SlideShare una empresa de Scribd logo
1 de 28
A Registry for Online Trust 
Don Thibeau 
Chairman & President
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
Four Problems Plague 
Trusted Transactions … 
… “Four Horsemen of the Identity Apocalypse”
… “Four Horsemen of the Identity Apocalypse” 
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
• Governance systems that are transparent in the service of trusted 
transactions in the “zero-trust” internet ecosystem 
• Liability is the legal enforcement and assignment of the duties of 
all actors in an identity system for the protection of all stakeholders 
• Certification options that are responsive to the speed, scale and 
dynamism of the internet 
• Adoption of a community of interest’s business, legal and technical 
interoperability requirements
© by Open Identity Exchange, 2014 
A Registry for Online Trust
Markets grow when there is trust between stakeholders, 
making transactions reliable and repeatable
Trusted identity systems need leverage
How do we leverage trusted identity systems?
Listings leverage identity data
Directories automate discovery
Exchanges grow markets
Registries build trust
Even dogs have registries!
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
There is no registry for trusted 
identity systems.
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
is building
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
Registries build trust
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
enable interoperability
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
increase the volume and velocity of trusted transactions
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
And accelerate market growth
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
How does it work?
© by Open Identity Exchange, 2014 
A Registry for Online Trust
Google, Microsoft, Ping Identity and salesforce to be the 
first to self-certify to the OpenID Connect standard and to 
be registered at the OIXnet pilot 
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
OIXnet Pilot 
Symantec providing a secure, trusted, scalable platform 
for conformance testing, self-certification and 
registration. 
OIX announces the pilot of the OIXnet registry and the 
the first self-certifications of OpenID Connect.
Registration 
Approval Package YES 
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
Pilot Registration Flow 
Registration 
Requirements FAQ 
& 
Terms of Service 
Approve 
? 
Registration 
Denial 
NO
Information Needed “To Be Trusted” 
COI’s are solely responsible for business, legal and technical 
requirements 
Information Needed “To Be Registered” 
OIX is solely responsible for business, legal and technical requirements 
GOVERNANCE 
LAYER 
ACCESS 
LAYER 
Manual/Automated Discovery 
Pilot Phase: Listing Service -- Future: Automated Discovery
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
Building OIXnet 
Testing Self-Certification and Registration 
Focusing on near-term, low cost, agile use-cases e.g. OpenID Connect 
Investing in legal research focused on liability in the OIXnet registry model 
Adapting Registry Models for OIXnet 
CA Browser Forum 
Cloud Security Alliance Star Registry 
U.S.-EU Safe Harbor 
IDESG Trust Framework and Trustmark Committee 
Liberty Alliance Project 
Piloting Registry Business, Legal and Technical Mechanisms 
Partnering with COI’s and e.g. OpenID Foundation and others 
Partnering with industry, government and academic leaders
… “Four Horsemen of the Identity Apocalypse” 
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
…“Four Horsemen of the Identity Apocalypse” 
• Governance: the full transparency of all COI and OIX business, 
legal and technical requirements builds trust 
• Liability: COI + OIXnet TOS agreements clearly assign and 
enforce all duties of all actors in an identity system 
• Certification: self certification + registration responds to the 
speed, scale and dynamism of internet identity 
• Adoption: OIXnet removes friction and speeds the discovery of a 
COI’s business, legal and technical requirements
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
Why OIX?
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
Global Cross-Sector Leadership 
Enterprise 
Data Aggregators 
Technology 
Consulting Services 
Banking 
Government 
Telcos
© by Open Identity Exchange, 2014 
A Registry for Online Trust 
Join OIX’s work to build trust in internet identity. 
Shape the future of trusted transactions online. 
Don Thibeau 
Chairman| Open Identity Exchange 
don.thibeau@openidentityexchange.org

Más contenido relacionado

La actualidad más candente

La actualidad más candente (10)

Scipay
ScipayScipay
Scipay
 
Making Blockchain Real for Business
Making Blockchain Real for BusinessMaking Blockchain Real for Business
Making Blockchain Real for Business
 
Open Identity Exchange - the Global Growth of Digital Identity
Open Identity Exchange - the Global Growth of Digital IdentityOpen Identity Exchange - the Global Growth of Digital Identity
Open Identity Exchange - the Global Growth of Digital Identity
 
Building trust attributes in e transactions (final) ver 3.0
Building trust attributes in e transactions (final) ver 3.0Building trust attributes in e transactions (final) ver 3.0
Building trust attributes in e transactions (final) ver 3.0
 
Blockchain as a process innovation in supply chains
Blockchain as a process innovation in supply chainsBlockchain as a process innovation in supply chains
Blockchain as a process innovation in supply chains
 
