<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:planet="http://planet.intertwingly.net/" xmlns:indexing="urn:atom-extension:indexing" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" indexing:index="no"><access:restriction xmlns:access="http://www.bloglines.com/about/specs/fac-1.0" relationship="deny" />
  <title>Planet Identity</title>
  <updated>2013-05-22T15:04:49Z</updated>
  <generator uri="http://intertwingly.net/code/venus/">Venus</generator>
  <author>
    <name>Pat Patterson</name>
    <email>pat@superpat.com</email>
  </author>
  <id>http://planetidentity.org/atom.xml</id>
  
  <link href="http://planetidentity.org" rel="alternate" />

  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/PlanetIdentity" /><feedburner:info uri="planetidentity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry xml:lang="en-US">
    <id>http://www.discoveringidentity.com/?p=3693</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/DFVz1LpRVBU/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Oracle: Proximity Changes Perception</title>
    <summary type="html">As I reviewed news stories about the tragic Oklahoma tornado, I couldn’t help but notice the stark contrast between a photo taken from far away and one taken up close and personal.  The first photo is from NASA: “The image was captured on May 20, 2013, at 19:40 UTC (2:40 p.m. CDT) as the tornado began [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;As I reviewed news stories about the tragic Oklahoma tornado, I couldn’t help but notice the stark contrast between a photo taken from far away and one taken up close and personal.  The first photo is from &lt;a href="http://www.nasa.gov/multimedia/imagegallery/image_feature_2513.html" target="blank"&gt;NASA&lt;/a&gt;: “The image was captured on May 20, 2013, at 19:40 UTC (2:40 p.m. CDT) as the tornado began its deadly swath.”&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.nasa.gov/multimedia/imagegallery/image_feature_2513.html" target="blank"&gt;&lt;img alt="OKStorm1" border="0" height="312" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/OKStorm1.jpg" style="display: block; margin-left: auto; margin-right: auto;" title="OKStorm1.jpg" width="580"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;The second is from a &lt;a href="http://www.cbsnews.com/8301-201_162-57585407/at-least-51-dead-after-massive-okla-tornado/" target="blank"&gt;CBS News&lt;/a&gt; account on the day the storm hit: “A child is pulled from the rubble of the Plaza Towers Elementary School in Moore, Okla., and passed along to rescuers Monday, May 20, 2013.”&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.cbsnews.com/8301-201_162-57585407/at-least-51-dead-after-massive-okla-tornado/" target="blank"&gt;&lt;img alt="OKstorm2" border="0" height="290" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/OKstorm2.jpg" style="display: block; margin-left: auto; margin-right: auto;" title="OKstorm2.jpg" width="580"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;My thoughts and prayers go out to the people who are struggling to cope with the aftermath of this huge disaster.  How wonderful to hear stories of the many, many people who are giving personal, selfless service to help the good people of Oklahoma.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=DFVz1LpRVBU:BnOuQEFXUFw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=DFVz1LpRVBU:BnOuQEFXUFw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=DFVz1LpRVBU:BnOuQEFXUFw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=DFVz1LpRVBU:BnOuQEFXUFw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/DFVz1LpRVBU" height="1" width="1"/&gt;</content>
    <updated>2013-05-22T14:59:06Z</updated>
    <category term="General" />
    <category term="Oklahoma" />
    <category term="Tornado" />
    <category term="Weather" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Exploring the science and magic of Identity and Access Management</subtitle>
      <title>Discovering Identity</title>
      <updated>2013-05-22T15:02:14Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2013/05/22/proximity-changes-perception/</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.discoveringidentity.com/?p=3689</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/qQiERrA3thw/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Oracle: Diagram: Identity is the New Perimeter</title>
    <summary type="html">I like the diagram Mark O’Neill of Vordel put in a recent post, “Identity is the New Perimeter.” That phrase has been floating around for some time, but I think this diagram illustrates the concept in the simplest, clearest way I have seen: The article does a good job of describing this new way of looking at security.  As [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;I like the diagram &lt;a href="http://www.linkedin.com/pub/mark-o-neill/0/34/129" target="blank"&gt;Mark O’Neill&lt;/a&gt; of &lt;a href="http://www.vordel.com/" target="blank"&gt;Vordel&lt;/a&gt; put in a recent post, “&lt;a href="http://www.soatothecloud.com/2013/05/identity-is-new-perimeter.html" target="blank"&gt;Identity is the New Perimeter&lt;/a&gt;.” That phrase has been floating around for some time, but I think this diagram illustrates the concept in the simplest, clearest way I have seen:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.soatothecloud.com/2013/05/identity-is-new-perimeter.html" target="blank"&gt;&lt;img alt="IdentityIsTheNewPerimeter" border="0" height="351" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/IdentityIsTheNewPerimeter.png" style="display: block; margin-left: auto; margin-right: auto;" title="IdentityIsTheNewPerimeter.png" width="580"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;The article does a good job of describing this new way of looking at security.  As Mark mentioned in the post, Bill Gates once said, “security should be based on policy, not topology.”&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=qQiERrA3thw:yMT9rP9M3hQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=qQiERrA3thw:yMT9rP9M3hQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=qQiERrA3thw:yMT9rP9M3hQ:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=qQiERrA3thw:yMT9rP9M3hQ:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/qQiERrA3thw" height="1" width="1"/&gt;</content>
    <updated>2013-05-22T14:39:01Z</updated>
    <category term="Identity" />
    <category term="Information Security" />
    <category term="Perimeter Security" />
    <category term="Vordel" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Exploring the science and magic of Identity and Access Management</subtitle>
      <title>Discovering Identity</title>
      <updated>2013-05-22T15:02:14Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2013/05/22/diagram-identity-is-the-new-perimeter/</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/executiveview_mcafeecloudsso7074622513</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/QTZfPTlbDHw/executiveview_mcafeecloudsso7074622513" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Executive View: McAfee Cloud Single Sign On - 70746</title>
    
