<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1096994277437474051</id><updated>2012-02-18T13:07:10.333-08:00</updated><title type='text'>IdentityCube</title><subtitle type='html'>Domenico Catalano's Blog on three dimensional Identity</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-1246382954581803127</id><published>2012-02-03T05:12:00.000-08:00</published><updated>2012-02-03T05:12:42.828-08:00</updated><title type='text'>UMA Tweet Chat</title><content type='html'>&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-GzTlkagEgoc/TyrNuwa3FKI/AAAAAAAAAV8/YJBXa99cTNg/s1600/UMA_logo_tweet.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="113" src="http://2.bp.blogspot.com/-GzTlkagEgoc/TyrNuwa3FKI/AAAAAAAAAV8/YJBXa99cTNg/s200/UMA_logo_tweet.jpg" width="200" /&gt;&lt;/a&gt;If you are interested in &lt;a href="http://kantarainitiative.org/confluence/display/uma/Home"&gt;User-Managed Access (UMA)&lt;/a&gt; from a technical standpoint, including UMA &lt;a href="http://kantarainitiative.org/confluence/display/uma/UMA+1.0+Core+Protocol"&gt;spec&lt;/a&gt;, UMA &lt;a href="http://kantarainitiative.org/confluence/display/uma/Implementations"&gt;implementations&lt;/a&gt;, development advice, best practices and intereroperability testing, don't miss the first-ever UMA Twitter chat on&amp;nbsp;&lt;i&gt;Wednesday, February 8, 2012, at 9-10am Pacific time&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;The hosts will be:&lt;br /&gt;Eve Maler, UMA group chair (&lt;a href="https://twitter.com/#!/xmlgrrl"&gt;@xmlgrrl&lt;/a&gt;) and&lt;br /&gt;Maciej Machulak, UMA group vice-chair (&lt;a href="https://twitter.com/#!/mmachulak"&gt;@mmachulak&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;The chat hashtag is &lt;a href="https://twitter.com/#!/search/%23UMAchat"&gt;#umachat&lt;/a&gt;. If you write in, be sure to use it! An easy way to follow along is to use &lt;a href="http://TweetChat.com/"&gt;TweetChat.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Join us!&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-pPBqiPA4zmY/TyueGAMvrZI/AAAAAAAAAWE/XNUIi9_PHxA/s400/DSC06889.jpg" width="400" /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-1246382954581803127?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/1246382954581803127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2012/02/uma-tweet-chat.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/1246382954581803127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/1246382954581803127'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2012/02/uma-tweet-chat.html' title='UMA Tweet Chat'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-GzTlkagEgoc/TyrNuwa3FKI/AAAAAAAAAV8/YJBXa99cTNg/s72-c/UMA_logo_tweet.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-7330397623179739553</id><published>2012-01-03T14:00:00.000-08:00</published><updated>2012-01-03T14:00:18.337-08:00</updated><title type='text'>UMA: Trust in a distributed authorization system</title><content type='html'>&lt;div style="color: #575759; font: normal normal normal 13px/normal Arial; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;                    &lt;/span&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/-gii2x7MMVto/Tu0n7iA4-_I/AAAAAAAAAVM/667Kz6Bjrqo/s1600/iStock_000006980385Small.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="132" src="http://2.bp.blogspot.com/-gii2x7MMVto/Tu0n7iA4-_I/AAAAAAAAAVM/667Kz6Bjrqo/s200/iStock_000006980385Small.jpg" width="200" /&gt;&lt;/a&gt;During the last &lt;a href="http://kantarainitiative.org/confluence/display/uma/Home"&gt;UMA WG&lt;/a&gt; Webinar (&lt;a href="http://kantarainitiative.org/confluence/download/attachments/37751312/Webinar-UMA-14Dec2011.pdf"&gt;slides&lt;/a&gt;) which was focused on multiple implementation demos and &lt;a href="http://identitycube.blogspot.com/2011/07/uma-openid-connect.html"&gt;UMA's OpenID Connect relationship&lt;/a&gt;, I had the opportunity to explain the current UMA trust model. Here are some descriptive details about this model.&lt;br /&gt;Many literatures try to define the concept of trust. According to the ITU-T X.509, Section 3.3.54, trust is defined as follows:&amp;nbsp;&lt;i&gt;“Generally an entity can be said to ‘trust’ a second entity when the first entity makes the assumption that the second entity will behave exactly as the first entity expects.”&lt;/i&gt;&lt;br /&gt;UMA trust model is built on the following implications that are based on the UMA features:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Host's Authorization decision is externalized to the Authorization Manager (AM).&lt;/li&gt;&lt;li&gt;There is no relationship between a Requester and the Authorization manager prior to a request for access.