<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Jim Phelps &#187; IdentityManagement</title>
	<atom:link href="http://jimphelps.info/tag/identitymanagement/feed/" rel="self" type="application/rss+xml" />
	<link>http://jimphelps.info</link>
	<description>Enterprise Architect , IT Architect in Madison, WI</description>
	<lastBuildDate>Fri, 02 Dec 2011 16:47:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='jimphelps.info' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Jim Phelps &#187; IdentityManagement</title>
		<link>http://jimphelps.info</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://jimphelps.info/osd.xml" title="Jim Phelps" />
	<atom:link rel='hub' href='http://jimphelps.info/?pushpress=hub'/>
		<item>
		<title>AACRAO Identity and Access Management 2007</title>
		<link>http://jimphelps.info/2007/07/27/aacrao-identity-and-access-management-2007/</link>
		<comments>http://jimphelps.info/2007/07/27/aacrao-identity-and-access-management-2007/#comments</comments>
		<pubDate>Fri, 27 Jul 2007 15:36:59 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Academia]]></category>
		<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[AACRAO]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2007/07/27/aacrao-identity-and-access-management-2007/</guid>
		<description><![CDATA[Karen Hanson (Assistant Registrar) and I ran a half-day workshop at the AACRAO Technology Conference on Identity and Access Management (IAM) and the Registrar&#8217;s role in IAM.   We had a great time even though the session was Sunday at 8AM.   The slides are here:  AACRAO 2007 IDM Slides We had a mix of &#8230; <a href="http://jimphelps.info/2007/07/27/aacrao-identity-and-access-management-2007/">Continue reading <span class="meta-nav">&#187;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=136&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Karen Hanson (Assistant Registrar) and I ran a half-day workshop at the <a href="http://www.aacrao.org/tech07/workshops.htm">AACRAO Technology Conference on Identity and Access Management (IAM) and the Registrar&#8217;s role in IAM</a>.   We had a great time even though the session was Sunday at 8AM.   The slides are here:  <a href="http://arch.doit.wisc.edu/jim/files/2007/07/aacrao-idm-hanson-and-phelps.pdf" title="AACRAO 2007 IDM Slides">AACRAO 2007 IDM Slides</a></p>
<p>We had a mix of people from central IT to Registrars in the audience.  We had schools that had fairly mature IAM systems to some who were just starting.  It was a fun time and there was good conversations.</p>
<p>Karen and I also had fun running around Minneapolis.  We had great food at Zelo and Masa and listened to the Spaghetti Western String Company.   We also saw the Picasso exhibit at the Walker Art Museum.</p>
<p>One of the better conferences trips that I&#8217;ve had in a while.<br />
<a href="http://arch.doit.wisc.edu/jim/files/2007/07/aacrao-idm-hanson-and-phelps.pdf" title="AACRAO 2007 IDM Slides"></a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/136/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/136/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/136/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=136&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2007/07/27/aacrao-identity-and-access-management-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
		<item>
		<title>Break Out Tables at CIC Identity Management</title>
		<link>http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/</link>
		<comments>http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/#comments</comments>
		<pubDate>Thu, 08 Jun 2006 13:44:37 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Work]]></category>
		<category><![CDATA[CIC]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/</guid>
		<description><![CDATA[There were two break out sessions at the CIC Identity Conference. The first was a breakout By Peer Groups. In this break out, Registrars sat together, CIOs sat together, etc. I was in the IT Idenity Management peer group. There were strong themes that came up during this discussion. Interestingly, the strongest themes were around: &#8230; <a href="http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/">Continue reading <span class="meta-nav">&#187;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=113&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There were two break out sessions at the <a href="http://www.cic.uiuc.edu/groups/CIOs/archive/ConferencePresentation/IdentityManagementConference2006/home.shtml">CIC Identity Conference</a>.</p>
<p>The first was a breakout <strong>By Peer Groups</strong>.  In this break out, Registrars sat together, CIOs sat together, etc.  I was in the IT Idenity Management peer group.  There were strong themes that came up during this discussion.  Interestingly, the strongest themes were around:</p>
<ul>
<li>Governance &#8211; how do you establish it on campus, how do you get buy in, who should be on the governance board, </li>
<li>Communication &#8211; the need for a common vocabulary for communicating with campus about Identity Management.</li>
<li>CAF <a href="http://www.cio.gov/eauthentication/documents/TCSPlist.pdf">Credential Assessment Framework PDF</a> &#8211; Especially as a tool to find gaps in the infrastructure and as a communication tool with campus.  If the campus want&#8217;s to use FASTLANE and NIH Grants and other applications, we will have to fill these gaps that are identified in the CAF Process.  </li>