    <updated>2013-05-22T14:36:35Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;In April 2013 McAfee announced the addition of Identity and Access Management solutions to its Security Connected portfolio. The products that were previously developed and sold by Intel include McAfee Cloud Single Sign On and McAfee One Time Password. In addition to the products McAfee also introduced the new McAfee Identity Center of Expertise, staffed with experts in identity and cloud security. That free service will assist users with support pertaining to identity and access...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/executiveview_mcafeecloudsso7074622513"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/QTZfPTlbDHw" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=QTZfPTlbDHw:KRTCcQ2Vc40:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=QTZfPTlbDHw:KRTCcQ2Vc40:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=QTZfPTlbDHw:KRTCcQ2Vc40:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=QTZfPTlbDHw:KRTCcQ2Vc40:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/QTZfPTlbDHw" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/executiveview_mcafeecloudsso7074622513</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.discoveringidentity.com/?p=3687</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/SpQiPagO4y4/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Oracle: #IoT, Big Data and Authenticity</title>
    <summary type="html">Today, I read an interesting white paper, “Big Data in M2M: Tipping Points and Subnets of Things,” published by Machina Research. From the introduction: This White Paper focuses on three hot topics in the TMT space currently: Big Data and the ‘Internet of Things’, both examined through the prism of machine-to-machine communications. We have grouped these [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Today, I read an interesting white paper, “&lt;a href="http://machinaresearch.com/static/media/uploads/Machina_Research_White_Paper_M2M_Big_Data.pdf" target="blank"&gt;Big Data in M2M: Tipping Points and Subnets of Things&lt;/a&gt;,” published by &lt;a href="http://machinaresearch.com/" target="blank"&gt;Machina Research&lt;/a&gt;. From the introduction:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;This White Paper focuses on three hot topics in the TMT space currently: Big Data and the ‘Internet of Things’, both examined through the prism of machine-to-machine communications. We have grouped these concepts together, since Big Data analytics within M2M really only exists within the context of heterogeneous information sources which can be combined for analysis. And, in many ways, the Internet of Things can be defined in those exact same terms: as a network of heterogeneous devices.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;The white paper does a good job of exploring the emerging trends of the Internet of Things, potential business opportunities and challenges faced.&lt;/p&gt;&#xD;
&lt;p&gt;As one could expect, “authenticity and security of different kinds of data,” was identified as a big challenge:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Big Data is about “mashing up” data from multiple sources, and delivering significant insights from the data. It is the combination of data from within the enterprise, from openly available data (for example, data made available by government agencies), from data communities, and from social media. And with every different source of data arises the issues of authenticity and security. Machina Research predicts that as a result of the need for data verification, enterprises will have a greater inclination to process internal and open (government) data prior to mashing-up with social media.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;The following diagram shows the increase security risk as more data from external sources is collected and analyzed.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://machinaresearch.com/static/media/uploads/Machina_Research_White_Paper_M2M_Big_Data.pdf" target="blank"&gt;&lt;img alt="Machina" border="0" height="355" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/machina.png" style="display: block; margin-left: auto; margin-right: auto;" title="machina.png" width="580"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;This yet another indicator of how Identity and Access Management will be critical in the successful evolution of the Internet of Things.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=SpQiPagO4y4:4y18_qMnQsU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=SpQiPagO4y4:4y18_qMnQsU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=SpQiPagO4y4:4y18_qMnQsU:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=SpQiPagO4y4:4y18_qMnQsU:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/SpQiPagO4y4" height="1" width="1"/&gt;</content>
    <updated>2013-05-22T03:41:19Z</updated>
    <category term="Identity" />
    <category term="Information Security" />
    <category term="Internet of Things" />
    <category term="Big Data" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Exploring the science and magic of Identity and Access Management</subtitle>
      <title>Discovering Identity</title>
      <updated>2013-05-22T15:02:14Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2013/05/21/iot-big-data-and-authenticity/</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.radiantlogic.com/?p=12634</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/w26COSItJ_4/" rel="alternate" type="text/html" />
    <link href="http://www.radiantlogic.com/2013/05/07/from-groups-to-roles-to-context-the-emergence-of-attributes-in-authorization/#comments" rel="replies" type="text/html" />
    <link href="http://www.radiantlogic.com/2013/05/07/from-groups-to-roles-to-context-the-emergence-of-attributes-in-authorization/feed/atom/" rel="replies" type="application/atom+xml" />
    <title xml:lang="en-US">Radiant Logic: From Groups to Roles to Context: The Emergence of Attributes in Authorization</title>
    <summary type="html" xml:lang="en-US">&lt;p&gt;Last week, I introduced my favorite topic—digital context—and laid out a plan for how to consider the case. Today, we’ll dive in with a real-world example, looking at how freeing context from across application silos helps us make more considered, immediate, and relevant access control decisions. For those of you who have been following along [...]&lt;/p&gt;&lt;p&gt;The post &lt;a href="http://www.radiantlogic.com/2013/05/07/from-groups-to-roles-to-context-the-emergence-of-attributes-in-authorization/"&gt;From Groups to Roles to Context: The Emergence of Attributes in Authorization&lt;/a&gt; appeared first on &lt;a alt="Radiant Logic" href="http://www.radiantlogic.com/"&gt;Radiant Logic, Inc&lt;/a&gt;&lt;/p&gt;</summary>
    <content type="html" xml:lang="en-US">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Last week, I introduced my favorite topic—&lt;a href="http://www.radiantlogic.com/?p=12560"&gt;digital context&lt;/a&gt;—and laid out a plan for how to consider the case. Today, we’ll dive in with a real-world example, looking at how freeing context from across application silos helps us make more considered, immediate, and relevant access control decisions. For those of you who have been following along (and thanks for sticking with me in my madness), this is blog 8 in response to Ian Glazer’s provocative video on &lt;a href="http://www.youtube.com/watch?v=0NFanER0g8w" rel="prettyphoto" title="Ian Glazer - Killing Identity Management in Order to Save It"&gt;killing IAM in order to save it&lt;/a&gt;. And if you haven’t been with me from the beginning: I’m in favor of skipping the murder and going straight to the resurrection. Those of you who are coming in late to the game, here’s the recent &lt;a href="http://www.radiantlogic.com/?p=12560"&gt;introduction to context&lt;/a&gt;, or you can catch up with the entire story in order here: &lt;a href="http://www.radiantlogic.com/?p=11895"&gt;one&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12042"&gt;two&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12211"&gt;three&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12272"&gt;four&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12314"&gt;five&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12367"&gt;six&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12560"&gt;seven&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;h3&gt;It All Starts with Groups: The Simple, Not Especially Sophisticated Solution&lt;/h3&gt;&#xD;
&lt;p&gt;Let’s start first with the notion of groups and their implementation. On the surface, nothing could be more straightforward: If I have to manage a sizeable set of users and assign them different rights to applications, I need to categorize those users into groups with the same profile, whether that’s by function, role, need to know, hierarchy, or some other factor. This is the simplest approach to any categorization, creating some “relevant” labels, then assigning people that fit within those label to define groups.&lt;/p&gt;&#xD;
&lt;p&gt;So let’s say we’re creating groups based work functions, such as sales, marketing, production, and administration. All we need to do is list all the people under a particular function, create a label, and then assign this label to those people. Couldn’t be easier, right? The simplicity of the process explains the huge success of groups—and although we implementers tend to make fun of groups as crude categorizations, I would guesstimate that at least 90% of our authorization policies are still implemented through groups. (So much for all that talk about advanced fine-grained authorization! But I’m getting ahead of myself here…)&lt;/p&gt;&#xD;
&lt;p&gt;In fact, we’ve become so dependent on groups that in many cases, especially with sizeable organization where the business processes are quite refined and well managed, we’re seeing that there are often more groups than users! At first glance, this seems paradoxical—after all, what’s the point of regrouping people if you have more groups than people? But the joke is on us technical people because we ignored another key reality: the business one. Sure, we could have a lot of people, but generally a well-managed and productive organization can have more activities (or different aspects of a given activity) that require the multiplication of those groups. So we gave our users a simple mechanism to categorize people into groups, and they used it—talk about being a victim of our own success! &lt;img alt=":)" class="wp-smiley" src="http://www.radiantlogic.com/radiantsite/wp-includes/images/smilies/icon_smile.gif"&gt;&lt;/img&gt; &lt;/p&gt;&#xD;
&lt;p&gt;Basically, we played the sorcerer’s apprentice and our simple formula yielded a multiplication of groups, which quickly became  un-manageable. So we went back to the formula and started to tweak it, creating groups inside groups, hierarchies of groups, and nested groups; introducing Boolean operations on groups; aggregating them into roles, and so on. So what we were just saying about groups being simple? Simple for whom? Simple for the group implementers—yes, definitely. Simple for a user in charge of the initial creation of the group—sure. But add any complexity into the mix and the chaos begins.&lt;/p&gt;&#xD;
&lt;h3&gt;So Much for the Digital Revolution: Every Change, Managed Manually&lt;/h3&gt;&#xD;
&lt;p&gt;From a computer’s point of view, the assignment of a user to a group is totally opaque—just an explicit list entered by the person in charge of creating the group. This explicit list contains no information about why or how a user is dispatched into or associated with a group. In short, the definition of membership rests with the group owner, which is fine on the face of it. But that excludes any automated assignment of a new member to the group without manual intervention of the group owner. That means every change must be entered by hand—imagine the complexity as people constantly change roles and shift responsibilities. And imagine how easy it would be for an overworked manager to miss removing the name of the person she just fired from just one of the groups he was part of. Now imagine the security risk if that guy’s still got access to sensitive files.&lt;/p&gt;&#xD;
&lt;p&gt;Without explicitly externalizing those rules, those policies, the administration of the system becomes tied to the group owners/creators. The effort of sub-categorizing with nested groups or introducing more flexible ways to combine groups by using Boolean operators just reveals the root of the problem: When you give users better ways to characterize their groups, you are forcing those users to either make explicit the formation rules of their groups—or continue to make every single change manually, even as those changes become more complex and unmanageable.&lt;/p&gt;&#xD;
&lt;p&gt;And that’s how we (re)discovered the value of attribute-based group definitions.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;span class="aligncenter"&gt;&lt;span class="frame"&gt;&lt;a class="imgeffect magnifier" href="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/labels-to-attributes.jpg" title="Labels to Attributes"&gt;&lt;img alt="Labels to Attributes" src="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/labels-to-attributes-515x349.jpg"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span id="more-12634"&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;h3&gt;Machine-Readable Groups: Using Attributes to Simplify Management and Make Policies Explicit&lt;/h3&gt;&#xD;
&lt;p&gt;We realized that if we wanted to automate, to simplify the management of all these groups, we needed to describe them at the lowest level as the set of attributes that defined a given group, role, and—yes—context. We discovered that groups and policies can be managed in a more finely-grained manner with increased automation (and greater productivity!) if &lt;strong&gt;we characterized them as a set of attributes&lt;/strong&gt;, combining them with the usual arsenal of Boolean expressions and functions. Basically, we needed an explicit computer representation of this characterization, instead of leaving such definitions in the head of an overtaxed administrator, hoping that auto-magically our human semantic would be interpreted and executable by our machines.&lt;/p&gt;&#xD;
&lt;p&gt;So we looked at how we represented those policies, groups, and roles and saw that an attribute-based system was a necessary condition. But unless we go further with this the analysis, we run the risk of oversimplification, of coming up with a solution that’s simplistic, instead of elegantly simple—and that would only create another set of problems down the road.&lt;/p&gt;&#xD;
&lt;span class="aligncenter"&gt;&lt;span class="frame"&gt;&lt;a class="imgeffect magnifier" href="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/separate-or-join-table.jpg" title="Seperate or Join Table"&gt;&lt;img alt="Seperate or Join Table" src="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/separate-or-join-table-515x477.jpg"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&#xD;
&lt;p&gt;So we could keep all the elements—group, subgroup, etc.—as separated “entities” and link them to a person, as in the first example above. Or we could fuse them together with the definition of a user, as we’ve done in second example. After all, both implementations can &lt;em&gt;technically&lt;/em&gt; yield the same categorization, meaning you can get to the definition of the groups and subgroups you need with the right members in both solutions.&lt;/p&gt;&#xD;
&lt;p&gt;But &lt;em&gt;semantically&lt;/em&gt;, we’re not talking about exactly the same thing. In one case, we have a notion of groups and subgroups separated from the definition of the person. In the other, we’ve bolted those groups and subgroups on as attributes of that person. So which one is the right definition? That all depends on what you need in your representation—by which I mean it’s contextual—but it’s very important for us to fully grasp the difference. The decomposition into attributes is key for fine-grained authorization, but unless we have a clear understanding about what we are doing, we can take the decomposition too far. In such a case, the world becomes a chaotic set of attributes, where we can’t see the forest for all those trees. While we can peer into a universe made up of the most elementary particles, most real-life problems demand that we recompose that world by gluing all those objects back together again.&lt;/p&gt;&#xD;
&lt;h3&gt;Breaking It Down and Building It Back Up, Better Than Before&lt;/h3&gt;&#xD;
&lt;p&gt;And that is where we begin to see the need to not only decompose the world into attributes, but also to &lt;strong&gt;reorganize that world into objects, relationships, and context&lt;/strong&gt;. What you get through this reorganization of your information representation is a more complete view of your system, where authorization can be enforced in a more granular way. This is the way we really intend to do it in our policies, as we would define them in natural language—and that’s exactly what we’ll be looking at in my next blog post.&lt;/p&gt;&#xD;
&lt;p&gt;So thanks for reading this introduction to my favorite topic, and be sure to check back for a deep dive into objects, relationships, and context. I’ll even show you how a marketing coordinator and a computer can learn to speak the same language!&lt;/p&gt;&#xD;
&lt;div align="center"&gt;&lt;a href="http://www.radiantlogic.com/?p=12560"&gt;← Part 1: In Context: The Next Frontier of Your Digital Identity&lt;/a&gt;&lt;/div&gt;&#xD;
&lt;div align="center" style="padding-bottom: 10px;"&gt;&lt;a href="http://www.radiantlogic.com/?p=12906"&gt;Part 3: Attributes, Predicates, and Sentences: The Building Blocks of Context →&lt;/a&gt;&lt;/div&gt;&lt;p&gt;The post &lt;a href="http://www.radiantlogic.com/2013/05/07/from-groups-to-roles-to-context-the-emergence-of-attributes-in-authorization/"&gt;From Groups to Roles to Context: The Emergence of Attributes in Authorization&lt;/a&gt; appeared first on &lt;a alt="Radiant Logic" href="http://www.radiantlogic.com/"&gt;Radiant Logic, Inc&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=w26COSItJ_4:TKPvjfkns3w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=w26COSItJ_4:TKPvjfkns3w:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=w26COSItJ_4:TKPvjfkns3w:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=w26COSItJ_4:TKPvjfkns3w:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/w26COSItJ_4" height="1" width="1"/&gt;</content>
    <updated>2013-05-21T21:44:26Z</updated>
    <published>2013-05-07T17:00:21Z</published>
    <category scheme="http://www.radiantlogic.com" term="Authors" />
    <category scheme="http://www.radiantlogic.com" term="Context-Aware Solutions" />
    <category scheme="http://www.radiantlogic.com" term="Michel Prompt" />
    <category scheme="http://www.radiantlogic.com" term="Context" />
    <category scheme="http://www.radiantlogic.com" term="Groups" />
    <category scheme="http://www.radiantlogic.com" term="Radiant Logic" />
    <author>
      <name>Michel Prompt, CEO &amp; Founder</name>
      <uri>http://www.radiantlogic.com</uri>
    </author>
    <source>
      <id>http://www.radiantlogic.com/feed/atom/</id>
      <link href="http://www.radiantlogic.com" rel="alternate" type="text/html" />
      <link href="http://www.radiantlogic.com/feed/atom/" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Radiant Logic uses model-driven virtualization to deliver a complete federated identity service for all your identity initiatives.</subtitle>
      <title xml:lang="en-US">Radiant Logic | Federated Identity Service Based on Virtualization</title>
      <updated>2013-05-21T22:55:36Z</updated>
    </source>
  <feedburner:origLink>http://www.radiantlogic.com/2013/05/07/from-groups-to-roles-to-context-the-emergence-of-attributes-in-authorization/</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.radiantlogic.com/?p=12906</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/4NcA4d-ASQA/" rel="alternate" type="text/html" />
    <link href="http://www.radiantlogic.com/2013/05/21/attributes-predicates-and-sentences-the-building-blocks-of-context/#comments" rel="replies" type="text/html" />
    <link href="http://www.radiantlogic.com/2013/05/21/attributes-predicates-and-sentences-the-building-blocks-of-context/feed/atom/" rel="replies" type="application/atom+xml" />
    <title xml:lang="en-US">Radiant Logic: Attributes, Predicates, and Sentences: The Building Blocks of Context</title>
    <summary type="html" xml:lang="en-US">&lt;p&gt;We covered the key role of attributes in my last blogpost, moving from the blunter scope of groups and roles to the more fine-grained approach of attributes. Now we’re going to take this progression a step further, as we narrow in on my favorite topic: digital context. (If you haven’t already, check out my first [...]&lt;/p&gt;&lt;p&gt;The post &lt;a href="http://www.radiantlogic.com/2013/05/21/attributes-predicates-and-sentences-the-building-blocks-of-context/"&gt;Attributes, Predicates, and Sentences: The Building Blocks of Context&lt;/a&gt; appeared first on &lt;a alt="Radiant Logic" href="http://www.radiantlogic.com/"&gt;Radiant Logic, Inc&lt;/a&gt;&lt;/p&gt;</summary>
    <content type="html" xml:lang="en-US">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;We covered the &lt;a href="http://www.radiantlogic.com/?p=12634"&gt;key role of attributes in my last blogpost&lt;/a&gt;, moving from the blunter scope of groups and roles to the more fine-grained approach of attributes. Now we’re going to take this progression a step further, as we narrow in on my favorite topic: digital context. (If you haven’t already, check out my first two posts on context, where I &lt;a href="http://www.radiantlogic.com/?p=12560"&gt;laid out the roadmap&lt;/a&gt; and &lt;a href="http://www.radiantlogic.com/?p=12634"&gt;looked at groups, roles, and attributes&lt;/a&gt;.) Our first order today is to travel back to logic class and think about predicates.* But Michel, you’re thinking, what does all this have to do with digital context? Well, one way to describe a context about something is to express it using sentences related to the question. While we will come back to the definition of context in a following post, for now let’s just say that we need some building blocks to express facts about the world, some form of sentences that can be interpreted by a computer, and logic is one of the tools for that.&lt;/p&gt;&#xD;
&lt;h3&gt;Subject-Predicate-Object: First Order Logic 101&lt;/h3&gt;&#xD;
&lt;p&gt;In my most recent post, we saw how the notions of groups and roles ended up in the increased use of attributes as a way to categorize or define identities. This should not be surprising. Behind this use of attributes lays a fundamental mechanism—a way to represent a simple fact. And it’s the same mechanism that we use when we reason based on the rules of formal logic, which has been in practice forever, or when we represent a fact on a computer (think SQL). In fact, one of the greatest achievements of the early 20th century has been the formalization of logic (needed for mathematic foundation) and computation. This type of logical representation is core to everything we do, as reasoned thinkers and as computer scientists.&lt;/p&gt;&#xD;
&lt;p&gt;But in case you’re a few years removed from logic class, let’s examine this mechanism at work by looking at some very simple diagrams about what we are doing when we associate some attribute with a person or an object, such as assigning a person to a group:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/memberOf.jpg" rel="prettyphoto"&gt;&lt;img alt="Assigning a person to a group" class="aligncenter" height="129" src="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/memberOf.jpg" width="515"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;Or assigning a subgroup to a group:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/subgroupOf.jpg" rel="prettyphoto"&gt;&lt;img alt="Assigning a subgroup to a group" class="aligncenter" height="130" src="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/subgroupOf.jpg" width="515"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;Each of these constructs can be summarized by the following diagram:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/subject-predicate-object.jpg" rel="prettyphoto"&gt;&lt;img alt="Subject-Predicate-Object" class="aligncenter" height="129" src="http://www.radiantlogic.com/radiantsite/wp-content/uploads/2013/05/subject-predicate-object.jpg" width="515"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;In this diagram, a fact can be asserted by the notation: subject-predicate-object. In predicate logic (AKA first order logic), it’s conventionally written as &lt;em&gt;predicate(X,Y)&lt;/em&gt;, where the variables &lt;em&gt;X&lt;/em&gt; and &lt;em&gt;Y&lt;/em&gt; could be themselves objects (references to entities) and/or values (arbitrarily “quoted” labels belonging to the initial vocabulary of our logic system). For instance, in our example above, the fact that “Jane is member of the product marketing group” can be written as &lt;em&gt;memberOf(“Jane”,”Product Marketing”)&lt;/em&gt; and &lt;em&gt;subGroupOf(“Product Marketing”,“Marketing”)&lt;/em&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;These kinds of predicates are called “binary” predicates and they are quite common. So if there are &lt;strong&gt;binary predicates&lt;/strong&gt;, the astute reader (that’s you!) might well wonder if there are also &lt;strong&gt;unary predicates&lt;/strong&gt; and, more generally, &lt;strong&gt;n-ary predicates&lt;/strong&gt;. Indeed, the unary predicate exists and generally it’s used to assign a label to an entity—so if we want to say that Jane is an executive, you would write it as &lt;em&gt;executive(“Jane”)&lt;/em&gt;. As for the n-ary predicate, well here’s where you will find the usual “n-slots” notation of entities/tables as they’re used in the relational/SQL world. So we’d see something like this: &lt;em&gt;age(“Jane”, “33”)&lt;/em&gt; or &lt;em&gt;employee(“Jane”, “33”,”product marketing”)&lt;/em&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;Now, if you look at all those diagrams above, you’ll notice they have a direction, an orientation that tells us which entity plays the role of subject, since the object for a given predicate cannot generally be substituted. This translates into a given order for the different slots of a predicate; for example, in the notation &lt;em&gt;age(“Jane”, “33”)&lt;/em&gt;, the first slot&lt;em&gt;—&lt;/em&gt;“Jane”&lt;em&gt;—&lt;/em&gt;is for the person, and the second&lt;em&gt;—&lt;/em&gt;“33”&lt;em&gt;—&lt;/em&gt;is for her age. Of course, there are always exceptions where the slots are permutable, such as the “brother binary predicate,” where if x is a brother of y&lt;em&gt;—brother(“x”,”y”)&lt;/em&gt;— then y is also a brother of x, which could read: &lt;em&gt;brother(“y”,”x”)= brother(“x”,”y”)&lt;/em&gt;. But in general order, orientation matters.&lt;/p&gt;&#xD;
&lt;p&gt;The diagrams above form directed graphs and the orientation is essential for preserving the semantics of this representation. After all, saying that x kills y&lt;em&gt;—Kill(“x”,”y”)&lt;/em&gt;—is very different from saying that y kills x&lt;em&gt;—Kill(“y”,”x”)&lt;/em&gt;!&lt;br&gt;&#xD;
&lt;span id="more-12906"&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;h3&gt;Essential Semantics: Describing Our World in First Order Sentences&lt;/h3&gt;&#xD;
&lt;p&gt;So all this is great, but what does it have to do with context? Stay with me here…we’ve seen that when we reduce everything into attributes, we are reducing the world to first principles. But at the same time, by associating attributes to an entity and recombining them progressively through predicates, we are describing a complete world based on “sentences” of first order logic. If you combine those sentences with the usual Boolean operators (Not, And, Or, and the rest of the derived Boolean Zoo members), you get a world that’s pretty complete—complete enough to act as the foundation of mathematics.&lt;/p&gt;&#xD;
&lt;p&gt;And the good news here is that this world is also pretty close to our own “world of discourse” (albeit a lot like my English: awkward and somewhat robotic). Basically, it’s made of simple sentences in the form of subject-predicate-value (where the predicate is the adjective or qualifier), or subject-attribute-object (where the attribute is the verb). Remember our friend Jane from above? Here are some things we know related to Jane:&lt;/p&gt;&#xD;
&lt;p&gt;Jane is member of marketing group.&lt;/p&gt;&#xD;
&lt;p&gt;AND&lt;/p&gt;&#xD;
&lt;p&gt;Product marketing is subgroup of marketing group.&lt;/p&gt;&#xD;
&lt;p&gt;The beauty of the predicate representation is that a huge part of our digital world is already encoded this way. In fact, all of our so-called “structured information”—databases, transactions, etc—runs according to these principles. But the maze of protocols and security representations we’re all dealing with, from SQL, to LDAP, to APIs, to programming languages, has long masked this reality. We need a way to rise above this modern tower of Babel, a way to translate all that structured, transactional data into something more useful, more contextually-driven. In my next post, I’m excited to show you that we’ve done exactly that: returned to first principles to deliver a “contextual and computational language” that’s &lt;strong&gt;as easy to interpret at the human level as it is to execute at the machine level&lt;/strong&gt;. And this is a huge leap forward. We know we can’t teach our marketing teams to think like machines—and believe me, I’VE TRIED—but imagine a world where a business person and an application can both understand, and act on, the exact same notation. Such a world is possible today…so do not miss my next post!&lt;/p&gt;&#xD;
&lt;p&gt;PS: Some of you have been in on this series from the beginning, but all this blogging began as a response to Ian Glazer’s video on &lt;a href="http://www.youtube.com/watch?v=0NFanER0g8w" rel="prettyphoto" title="Ian Glazer - Killing Identity Management in Order to Save It"&gt;killing IAM in order to save it&lt;/a&gt;. For those of you just joining the story, you can catch up with the entire story here: &lt;a href="http://www.radiantlogic.com/?p=11895"&gt;one&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12042"&gt;two&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12211"&gt;three&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12272"&gt;four&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12314"&gt;five&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12367"&gt;six&lt;/a&gt;, &lt;a href="http://www.radiantlogic.com/?p=12560"&gt;seven&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;*See what I did there? That was for all the mathematicians…and for &lt;a href="http://blog.aniljohn.com/" target="_blank"&gt;Anil John&lt;/a&gt;, who’s just as a big a logic geek as I am. &lt;img alt=":)" class="wp-smiley" src="http://www.radiantlogic.com/radiantsite/wp-includes/images/smilies/icon_smile.gif"&gt;&lt;/img&gt; &lt;/p&gt;&#xD;
&lt;div align="center" style="padding-bottom: 10px;"&gt;&lt;a href="http://www.radiantlogic.com/?p=12634"&gt;← Part 2: From Groups to Roles to Context: The Emergence of Attributes in Authorization&lt;/a&gt;&lt;/div&gt;&lt;p&gt;The post &lt;a href="http://www.radiantlogic.com/2013/05/21/attributes-predicates-and-sentences-the-building-blocks-of-context/"&gt;Attributes, Predicates, and Sentences: The Building Blocks of Context&lt;/a&gt; appeared first on &lt;a alt="Radiant Logic" href="http://www.radiantlogic.com/"&gt;Radiant Logic, Inc&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=4NcA4d-ASQA:XavcfzwE4Z0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=4NcA4d-ASQA:XavcfzwE4Z0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=4NcA4d-ASQA:XavcfzwE4Z0:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=4NcA4d-ASQA:XavcfzwE4Z0:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/4NcA4d-ASQA" height="1" width="1"/&gt;</content>
    <updated>2013-05-21T21:35:46Z</updated>
    <published>2013-05-21T16:00:32Z</published>
    <category scheme="http://www.radiantlogic.com" term="Authors" />
    <category scheme="http://www.radiantlogic.com" term="Context-Aware Solutions" />
    <category scheme="http://www.radiantlogic.com" term="Michel Prompt" />
    <category scheme="http://www.radiantlogic.com" term="Context" />
    <category scheme="http://www.radiantlogic.com" term="Graph" />
    <category scheme="http://www.radiantlogic.com" term="Groups" />
    <category scheme="http://www.radiantlogic.com" term="Predicates" />
    <category scheme="http://www.radiantlogic.com" term="Radiant Logic" />
    <author>
      <name>Michel Prompt, CEO &amp; Founder</name>
      <uri>http://www.radiantlogic.com</uri>
    </author>
    <source>
      <id>http://www.radiantlogic.com/feed/atom/</id>
      <link href="http://www.radiantlogic.com" rel="alternate" type="text/html" />
      <link href="http://www.radiantlogic.com/feed/atom/" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Radiant Logic uses model-driven virtualization to deliver a complete federated identity service for all your identity initiatives.</subtitle>
      <title xml:lang="en-US">Radiant Logic | Federated Identity Service Based on Virtualization</title>
      <updated>2013-05-21T22:55:36Z</updated>
    </source>
  <feedburner:origLink>http://www.radiantlogic.com/2013/05/21/attributes-predicates-and-sentences-the-building-blocks-of-context/</feedburner:origLink></entry>