BCS ITNow 201509 - Identity
BCS ITNow 201509 - IdentityBCS ITNow 201509 - Identity
BCS ITNow 201509 - Identity
 
IEF2019 Infocredit
IEF2019 InfocreditIEF2019 Infocredit
IEF2019 Infocredit
 
Legal Tech Landscape Italy & Malta
Legal Tech Landscape Italy & MaltaLegal Tech Landscape Italy & Malta
Legal Tech Landscape Italy & Malta
 
Dictao Company Presentation
Dictao Company PresentationDictao Company Presentation
Dictao Company Presentation
 
E-government eIDAS - June 2016
E-government eIDAS - June 2016E-government eIDAS - June 2016
E-government eIDAS - June 2016
 

Similar a THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

ThisIsMe_Co.Profile_WebVersion_SA
ThisIsMe_Co.Profile_WebVersion_SAThisIsMe_Co.Profile_WebVersion_SA
ThisIsMe_Co.Profile_WebVersion_SA
Nad Shahid
 

Similar a THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED (20)

The Challenges of Third Party Credentials & Why a Trusted Identity Registry i...
The Challenges of Third Party Credentials & Why a Trusted Identity Registry i...The Challenges of Third Party Credentials & Why a Trusted Identity Registry i...
The Challenges of Third Party Credentials & Why a Trusted Identity Registry i...
 
A Business Case for "Findy"
A Business Case for "Findy" A Business Case for "Findy"
A Business Case for "Findy"
 
Carrie Peter
Carrie PeterCarrie Peter
Carrie Peter
 
IAM
IAMIAM
IAM
 
Session 1 - Introduction to i4Trust Data Spaces, building blocks, and roles |...
Session 1 - Introduction to i4Trust Data Spaces, building blocks, and roles |...Session 1 - Introduction to i4Trust Data Spaces, building blocks, and roles |...
Session 1 - Introduction to i4Trust Data Spaces, building blocks, and roles |...
 
IDENTITY ACCESS MANAGEMENT
IDENTITY ACCESS MANAGEMENTIDENTITY ACCESS MANAGEMENT
IDENTITY ACCESS MANAGEMENT
 
Blockchain explained FIATA Congress 20180910
Blockchain explained FIATA Congress 20180910Blockchain explained FIATA Congress 20180910
Blockchain explained FIATA Congress 20180910
 
ThisIsMe_Co.Profile_WebVersion_SA
ThisIsMe_Co.Profile_WebVersion_SAThisIsMe_Co.Profile_WebVersion_SA
ThisIsMe_Co.Profile_WebVersion_SA
 
Ron Atzmon, Au10tix - NOAH18 London
Ron Atzmon, Au10tix - NOAH18 LondonRon Atzmon, Au10tix - NOAH18 London
Ron Atzmon, Au10tix - NOAH18 London
 
Managing Sensitive Information in an API and Microservices World
Managing Sensitive Information in an API and Microservices WorldManaging Sensitive Information in an API and Microservices World
Managing Sensitive Information in an API and Microservices World
 
Managing identity for the future how everybody can win - david alexander - ...
Managing identity for the future   how everybody can win - david alexander - ...Managing identity for the future   how everybody can win - david alexander - ...
Managing identity for the future how everybody can win - david alexander - ...
 
Shaping the Future of Trusted Digital Identity
Shaping the Future of Trusted Digital IdentityShaping the Future of Trusted Digital Identity
Shaping the Future of Trusted Digital Identity
 
OpenAthens Conference 2018 - Don Thibeau - OpenID Connect
OpenAthens Conference 2018 - Don Thibeau - OpenID ConnectOpenAthens Conference 2018 - Don Thibeau - OpenID Connect
OpenAthens Conference 2018 - Don Thibeau - OpenID Connect
 
CIS 2017 - So you want to use standards to secure your APIs?
CIS 2017 - So you want to use standards to secure your APIs?CIS 2017 - So you want to use standards to secure your APIs?
CIS 2017 - So you want to use standards to secure your APIs?
 
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
 
ENTITY EXCHANGE FOR SELL-SIDE FIRMS
ENTITY EXCHANGE FOR SELL-SIDE FIRMSENTITY EXCHANGE FOR SELL-SIDE FIRMS
ENTITY EXCHANGE FOR SELL-SIDE FIRMS
 
Shufti Pro| Digital Identity Verification Solution
Shufti Pro| Digital Identity Verification SolutionShufti Pro| Digital Identity Verification Solution
Shufti Pro| Digital Identity Verification Solution
 
RIVIO Clerainghouse Overview
RIVIO Clerainghouse OverviewRIVIO Clerainghouse Overview
RIVIO Clerainghouse Overview
 