<li>Mapping of Levels of Assurance to Risk Assessments for various applications.  Development of a Framework to map LOAs to <a href="http://www.cio.gov/eauthentication/era.htm">Risk Levels </a>for Applications. </li>
</ul>
<p><span id="more-113"></span></p>
<p>It is interesting that the Technologists didn&#8217;t list a bunch of technologies.  There concerns were mostly around communication, governance and policy.</p>
<p>We then had a break-out by University.  Each University would then gather and discuss what they had learned, their concerns, their thoughts on what their next steps should be.  From the <strong>University of Wisconsin &#8211; Madison break-out</strong>, I had the following list (which aligns with the list that we presented but isn&#8217;t exactly the same):</p>
<ol>
<li>Doing a CAF analysis and obtaining level 1 of LOA </li>
<li>Building a business case for Identity Management for campus.  (Note:  I believe that the CAF process can feed into the business case) </li>
<li>Tracking the Federal eAuthentication, CAF, Federal Identifier and other initiatives.  We need to keep up with the Federal initiatives and changes and to communicate those changes with campus </li>
<li>Build out of Identity Management infrastructure (specifically our PASE initiative which manages Groups and Entitlements). </li>
</ol>
<p><strong>Report out from all of the Universities:</strong></p>
<p>Common threads were:</p>
<ul>
<li>Establishing Governance, building a common vocabulary and Funding and Prioritization and Staffing. </li>
<li>Going through some version of the CAF process (maybe not bringing in the OMB but working through the analysis internally). </li>
<li>Dealing with &#8220;Privilege Bloat&#8221; &#8211; users accumulating access as they move around campus and change jobs</li>
<li>Federating with Federal Government especially around Research. </li>
<li>Separating Authentication from Authorization.</li>
<li>Education of the population &#8211; how to protect their own data and the institutional data.</li>
<li>How to serve affiliated populations &#8211; like distance ed, research collaborators, etc</li>
<li>2-factor Authentication came up at U-Minn. </li>
<li>Look at joining inCommon which will push people to document what they do.</li>
</ul>
<p><em>Next Steps</em></p>
<ol>
<li>Each University submit their summary / prioritized list so that they can be published as a group</li>
<li>The Universities that are going through the CAF process would like to gather to compare notes</li>
<li>Work together and join InCommon so we can federate with each other and to show vendors that we think this is important</li>
<li>Sharing notes on Governance &#8211; especially those who are building new governance structures &#8211; what are you trying, how is it going, documentation that might be sharable and adaptable</li>
<li>Should there be a regular CIC Identity Management Meeting?  Take this up via email and the CIC CIOs planning group</li>
<li>Generate common requirements for software that we could use with vendors.  Note: there are two flavors of this:  (1) What the software should do now and (2) what the vendors should be working towards.  The second is where the CIC might want to focus</li>
</ol>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/113/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/113/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=113&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
		<item>
		<title>CIC Identity Managment &#8211; Federated Identity and Sharing Resources</title>
		<link>http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/</link>
		<comments>http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/#comments</comments>
		<pubDate>Mon, 05 Jun 2006 18:45:38 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[CIC]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/</guid>
		<description><![CDATA[Session Details This panel session discussed Federated Identity Management and Sharing Resources. The slides are here as a PDF I was the moderator for the session. The panelists were: Kevin Morooney, PSU, Senior Director, Academic Services Kenneth Forstmeier, PSU, Director Office of Research Information Systems Mike Grady, UIUC, Sr. Technology Architect &#38; Strategist Phyllis Davidson, &#8230; <a href="http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/">Continue reading <span class="meta-nav">&#187;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=111&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Session Details</strong></p>
<p>This panel session discussed Federated Identity Management and Sharing Resources.  The slides are <a href="http://arch.doit.wisc.edu/jim/wp-content/uploads/2006/06/CICFederatedIdM.pdf">here as a PDF</a></p>
<p>I was the moderator for the session.  The panelists were:</p>
<ol>
<li>Kevin Morooney, PSU, Senior Director, Academic Services</li>
<li>Kenneth Forstmeier, PSU, Director Office of Research Information Systems</li>
<li>Mike Grady, UIUC, Sr. Technology Architect &amp; Strategist</li>
<li>Phyllis Davidson, IU, Interim Assistant Dean for Digital and I.T. Services</li>
</ol>
<p>Below are the highlights that I took away from the panel.</p>
<p><span id="more-111"></span></p>
<p><em>Kevin Morooney</em></p>
<p>Penn State University (PSU) has moved along way down the identity management roadmap.  They have two levels of internal authentication with their WebAccess for most applications and SecureID for higher level of assurance applications.  They are using Shibboleth to handle federated IdM with several outside service providers.</p>