  <entry>
    <id>http://blogs.kuppingercole.com/kearns/2013/05/21/passwords-authentications-zombies/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/AaySGxV-Qls/" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Passwords, Authentication’s Zombies</title>
    
    <updated>2013-05-21T14:19:42Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:07Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;In &lt;a href="http://blogs.kuppingercole.com/kearns"&gt;Dave Kearns&lt;/a&gt; &lt;br&gt;&lt;br&gt;&lt;p&gt;Another &lt;a href="http://www.id-conf.com/" target="_blank"&gt;European Identity (and Cloud) Conference&lt;/a&gt; has come and gone, and once again it was an exciting week with packed session rooms, and excellent attendance at the evening events. I’m not sure we can continue to call it the “European” Id Conference, though, as I met folks from Australia, New Zealand, Japan, South Africa and all over north and south America. And lots of Europeans, also, I should note. Nor were the attendees content to sit back and soak it all in. At least in the sessions I conducted there was a great deal of give and take between the audience and the speakers and panelists. Most good natured and looking for information but – occasionally – it got a bit raucous.&lt;/p&gt;&#xD;
&lt;p&gt;The track on authentication and authorization – so near and dear to my heart – drew a standing room only crowd who were eager to join in the discussion. As always when AuthN is discussed, passwords drew an inordinate amount of the discussion. I reminded the panelists and the audience that no less a personage than Bill Gates &lt;a href="http://news.cnet.com/2100-1029-5164733.html" target="_blank"&gt;predicted&lt;/a&gt; the “death of passwords” back in 2004. And that even within Microsoft, passwords were still in use.&lt;/p&gt;&#xD;
&lt;p&gt;Too much energy is being spent of both trying to remove username/password from the authentication process and in trying to “strengthen” the passwords that are used. Neither approach is going to be effective.  Passwords, or the “something you know” are far easier to use than “something you have” (security token) and far less scary than “something you are” (biometrics) for the general public to ever entertain the idea of switching.&lt;/p&gt;&#xD;
&lt;p&gt;Password strength is, essentially, a myth. Brute force attacks become quicker every day, so hacking the password directly becomes easier every day. Phishing attacks are getting so sophisticated that there’s no need to hack a password (and possibly set off security alarms) when you can induce the user to give it to you willingly.&lt;/p&gt;&#xD;
&lt;p&gt;Two factor authentication (2FA) had some champions, but most methods have already been shown to be vulnerable to either direct attacks (man in the middle style, or MIM) or the same phishing attacks that subvert “strong” passwords. The object of the phishing attack is, after all, for the user to login with their credentials which are then subsumed by the hacker. So go three factors if you want – it’s not much stronger.&lt;/p&gt;&#xD;
&lt;p&gt;I found widespread agreement (with a few diehard holdouts) for a context-collecting risk-based system for Access Control (which I’ve called RiskBAC). Knowing the who, what, when, where, how and why of the authentication ceremony leaves the username/password combo as only one of many factors (the who). In fact, entering a username and correct password isn’t the end of the authentication but merely the trigger to begin the Risk-based Access ceremony or transaction. The other factors are all gathered automatically through system dialogs after the entry of the password has identified the account to which the claimant wishes access.&lt;/p&gt;&#xD;
&lt;p&gt;Of course, once we’re satisfied that the claimant is most likely who he/she claims to be, we then take that information into account along with the other contextual elements to determine the degree of access we’ll authorize to the resource they’re seeking.&lt;/p&gt;&#xD;
&lt;p&gt;While the presentation was called “the Future of Authentication and Authorization,” I did remind the audience that over 2000 years ago the Romans used the same methods for access control. Biometrics (what you are) was represented by facial recognition, tokens (what you have) by scrolls sealed with the leader’s ring (early use of a security signature) and passwords were, well passwords – and often changed daily to guard against leaks of the information, something more of us should do today.&lt;/p&gt;&#xD;
&lt;p&gt;There was also a contextual element to the access control ceremony when the guard, on observing the claimant, was able to identify him in the context of where he knew the face from – the morning roll call, or the guardhouse. The sealed scroll had context based on what the guard knew about the location (at the camp or thousands of miles away) and condition (alive and kicking, or breathing his last) of the official who sealed the token.&lt;/p&gt;&#xD;
&lt;p&gt;There were lots of other exciting moments – even aha! Moments – in the tracks I did on Trust Frameworks and Privacy by Design as well as in others’ session especially those on Life Management Platforms, a coming technology that many who were hearing about it for the first time agreed will be game-changing when it arrives – and that may not be too far off. If you’d like to catch up, see the just released Advisory Note: “&lt;a href="http://www.kuppingercole.com/report/advisorynote_lidmanagementcontrol70745140513"&gt;Life Management Platforms: Control and Privacy for Personal Data&lt;/a&gt;” (#70745).&lt;/p&gt;&#xD;
&lt;p&gt;And there was exciting, non-Identity related, news as well. We of course announced EIC 2014 for next May but – remember up at the top of this post I said that it was a larger than European conference? Well we also announced EIC 2014 London, EIC 2014 Toronto and EIC 2014 Singapore. EIC is going worldwide, and the people involved in identity couldn’t be happier. Dates for the new venues haven’t been finalized yet, but I’ll be sure to tell you about them when they are.&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/AaySGxV-Qls" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=AaySGxV-Qls:VZZF7_8y4z4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=AaySGxV-Qls:VZZF7_8y4z4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=AaySGxV-Qls:VZZF7_8y4z4:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=AaySGxV-Qls:VZZF7_8y4z4:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/AaySGxV-Qls" height="1" width="1"/&gt;</content><feedburner:origLink>http://blogs.kuppingercole.com/kearns/2013/05/21/passwords-authentications-zombies/</feedburner:origLink></entry>

  <entry>
    <id>http://wayf.dk/en/news/news-2013/553-former-must-attribute-mail-now-a-may-attribute</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/Yrkk6r9AOQs/553-former-must-attribute-mail-now-a-may-attribute" rel="alternate" type="text/html" />
    <title>WAYF News: Former MUST attribute 'mail' now a MAY attribute</title>
    
    <updated>2013-05-21T09:56:08Z</updated>
    <source>
      <id>http://wayf.dk/</id>
      <author>
        <name>WAYF News</name>
      </author>
      <link href="http://wayf.dk/" rel="alternate" type="text/html" />
      <link href="http://wayf.dk/index.php/component/ninjarsssyndicator/?feed_id=4&amp;format=raw&amp;lang=en" rel="self" type="application/atom+xml" />
      <subtitle>News from WAYF—Where Are You From—Denmark's leading federation of electronic identities.</subtitle>
      <title>News from WAYF</title>
      <updated>2013-05-22T15:02:22Z</updated>
    </source>
  <content type="html">&lt;p&gt;Many of WAYF's identity providers are unable to deliver e-mail addresses for their users. The reason is that many institutions no longer run e-mail systems of their own, and so are no longer able to deliver this kind of information. As a result, WAYF now changes the official status of the &lt;a href="http://www.wayf.dk/en/component/content/article/112"&gt;&lt;i&gt;mail&lt;/i&gt; attribute&lt;/a&gt;, from MUST to MAY. WAYF thus no longer guarantees its connected services the delivery of a valid e-mail address for every user attempting to log in.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Yrkk6r9AOQs:QQ40ewhJkHM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Yrkk6r9AOQs:QQ40ewhJkHM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Yrkk6r9AOQs:QQ40ewhJkHM:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=Yrkk6r9AOQs:QQ40ewhJkHM:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/Yrkk6r9AOQs" height="1" width="1"/&gt;</content><feedburner:origLink>http://wayf.dk/en/news/news-2013/553-former-must-attribute-mail-now-a-may-attribute</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/executiveview_betasystemsgarancy7078421513</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/zmlxg3OfqxA/executiveview_betasystemsgarancy7078421513" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Executive View: Beta Systems Garancy Access Intelligence Manager - 70784</title>
    
