* Identification using one identity, but multiple personas
endif; ?>Last time I gave you some definitions of identity, persona and role and their relationship in the identity management hierarchy. We defined “identity” as a person, an individual, a constant that cannot change (validated by DNA) and “persona” as an aspect of identity in a specific situation: office persona, parenting persona and so on. “Role” is then a specific application within a persona. In an office persona, for example, you might have a manager role, a mentor role, an employee role, etc.
So what can you do with these concepts?
Each, surprisingly, can have a definition that is unique to the concept, yet independent of the others. That is, just because a role is an aspect of a persona, the same role could exist for different personas – even for the same identity.
If you have an account with a car rental agency, for example, you are filling the role of “automobile renter.” This role has certain attributes – a driver’s license (with its own ID number from an issuing government agency), a credit card (yet another ID number from a commercial agency) and perhaps an insurance policy (one more ID number from a commercial agency).
You might, though, have two personas with the car rental agency: a “business persona” and a “leisure persona.” Your preferences for type of vehicle will differ for the two personas and the credit card “attribute” might differ also. Since the concept of “persona” is still fairly new, most car rental agencies aren’t equipped to handle more than one per identity. So you’ll need to finesse the problem by establishing two “identities” (actually, two different usernames) with the agency. You might need two separate e-mail addresses and/or two separate phone numbers as well, depending on how the car rental agency indexes their accounts.
You are still you, you have only one identity. You have two personas in this example, the Business Persona and the Leisure Persona. But you also have only one role – that of “vehicle renter.” That role has a number of attributes associated with it. Some of those attributes will differ between your two personas, but the object that is the vehicle renter role will be identical between the two personas.
Extrapolate into a Liberty Alliance “Circle of Trust” and you’ll see the applicability. You (the singular identity, unique in all the world for all time and all places) have accounts with a car rental agency and an airline. You may have multiple personas with each, which may or may not require multiple accounts with each, but generally you’ll play a single role with each – “air traveler” with the airline and “vehicle renter” with the car agency.
The Liberty specification holds that you need to establish separate accounts with each member of the circle of trust you wish to access and then link, or federate, these accounts. Thus you would federate the Business Persona at the car rental agency with the Business Persona at the airline. You’d do the same with the Leisure Persona at each. When you’re authenticated to one in your Business Persona, moving to the other would automatically authenticate you as the Business Persona with all of the attributes associated with it.
This still seems to require separate accounts, usernames and identifiers for each persona, though. What’s needed is another service, probably locally based (or, at least, on a network near you logically) which allows you to authenticate with your single, unique identity and then navigate based on the persona you wish to use at that particular time. Suggestions ARE welcome.




