What identity systems can learn from the toys of our youth

Opinion
Apr 30, 20074 mins

* Identity system construction kits

Kim Cameron, Microsoft’s identity architect delivered the keynote address at last week’s Directory Experts Conference. You can read all the details of his talk in John Fontana’s story at Network World, but I want to concentrate on a new term that Cameron coined: Legonics. Specifically, he referred to the “Legonic Identity System.” This was a reference to the well-known children’s (and quite a few adults, I’ll add) construction sets from Danish producer Lego Systems.

Lego toys are virtually indestructible, but the really amazing thing is that almost all of the pieces are able to connect to almost all of the other pieces – blocks, bricks, trees, bodies, heads, hands, hats, wheels and on, and on. Cameron meant that the ideal identity system would work in much the same way, with numerous pieces all fitting together and easily put together by the user, to produce an end-to-end identity system.

Well, this got me thinking about other toys from my long lost youth. Is there a toy metaphor for identity systems?

Consider three other construction sets or toys: the Erector Set (Meccano for my U.K. readers), Tinker Toys and Lincoln Logs.

Lincoln Logs, in my youth, were the most realistic looking of the construction sets. Made from real wood, they were easily put together to build log cabins, even forts! Unfortunately, after you’ve built the fort and the house there wasn’t much else you could do with the pieces. Most early identity systems were like this – they did one thing, and often did it well, but there wasn’t really room for expansion when you wanted to add other features.

Tinker Toys let you build interesting objects (bridges, ferris wheels and more) using a “hub and spoke” approach to connecting the various pieces. We might call this the “metadirectory model” of identity, which connects various identity stores, applications and services with “connectors” all leading through a central repository. The more objects you need to connect, though, the more hubs needed to be used and the more unstable your Tinker Toy construction becomes – just as linking multiple metadirectories creates instabilities in your identity system.

My Erector Set didn’t have a problem with extensibility, though. It was robust. That’s because everything was connected with nuts and bolts which were often easier to put on then to take off! It was fun, but for any project more involved than, say, a square building, I usually had to get my dad involved to “help.” That’s like many proprietary identity systems which require the services of some high-priced consultants in order to build anything really useful. And then, once it’s built, you most likely need to call them in to dismantle it and start over should you want to expand its scope.

But Legos, ah Legos. Over the years my wife and I must have purchased dozens and dozens of different sets. All eventually got dumped together into a large storage chest which still gets dragged out for our grandchildren. And, each time, brand new objects are created, using parts from many different sets. Items that weren’t even imaginable (say, cell phones) when the first Lego sets were purchased can nevertheless be modeled with those 30-year-old pieces and blocks. This is what an agile identity system should be – easy enough so that anyone with a modicum of “software dexterity” can construct a useful system and agile enough so that the system can be extended and expanded without having to take it apart. The Legonic Identity System, easily the second most ingenious use of Legos I’ve seen this year (see here for the first!) and a model we could all use in designing the building blocks of identity systems.