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;span id="goog_680855848"&gt;&lt;/span&gt;&lt;span id="goog_680855849"&gt;&lt;/span&gt;&lt;a href="http://www.blogger.com/"&gt;&lt;/a&gt;Externalizing an authorization decision requires a formal registration process and consequently a delegation of protection of a resource.&lt;br /&gt;Furthermore, because the AM does not know the requester directly, it has to use information from third parties who know the requester better. Normally, the AM trusts these third parties only for certain things and only to certain degrees.  &lt;br /&gt;These trust and delegation aspects make UMA's authorization system different from traditional access control.&lt;br /&gt;&lt;div&gt;The following diagram illustrates is an high level representation of the UMA Trust Model which describes the trust relationship. We use a multiple triangles representation because it's useful to represent this complex &amp;nbsp;trust relationship (2 parties + one authority).&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-2geY_oaRWYc/Tu0zhiuOIeI/AAAAAAAAAVs/kh6JRJAXwFQ/s1600/UMA_TM-02.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-2geY_oaRWYc/Tu0zhiuOIeI/AAAAAAAAAVs/kh6JRJAXwFQ/s1600/UMA_TM-02.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span id="goog_138133816"&gt;&lt;/span&gt;&lt;span id="goog_138133817"&gt;&lt;/span&gt;&lt;/div&gt;In the diagram are represented the three main aspects of the trust model: Registration, Trusted Claims and Delegation of Authority respectively related to the UMA functional model which includes: Protect, Authorize and Access (that you can see in the centered triangle).&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The Registration aspect describes the Host-AM Trust Relationship, this includes technical procedures (such as private key exchange), legal agreements and policies. &lt;br /&gt;On the left side, the vertex called "Accreditation system" represents a third party (e.g. Registration Authority) that we think&amp;nbsp;could be involved to guarantee an adequate level of trustworthiness about the parties in case of a specific business (i.e. Healthcare, financial credit).  It is not about identity exclusively.&lt;br /&gt;&lt;br /&gt;The Trusted Claims aspect describes the AM-Requester Trust Relationship. For this specific aspect we leverage &lt;a href="http://openid.net/connect/"&gt;OpenID Connect specification&lt;/a&gt; and its levels of assurance to enable an Claim-based authorization system (see slideshare &lt;a href="http://www.slideshare.net/domcat/uma-trusted-claims"&gt;here&lt;/a&gt;). The SmartAM demo in the webinar showed a case of OpenID Connect-sourced trusted claims.&lt;br /&gt;&lt;br /&gt;Last is the Delegation of Authority aspect which describes the Host-Requester Trust relationship, which is based on a delegation process, specific of the UMA protocol sequence which enables the propagation of trust.&lt;br /&gt;Examples of delegation are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The Authorizing User delegates rights of protecting its resource to the Authorization Manager.&lt;/li&gt;&lt;li&gt;The Host delegates rights of authorizing decision to the Authorization Manager.&amp;nbsp;&lt;/li&gt;&lt;li&gt;The Authorization Manager delegates rights of the Requester’s proof-of claims’s to a 3rd party Claims Provider.&lt;/li&gt;&lt;/ul&gt;For more details about the expectations and responsibilities of various parties interoperating in the User-Managed Access (UMA) context, please take a look at&amp;nbsp;&lt;a href="http://kantarainitiative.org/confluence/display/uma/UMA+Trust+Model"&gt;UMA Trust Model document&lt;/a&gt;&amp;nbsp;and the approach for &lt;a href="http://kantarainitiative.org/confluence/display/uma/Measuring+elements+of+Trust"&gt;Measuring Element of Trust&lt;/a&gt;.&lt;br /&gt;See also UMA Trust and Security Implication &lt;a href="http://kantarainitiative.org/confluence/display/uma/UMA+FAQ#UMAFAQ-TrustandSecurityImplications"&gt;FAQ&lt;/a&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-7330397623179739553?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/7330397623179739553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2012/01/uma-trust-in-distributed-authorization.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/7330397623179739553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/7330397623179739553'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2012/01/uma-trust-in-distributed-authorization.html' title='UMA: Trust in a distributed authorization system'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-gii2x7MMVto/Tu0n7iA4-_I/AAAAAAAAAVM/667Kz6Bjrqo/s72-c/iStock_000006980385Small.