    <updated>2013-05-21T04:33:21Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:08Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Mit dem Garancy Access Intelligence Manager hat die Beta Systems AG eine neue, spezialisierte Lösung für die Analyse von Zugriffsberechtigungen auf den Markt gebracht. Wie der Produktname schon sagt, handelt es sich um eine Lösung für „Access Intelligence“, einen Teilbereich von IAG (Identity and Access Governance). Access Governance-Lösungen bieten üblicherweise bereits integrierte Reporting-Funktionen, um die gesammelten Informationen über...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/executiveview_betasystemsgarancy7078421513"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/zmlxg3OfqxA" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zmlxg3OfqxA:wPfdGY3_A9Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zmlxg3OfqxA:wPfdGY3_A9Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zmlxg3OfqxA:wPfdGY3_A9Q:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=zmlxg3OfqxA:wPfdGY3_A9Q:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/zmlxg3OfqxA" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/executiveview_betasystemsgarancy7078421513</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-6940728126479075612.post-7339026469977782896</id>
    <link href="http://anil-identity.blogspot.com/feeds/7339026469977782896/comments/default" rel="replies" type="application/atom+xml" />
    <link href="http://www.blogger.com/comment.g?blogID=6940728126479075612&amp;postID=7339026469977782896" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default/7339026469977782896?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default/7339026469977782896?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/5WdgnGJE5DI/access-control-best-practices.html" rel="alternate" type="text/html" />
    <title>Anil Saldhana - Red Hat: Authorization (Access Control) Best Practices</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;div dir="ltr" style="text-align: left;"&gt;&#xD;
After the recent wrestling match in the blogosphere that included vendors and analysts on XACML, I want to provide some best practices for access control/authorization.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
The wrestling match is covered in my earlier &lt;a href="http://anil-identity.blogspot.com/2013/05/is-xacml-really-dead-should-we-all-go.html" target="_blank"&gt;post&lt;/a&gt;.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
Let me insert my favorite punch line before I mention the best practices.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;span style="background-color: white;"&gt;&lt;span style="color: #e06666; font-size: large;"&gt;&lt;i&gt;Authentication is finite while Authorization is infinite.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
Best practices for access control:&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;h2&gt;&#xD;
1. Know that you will need access control/authorization.&lt;/h2&gt;&#xD;
&lt;div&gt;&#xD;
Too many times architects spend majority of their system security design time on authentication and federated identity. This leads to limited time provided to authorization. Compared to authentication, authorization can get very complex over time. &lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
2. Externalize the access control policy processing&lt;/h2&gt;&#xD;
&lt;div&gt;&#xD;
You are headed toward disaster if your access control processing is embedded in your application. This is because access control requirements are never complete during the first phase of application development. Authorization rules or requirements change over the application lifecycle as business needs or environment change.  If the access control processing is not decoupled from the application, you will face hardship. Lots of band-aid will be applied to the application code to meet the changing/ever-growing authorization requirements.&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
3. Understand the difference between coarse grained and fine grained authorization&lt;/h2&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
Google/Bing will help you understand the difference. Wikipedia will definitely help you here. Application designers tend to create a model of authorization (for simplicity) during initial design. Almost always, this model tends to be a simple coarse grained authorization model. The challenge is that the read world authorization needs for your application is not set in stone. It is an ever changing phenomenon that will just pull your model in all directions.&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
4. Design for coarse grained authorization but keep the design flexible for fine grained authorization&lt;/h2&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
This goes in line with item 2 where the access control policy has to be separated or decoupled from your application.  If your initial design for the access control system or library is designed for coarse grained authorization, because of the low coupling, it becomes easier to incorporate fine grained authorization logic over time.&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
5. Know the difference between Access Control Lists and Access Control standards&lt;/h2&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
Access Control Lists (ACL) are pretty popular among system designers. The challenge is that they are proprietary and not usable across applications or domains. You may earn your bonus or accolades using ACLs in your application. Over time, they tend to become restrictive due to changing requirements.&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
There are 2 prominent access control standards that I list here:&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
a) IETF OAuth2: this is a REST style Internet Scale lightweight resource authorization framework.&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
b) OASIS XACML: standard for fine grained authorization. Has an access control architecture namely PEP (Policy Enforcement Point), PDP (Policy Decision Point), PIP (Policy Information Point) and PAP (Policy Administration Point).&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&#xD;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://community.jboss.org/servlet/JiveServlet/downloadImage/102-10840-35-2514/310-183/XACML.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="236" src="https://community.jboss.org/servlet/JiveServlet/downloadImage/102-10840-35-2514/310-183/XACML.png" width="400"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&#xD;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Fig: Typical XACML Fine Grained Access Control Architecture&lt;/td&gt;&lt;/tr&gt;&#xD;
&lt;/tbody&gt;&lt;/table&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
6. Adopt Rule Based Access Control : view Access Control as Rules and Attributes&lt;/h2&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
Access Control should be viewed as rules on various entities (and their attributes) involved in the authorization check.&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
I am not forcing you to use XACML.  But I would certainly encourage you to design your access control system in terms of rules and attributes.  Have a look at my article on &lt;a href="https://community.jboss.org/wiki/FineGrainedAccessControlStrategies" target="_blank"&gt;Access Control Strategies&lt;/a&gt;. It is critical that you design your access control system as rules and attributes.&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;i&gt;Hey, Drools based access control system is certainly not bad as long as you decouple the access control system. It is a trade off between proprietary rigid ACLs and flexible fine grained XACML. You can manage your Drools Rules via Guvnor.&lt;/i&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;br&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
7. Adopt REST Style Architecture when your situation demands scale and thus REST authorization standards &lt;/h2&gt;&#xD;
&lt;br&gt;&#xD;
With the growing demand for web based services and APIs and the proliferation of mobile devices in the world, it has become essential to incorporate REST style architecture to your system design.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
It is essential for you to use OAuth2 standard for REST authorization. While OAuth2 takes care of defining the tokens and some rules for authorization (scope of authorization and actor/resource), it may still be essential for system architects to incorporate fine grained authorization.  Certainly give a look at the REST Profile of XACML v3. There is also JSON binding available.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
8. Understand the difference between Enforcement versus Entitlement model&lt;/h2&gt;&#xD;
&lt;br&gt;&#xD;
Prominent access control strategies and standards involve the Enforcement model. The access control system is trying to enforce access to a resource. This leads to a Yes/No type question.  The enforcement model does not scale in a cloud or a resource constrained environment. &lt;br&gt;&#xD;
&lt;br&gt;&#xD;
Entitlement model is where in the access control system does not perform enforcement or access checks. Rather it answers questions such as "What permissions does this user have?". The question seeker will then use the returned answer to perform local enforcement.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&#xD;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-qZ2-TrRXVhQ/UZXGd81fk8I/AAAAAAAAFw8/3okM-vMyAMI/s1600/EnforcementEntitlement.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="392" src="http://2.bp.blogspot.com/-qZ2-TrRXVhQ/UZXGd81fk8I/AAAAAAAAFw8/3okM-vMyAMI/s400/EnforcementEntitlement.png" width="400"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&#xD;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Cloud Enforcement vs Entitlement Model&lt;/td&gt;&lt;/tr&gt;&#xD;
&lt;/tbody&gt;&lt;/table&gt;&#xD;
&lt;br&gt;&#xD;
&lt;div class="page" title="Page 1"&gt;&#xD;
&lt;/div&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;h2 style="text-align: left;"&gt;&#xD;
References&lt;/h2&gt;&#xD;
&lt;div&gt;&#xD;
&lt;a href="https://community.jboss.org/wiki/PicketBoxXACMLJBossXACML" target="_blank"&gt;PicketBox XACML&lt;/a&gt;: Open Source free implementation of OASIS XACML v2.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;a href="https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=cloudauthz" target="_blank"&gt;OASIS Cloud Authorization TC&lt;/a&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
Please do not forget to view the presentation above. :)&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5WdgnGJE5DI:y10_WnMyqvs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5WdgnGJE5DI:y10_WnMyqvs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5WdgnGJE5DI:y10_WnMyqvs:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=5WdgnGJE5DI:y10_WnMyqvs:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/5WdgnGJE5DI" height="1" width="1"/&gt;</content>
    <updated>2013-05-21T03:35:50Z</updated>
    <published>2013-05-17T05:35:00Z</published>
    <category scheme="http://www.blogger.com/atom/ns#" term="accesscontrol" />
    <category scheme="http://www.blogger.com/atom/ns#" term="bestpractices" />
    <category scheme="http://www.blogger.com/atom/ns#" term="XACML" />
    <category scheme="http://www.blogger.com/atom/ns#" term="oauth" /><feedburner:origlink>http://anil-identity.blogspot.com/2013/05/access-control-best-practices.html</feedburner:origlink>
    <author>
      <name>Anil Saldhana</name>
      <email>noreply@blogger.com</email>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-6940728126479075612</id>
      <category term="ACL" />
      <category term="cyber-bullying" />
      <category term="javasecurity" />
      <category term="JBAS5" />
      <category term="html5" />
      <category term="2-pass" />
      <category term="malware" />
      <category term="identity_theft" />
      <category term="maven" />
      <category term="events" />
      <category term="password_management" />
      <category term="openshift" />
      <category term="chrome" />
      <category term="JBoss5" />
      <category term="jsr" />
      <category term="lessig" />
      <category term="JBossSAML" />
      <category term="tips" />
      <category term="javaEE" />
      <category term="xspa" />
      <category term="Fraud" />
      <category term="Privacy" />
      <category term="XACMLInteroperabilityAtBurtonCatalyst07" />
      <category term="JBossAS5" />
      <category term="News" />
      <category term="kerberos" />
      <category term="facebook" />
      <category term="DataProtection" />
      <category term="himss2009" />
      <category term="securityconference" />
      <category term="authentication" />
      <category term="security" />
      <category term="RSA2008" />
      <category term="social_login" />
      <category term="socialnetworks" />
      <category term="picketbox" />
      <category term="cloud" />
      <category term="SAML" />
      <category term="JBoss/Tomcat" />
      <category term="OpenID" />
      <category term="JBossSecurity" />
      <category term="social_intelligence" />
      <category term="idtrust2008" />
      <category term="SecurityPeople" />
      <category term="jboss_vulnerabilities" />
      <category term="jbossandsaml" />
      <category term="XACML" />
      <category term="book_review" />
      <category term="Mystery" />
      <category term="oasis" />
      <category term="commoncriteria" />
      <category term="EESecurity" />
      <category term="subversion" />
      <category term="legislation" />
      <category term="keymanagement" />
      <category term="Interoperability" />
      <category term="cybersecurity" />
      <category term="ws-trust" />
      <category term="idtrust2009" />
      <category term="gsoc" />
      <category term="Phishing" />
      <category term="bigdata" />
      <category term="W3C" />
      <category term="cloudsecurity" />
      <category term="jbossspnego" />
      <category term="IdentityManagement" />
      <category term="nist" />
      <category term="fedora" />
      <category term="DirectoryServer" />
      <category term="EAP" />
      <category term="paas" />
      <category term="himss_healthcare" />
      <category term="singlesignon" />
      <category term="saml_ejb" />
      <category term="vivek_kundra" />
      <category term="JBossXACML" />
      <category term="STS" />
      <category term="JBossTips" />
      <category term="opensource" />
      <category term="javaone" />
      <category term="EKMI" />
      <category term="paulwright" />
      <category term="oauth" />
      <category term="US-CERT" />
      <category term="SSL" />
      <category term="GeneralSecurity" />
      <category term="jaxrs" />
      <category term="idtrust" />
      <category term="accesscontrol" />
      <category term="XACMLInteroperabilityAtRSAConference2008" />
      <category term="PCI" />
      <category term="OSGi" />
      <category term="jbossnegotiation" />
      <category term="picketlink" />
      <category term="opensso" />
      <category term="sso" />
      <category term="cookies" />
      <category term="EE" />
      <category term="identity_cloud_computing" />
      <category term="jbossidentity" />
      <category term="FederatedIdentity" />
      <category term="securityintelligence" />
      <category term="InternetSecurity" />
      <category term="eGovernmentSecurity" />
      <category term="bestpractices" />
      <category term="browsersecurity" />
      <category term="JBossSSO" />
      <category term="existdb" />
      <category term="identity" />
      <category term="healthcare" />
      <category term="OpenDS" />
      <category term="jboss" />
      <category term="jsr-196" />
      <category term="jbosskerberos" />
      <category term="securecoding" />
      <category term="jbossas" />
      <category term="xacml_exist" />
      <category term="secure_jboss" />
      <category term="Analysis" />
      <category term="gmail" />
      <author>
        <name>Anil Saldhana</name>
        <email>noreply@blogger.com</email>
      </author>
      <link href="http://anil-identity.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://anil-identity.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/6940728126479075612/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/AnilsSecurityAndIdentityManagementBlog" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>This blog is a personal online diary of Security/ IDM related thoughts, muses, stories and rumors. The blog posts are a personal opinion only and neither reflect the views of current/past employers nor any OTHER person living/dead on this planet.

I am the Lead Security Architect at JBoss (Middleware for Red Hat Inc). I strive to make JBoss secure for users and customers alike.</subtitle>
      <title>Anil's Security &amp; Identity Management Blog</title>
      <updated>2013-05-21T03:35:50Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/AnilsSecurityAndIdentityManagementBlog/~3/90MdJ9sOjqY/access-control-best-practices.html</feedburner:origLink></entry>

  <entry xml:lang="en-us">
    <id>http://www.centrify.com/blogs/tomkemp/big_mo_mentum_continues.asp</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/p4U2rOKfpP4/big_mo_mentum_continues.asp" rel="alternate" type="text/html" />
    <title>Tom Kemp - Centrify: The Momentum Continues</title>
    
    <updated>2013-05-20T13:59:00Z</updated><feedburner:origlink>http://www.centrify.com/blogs/tomkemp/big_mo_mentum_continues.asp</feedburner:origlink>
    <source>
      <id>http://www.centrify.com/blogs/tomkemp</id>
      <author>
        <name>Tom Kemp - Centrify</name>
      </author>
      <link href="http://www.centrify.com/blogs/tomkemp" rel="alternate" type="text/html" />
      <link href="http://feeds.centrify.com/TomKempsCentrifyBlog" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Lists the newest blog entries.</subtitle>
      <title>Tom Kemp's Centrify Blog</title>
      <updated>2013-05-22T10:02:58Z</updated>
    </source>
  <content type="html">It has been a few weeks since I last blogged and it's definitely time I get back into it. Since the beginning of February we (a) launched a major upgrade to Centrify Suite for UNIX/Linux/Mac, (b) entered the Windows privilege management market with DirectAuthorize for Windows; (c) are now fully participating (and doing quite well out of the gates) in the cloud identity management market with Centrify for SaaS; and (d) launched a major partnership with Samsung. And the nice thing is that this product and technology momentum is also being replicated in other areas of our business.&lt;img height="1" src="http://feeds.feedburner.com/~r/TomKempsCentrifyBlog/~4/JC515HIUoaw" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=p4U2rOKfpP4:JC515HIUoaw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=p4U2rOKfpP4:JC515HIUoaw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=p4U2rOKfpP4:JC515HIUoaw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=p4U2rOKfpP4:JC515HIUoaw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/p4U2rOKfpP4" height="1" width="1"/&gt;</content><feedburner:origLink>http://feeds.centrify.com/~r/TomKempsCentrifyBlog/~3/JC515HIUoaw/big_mo_mentum_continues.asp</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3572</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/yntrQy8XbVo/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: This promises to be a good comments thread.</title>
    