<p>Kevin lists many of the Web2.0 applications (like Flickr, Wikis et al) as an interesting case that we need to think about.   Much of our students and faculty are using these applications.  Should the University provide a federated IdM process for their faculty and students to access these applications?  Which ones should be brought in house?</p>
<p><em>Kenneth Forstmeir</em></p>
<p>Researchers interacting with the federal government need to manage dozens of user accounts and passwords.  Each of the applications that they use have their own username/password pair and their own policies regarding password change policies.  The researcher cannot synchronize their usernames across these systems.  Federation would help with part of this problem but the solution must include a method for researchers to maintain their account information when they change institutions.  The researcher must be able to remap their identity with the government to a new set of credentials.</p>
<p><em>Mike Grady</em></p>
<p>UIUC started looking at using Shibboleth for library content &#8211; specifically content providers like Elsevier et al.   The contracts with the content providers are often based on a fixed set of IP addresses and they are often for multiple years.  The change to federation would allow UIUC to move groups to new IP ranges.  The change to a federated system would cause users to log in to resources which they were used to accessing automatically (because they were in the IP address range).</p>
<p>UIUC also uses federation intra-institutional.  Federation technology (like Shibboleth) can be used inside the institution to federate between separate identity management systems.</p>
<p><em>Phyllis Davidson</em></p>
<p>Phyllis presented several interesting use cases for federated identity management.  One of which is &#8220;Chat Reference&#8221;.  The library provides reference support via chat 24 hours a day.  They would like to be able to share the resources with other libraries.  Each library would provide some hours of support but be able to reduce their overall cost.  Other use cases involve Digitized Collections which could be hosted at various institutions but shared amongst the whole.</p>
<p>IP based access does not let you control levels of access based on Roles.  This is another thing that would come with federated identity and access management.</p>
<p><em>The Q and A </em></p>
<p>Where do Help Desk Questions go?  When a user can&#8217;t log in to a resource, who do they call?  How do they know who to call?  This is negotiated in the SLA between the Service Provider and the Identity Provider.  Scott Cantor states that it must be the Service Provider first.</p>
<p>The legal agreements between the Service Provider and Service Consumer need to include agreements about how help desk issues will be dealt with.  This agreement then needs to be communicated to the end users so they know who to call.</p>
<p>JimPhelps, ITArchitect, IT-Architecture, IdM, IdentityManagment,</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/111/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/111/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/111/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=111&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
		<item>
		<title>2005 EDUCAUSE National Meeting</title>
		<link>http://jimphelps.info/2005/10/18/2005-educause-national-meeting/</link>
		<comments>http://jimphelps.info/2005/10/18/2005-educause-national-meeting/#comments</comments>
		<pubDate>Tue, 18 Oct 2005 21:34:02 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[EDUCAUSE]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2005/10/18/2005-educause-national-meeting/</guid>
		<description><![CDATA[2005 EDUCAUSE National Meeting * * SF Middleware Initiative: Identity and Privilege Management Model * * Identity Management Roundtable<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=47&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.educause.edu/conference/annual/2005">2005 EDUCAUSE National Meeting </a><br />
* * <em><a href="http://www.educause.edu/LibraryDetailPage/666?ID=EDU05176">SF Middleware Initiative: Identity and Privilege Management Model</a></em><br />
* * <em><a href="http://www.educause.edu/E05/Program/5085?PRODUCT_CODE=E05/CI14">Identity Management Roundtable</a></em></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/47/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/47/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/47/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=47&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2005/10/18/2005-educause-national-meeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
		<item>
		<title>Identity Assertions, Extending Services and my Cell Phone</title>
		<link>http://jimphelps.info/2005/09/29/identity-assertions-extending-services-and-my-cell-phone/</link>
		<comments>http://jimphelps.info/2005/09/29/identity-assertions-extending-services-and-my-cell-phone/#comments</comments>
		<pubDate>Thu, 29 Sep 2005 14:28:17 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Work]]></category>
		<category><![CDATA[IdentityManagement]]></category>
		<category><![CDATA[Internet2]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2005/09/29/identity-assertions-extending-services-and-my-cell-phone/</guid>
