Keeping your identity under lock and key

Opinion
May 5, 20043 mins

* How a bank's safe deposit box could be the answer to our identity mgmt. issues

Last issue, I talked about the differences between WS-Federation and the Liberty Alliance schemes for federated identity. While having a free-ranging discussion with Arvind Krishna, IBM’s Vice President of Provisioning and Security Development, I realized that the major obstacle to consumer acceptance of federated identity might be the issue of where data is stored: on the local PC, at a single “identity provider” site, or scattered among all of the organizations with which the user has accounts.

Each of these scenarios has major drawbacks. Local storage is only available when you are using the PC the data is stored on. A single holder of identity data – even when that’s someone as trustworthy as a credit card company – is fraught with privacy and identity theft concerns. But data that’s scattered over multiple sites, so that the “federated identity” becomes little more that a single sign-on function, requires drudge work by the consumer to keep the data up-to-date and synchronized. Could there be a better way?

Krishna and I agreed that while we might trust a bank to hold and protect our financial identity data, we wouldn’t be as ready to let that bank dole out our medical identity data. But thinking about banks led me to think about a service they offer and have offered almost since banks first came into existence – safe deposit boxes.

Dictionary.com defines “safe deposit box” as: “A fireproof metal box, usually in a bank vault, for the safe storage of valuables.” The University of Minnesota’s Info-U (https://www.extension.umn.edu/info-u/finances/BF821.html) says that, “Safe deposit box storage is recommended for records or items that have high monetary value or would be difficult or expensive to replace.”

What’s more valuable, or more difficult to replace, than your personal identity information? There are also very stringent rules about who can and cannot open a safe deposit box and the conditions necessary for anyone besides the owner to do so are strictly enumerated.

A safe deposit box at your bank requires two keys to open, one supplied by the bank and one supplied by the person opening the box. My bank, at least, requires that I authenticate myself by showing a photo ID and using a signature, before being allowed to insert my key.

So what we’ve got is a system where the user, who was previously validated when the account was opened, must actively authenticate to gain access to the resource (the box) and then must supply a key, along with the bank’s own key, in order to actually open the box. Compare that to a user wishing to authenticate to a site, access a resource and open a file that’s been encrypted with a key – or two keys. See the similarities?

Drop me a note (identity@vquill.com) with your thoughts on a safe deposit box model for identity data and federation. In a week or too, I’ll summarize the correspondence and maybe, just maybe, we can begin to find a method that works for everybody.