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-6783079235900822634</id><published>2011-07-29T06:02:00.000-07:00</published><updated>2011-07-29T06:02:41.429-07:00</updated><title type='text'>Privacy Control for User-Managed Access</title><content type='html'>This post is about my recent work at &lt;a href="http://www.ncl.ac.uk/"&gt;Newcastle University&lt;/a&gt; as contributor on the&amp;nbsp;&lt;a href="http://smartjisc.wordpress.com/"&gt;Smart project&lt;/a&gt;. The study explores visualization techniques to enhance privacy control user experience for &lt;a href="http://kantarainitiative.org/confluence/display/uma/Home"&gt;User-Managed Access (UMA)&lt;/a&gt; protocol, applied to SmartAM system.&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-7uPTBTPfTNQ/TjKuVZ1yCqI/AAAAAAAAAUM/sWtVAwUBvxE/s1600/UMA_Connection2.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-7uPTBTPfTNQ/TjKuVZ1yCqI/AAAAAAAAAUM/sWtVAwUBvxE/s1600/UMA_Connection2.jpg" /&gt;&lt;/a&gt;The goal is to mitigate risks of lost of privacy and the exploitation of online personal data caused from user difficulty to maintain control, correlate web resources and assign privileges for specific scope in the data sharing process.&lt;br /&gt;The approach (see slideshare presentation below) introduces the concepts of Connection, Control bridge and visualization tools for this purpose.&lt;br /&gt;&lt;br /&gt;&lt;div id="__ss_8673854" style="width: 425px;"&gt;&lt;strong style="display: block; margin: 12px 0 4px;"&gt;&lt;a href="http://www.slideshare.net/domcat/exploring-visualization-techniques-to-enhance-privacy-control-ux-for-usermanaged-access-8673854" target="_blank" title="Exploring Visualization Techniques to Enhance Privacy Control UX for User-Managed Access"&gt;Exploring Visualization Techniques to Enhance Privacy Control UX for User-Managed Access&lt;/a&gt;&lt;/strong&gt; &lt;iframe frameborder="0" height="355" marginheight="0" marginwidth="0" scrolling="no" src="http://www.slideshare.net/slideshow/embed_code/8673854" width="425"&gt;&lt;/iframe&gt; &lt;br /&gt;&lt;div style="padding: 5px 0 12px;"&gt;View more &lt;a href="http://www.slideshare.net/" target="_blank"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/domcat" target="_blank"&gt;domcat&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-6783079235900822634?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/6783079235900822634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2011/07/privacy-control-for-user-managed-access.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/6783079235900822634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/6783079235900822634'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2011/07/privacy-control-for-user-managed-access.html' title='Privacy Control for User-Managed Access'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-7uPTBTPfTNQ/TjKuVZ1yCqI/AAAAAAAAAUM/sWtVAwUBvxE/s72-c/UMA_Connection2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-5394835201152089703</id><published>2011-07-18T10:53:00.000-07:00</published><updated>2011-07-25T03:55:57.171-07:00</updated><title type='text'>UMA &amp; OpenID Connect</title><content type='html'>As part of my visit at the &lt;a href="http://www.ncl.ac.uk/"&gt;Newcastle University&lt;/a&gt;,&amp;nbsp;thanks to the&amp;nbsp;&lt;a href="http://smartjisc.wordpress.com/"&gt;Smart team&lt;/a&gt;&amp;nbsp;and prof. Aad van Moorsel,&amp;nbsp;&amp;nbsp;last Wednesday,&amp;nbsp;I had the opportunity to talk at the Computer Science Group Talk to a group of PhD students and researchers&amp;nbsp;about &lt;a href="http://kantarainitiative.org/confluence/display/uma/Home"&gt;UMA protocol&lt;/a&gt; and the extension to support Trusted Claims using OpenID Connect. The integration scenario (see slideshare below) shows an user interaction to get access to&amp;nbsp;UMA protected resource with&amp;nbsp;access restrictions based on requester's information/claims (i.e. email address, age, and gender) using OpenID Connect.&lt;br /&gt;Interestingly, yesterday was released a first &lt;a href="http://oauthssodemo.appspot.com/step/1"&gt;OpenID Connect demo w/Google&lt;/a&gt;. This is very useful for a further investigation about the integration approach and interfaces between UMA and OpenID Connect!&lt;br /&gt;&lt;div id="__ss_8585758" style="width: 425px;"&gt;&lt;strong style="display: block; margin: 12px 0 4px;"&gt;&lt;a href="http://www.slideshare.net/domcat/uma-trusted-claims" target="_blank" title="UMA Trusted Claims"&gt;UMA Trusted Claims&lt;/a&gt;&lt;/strong&gt; &lt;iframe frameborder="0" height="355" marginheight="0" marginwidth="0" scrolling="no" src="http://www.slideshare.net/slideshow/embed_code/8585758" width="425"&gt;&lt;/iframe&gt; &lt;br /&gt;&lt;div style="padding: 5px 0 12px;"&gt;View more &lt;a href="http://www.slideshare.net/" target="_blank"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/domcat" target="_blank"&gt;domcat&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-KjMLVA8PYeY/TiRwB5--cFI/AAAAAAAAAUE/Ras_jes1hq0/s1600/Smart+Team.