    <updated>2013-05-20T10:28:00Z</updated>
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;This promises to be a good comments thread.&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://www.antipope.org/charlie/blog-static/2013/05/the-language-of-alienation.html" rel="nofollow"&gt;http://www.antipope.org/charlie/blog-static/2013/05/the-language-of-alienation.html&lt;/a&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;i&gt;can you come up with some examples of sentences that would be incomprehensible (without explanation) to a denizen of 2003 that don't revolve around ephemeral tech or pop culture churn? And can you provide and deconstruct some sentences from 2023 that, if we had sufficient foresight, we ought to be able to understand and interpolate a context for?&lt;/i&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
My fav so far. "Skype trojan forces Bitcoin mining, security firm warns"&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://www.bbc.co.uk/news/technology-22064534" rel="nofollow"&gt;http://www.bbc.co.uk/news/technology-22064534&lt;/a&gt;&lt;hr&gt;&lt;/hr&gt;&lt;div&gt;&lt;a href="http://www.antipope.org/charlie/blog-static/2013/05/the-language-of-alienation.html"&gt;&lt;img src="https://lh6.googleusercontent.com/proxy/g5tYsKhHxDINwXPIqA0gyziWMx-bvJ20s3amiPcizPbCfLSo0sR1JCKCHR6FXE_d_6vpiGzV23FndGScbNuetqt51TSW7iqj4SBMceqsH8k=w125-h125" style="padding-right: 10px; float: left;"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="https://s2.googleusercontent.com/s2/favicons?domain=www.antipope.org" style="padding-right: 5px;"&gt;&lt;/img&gt; &lt;a href="http://www.antipope.org/charlie/blog-static/2013/05/the-language-of-alienation.html"&gt;The language of alienation - Charlie's Diary »&lt;/a&gt;&lt;br&gt;&#xD;
Some examples, culled from reddit, to get you started: hang2er: "I can't get a 4G signal here, I'll skype you on my droid as soon as I hit a hotspot, I need a coffee anyway." Retinence: "The headline, 'Galaxy Nexus: Android Ice Cream Sandwich guinea pig.'" (But tech is easy ...) ...&lt;br&gt;&#xD;
&lt;/div&gt;&lt;br&gt;&#xD;
[from: &lt;a href="https://plus.google.com/106416716945076707395/posts/Kvr2gs5MMvZ"&gt;Google+ Posts&lt;/a&gt;]&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yntrQy8XbVo:RKlywsqMudY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yntrQy8XbVo:RKlywsqMudY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yntrQy8XbVo:RKlywsqMudY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=yntrQy8XbVo:RKlywsqMudY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/yntrQy8XbVo" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3572</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3571</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/O5lvirX6Bys/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: Chaipuccino is not a thing, no matter what Starbucks may say. If you run a cafe and you have Chai tea...</title>
    
    <updated>2013-05-19T16:33:00Z</updated>
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Chaipuccino is not a thing, no matter what Starbucks may say. If you run a cafe and you have Chai tea bags as well as the usual English Breakfast, then congratulations. But putting hot frothed milk in a fancy tea pot, adding a chai tea bag and serving it with a fancy cup is just plain wrong. Please just treat it like Workman's Tea. A mug, tea bag, boiling water and a splash of milk once its brewed a bit is fine.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
And Starbucks, no thanks for the Chai Tea Latte. Maybe some people like it, but I reckon that's just wrong as well.&lt;br&gt;&#xD;
[from: &lt;a href="https://plus.google.com/106416716945076707395/posts/gEFKzkjHV6f"&gt;Google+ Posts&lt;/a&gt;]&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=O5lvirX6Bys:iFFh7Bfgtts:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=O5lvirX6Bys:iFFh7Bfgtts:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=O5lvirX6Bys:iFFh7Bfgtts:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=O5lvirX6Bys:iFFh7Bfgtts:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/O5lvirX6Bys" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3571</feedburner:origLink></entry>

  <entry>
    <id>http://blog.aniljohn.com/2013/05/likelihood-alien-invasion-assurance-levels</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/0kV6N0c8W5k/likelihood-alien-invasion-assurance-levels.html" rel="alternate" type="text/html" />
    <title>Anil John: Likelihood of Alien Invasions and Assurance Levels</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;One of the first steps taken to protect a system from authentication errors is the determination of its assurance level requirement. That risk assessment process takes as input &lt;em&gt;potential harm&lt;/em&gt; and &lt;em&gt;likelihood of harm&lt;/em&gt;. This blog post looks at the applicability of the &lt;em&gt;likelihood&lt;/em&gt; factor when assessing assurance level requirements for Internet connected systems.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&lt;img class="scale-with-grid" src="http://blog.aniljohn.com/img/iday.png" style="display: block; margin-left: auto; margin-right: auto;"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;The classic "&lt;a href="http://csrc.nist.gov/drivers/documents/m04-04.pdf" title="E-Authentication Guidance for Federal Agencies (OMB-M04-04)"&gt;E-Authentication Guidance for Federal Agencies (OMB-M04-04) [PDF]&lt;/a&gt;" defines risk from authentication error as a function of two factors: (a) potential harm or impact and (b) the likelihood of such harm or impact. The categories of harm and impact and how to apply them, per OMB-04-04, can be found in my earlier blog post on &lt;a href="http://blog.aniljohn.com/2011/10/how-to-conduct-risk-assessment-to.html" title="HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials"&gt;HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials&lt;/a&gt;.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;The key point to note is that most risk assessment methodologies allow for “tuning” the risk using a “likelihood of harm/impact” factor, which looks something like this:&lt;/p&gt;&#xD;
&#xD;
&lt;p class="text-center"&gt;&lt;strong&gt;Risk of Authentication Error = Potential Impact/Harm * Likelihood of Impact/Harm&lt;/strong&gt;&lt;/p&gt;&#xD;
&#xD;
&#xD;
&lt;p&gt;But how does one determine the "likelihood of harm" number? The two classic approaches are to explore "&lt;a href="http://en.wikipedia.org/wiki/Base_rate"&gt;base rates&lt;/a&gt;" or to consult with experts. But there is a gotcha with experts:&lt;/p&gt;&#xD;
&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;The simplest and most intuitive advice we can offer [...] is that when you’re trying to gather good information and reality-test your ideas, go talk to an expert. Here’s what is less intuitive: Be careful what you ask them. Experts are pretty bad at predictions. But they are great at assessing base rates.&lt;/p&gt;&#xD;
&lt;cite&gt;&lt;a href="http://heathbrothers.com/books/decisive/"&gt;Decisive: How to Make Better Choices in Life and Work&lt;/a&gt;&lt;/cite&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&#xD;
&#xD;
&lt;p&gt;So a prediction by an expert may not be all that valuable. But what about the base rates? My concern there is the &lt;strong&gt;constantly evolving threat environment that is the Internet&lt;/strong&gt;, and how base rates that are based on past data are an unreliable predictor of the future.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;So my recommendation in this particular case is rather simple. In this type of evaluation set the "likelihood" factor equal to 1. &lt;strong&gt;DO NOT discount the likelihood of harm, and ALWAYS assume there is a likelihood of harm&lt;/strong&gt;:&lt;/p&gt;&#xD;
&#xD;
&lt;p class="text-center"&gt;&lt;strong&gt;Risk of Authentication Error = Potential Impact/Harm * 1&lt;/strong&gt;&lt;/p&gt;&#xD;
&#xD;
&#xD;
&lt;p&gt;What that means is that, if as part of your assurance assessment you need to factor in the impact or harm from an alien invasion, do not discount the likelihood! Stand firm, fully account for it, and put into place compensating controls to mitigate the consequences.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&lt;strong&gt;RELATED INFO&lt;/strong&gt;&lt;/p&gt;&#xD;
&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;&lt;a href="http://csrc.nist.gov/drivers/documents/m04-04.pdf" title="E-Authentication Guidance for Federal Agencies (OMB-M04-04)"&gt;E-Authentication Guidance for Federal Agencies (OMB-M04-04) [PDF]&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;li&gt;&lt;a href="http://blog.aniljohn.com/2011/10/how-to-conduct-risk-assessment-to.html" title="HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials"&gt;HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&#xD;
&lt;hr&gt;&lt;/hr&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;img height="1" src="http://feeds.feedburner.com/~r/AnilJohn/~4/3qQAN5tUYnA" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0kV6N0c8W5k:QeXvWk_xzDw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0kV6N0c8W5k:QeXvWk_xzDw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=0kV6N0c8W5k:QeXvWk_xzDw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=0kV6N0c8W5k:QeXvWk_xzDw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/0kV6N0c8W5k" height="1" width="1"/&gt;</content>
    <updated>2013-05-18T19:00:00Z</updated>
    <published>2013-05-18T19:00:00Z</published><feedburner:origlink>http://blog.aniljohn.com/2013/05/likelihood-alien-invasion-assurance-levels.html</feedburner:origlink>
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
    <source>
      <id>http://blog.aniljohn.com/</id>
      <icon>http://blog.aniljohn.com/img/favicon.ico</icon>
      <logo>http://lh4.googleusercontent.com/-bdzCv-OkbiM/UN3mPNGG7QI/AAAAAAAAAUk/iADZchWRUXc/s800/aniljohnblog.png</logo>
      <author>
        <name>Anil John</name>
        <email>noreply@aniljohn.com</email>
        <uri>http://www.aniljohn.com/</uri>
      </author>
      <link href="http://blog.aniljohn.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/AnilJohn" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>On Architecture, Digital Security, Privacy...</subtitle>
      <title>Anil John | Blog</title>
      <updated>2013-05-20T11:34:42Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/AnilJohn/~3/3qQAN5tUYnA/likelihood-alien-invasion-assurance-levels.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3570</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/3uMR2p2lhHI/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: Something to get lost in. http://electronicexplorations.org/?show=zhou Fairly short and quirky mix of...</title>
    
    <updated>2013-05-18T10:28:00Z</updated>
    <category term="Music" />
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Something to get lost in. &lt;a class="ot-anchor" href="http://electronicexplorations.org/?show=zhou" rel="nofollow"&gt;http://electronicexplorations.org/?show=zhou&lt;/a&gt; Fairly short and quirky mix of tunes "that I would want to listen to". Recommended.&lt;hr&gt;&lt;/hr&gt;&lt;div&gt;&lt;a href="http://electronicexplorations.org/?show=zhou"&gt;&lt;img src="https://lh5.googleusercontent.com/proxy/EmGSGcSK46in1aAmHugkdmO4mEBFt2eLqN4gbJKhEKaVJt7-lxcGPMbg2-uknHgc6ltzaOhzj1Ps3-EjB9Fu4HOFj2xfpskO=w125-h125" style="padding-right: 10px; float: left;"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="https://s2.googleusercontent.com/s2/favicons?domain=electronicexplorations.org" style="padding-right: 5px;"&gt;&lt;/img&gt; &lt;a href="http://electronicexplorations.org/?show=zhou"&gt;Zhou »&lt;/a&gt;&lt;br&gt;&#xD;
"I chose to focus on the less dance floor orientated sounds for this mix and instead tried to compile a selection of tunes that I would want to listen to. It is a mix highlighting some of the music currently coming out of Bristol that I find most exciting as well as tracks that have informed the music we make ...&lt;br&gt;&#xD;
&lt;/div&gt;&lt;br&gt;&#xD;
[from: &lt;a href="https://plus.google.com/106416716945076707395/posts/777Gh6EynRD"&gt;Google+ Posts&lt;/a&gt;]&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3uMR2p2lhHI:zau_7mptsKc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3uMR2p2lhHI:zau_7mptsKc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3uMR2p2lhHI:zau_7mptsKc:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=3uMR2p2lhHI:zau_7mptsKc:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/3uMR2p2lhHI" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3570</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.stormpath.com/168 at http://www.stormpath.com</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/LF9OJ_QeI9k/stormpath-community-roundup-tasty-biscuits-edition" rel="alternate" type="text/html" />
    <title xml:lang="en">Katasoft: Stormpath Community Roundup - Tasty Biscuits Edition</title>
    
    <updated>2013-05-18T02:19:45Z</updated>
    <author>
      <name>Claire Hunsaker</name>
    </author>
    <source>
      <id>http://www.stormpath.com/blog</id>
      <link href="http://www.stormpath.com/blog" rel="alternate" type="text/html" />
      <link href="http://www.katasoft.com/blog/feed" rel="self" type="application/rss+xml" />
      <title xml:lang="en">Stormpath blogs</title>
      <updated>2013-05-22T12:03:46Z</updated>
    </source>
  <content type="html" xml:lang="en">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;div class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;&lt;div class="field-items"&gt;&lt;div class="field-item even"&gt; &lt;p&gt;&lt;span style="line-height: 1.538em;"&gt;Today is National Buttermilk Biscuit Day. Biscuits fill me with joy, as do community integrations, so here's a post packed with deliciousness from the amazing people in the Stormpath community. (First, here's an &lt;/span&gt;&lt;a href="http://eatocracy.cnn.com/2011/09/30/the-biscuit-recipe-that-cant-be-beat/" style="line-height: 1.538em;" target="_blank" title="Biscuit Boot Camp"&gt;awesome biscuit recipe&lt;/a&gt;&lt;span style="line-height: 1.538em;"&gt;. Happy Biscuit Day!)&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;CAS-Addons, now with Richer Stormpath Support&lt;/li&gt;&#xD;
&lt;li&gt;Python Login Skeleton for Stormpath&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;&lt;img alt="Biscuits!" height="308" src="http://www.stormpath.com/sites/default/files/Buttermilk-biscuits.jpg" style="display: block; margin-left: auto; margin-right: auto;" title="Biscuits!" width="450"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&lt;h2&gt;CAS-Addons, now with Richer Stormpath Support&lt;/h2&gt;&#xD;
&lt;div style="padding-left: 30px;"&gt;&lt;a href="http://www.stormpath.com/blog/cas-35-integration-stormpath"&gt;Last fall&lt;/a&gt;, the team at Unicon released &lt;a href="https://github.com/Unicon/cas-addons/wiki/Stormpath-Authentication-Support" target="_blank"&gt;CAS 3.5 Integration with Stormpath&lt;/a&gt;, which allows &lt;a href="https://github.com/Unicon/cas-addons/wiki/Configuring-Stormpath-Authentication-Handler" title="Stormpath CAS Integration"&gt;Stormpath&lt;/a&gt; to be used as a primary authentication source for CAS servers. They just added the ability to source Stormpath attributes and expose them as regular CAS Principal attributes. To quote Dmitriy at Unicon, "No need for a complex IPersonDirectoryDao impl, etc. Just a rich StormpathPrincipal encapsulating Account instances."&lt;/div&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&#xD;
&lt;div style="padding-left: 30px;"&gt;He also added custom XML namespace support for Stormpath-related beans. The authentication manager element now contains all the Stormpath-related objects. For example, to define a top-level authentication manager containing Stormpath handler and attributes resolution, one would simply need to do this:&lt;/div&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&#xD;
&lt;div style="padding-left: 30px;"&gt;&amp;lt;cas:authentication-manager-with-stormpath-handler&lt;/div&gt;&#xD;
&lt;div style="padding-left: 60px;"&gt;access-id="${stormpath.apiKey.id}"&lt;/div&gt;&#xD;
&lt;div style="padding-left: 60px;"&gt;secret-key="${stormpath.apiKey.secret}"&lt;/div&gt;&#xD;
&lt;div style="padding-left: 60px;"&gt;application-id="${stormpath.application.id}"/&amp;gt;&lt;/div&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&#xD;
&lt;div style="padding-left: 30px;"&gt;This encapsulates:&lt;/div&gt;&#xD;
&lt;div style="padding-left: 30px;"&gt;&lt;ol&gt;&#xD;
&lt;li&gt;Top level AuthenticationManager bean definition&lt;/li&gt;&#xD;
&lt;li&gt;List of handlers with default HttpBased handler and StormpathAuthenticationHandler&lt;/li&gt;&#xD;
&lt;li&gt;List of principal resolvers with default HTTP principal resolver and StormpathPrincipalResolver (which automatically exposes Stormpath Account data as CAS Principal attributes)&lt;/li&gt;&#xD;
&lt;/ol&gt;&lt;/div&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&#xD;
&lt;div style="padding-left: 30px;"&gt;...and eliminates any boilerplate bean definition constructs.&lt;/div&gt;&#xD;
&lt;p&gt;&lt;/p&gt;&#xD;
&lt;h2&gt;Python Login Skeleton for Stormpath&lt;/h2&gt;&#xD;
&lt;p&gt;Brian Peterson just released a simple and very intuitive login skeleton for Stormpath that uses the &lt;a href="https://bitbucket.org/bpeterso2000/stormpath_login_skeleton" target="_blank"&gt;Stormpath Python SDK&lt;/a&gt;. This makes it really (I mean, &lt;em&gt;&lt;strong&gt;really&lt;/strong&gt;&lt;/em&gt;) easy for Pythonistas to use and understand Stormpath.&lt;/p&gt;&#xD;
&lt;p&gt;He also did a great job of explaining and diagramming the actions of the SDK. Fork it, play with it, send him (and us!) your suggestions and pull requests. As we roll out the Python SDK update, which will include 2.7 support as well as a simplifying refactor, we'll also be updating this handy tool. Nice work!&lt;/p&gt;&#xD;
&lt;p&gt;&lt;img alt="Stormpath SDK Actions" height="464" src="https://docs.google.com/file/d/0B4t8kuRsJxkUU2NhNzUyMlFIQU0/image?pagenumber=1&amp;amp;w=600" style="display: block; margin-left: auto; margin-right: auto;" width="600"&gt;&lt;/img&gt;&lt;/p&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=LF9OJ_QeI9k:7BCI1sHaC2Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=LF9OJ_QeI9k:7BCI1sHaC2Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=LF9OJ_QeI9k:7BCI1sHaC2Q:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=LF9OJ_QeI9k:7BCI1sHaC2Q:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/LF9OJ_QeI9k" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.stormpath.com/blog/stormpath-community-roundup-tasty-biscuits-edition</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3569</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/pj4ZuVmoWEU/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: Shock horror. Festivals are expensive and only middle aged, middle class people can afford it.</title>
    