Identity Verification API The Cornerstone of Digital Trust.docx
Identity Verification API The Cornerstone of Digital Trust.docxIdentity Verification API The Cornerstone of Digital Trust.docx
Identity Verification API The Cornerstone of Digital Trust.docx
 
IDfy Booklet
IDfy BookletIDfy Booklet
IDfy Booklet
 

Más de ForgeRock

Más de ForgeRock (20)

Digital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at ScaleDigital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
 
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and BeyondGet the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
 
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Sydney: Identity Management  - A Strategic OpportunityIdentity Live Sydney: Identity Management  - A Strategic Opportunity
Identity Live Sydney: Identity Management - A Strategic Opportunity
 
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity CapabilityIdentity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity Capability
 
Identity Live Singapore 2018 Keynote Presentation
Identity Live Singapore 2018 Keynote PresentationIdentity Live Singapore 2018 Keynote Presentation
Identity Live Singapore 2018 Keynote Presentation
 
Identity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote PresentationIdentity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote Presentation
 
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'EmIdentity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'Em
 
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected SocietyIdentity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected Society
 
Identity Live Sydney: Intelligent Authentication
Identity Live Sydney: Intelligent Authentication Identity Live Sydney: Intelligent Authentication
Identity Live Sydney: Intelligent Authentication
 
Identity Live Sydney: Building Trust and Privacy in a Connected Society
Identity Live  Sydney:  Building Trust and Privacy in a Connected SocietyIdentity Live  Sydney:  Building Trust and Privacy in a Connected Society
Identity Live Sydney: Building Trust and Privacy in a Connected Society
 
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep DiveGet the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
 
Get the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - OverviewGet the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - Overview
 
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
ForgeRock and Trusona - Simplifying the Multi-factor User ExperienceForgeRock and Trusona - Simplifying the Multi-factor User Experience
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
 
Opening Keynote (Identity Live Berlin 2018)
Opening Keynote (Identity Live Berlin 2018)Opening Keynote (Identity Live Berlin 2018)
Opening Keynote (Identity Live Berlin 2018)
 
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
 
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
 
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
 
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
 
Shift from GDPR readiness to sustained compliance to improve your business an...
Shift from GDPR readiness to sustained compliance to improve your business an...Shift from GDPR readiness to sustained compliance to improve your business an...
Shift from GDPR readiness to sustained compliance to improve your business an...
 
Intelligent Authentication (Identity Live Berlin 2018)
Intelligent Authentication  (Identity Live Berlin 2018)Intelligent Authentication  (Identity Live Berlin 2018)
Intelligent Authentication (Identity Live Berlin 2018)
 

Último

The title is not connected to what is inside
The title is not connected to what is insideThe title is not connected to what is inside
The title is not connected to what is inside
shinachiaurasa2
 
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdfintroduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
VishalKumarJha10
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
VictorSzoltysek
 

Último (20)

ManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide DeckManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide Deck
 
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdfPayment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
Payment Gateway Testing Simplified_ A Step-by-Step Guide for Beginners.pdf
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdfAzure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
 
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
 
The title is not connected to what is inside
The title is not connected to what is insideThe title is not connected to what is inside
The title is not connected to what is inside
 
8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students
 
Microsoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdfMicrosoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdf
 
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
 
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
Direct Style Effect Systems -The Print[A] Example- A Comprehension AidDirect Style Effect Systems -The Print[A] Example- A Comprehension Aid
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Chinsurah Escorts ☎️8617697112 Starting From 5K to 15K High Profile Escorts ...
Chinsurah Escorts ☎️8617697112  Starting From 5K to 15K High Profile Escorts ...Chinsurah Escorts ☎️8617697112  Starting From 5K to 15K High Profile Escorts ...
Chinsurah Escorts ☎️8617697112 Starting From 5K to 15K High Profile Escorts ...
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation Template
 
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verifiedSector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
 
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdfintroduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
 
Define the academic and professional writing..pdf
Define the academic and professional writing..pdfDefine the academic and professional writing..pdf
Define the academic and professional writing..pdf
 