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-KjMLVA8PYeY/TiRwB5--cFI/AAAAAAAAAUE/Ras_jes1hq0/s400/Smart+Team.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Smart team at Newcastle University&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-5394835201152089703?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/5394835201152089703/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2011/07/uma-openid-connect.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/5394835201152089703'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/5394835201152089703'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2011/07/uma-openid-connect.html' title='UMA &amp; OpenID Connect'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-KjMLVA8PYeY/TiRwB5--cFI/AAAAAAAAAUE/Ras_jes1hq0/s72-c/Smart+Team.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-2876758713330215191</id><published>2011-07-10T06:19:00.000-07:00</published><updated>2011-07-10T06:19:28.336-07:00</updated><title type='text'>User-Managed Access (UMA): Power to the people</title><content type='html'>&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/-ABaG0xswhuU/TPVcdD86ZpI/AAAAAAAAARo/jCwTdZbS3SI/s1600/UMA_logo.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-ABaG0xswhuU/TPVcdD86ZpI/AAAAAAAAARo/jCwTdZbS3SI/s1600/UMA_logo.png" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;As contributor and member of the leadership team at &lt;a href="http://kantarainitiative.org/confluence/display/uma/Home"&gt;Kantara&amp;nbsp;UMA WG&lt;/a&gt;, I'm very excited for the&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;a href="http://kantarainitiative.org/wordpress/2011/07/announcing-user-managed-access-uma-gives-data-sharing-power-to-the-people/"&gt;announced release of a first draft recommendation for UMA to the IETF for consideration&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;This is a fundamental milestone for the creation of a new generation of authorization system which gives data-sharing power to the people.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;The &amp;nbsp;approach addresses the emerging issues for data-sharing and identity in the cloud.&amp;nbsp;From a security and privacy perspective, UMA protocol, which is build on top of the IETF&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;a href="http://en.wikipedia.org/wiki/OAuth#OAuth_2.0"&gt;Oauth 2.0&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&amp;nbsp;effort, gives the user the capabilities to control what information will be revealed, for what purpose and with which party, indipendently from where the user information are stored.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/-9ORZ52oLku0/ThmkQU2_x7I/AAAAAAAAAT8/gW3d5hqVyE4/s1600/Newcastle-University.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="70" src="http://4.bp.blogspot.com/-9ORZ52oLku0/ThmkQU2_x7I/AAAAAAAAAT8/gW3d5hqVyE4/s200/Newcastle-University.jpg" width="200" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;This announce happens meanwhile I'm visiting Newcastle University where I joint the&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;a href="http://smartjisc.wordpress.com/"&gt;Smart team&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&amp;nbsp;for contributing on&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;SmartAM project&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&amp;nbsp;(another exciting challenge!!), which implements UMA specification.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;The Working group will demonstrate UMA's benefits in a public webinar on Wednesday, July 13, at 9am pacific time. Join us.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;You can register &lt;a href="https://ieee-isto.webex.com/mw0306ld/mywebex/default.do?service=1&amp;amp;siteurl=ieee-isto&amp;amp;nomenu=true&amp;amp;main_url=%2Fmc0805ld%2Fe.do%3Fsiteurl%3Dieee-isto%26AT%3DMI%26EventID%3D13129823%26UID%3D20430508%26Host%3D036f7a146b08002f031803%26RG%3D1%26FrameSet%3D2"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-2876758713330215191?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/2876758713330215191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2011/07/user-managed-access-uma-power-to-people.