SANTA CLARA, CALIF. – Microsoft says the enterprise goal of its forthcoming InfoCard technology is to strip access control from centralized deployments and return it to the owners of specific network resources.
Microsoft’s InfoCard technology and its UI implementation called CardSpace, presents users with an identity selector interface, basically a palette of secure identity cards, that can be used to authenticate to various Web sites or network resources such as applications or databases.
Speaking at this week’s Digital ID Conference, Kim Cameron, Microsoft’s identity architect, said the main role of InfoCard within corporations is to “devolve access control to resource owners.”
Microsoft plans to release CardSpace as part of the Vista operating system, which is slated to ship in November to corporate customers.
“The resource owner can say to the user you have a palette of identities and the resource will say ‘I will work with this identity,’” said Cameron. The resource owner would determine the depth of identity information needed and the level of trust, such as requiring that the issuer of the identity card be a trusted third party.
Cameron says the simplicity of using CardSpace identity cards and the visual nature of the interface, which highlights only the cards that will work with a particular resource, allow access controls to move away from centralized IT control.
“In the enterprise, local control decisions should be done by the business unit and not IT, but that has been impossible because it is too hard.” says Cameron. He says the trick is making the process of granting access so easy that users can do it “under adult supervision.”
He says the InfoCard technology is designed so that trust is localized and that the resource owner decides who and what can access their resources.
The decision can be delegated to an authorization gateway where rules and policies can be established for the resource. The gateway Microsoft is developing is called a Security Token Service and it is built on the WS-Trust Web services protocol.
Cameron also says that using the CardSpace UI implementation of the InfoCard technology, which ships in both the home and business versions of Vista, will help reduce the level of training that has to go into getting users up to speed with new technologies.
He likens it to word processing, which he says is a skill that no longer needs to be taught to end-users.
“CardSpace is a single user experience in the home and business,” he said. “When people come to work you won’t have to teach them about access controls and the model.”
To extend the CardSpace technology even further, Microsoft partner Ping Identity also announced at Digital ID World that it would ship software currently being developed under the name Java InfoCard Server that would act as a sort of middleware to tie the Microsoft InfoCard technology to non-Windows platforms. The software would ship sometime after Vista.
“We are helping to deliver this Microsoft technology into non-Microsoft environments,” says Andre Durand, CEO of Ping. “We see a lot of companies that have customer facing applications running on the LAMP stack and they need some integration point for InfoCard support.”