    <updated>2013-05-17T17:53:00Z</updated>
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Shock horror. Festivals are expensive and only middle aged, middle class people can afford it.&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://www.factmag.com/2013/05/16/study-60-of-young-people-priced-out-of-festivals-average-festival-costs-420" rel="nofollow"&gt;http://www.factmag.com/2013/05/16/study-60-of-young-people-priced-out-of-festivals-average-festival-costs-420&lt;/a&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
Which explains how white, middle aged and middle class, Glastonbury can appear to be. (sez, the balding old git).&lt;hr&gt;&lt;/hr&gt;&lt;div&gt;&lt;a href="http://www.factmag.com/2013/05/16/study-60-of-young-people-priced-out-of-festivals-average-festival-costs-420/"&gt;&lt;img src="https://lh4.googleusercontent.com/proxy/oe5aR8vCwB7Q3J-TZwBw8V5CTiW6ZGwmLKU_EAdfBomOxIF7jzCoWmzCHPa46PfLDefQTVZXD3jv5-9jMtyHtT0KSRsogBE3azWZW3zfJZN2d8Ns8hJOBP1JRXttdfEO-XKzy5D2oM7-8UszsUQ=w125-h125" style="padding-right: 10px; float: left;"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="https://s2.googleusercontent.com/s2/favicons?domain=www.factmag.com" style="padding-right: 5px;"&gt;&lt;/img&gt; &lt;a href="http://www.factmag.com/2013/05/16/study-60-of-young-people-priced-out-of-festivals-average-festival-costs-420/"&gt;Study: 60% of young people priced out of festivals; average festival costs £420 »&lt;/a&gt;&lt;br&gt;&#xD;
FACT is the UK's best online music magazine and home to the weekly FACT mix series.&lt;br&gt;&#xD;
&lt;/div&gt;&lt;br&gt;&#xD;
[from: &lt;a href="https://plus.google.com/106416716945076707395/posts/iipCbZYMSy8"&gt;Google+ Posts&lt;/a&gt;]&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pj4ZuVmoWEU:NVmTqUmE1zo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pj4ZuVmoWEU:NVmTqUmE1zo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=pj4ZuVmoWEU:NVmTqUmE1zo:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=pj4ZuVmoWEU:NVmTqUmE1zo:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/pj4ZuVmoWEU" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3569</feedburner:origLink></entry>

  <entry>
    <id>f1397696-738c-4295-afcd-943feb885714:97174</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/7WQY00Rb_Q4/Cloud-Security-Get-Ahead-of-the-Risk-Curve-with-Access-Intelligence" rel="alternate" type="text/html" />
    <title>Courion: Cloud Security - Get Ahead of the Risk Curve with Access Intelligence</title>
    
    <updated>2013-05-17T13:16:00Z</updated>
    <author>
      <name>Kurt Johnson - VP Strategy</name>
    </author>
    <source>
      <id>http://blog.courion.com/</id>
      <link href="http://blog.courion.com/" rel="alternate" type="text/html" />
      <link href="http://blog.courion.com/CMS/UI/Modules/BizBlogger/rss.aspx?tabid=89075&amp;moduleid=92273&amp;maxcount=25" rel="self" type="application/rss+xml" />
      <subtitle>RSS feeds for Courion Access Assurance Blog</subtitle>
      <title>Courion Corporation</title>
      <updated>2013-05-22T15:04:40Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Access Risk Management Blog | Courion&lt;/p&gt;&lt;p&gt;&lt;img alt="Kurt Johnson" border="0" class="alignLeft" src="http://blog.courion.com/Portals/41102/images/kurt_johnson.jpg" style="FLOAT: left;"&gt;&lt;/img&gt;Securing an enterprise is no mean feat and is made more difficult by the rapidly expanding use of software in the Cloud. Although security is often cited as a concern with a move to the Cloud, what may not be fully appreciated is how cloud computing amplifies the existing risks of how to best manage millions, if not billions of identity and access relationships.&lt;/p&gt;&#xD;
&lt;p&gt;Check out this article by Kurt Johnson, Courion VP of Strategy and Corporate Development, to learn about the need for real-time access intelligence to manage the risk of improper access to systems and resources that span the enterprise and the Cloud, as well as how organizations can reduce risks &lt;em&gt;before&lt;/em&gt; they become bona fide breaches.  &lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.businesscloud9.com/content/cloud-security-get-ahead-risk-curve-0"&gt;Click here&lt;/a&gt; to read the full story.&lt;/p&gt;&lt;p&gt;blog.courion.com&lt;/p&gt;&#xD;
&lt;img src="http://track.hubspot.com/__ptq.gif?a=41102&amp;amp;k=14&amp;amp;bu=http://blog.courion.com/access_risk_management_blog/&amp;amp;r=http://blog.courion.com/access_risk_management_blog/bid/97174/Cloud-Security-Get-Ahead-of-the-Risk-Curve-with-Access-Intelligence&amp;amp;bvt=rss"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=7WQY00Rb_Q4:X7oh7WJUk2I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=7WQY00Rb_Q4:X7oh7WJUk2I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=7WQY00Rb_Q4:X7oh7WJUk2I:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=7WQY00Rb_Q4:X7oh7WJUk2I:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/7WQY00Rb_Q4" height="1" width="1"/&gt;</content><feedburner:origLink>http://blog.courion.com/access_risk_management_blog/bid/97174/Cloud-Security-Get-Ahead-of-the-Risk-Curve-with-Access-Intelligence</feedburner:origLink></entry>

  <entry>
    <id>http://wayf.dk/en/news/news-2013/551-mecenat-student-discounts-through-wayf</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/LWup61Ezl1c/551-mecenat-student-discounts-through-wayf" rel="alternate" type="text/html" />
    <title>WAYF News: Mecenat student discounts through WAYF</title>
    
    <updated>2013-05-17T11:55:41Z</updated>
    <source>
      <id>http://wayf.dk/</id>
      <author>
        <name>WAYF News</name>
      </author>
      <link href="http://wayf.dk/" rel="alternate" type="text/html" />
      <link href="http://wayf.dk/index.php/component/ninjarsssyndicator/?feed_id=4&amp;format=raw&amp;lang=en" rel="self" type="application/atom+xml" />
      <subtitle>News from WAYF—Where Are You From—Denmark's leading federation of electronic identities.</subtitle>
      <title>News from WAYF</title>
      <updated>2013-05-22T15:02:22Z</updated>
    </source>
  <content type="html">&lt;p&gt;Students from a range of educational institutions now have the ability to confirm, through WAYF, their student status with &lt;a href="http://www.mecenat.dk/om-mecenat/om-mecenat"&gt;Mecenat&lt;/a&gt;, thereby obtaining access to purchasing discounted items from Mecenat's business partners. Educational institutions with an interest can get further information from &lt;a href="http://wayf.dk/mailto:lasse.urth@mecenat.dk"&gt;Lasse Urth&lt;/a&gt; of Mecenat (phone +45 2851 2171).&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=LWup61Ezl1c:6g8Qn2TpyDo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=LWup61Ezl1c:6g8Qn2TpyDo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=LWup61Ezl1c:6g8Qn2TpyDo:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=LWup61Ezl1c:6g8Qn2TpyDo:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/LWup61Ezl1c" height="1" width="1"/&gt;</content><feedburner:origLink>http://wayf.dk/en/news/news-2013/551-mecenat-student-discounts-through-wayf</feedburner:origLink></entry>

  <entry>
    <id>http://wayf.dk/en/news/news-2013/550-peoplexs-now-a-wayf-service</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/mVhXs1V-ysE/550-peoplexs-now-a-wayf-service" rel="alternate" type="text/html" />
    <title>WAYF News: PeopleXS now a WAYF service</title>
    
    <updated>2013-05-17T11:46:14Z</updated>
    <source>
      <id>http://wayf.dk/</id>
      <author>
        <name>WAYF News</name>
      </author>
      <link href="http://wayf.dk/" rel="alternate" type="text/html" />
      <link href="http://wayf.dk/index.php/component/ninjarsssyndicator/?feed_id=4&amp;format=raw&amp;lang=en" rel="self" type="application/atom+xml" />
      <subtitle>News from WAYF—Where Are You From—Denmark's leading federation of electronic identities.</subtitle>
      <title>News from WAYF</title>
      <updated>2013-05-22T15:02:21Z</updated>
    </source>
  <content type="html">&lt;p&gt;People employed at institutions using e-recruitment solutions from &lt;a href="http://peoplexs.com"&gt;people&lt;sup style="color: inherit; font-weight: inherit;"&gt;XS&lt;/sup&gt;&lt;/a&gt; now have the ability to log into the people&lt;sup style="color: inherit; font-weight: inherit;"&gt;XS&lt;/sup&gt; online service using their institutional login, through WAYF. In case of interest, contact people&lt;sup style="color: inherit; font-weight: inherit;"&gt;XS&lt;/sup&gt; for further information.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=mVhXs1V-ysE:_Wvg-C5Txu8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=mVhXs1V-ysE:_Wvg-C5Txu8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=mVhXs1V-ysE:_Wvg-C5Txu8:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=mVhXs1V-ysE:_Wvg-C5Txu8:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/mVhXs1V-ysE" height="1" width="1"/&gt;</content><feedburner:origLink>http://wayf.dk/en/news/news-2013/550-peoplexs-now-a-wayf-service</feedburner:origLink></entry>