		<description><![CDATA[When my cell phone rings, I flip open the cover and check the phone number of the caller. If the caller&#8217;s number is blocked or is not in my address book, I usually let the call go to voice mail. If the caller leaves a message, I listen to the message and then decide whether &#8230; <a href="http://jimphelps.info/2005/09/29/identity-assertions-extending-services-and-my-cell-phone/">Continue reading <span class="meta-nav">&#187;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=34&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>When my cell phone rings, I flip open the cover and check the phone number of the caller.  If the caller&#8217;s number is blocked or is not in my address book, I usually let the call go to voice mail.   If the caller leaves a message, I listen to the message and then decide whether or not I will call them back.   This is a simple case of Identity Assertion, Checking Access Rights and Extending Service.</p>
<p><span id="more-34"></span></p>
<p>It is an interesting example of the basic Authentication / Authorization flow:</p>
<p>1.  The Authentication is based on the &#8220;something you have&#8221; and &#8220;something you know&#8221; schemes.  They have a phone with a phone number and they know my phone number (or they have misdialed).<br />
2.  The caller presents an Identifier &#8211; their phone number.<br />
3.  My phone checks the Identifier against the &#8220;known and trusted user&#8221; directory &#8211; my Address book.<br />
  &#8212;  If the Identifier matches a user the directory, Bio/Demo data is expressed and I grant access or deny based on criteria for service access (if I&#8217;m in a meeting, I may not answer a call from my Wife but may answer a call from the CIO).    Another way to think of this is that different users have different access levels &#8211; the CIO has a high access level during work hours, my nephew has a lower access level during work hours.<br />
  &#8212;  If the Identifier doesn&#8217;t match a user in the directory, I may grant access or I may request further Identifiers (e.g. the user&#8217;s voice and message of intent in my voice mail)</p>
<p>This example highlights some interesting challenges in Authentication / Authorization schemes:  Access based on time (user X can get access services during normal business hours but not after hours), Exertion of further Identifiers (user X is not in our Directory but is in another trusted Directory or can present further credentials to gain access), Requiring additional credentials prior to granting access (user X has successfully logged in  with NetID and Password but needs another credential to gain further access).</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/34/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/34/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/34/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=34&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2005/09/29/identity-assertions-extending-services-and-my-cell-phone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
		<item>
		<title>NMI-EDIT CAMP &#8211; Monday 27 June 2005</title>
		<link>http://jimphelps.info/2005/06/27/nmi-edit-camp-monday-27-june-2005/</link>
		<comments>http://jimphelps.info/2005/06/27/nmi-edit-camp-monday-27-june-2005/#comments</comments>
		<pubDate>Mon, 27 Jun 2005 14:06:05 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Work]]></category>
		<category><![CDATA[EDUCAUSE]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2005/06/27/nmi-edit-camp-monday-27-june-2005/</guid>
		<description><![CDATA[Keith&#8217;s Opening Presentation Dealing with new hires. Desire to deliver email prior to hire. Getting HR to understand that they are part of a larger flow. The only interest isn&#8217;t just in the HR department. Can&#8217;t treat the value of the identity of a &#8220;potential student&#8221; as equal with a &#8220;PI&#8221; on campus. What do &#8230; <a href="http://jimphelps.info/2005/06/27/nmi-edit-camp-monday-27-june-2005/">Continue reading <span class="meta-nav">&#187;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=22&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Keith&#8217;s Opening Presentation</strong></p>
<p>Dealing with new hires.  Desire to deliver email prior to hire.  Getting HR to understand that they are part of a larger flow.  The only interest isn&#8217;t just in the HR department. </p>
<p>Can&#8217;t treat the value of the identity of a &#8220;potential student&#8221; as equal with a &#8220;PI&#8221; on campus.</p>
<p>What do you want to do for people?  Getting agreement on that on campus is 80% of the work.</p>
<p>We have to create a vision of the better place to be.  Then you can talk about the vision for the future and the techniques for getting there</p>
<p>Key functions of the future:</p>
<ol>
<li>Reflect &#8211; track information from key systems.  Can&#8217;t gather all information from all systems but pick the best source for the population</li>
<li> Join &#8211; combine identities from various sources to represent the actual individuals.</li>
</ol>
<p><strong>Michael Gettes &#8211; Credentialing</strong></p>
<p>What are the process (business process) that you have for credentialling?</p></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/22/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/22/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=22&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2005/06/27/nmi-edit-camp-monday-27-june-2005/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
	</channel>
</rss>