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/2876758713330215191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/2876758713330215191'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2011/07/user-managed-access-uma-power-to-people.html' title='User-Managed Access (UMA): Power to the people'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-ABaG0xswhuU/TPVcdD86ZpI/AAAAAAAAARo/jCwTdZbS3SI/s72-c/UMA_logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-5799904681561149210</id><published>2011-02-21T12:46:00.000-08:00</published><updated>2011-02-21T12:46:41.533-08:00</updated><title type='text'>Microsoft won't ship CardSpace 2.0</title><content type='html'>&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-e6WXNzz459M/TWKQb17ndeI/AAAAAAAAASg/3hT8TWffrYk/s1600/infocard_300x210.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="140" src="http://1.bp.blogspot.com/-e6WXNzz459M/TWKQb17ndeI/AAAAAAAAASg/3hT8TWffrYk/s200/infocard_300x210.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Last week, at &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.rsaconference.com/2011/usa/"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;RSA Conference&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;, Microsoft &lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.msdn.com/b/card/archive/2011/02/15/beyond-windows-cardspace.aspx"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;announced&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; not to ship Windows &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/windows/products/winfamily/cardspace/default.mspx"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;CardSpace&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; 2.0. This decision is very significant because Cardspace was considered&amp;nbsp;one of the most interesting user-centric technologies along with &lt;/span&gt;&lt;/span&gt;&lt;a href="http://openid.net/"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;OpenID&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;The Windows CardSpace software enables people to maintain a set of personal digital identities that are shown to them as visual “&lt;/span&gt;&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_Card"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Information Cards&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;”.&amp;nbsp;This approach mitigates phishing attacks and encourages a move away from passwords. &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;The card approach combined with the claims-based approach also has some potential privacy benefits.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;It seems that Microsoft is reconsidering the state of art of the identity landscape and the evolution of tools and cloud services and trying to focusing on claim-based identity using new approaches (see &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.identityblog.com/?p=1164"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Kim Cameron's Identity weblog: From CardSpace to Verified Claims&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;On the other hand, the claim-based Identity remains one of the vibrant concept to address permissioned data sharing scenarios in the cloud.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Claim-based Identity is also one of the main interest and priority of &lt;/span&gt;&lt;/span&gt;&lt;a href="http://kantarainitiative.org/confluence/display/uma/Home"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Kantara UMA WG&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; (Trusted Claims), where we are exploring some interesting &lt;/span&gt;&lt;/span&gt;&lt;a href="http://kantarainitiative.org/confluence/download/attachments/19660903/UMA_Enterprise_tClaims_V3.pdf"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;user experience&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; and the relationship with OpenID Connect to provide a claim-based access control spec in order to restrict and personalize access to cloud services.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-5799904681561149210?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/5799904681561149210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2011/02/microsoft-wont-ship-cardspace-20.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/5799904681561149210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/5799904681561149210'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2011/02/microsoft-wont-ship-cardspace-20.html' title='Microsoft won&apos;t ship CardSpace 2.0'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-e6WXNzz459M/TWKQb17ndeI/AAAAAAAAASg/3hT8TWffrYk/s72-c/infocard_300x210.