  <entry>
    <id>tag:blogger.com,1999:blog-37220752.post-4487976271721511384</id>
    <link href="http://ignisvulpis.blogspot.com/feeds/4487976271721511384/comments/default" rel="replies" type="application/atom+xml" />
    <link href="http://www.blogger.com/comment.g?blogID=37220752&amp;postID=4487976271721511384" rel="replies" type="text/html" />
    <link href="http://www.blogger.com/feeds/37220752/posts/default/4487976271721511384?v=2" rel="edit" type="application/atom+xml" />
    <link href="http://www.blogger.com/feeds/37220752/posts/default/4487976271721511384?v=2" rel="self" type="application/atom+xml" />
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/hxSD7pCEFYg/fido-alliance.html" rel="alternate" type="text/html" />
    <title>Axel Nennker: FIDO Alliance</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;I am not happy with the FIDO Alliance and their &lt;a href="http://www.fidoalliance.org/faqs.html" target="_blank"&gt;FAQ &lt;/a&gt;do not eliminate my concerns.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
The major concern beeing: "Why isn't this going straight to a standards body?"&lt;br&gt;&#xD;
Their answer:&lt;br&gt;&#xD;
&lt;blockquote class="tr_bq"&gt;&#xD;
&lt;h5&gt;&#xD;
The FIDO authentication protocol needs to be part of a standardized,&#xD;
 interoperable ecosystem to be successful. Building this ecosystem &#xD;
requires the active commitment of everybody from hardware chipset &#xD;
vendors, to the manufacturers of back-end server systems. Coordination &#xD;
across the divergent interests of these players is a complex affair, and&#xD;
 one that current technical standards bodies are not well suited to &#xD;
handle.&lt;/h5&gt;&#xD;
&lt;h5&gt;&#xD;
The FIDO Alliance will refine the protocol, and monitor the &#xD;
extensions required to meet market needs and to make the protocol robust&#xD;
 and mature.  Implementation will not be undertaken by the FIDO &#xD;
Alliance.  The mature protocol will be presented to the IETF, W3C or &#xD;
similar body after which it will be open to all industry players to &#xD;
implement.&lt;/h5&gt;&#xD;
&lt;/blockquote&gt;&#xD;
This is what standardization bodies working groups are for. Work on protocols and formats. Work on security considerations. Use the experience of "the community".&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
So FIDO is developing a protocol and will then present it to one standardization body...&lt;br&gt;&#xD;
Meanwhile it is a closed thing and it costs relevant amounts of &lt;a href="http://www.fidoalliance.org/join.html" target="_blank"&gt;money &lt;/a&gt;to join the alliance.&lt;br&gt;&#xD;
This neither free nor open.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
During IIW there were several sessions on FIDO (&lt;a href="http://iiw.idcommons.net/Strong_2-Factor_For_All_%E2%80%93_Google_and_FIDO_Alliance" target="_blank"&gt;1&lt;/a&gt;, &lt;a href="http://iiw.idcommons.net/FIDO_Alliance_%E2%80%93_Fast_Identity_Online_Overview/Nutshell" target="_blank"&gt;2&lt;/a&gt;). Each full of good intentions and marketing speek but no substance. No real information. You have to join the alliance to get that. Well, ...&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
Somebody at &lt;a href="https://www.noknok.com/" target="_blank"&gt;Nok Nok Labs&lt;/a&gt; convinced somebody at Paypal to hire them and found FIDO. Why Google joined despite Google's support for the &lt;a href="http://www.w3.org/2012/webcrypto/" target="_blank"&gt;W3C WebCrypto&lt;/a&gt; group I have no idea.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
The W3C WebCrypto group is were this belongs. This might need &lt;a href="http://www.w3.org/2011/11/webcryptography-charter.html" target="_blank"&gt;rechartering&lt;/a&gt; of the group. But that is doable. Especially if the proposal is backed by a prototype implementation. Especially if it is backed by by Paypal, Lenovo, Google, Nxp and &lt;a href="http://www.fidoalliance.org/members.html" target="_blank"&gt;others&lt;/a&gt;.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
I believe that we need better authentication methods beyond username and password. I think that bring your own (hardware) identiy might work to that goal. I believe that mobile phones, and SIM cards and NFC help to achieve this. I believe that the mobile wallet is the right user interface to choose your identity.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
I believe that doing it in a closed group is not the right way. &lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;img border="0" src="https://lh3.ggpht.com/-QoVBbOx3bcw/UZX28alXeWI/AAAAAAAAI7E/wJZG4_2NXyo/s1600/nopasswords3.png" style="display: block; margin-left: auto; margin-right: auto;"&gt;&lt;/img&gt;&lt;br&gt;&#xD;
&lt;br&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/Ignisvulpis/~4/ZYJrZEPhA64" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=hxSD7pCEFYg:aOtAxXnVEuo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=hxSD7pCEFYg:aOtAxXnVEuo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=hxSD7pCEFYg:aOtAxXnVEuo:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=hxSD7pCEFYg:aOtAxXnVEuo:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/hxSD7pCEFYg" height="1" width="1"/&gt;</content>
    <updated>2013-05-17T09:34:57Z</updated>
    <published>2013-05-17T09:34:00Z</published>
    <category scheme="http://www.blogger.com/atom/ns#" term="mobile wallet" />
    <category scheme="http://www.blogger.com/atom/ns#" term="Standards" />
    <category scheme="http://www.blogger.com/atom/ns#" term="cloud" />
    <category scheme="http://www.blogger.com/atom/ns#" term="password" />
    <category scheme="http://www.blogger.com/atom/ns#" term="2FA" />
    <category scheme="http://www.blogger.com/atom/ns#" term="wallet" />
    <category scheme="http://www.blogger.com/atom/ns#" term="nfc" />
    <category scheme="http://www.blogger.com/atom/ns#" term="open" />
    <category scheme="http://www.blogger.com/atom/ns#" term="identity" />
    <category scheme="http://www.blogger.com/atom/ns#" term="BYOD" /><feedburner:origlink>http://ignisvulpis.blogspot.com/2013/05/fido-alliance.html</feedburner:origlink>
    <author>
      <name>Axel Nennker</name>
      <email>noreply@blogger.com</email>
      <uri>https://plus.google.com/111887082778273605100</uri>
    </author>
    <source>
      <id>tag:blogger.com,1999:blog-37220752</id>
      <category term="clickonce" />
      <category term="security token" />
      <category term="DigitalMe" />
      <category term="AES" />
      <category term="livehttpheaders" />
      <category term="Firefox plugin" />
      <category term="Trust Center" />
      <category term="bug" />
      <category term="InclusiveNamespaces" />
      <category term="robot" />
      <category term="iiw2009a" />
      <category term="fun communications" />
      <category term="UI" />
      <category term="layalty system" />
      <category term="Berlin" />
      <category term="privacy" />
      <category term="cmort" />
      <category term="IIW IIW2007b identity" />
      <category term="identity selector" />
      <category term="identity selector selector" />
      <category term="healthvault" />
      <category term="asn.1 to java" />
      <category term="web2.0 summit" />
      <category term="&quot;off topic&quot; xkcd comic" />
      <category term="data portability" />
      <category term="extension" />
      <category term="spam" />
      <category term="U-Prove" />
      <category term="FriendsWithCards" />
      <category term="subject confirmation" />
      <category term="license" />
      <category term="video" />
      <category term="Information Card Foundation" />
      <category term="enabler" />
      <category term="xhtml" />
      <category term="maowberlin09" />
      <category term="eic" />
      <category term="CS4FF" />
      <category term="liberty alliance" />
      <category term="extended validation certificates" />
      <category term="multifactor" />
      <category term="google wave" />
      <category term="catalyst09" />
      <category term="information card" />
      <category term="OpenId" />
      <category term="Salesforce" />
      <category term="iiw2009b" />
      <category term="icf" />
      <category term="java" />
      <category term="authentication" />
      <category term="xsd" />
      <category term="user agent" />
      <category term="ooTao" />
      <category term="nfc" />
      <category term="codeswarm" />
      <category term="plugin2" />
      <category term="ADFS" />
      <category term="Kantara" />
      <category term="CeBIT" />
      <category term="oidf" />
      <category term="id selector advertising" />
      <category term="iiw8" />
      <category term="vrm" />
      <category term="CardSpace openinfocard firefox extension" />
      <category term="reputation management" />
      <category term="datasharing summit" />
      <category term="The Laws of Identity" />
      <category term="j2me" />
      <category term="iPhone" />
      <category term="compatibility" />
      <category term="Azigo" />
      <category term="hexbug" />
      <category term="electronic signature" />
      <category term="osis" />
      <category term="IdentitySelector" />
      <category term="information card image" />
      <category term="geneva" />
      <category term="G1" />
      <category term="firefox mobile" />
      <category term="CardSpace 1.5" />
      <category term="IdP" />
      <category term="relationship management" />
      <category term="holder-of-key" />
      <category term="Deutsche Telekom" />
      <category term="Online Communities" />
      <category term="verisign" />
      <category term="crypto" />
      <category term="json" />
      <category term="google" />
      <category term=".NET" />
      <category term="lame++" />
      <category term="eID" />
      <category term="cyberspace" />
      <category term="tile" />
      <category term="weave" />
      <category term="geopriv" />
      <category term="rsa2008" />
      <category term="web guide" />
      <category term="account manager" />
      <category term="Microsoft" />
      <category term="cardstore" />
      <category term="rsa" />
      <category term="ISO" />
      <category term="teletrust" />
      <category term="iiw2008b" />
      <category term="no-SSL" />
      <category term="IDIB" />
      <category term="consent" />
      <category term="CardSpace4Firefox" />
      <category term="identity bus" />
      <category term="event" />
      <category term="BurtonGroupCatalyst07 xmldap openinfocard identity interop" />
      <category term="ssosummit" />
      <category term="user centric identity" />
      <category term="developer garden" />
      <category term="perpetual-motion" />
      <category term="voice search" />
      <category term="drag and drop" />
      <category term="logo" />
      <category term="FAT" />
      <category term="accountchooser" />
      <category term="2FA" />
      <category term="java firefox plugin" />
      <category term="bearer" />
      <category term="unlinkability" />
      <category term="opensource" />
      <category term="plugin" />
      <category term="dotNET" />
      <category term="KeeLoq" />
      <category term="openid connect" />
      <category term="opengovernment opengov" />
      <category term="open identity" />
      <category term="xauth" />
      <category term="off topic" />
      <category term="idtbd" />
      <category term="&quot;IDDY 2007&quot; openinfocard" />
      <category term="web2.0 expo europe" />
      <category term="id selector" />
      <category term="SSL" />
      <category term="Fraunhofer Fokus" />
      <category term="xbl" />
      <category term="ENISA" />
      <category term="rsa2009" />
      <category term="ceremony" />
      <category term="xsd to asn.1" />
      <category term="snake oil" />
      <category term="social network" />
      <category term="Microsoft tags" />
      <category term="periodic table" />
      <category term="personas" />
      <category term="openinfocard" />
      <category term="Identity TTL" />
      <category term="metasystem" />
      <category term="cisa" />
      <category term="cissp" />
      <category term="startup" />
      <category term="relyingparty" />
      <category term="easter-egg" />
      <category term="codeplex" />
      <category term="Mobile Monday" />
      <category term="Momo" />
      <category term="NSAPI" />
      <category term="brown bag" />
      <category term="iPhone CardSpace &quot;Bandit Project&quot; openinfocard" />
      <category term="Google Chrome" />
      <category term="OSIS PIP verisignlabs &quot;laws of identity&quot; xmldap &quot;id selector&quot;" />
      <category term="open government" />
      <category term="rsac" />
      <category term="speaker verification" />
      <category term="mime-handler" />
      <category term="Klaatu brada nikto" />
      <category term="identity" />
      <category term="openinfocard firefox extension &quot;Kevin Miller&quot;" />
      <category term="iiw2008a" />
      <category term="gender" />
      <category term="telco" />
      <category term="keystore" />
      <category term="facebook jvsmith" />
      <category term="problem" />
      <category term="openinfocard drag'n'drop user-centric" />
      <category term="mobile" />
      <category term="interop" />
      <category term="concordia" />
      <category term=".net3.5" />
      <category term="Novell" />
      <category term="identity management" />
      <category term="html5" />
      <category term="Standards" />
      <category term="ASN.1" />
      <category term="datasharing" />
      <category term="cyberspace policy" />
      <category term="BarCamp" />
      <category term="bsi" />
      <category term="proprietary crypto" />
      <category term="open source" />
      <category term="eic2008" />
      <category term="Information Cards" />
      <category term="firefox" />
      <category term="location" />
      <category term="dss2008" />
      <category term="PDC2008" />
      <category term="XPCOM" />
      <category term="css" />
      <category term="ActiveX" />
      <category term="e4x" />
      <category term="wallet" />
      <category term="r-cards" />
      <category term="BYOD" />
      <category term="sun" />
      <category term="quillp" />
      <category term="microformat" />
      <category term="link" />
      <category term="ip location" />
      <category term="ISIP" />
      <category term="eic2009" />
      <category term="yhoo" />
      <category term="eclipse" />
      <category term="DIDW" />
      <category term="windows mobile" />
      <category term="didw2008" />
      <category term="IRM" />
      <category term="openinfocard firefox extension" />
      <category term="humor" />
      <category term="xml" />
      <category term="IE7" />
      <category term="magic wand" />
      <category term="midlet" />
      <category term="html object" />
      <category term="higgins" />
      <category term="controls" />
      <category term="cardspace geneva" />
      <category term="security" />
      <category term="german language" />
      <category term="xrds" />
      <category term="age verification" />
      <category term="Sun Microsystems" />
      <category term="elf" />
      <category term="toolbar" />
      <category term="federation" />
      <category term="WS-Trust" />
      <category term="cloud" />
      <category term="SSO" />
      <category term="DIDW2007" />
      <category term=".net3" />
      <category term="internet identity workshop" />
      <category term="CardSpace" />
      <category term="SAML" />
      <category term="oracle" />
      <category term="LDAP" />
      <category term="t-home" />
      <category term="&quot;sign midlet&quot; midlet j2me &quot;code signing&quot; &quot;intermediate  certificate&quot;" />
      <category term="icardie.dll" />
      <category term="claims" />
      <category term="single-sign-on" />
      <category term="geolocation" />
      <category term="mobile wallet" />
      <category term="local chapter" />
      <category term="rsa2" />
      <category term="GPS" />
      <category term="certificate" />
      <category term="probile" />
      <category term="selector" />
      <category term="fun" />
      <category term="active client" />
      <category term="id selector selector" />
      <category term="bugzilla" />
      <category term="variable claim" />
      <category term="xmldap &quot;id selector&quot; openidcard sxip SAML" />
      <category term="Avoco" />
      <category term="wiki" />
      <category term="javascript" />
      <category term="trust" />
      <category term="smartcard" />
      <category term="iiw2010a" />
      <category term="reputation" />
      <category term="informationcard  openinfocard" />
      <category term="map" />
      <category term="glassfish" />
      <category term="relying party" />
      <category term="firefox3" />
      <category term="Firefix" />
      <category term="identity metasystem" />
      <category term="conference" />
      <category term="paymentCard" />
      <category term="identropy" />
      <category term="sex" />
      <category term="eternal optimist" />
      <category term="Kim Cameron" />
      <category term="STS" />
      <category term="wordle" />
      <category term="python" />
      <category term="firefox4" />
      <category term="deep dive" />
      <category term="bandit project" />
      <category term="claims informationcard" />
      <category term="WLAN" />
      <category term="open" />
      <category term="oauth" />
      <category term="civicloc" />
      <category term="iiw" />
      <category term="Android" />
      <category term="wave" />
      <category term="addon" />
      <category term="IMI" />
      <category term="developer phone" />
      <category term="Yahoo" />
      <category term="untracebility" />
      <category term="pageaction" />
      <category term="fennec" />
      <category term="Firefox extension" />
      <category term="apache" />
      <category term="msft" />
      <category term="iiw2007b" />
      <category term="recommendation" />
      <category term="multiple claims" />
      <category term="xmldap" />
      <category term="opensso" />
      <category term="trustbearer" />
      <category term="OASIS" />
      <category term="openinfocard.org" />
      <category term="rsac2010US" />
      <category term="information card icon" />
      <category term="openinfocard interop" />
      <category term="ISIP1.5" />
      <category term="Symbian" />
      <category term="&quot;id selector&quot; java openinfocard signature" />
      <category term="Open Source Projects" />
      <category term="keytool" />
      <category term="openifnocard" />
      <category term="minimal disclosure token" />
      <category term="pingidentity" />
      <category term="jobs" />
      <category term="xml schema" />
      <category term="search" />
      <category term="IDM" />
      <category term="Credentica" />
      <category term="eGovernment" />
      <category term="IE" />
      <category term="mozilla" />
      <category term="infocard" />
      <category term="informationcard" />
      <category term="metadata" />
