* Microsoft includes CardSpace in Vista
Momentum continues to grow in the user-centric identity space. The recent release of Microsoft’s Vista desktop operating system, the first to include the CardSpace technology, could be the catalyzing event. CardSpace, itself, uses the Internet Explorer browser as the basis for the user interface but there are now two different Firefox-based implementations for those who avoid IE whenever possible.
The later of the two is by Kevin Miller while the pioneer work is by Chuck Mortimore. Mortimore’s code implements a Relying Party (RP) service for CardSpace and Firefox, while Miller’s implementation adds a card selector system so that other iCards besides the Microsoft implementation can be used. Both of these efforts deserve support if we want to see the whole Identity Card (iCard) paradigm moved forward. In fact, it was Mike Jones, Microsoft director of distributed systems customer strategy and evangelism, who drew my attention to Miller’s work.
Besides iCards, the other major thrust in user-centric identity is OpenID, which also seems to be gaining momentum. For anyone who couldn’t make it to the recent Internet Identity Workshop, Enomaly – the Canadian open source consultancy – has posted a complete, yet concise, description of how OpenID works. In a nutshell, “OpenID starts with the concept that anyone can identify themselves on the Internet the same way websites do-with a URI (also called a URL or Web address). Since URIs are at the very core of Web architecture, they provide a solid foundation for user-centric identity.” Head over to the site and read the rest.
Before wrapping up for this year I also want to point you to two recent papers related to identity in what might be termed niche areas but which could become important quicker than we might realize.
Grid computing creates supercomputer power from clusters of inexpensive PC boxes (for more about grid computing, see “Grid computing comes of age”). The Open Grid Forum published a paper – “Conceptual Grid Authorization Framework and Classification” – which just recently came to my attention, outlining a proposed authorization system for the grid computing environment. This is quite different, even from the networked systems we currently use. It’s long, it’s detailed, but it could be useful to you.
Finally, there’s a new paper in the area of identity-based encryption published by the International Association for Cryptologic Research. “New Identity-Based Authenticated Key Agreement Protocols from Pairings” probably isn’t what could be called a “page turner” or a “pot boiler” but it does present some interesting information about using identity in a PKI environment, which might be very important in the near future. Read this when you’ve got a couple of quiet hours – and are fully awake. But do read it.
That’s it for 2006; we’ll catch you on the other side of the New Year’s revels. Stay safe, and remember who you are!