THE CHALLENGES OF THIRD-PARTY IDENTITY CREDENTIALS & WHY A TRUSTED IDENTITY REGISTRY IS NEEDED

  • 1. A Registry for Online Trust Don Thibeau Chairman & President
  • 2. © by Open Identity Exchange, 2014 A Registry for Online Trust Four Problems Plague Trusted Transactions … … “Four Horsemen of the Identity Apocalypse”
  • 3. … “Four Horsemen of the Identity Apocalypse” © by Open Identity Exchange, 2014 A Registry for Online Trust • Governance systems that are transparent in the service of trusted transactions in the “zero-trust” internet ecosystem • Liability is the legal enforcement and assignment of the duties of all actors in an identity system for the protection of all stakeholders • Certification options that are responsive to the speed, scale and dynamism of the internet • Adoption of a community of interest’s business, legal and technical interoperability requirements
  • 4. © by Open Identity Exchange, 2014 A Registry for Online Trust
  • 5. Markets grow when there is trust between stakeholders, making transactions reliable and repeatable
  • 6. Trusted identity systems need leverage
  • 7. How do we leverage trusted identity systems?
  • 12. Even dogs have registries!
  • 13. © by Open Identity Exchange, 2014 A Registry for Online Trust There is no registry for trusted identity systems.
  • 14. © by Open Identity Exchange, 2014 A Registry for Online Trust is building
  • 15. © by Open Identity Exchange, 2014 A Registry for Online Trust Registries build trust
  • 16. © by Open Identity Exchange, 2014 A Registry for Online Trust enable interoperability
  • 17. © by Open Identity Exchange, 2014 A Registry for Online Trust increase the volume and velocity of trusted transactions
  • 18. © by Open Identity Exchange, 2014 A Registry for Online Trust And accelerate market growth
  • 19. © by Open Identity Exchange, 2014 A Registry for Online Trust How does it work?
  • 20. © by Open Identity Exchange, 2014 A Registry for Online Trust
  • 21. Google, Microsoft, Ping Identity and salesforce to be the first to self-certify to the OpenID Connect standard and to be registered at the OIXnet pilot © by Open Identity Exchange, 2014 A Registry for Online Trust OIXnet Pilot Symantec providing a secure, trusted, scalable platform for conformance testing, self-certification and registration. OIX announces the pilot of the OIXnet registry and the the first self-certifications of OpenID Connect.
  • 22. Registration Approval Package YES © by Open Identity Exchange, 2014 A Registry for Online Trust Pilot Registration Flow Registration Requirements FAQ & Terms of Service Approve ? Registration Denial NO
  • 23. Information Needed “To Be Trusted” COI’s are solely responsible for business, legal and technical requirements Information Needed “To Be Registered” OIX is solely responsible for business, legal and technical requirements GOVERNANCE LAYER ACCESS LAYER Manual/Automated Discovery Pilot Phase: Listing Service -- Future: Automated Discovery
  • 24. © by Open Identity Exchange, 2014 A Registry for Online Trust Building OIXnet Testing Self-Certification and Registration Focusing on near-term, low cost, agile use-cases e.g. OpenID Connect Investing in legal research focused on liability in the OIXnet registry model Adapting Registry Models for OIXnet CA Browser Forum Cloud Security Alliance Star Registry U.S.-EU Safe Harbor IDESG Trust Framework and Trustmark Committee Liberty Alliance Project Piloting Registry Business, Legal and Technical Mechanisms Partnering with COI’s and e.g. OpenID Foundation and others Partnering with industry, government and academic leaders
  • 25. … “Four Horsemen of the Identity Apocalypse” © by Open Identity Exchange, 2014 A Registry for Online Trust …“Four Horsemen of the Identity Apocalypse” • Governance: the full transparency of all COI and OIX business, legal and technical requirements builds trust • Liability: COI + OIXnet TOS agreements clearly assign and enforce all duties of all actors in an identity system • Certification: self certification + registration responds to the speed, scale and dynamism of internet identity • Adoption: OIXnet removes friction and speeds the discovery of a COI’s business, legal and technical requirements
  • 26. © by Open Identity Exchange, 2014 A Registry for Online Trust Why OIX?
  • 27. © by Open Identity Exchange, 2014 A Registry for Online Trust Global Cross-Sector Leadership Enterprise Data Aggregators Technology Consulting Services Banking Government Telcos
  • 28. © by Open Identity Exchange, 2014 A Registry for Online Trust Join OIX’s work to build trust in internet identity. Shape the future of trusted transactions online. Don Thibeau Chairman| Open Identity Exchange don.thibeau@openidentityexchange.org

Notas del editor

  1. We are here to solve four problems and to solve four problems The first step is demystifying or deconstructing the problems OIX does this through white papers, pilots and workshops. Others help solve these problems like OpendID Foundation, IETF, etc. solve in working groups in a SDO
  2. Use faded graghic from four horseman of the identity apo
  3. Certification + registration answers the question “who do I trust?” COIs: “We’ll trust OIXnet registrants” Investing in legal research focused on liability in the OIXnet registry model 1st clear and compelling (part of) solution overcoming two biggest roadblocks: certification and liability Self-certification will now be a legitimate global certification solution Self-certification doesn’t replace 3rd party certification but rather complements them and offers an alternative Simplest way of trusting: low cost + low overhead NO contract(s) NO meeting(s) OIX IPR Agreement is effective: rivals + rival sectors New sectors: banking + retail