Oracle has the project's specifications posted at the IGF Web site.

Learn more about this topic

Oracle opened SMB center in Russia

08/24/06

Vendors emphasize identity management at RSA conference, Part 2

02/22/06

Industry views on Oracle's purchase of Oblix

04/06/05

Join the Network World communities on Facebook and LinkedIn to comment on topics that are top of mind.
Take IDG’s 2020 IT Salary Survey: You’ll provide important data and have a chance to win $500.