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-1374533154379059986</id><published>2010-12-01T04:23:00.000-08:00</published><updated>2010-12-01T04:23:55.586-08:00</updated><title type='text'>OAuth, UMA and the Enterprise</title><content type='html'>&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;As reported from&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://independentidentity.blogspot.com/"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Phil Hunt&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt; Blog, a lot of Interest on OAuth applied to Enterprise scenario have emerged at last&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://www.internetidentityworkshop.com/iiwxi-11-in-mountain-view/"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;IIW#11&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;at Mountain View &amp;nbsp;(&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://www.blogger.com/goog_505530765"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;I&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://independentidentity.blogspot.com/2010/11/iiw-oauth-enterprise-bof-scenarios.html"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;IW OAuth Enterprise BOF&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_7I6p_e3WYTY/TPVcdD86ZpI/AAAAAAAAARo/V42W8gAaE9c/s1600/UMA_logo.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_7I6p_e3WYTY/TPVcdD86ZpI/AAAAAAAAARo/V42W8gAaE9c/s1600/UMA_logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Starting in 2008, I have worked on the Sun internal project led by&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://www.xmlgrrl.com/"&gt;Eve Maler&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;that formed the basis for User-Managed Access (UMA), based on OAuth, and later joined the Kantara UMA Work Group, now as Oracle employee, after Sun acquisition.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;div&gt;I've noted with much interest that the discussed scenarios at IIW BOF are very similar to the scenario and use case that I've proposed and then accepted from&amp;nbsp;&lt;a href="http://kantarainitiative.org/confluence/display/uma/"&gt;Kantara UMA WG&lt;/a&gt;&lt;u&gt;,&lt;/u&gt;&amp;nbsp;where I'm contributing as leadership team member.&lt;/div&gt;&lt;div&gt;The scenario that I've proposed is about an&amp;nbsp;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;a href="http://kantarainitiative.org/confluence/display/uma/loan_scenario"&gt;Online Personal loan&lt;/a&gt;&amp;nbsp;request that is a use case in which a user apply a request for a personal loan to a financial service.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;In brief&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;, to approve or reject the loan request, the financial service must verify many pieces of user personal information from different Service Provider/host. For instance, the amount of monthly user salary (i.e. 3 last monthly salary) from user's Employer, user bank account information (account number, net) and need to access to the user credit information (credit history, score, ect.) from the Financial Risk central service.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;The actors in UMA terminology:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;User as Authorizing User&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;Financial Service as Requester&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;User's Employer as Host (salary information)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;User Bank as Host (user account information)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;Financial Risk central service as Host (user credit information)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;Authorization Manager&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_7I6p_e3WYTY/TPVD9HjGpEI/AAAAAAAAARk/vzH3m3qJhrw/s1600/loan_request_scenario.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="307" src="http://4.bp.blogspot.com/_7I6p_e3WYTY/TPVD9HjGpEI/AAAAAAAAARk/vzH3m3qJhrw/s400/loan_request_scenario.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;Distinctive&amp;nbsp;aspects:&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: Helvetica;"&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The Authorizing User delegates authorization to a Requester to access to Service Providers.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;A Requester that needs a collection of information from multiple sources (resource aggregation).&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;A high-value, privacy-sensitive transaction.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Ensuring that information about the user is third-party verified by using the third parties directly as SPs/Hosts.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span class="Apple-style-span" style="font-family: Helvetica, Arial, sans-serif;"&gt;Through this and other scenarios&amp;nbsp;UMA WG is developing the next generation user-centric access management platform, based on OAuth 2.0 specification, but with the following key differentiators and capabilities:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Helvetica, Arial, sans-serif;"&gt;Provide a Centralized Policy Decision Point functionality based on end-user policy.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Helvetica, Arial, sans-serif;"&gt;Possibility to aggregate protected resources in a single basket to allow the requester to collect data from multiple resources.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Helvetica, Arial, sans-serif;"&gt;Enhance control on user privacy through an analytics dashboard and auditing to control &amp;nbsp;who access to what.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Furthermore, in order to address specific trust management issue that can be valuable in the Enterprise scenario, at Kantara UMA WG, we are defining an approach to extend UMA access control mechanism to support trusted Claims.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Helvetica;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;T&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;he UMA protocol supports the policy-driven ability of an AM to demand claims from a requesting party before authorization is granted. The claims may be self-asserted or third-party-asserted. In this novel approach, UMA leverages&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;the notion of a Trust Framework (defined by the&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://openidentityexchange.org/sites/default/files/the-open-identity-trust-framework-model-2010-03.pdf"&gt;Open Identity Trust Framework&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;(OITF) Model paper as&amp;nbsp;&lt;/span&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;“a set of technical, operational, and legal requirements and enforcement mechanisms for parties exchanging identity information”&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;and sometimes called a federation).&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Helvetica;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;For more details see last&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://kantarainitiative.org/confluence/display/uma/User+Experience#UserExperience-UMATrustedClaims"&gt;set of wireframes&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;developed to explore a person-to-person data sharing scenario&amp;nbsp;in which the Authorizing User wants to restrict sharing to a specific Requesting Party identity.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Helvetica;"&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;It is not complex extend the person-to-person data sharing scenario in a service-to-person scenario, where a Bank service, for instance, to grant access to specific resource to the customers could require specific user-managed trusted claims!!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-1374533154379059986?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/1374533154379059986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2010/12/oauth-uma-and-enterprise.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/1374533154379059986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/1374533154379059986'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2010/12/oauth-uma-and-enterprise.html' title='OAuth, UMA and the Enterprise'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_7I6p_e3WYTY/TPVcdD86ZpI/AAAAAAAAARo/V42W8gAaE9c/s72-c/UMA_logo.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1096994277437474051.post-8124529284134182918</id><published>2010-12-01T00:44:00.000-08:00</published><updated>2010-12-01T00:46:51.282-08:00</updated><title type='text'>A new blog site</title><content type='html'>This is my new blog site at &lt;a href="http://identitycube.blogspot.com/"&gt;identitycube.blogspot.com&lt;/a&gt;&lt;br /&gt;You can find my previous blogs at &lt;a href="http://blogs.sun.com/domcat"&gt;blogs.sun.com/domcat&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1096994277437474051-8124529284134182918?l=identitycube.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identitycube.blogspot.com/feeds/8124529284134182918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://identitycube.blogspot.com/2010/12/new-blog.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/8124529284134182918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1096994277437474051/posts/default/8124529284134182918'/><link rel='alternate' type='text/html' href='http://identitycube.blogspot.com/2010/12/new-blog.html' title='A new blog site'/><author><name>domcat</name><uri>http://www.blogger.com/profile/03828679426975865343</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