      <category term="password" />
      <category term="identity theft" />
      <category term="xmldap infocard sts relyingparty" />
      <category term="merger" />
      <category term="DIDW DIDW2007" />
      <author>
        <name>Axel Nennker</name>
        <email>noreply@blogger.com</email>
        <uri>https://plus.google.com/111887082778273605100</uri>
      </author>
      <link href="http://ignisvulpis.blogspot.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" />
      <link href="http://ignisvulpis.blogspot.com/" rel="alternate" type="text/html" />
      <link href="http://www.blogger.com/feeds/37220752/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" rel="next" type="application/atom+xml" />
      <link href="http://feeds.feedburner.com/Ignisvulpis" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <title>ignisvulpis</title>
      <updated>2013-05-17T09:34:57Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/Ignisvulpis/~3/ZYJrZEPhA64/fido-alliance.html</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://blog.bavoderidder.com/?p=426</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/yMRghriCVRA/" rel="alternate" type="text/html" />
    <title>Bavo De Ridder: Recap of European Identity &amp; Cloud Conference 2013</title>
    <summary type="html">The 2013 edition of the European Identity &amp;amp; Cloud Conference just finished. As always KuppingerCole Analysts has created a great industry conference and I am glad I was part of it this year. To relive the conference you can search for the tag #EIC13 on Twitter. KuppingerCole manages each time to get all the Identity [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;The 2013 edition of the &lt;a href="http://www.id-conf.com/"&gt;European Identity &amp;amp; Cloud Conference&lt;/a&gt; just finished. As always &lt;a href="http://www.kuppingercole.com/"&gt;KuppingerCole Analysts&lt;/a&gt; has created a great industry conference and I am glad I was part of it this year. To relive the conference you can search for the tag #EIC13 on Twitter.&lt;/p&gt;&#xD;
&lt;p&gt;KuppingerCole manages each time to get all the Identity thought leaders together which makes the conference so valuable. You know you’ll be participating in some of the best conversations on Identity and Cloud related topics when people like Dave Kearns, Doc Searls, Paul Madsen, Kim Cameron, Craig Burton … are present. It’s a clear sign that KuppingerCole has grown into the international source for Identity related topics if you know that some of these thought leaders are employed by KuppingerCole themselves.&lt;/p&gt;&#xD;
&lt;p&gt;Throughout the conference a few topics kept popping up making them the ‘hot topics’ of 2013. These topics represent what you should keep in mind when dealing with Identity in the coming years:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;XACML and SAML are ‘too complicated’&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p&gt;It seems that after the &lt;a href="http://blogs.forrester.com/andras_cser/13-05-07-xacml_is_dead"&gt;announced death of XACML&lt;/a&gt; everyone felt liberated and dared to talk. Many people find XAMCL too complicated. &lt;a href="http://blogs.kuppingercole.com/burton/2012/09/19/saml-is-dead-long-live-saml/"&gt;Soon SAML joined the club of ‘too complicated’&lt;/a&gt;. The source of the complexity was identified as XML, SOAP and satellite standards like WS-Security.&lt;/p&gt;&#xD;
&lt;p&gt;There is a reason protocols like &lt;a href="http://oauth.net/"&gt;OAuth&lt;/a&gt;, which stays far away from XML and family, have so rapidly gained so much followers. REST and JSON have become ‘sine qua none’ for Internet standards.&lt;/p&gt;&#xD;
&lt;p&gt;There is an ongoing effort for a &lt;a href="https://wiki.oasis-open.org/xacml/RestProfileRequirements"&gt;REST/JSON profile for XACML&lt;/a&gt;. It’s not finished, let alone adopted, so we will have to wait and see what it gives.&lt;/p&gt;&#xD;
&lt;p&gt;That reminds me of a quote from Craig Burton during the conference:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;Once a developer is bitten by the bug of simplicity, it’s hard to stop him.&lt;/em&gt;&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;It sheds some light on the (huge) success of OAuth and other Web 2.0 API’s. It also looks like a developer cannot be easily bitten by the bug of complexity. Developers must see serious rewards before they are willing to jump into complexity.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;OAuth 2.0 has become the de-facto standard&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p&gt;Everyone declared OAuth 2.0, and it’s cousin OpenID Connect, to be the de facto Internet standard for federated authentication.&lt;/p&gt;&#xD;
&lt;p&gt;Why? Because it’s simple, even a mediocre developer who hasn’t seen anything but bad PHP is capable of using it. Try to achieve that with SAML. Of course, that doesn’t mean it’s not without problems. OAuth uses Bearer tokens that are not well understood by everyone which leads to some often seen security issues in the use of OAuth. On the other hand, given the complexity of SAML, do we really think everyone would use it as it should be used, avoiding security issues? Yes, indeed …&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;API Economy&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p&gt;A lot of talk about the ‘API Economy’. There are literally thousands and thousands of publicly available APIs (named “Open APIs”) and magnitudes more of hidden APIs (named “Dark APIs”) on the web. It has become so big and pervasive that it has become an ecosystem of its own.&lt;/p&gt;&#xD;
&lt;p&gt;New products and &lt;a href="http://datownia.com/"&gt;cloud services&lt;/a&gt; are being created around this phenomena. It’s not just about exposing a REST/JSON interface to your date. You need a whole infrastructure: throttling services, authentication, authorization, perhaps even an app store.&lt;/p&gt;&#xD;
&lt;p&gt;It’s also clear that developers once more become an important group. There is nu use to an Open API if nobody can or is willing to use it. Companies that depend on the use of their Open API suddenly see a whole new type of customer: developers. Having a good Developer API Portal is a key success factor.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Context for AuthN and AuthZ&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p&gt;Manye keynote and presentations referred to the need for authn and authz to become ‘contextual’. It was not entirely sure what was meant with that, nobody could give a clear picture. No idea what kind of technology or new standards it will require. But it was all agreed this was what we should be going to &lt;img alt=";)" class="wp-smiley" src="http://blog.bavoderidder.com/wp-includes/images/smilies/icon_wink.gif"&gt;&lt;/img&gt; &lt;/p&gt;&#xD;
&lt;p&gt;Obviously, the more information we can take into account when performing authn or authz, the better the result will be. Authz decisions that take present and past into account and not just whatever is directly related to the request, can produce a much more precise answer. In theory that is …&lt;/p&gt;&#xD;
&lt;p&gt;The problem with this is that computers are notoriously bad at anything that is not rule based. Once you move up the chain and starting including the context, next the past (heuristics) and ending at principles, computers are giving up pretty fast.&lt;/p&gt;&#xD;
&lt;p&gt;Of course, nothing keeps you from defining more rules that take contextual factors into account. But I would hardly call that ‘contextual’ authz. That’s just plain RuBAC with more PIPs available. It only becomes interesting if the authz engine is smart in itself and can decide, without hard wiring the logic in rules, which elements of the context are relevant and which aren’t. But as I said, computers are absolutely not good at that. They’ll look at us in despair and beg for rules, rules they can easily execute, millions at a time if needed.&lt;/p&gt;&#xD;
&lt;p&gt;The last day there was a presentation on RiskBAC or Risk Based Access Control. This is situated in the same domain of contextual authz. It’s something that would solve a lot but I would be surprised to see it anytime soon.&lt;/p&gt;&#xD;
&lt;p&gt;Don’t forget, the first thing computers do with anything we throw at them, is turning it into numbers. Numbers they can add and compare. So risks will be turned into numbers using rules we gave to computers and we &lt;a href="http://en.wikipedia.org/wiki/Financial_crisis_of_2007%E2%80%9308"&gt;all know what happens if we, humans, forgot to include a rule&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Graph Stores for identities&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p&gt;People got all excited by Graph Stores for identity management. Spurred by the interest in NoSQL and &lt;a href="http://msdn.microsoft.com/en-us/library/windowsazure/hh974482.aspx"&gt;Windows Azure Active Directory Graph&lt;/a&gt;, people saw it as a much better way to store identities.&lt;/p&gt;&#xD;
&lt;p&gt;I can only applaud the refocus on relations when dealing with identity. It’s what I have been saying for almost 10 years now: Identities are the manifestations of relationship between two parties. I had some interesting conversations with people at the conference about this and it gave me some new ideas. I plan to pour some of those into a couple of blog articles. Keep on eye on this site.&lt;/p&gt;&#xD;
&lt;p&gt;The graph stores themselves are a rather new topic for me so I can’t give more details or opinions. I suggest you hop over to that Windows Azure URL and give it a read. Don’t forget that &lt;a href="http://www.forgerock.org/"&gt;ForgeRock&lt;/a&gt;  already had a REST/JSON API on top of their &lt;a href="http://opendj.forgerock.org/"&gt;directory&lt;/a&gt; and &lt;a href="http://openidm.forgerock.org/"&gt;IDM&lt;/a&gt; components.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Life Management Platforms&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p&gt;Finally there was an entire separate track on &lt;a href="http://blogs.law.harvard.edu/vrm/2012/05/15/life-management-platforms/"&gt;Life Management Platforms&lt;/a&gt;. It took me a while to understanding what it was all about. Once I found out it was related to the &lt;a href="http://blogs.law.harvard.edu/vrm/"&gt;VRM&lt;/a&gt; project of Doc Searls, it became more clear.&lt;/p&gt;&#xD;
&lt;p&gt;Since this recap is almost getting longer than the actual conference, I’ll hand the stage to Martin Kuppinger and let him explain &lt;a href="http://blogs.kuppingercole.com/kuppinger/2012/05/15/intention-and-attention-how-life-management-platforms-can-improve-marketing/"&gt;Life Management Platforms&lt;/a&gt;. &lt;/p&gt;&#xD;
&lt;p&gt;That was the 2013 edition of the European Identity &amp;amp; Cloud Conference for me. It was a great time and even though I haven’t even gotten home yet, I already intend to be there as well next year.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yMRghriCVRA:27O5XF6S0lU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yMRghriCVRA:27O5XF6S0lU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=yMRghriCVRA:27O5XF6S0lU:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=yMRghriCVRA:27O5XF6S0lU:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/yMRghriCVRA" height="1" width="1"/&gt;</content>
    <updated>2013-05-16T19:19:29Z</updated>
    <category term="Access Control" />
    <category term="Architecture" />
    <category term="Cloud" />
    <category term="EIC" />
    <category term="Identity" />
    <category term="Privacy" />
    <category term="Security" />
    <author>
      <name>Bavo De Ridder</name>
    </author>
    <source>
      <id>http://blog.bavoderidder.com</id>
      <link href="http://blog.bavoderidder.com/?feed=rss2" rel="self" type="application/atom+xml" />
      <link href="http://blog.bavoderidder.com" rel="alternate" type="text/html" />
      <subtitle>Bavo De Ridder's blog: software architecture, software engineering, security and anything else worthwhile.</subtitle>
      <title>Ruminations on Architecture and Security</title>
      <updated>2013-05-16T19:33:03Z</updated>
    </source>
  <feedburner:origLink>http://blog.bavoderidder.com/?p=426</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.discoveringidentity.com/?p=3684</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/5udpVRL7Agg/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Oracle: Enabling Collaboration by with Social BPM</title>
    <summary type="html">This morning, I was read a recent Oracle White Paper entitled, “Transforming Customer Experience: The Convergence of Social, Mobile and   Business Process Management.”  It gave interesting perspective on the blending of emerging paradigms – mobile and social – with the older discipline of Business Process Management. To stay ahead in today’s rapidly changing business [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://www.oracle.com/us/technologies/bpm/bpm-for-integrating-experience-1891063.pdf" target="blank"&gt;&lt;img alt="Collaborate" border="0" height="140" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/collaborate.png" style="float: right;" title="collaborate.png" width="280"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;This morning, I was read a recent Oracle White Paper entitled, “&lt;a href="http://www.oracle.com/us/technologies/bpm/bpm-for-integrating-experience-1891063.pdf" target="blank"&gt;Transforming Customer Experience: The Convergence of Social, Mobile and   Business Process Management&lt;/a&gt;.”  It gave interesting perspective on the blending of emerging paradigms – mobile and social – with the older discipline of Business Process Management.&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;To stay ahead in today’s rapidly changing business environment, organizations need agile business processes that allow them to adapt quickly to evolving markets, customer needs, policies, regulations, and business models. … Social and mobile business models have already contributed important new frameworks for collaboration and information sharing in the enterprise. While these technologies are still in a nascent state, BPM and service oriented architecture (SOA) solutions are well established, providing a history of clear and complementary benefits.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;The key is effectively leveraging the strengths of existing, proven architectures while taking advantage of new opportunities:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;The term “Social BPM” is sometimes used to describe the use of social tools and techniques in business process improvement efforts. Social BPM helps eliminate barriers between decision makers and the people affected by their decisions. These tools facilitate communication that companies can leverage to improve business processes. Social BPM enables collaboration in the context of BPM and adds the richness of modern social communication tools.&lt;/p&gt;&#xD;
&lt;p&gt;… Social BPM increases business value by extracting information from enterprise systems and using it within social networks. Meanwhile, social technologies permit employees to utilize feedback from social networks to improve business processes.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;I found one use case presented in the paper to be particularly instructive. As illustrated in the following diagram,&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;A claims management system assigns a task to an individual claims worker with the expectation that the user will complete the task to advance the process. Of course, to accomplish this type of knowledge-based task, the individual must often engage other people within the business .&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;&lt;img alt="Bpm1" border="0" height="314" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/bpm1.png" style="display: block; margin-left: auto; margin-right: auto;" title="bpm1.png" width="580"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&lt;p&gt;However, Social BPM enables the use of social networking tools to extend collaboration beyond the traditional enterprise boundaries, as shown in the following diagram:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;img alt="Bpm2" border="0" height="359" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/bpm2.png" style="display: block; margin-left: auto; margin-right: auto;" title="bpm2.png" width="580"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Not only can internal knowledge workers use social networking tools to find each other and share information, but also customers can interact with the process at specific steps, using mobile devices, to supply their own information into a business process. For example, a customer involved in an auto accident might upload photos taken with a cell phone into the process via a claims management app provided by the insurance company.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;In order to make this all work, participants will need to use both enterprise and social identity credentials. Because they are using mobile devices, the IAM system must accommodate  mobile, social and cloud infrastructures in order to effectively use information.  This is very much in line with the principles set forth in the &lt;a href="http://www.discoveringidentity.com/2013/05/15/gartner-the-nexus-of-forces-social-mobile-cloud-and-information/" target="blank"&gt;Gartner Nexus&lt;/a&gt; I addressed yesterday.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5udpVRL7Agg:5s3JNmYSzbk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5udpVRL7Agg:5s3JNmYSzbk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=5udpVRL7Agg:5s3JNmYSzbk:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=5udpVRL7Agg:5s3JNmYSzbk:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/5udpVRL7Agg" height="1" width="1"/&gt;</content>
    <updated>2013-05-16T17:15:11Z</updated>
    <category term="Identity" />
    <category term="Business Process Management" />
    <category term="Mobile" />
    <category term="Social" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Exploring the science and magic of Identity and Access Management</subtitle>
      <title>Discovering Identity</title>
      <updated>2013-05-22T15:02:14Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2013/05/16/enabling-collaboration-by-with-social-bpm/</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3568</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/i9RhF6-TM4A/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: Realists have no idea how they ended up living on this once hospitable planet with all these fools</title>
    
    <updated>2013-05-16T15:49:00Z</updated>
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;i&gt;Realists have no idea how they ended up living on this once hospitable planet with all these fools&lt;/i&gt;&lt;hr&gt;&lt;/hr&gt;&lt;div&gt;&lt;a href="http://www.declineoftheempire.com/2013/05/chinese-demand-peak-oil-and-realism.html"&gt;&lt;img src="https://lh6.googleusercontent.com/proxy/H32f0H79qlLfsb735c2xvDuk0vjPZsquLiu1hp7dOwtSYOHRZ4ek_CX1PC-1C7-iYn2N4ckCA8Lz4U5HqLXh475kCMq0cXD1tz2Uy8Ofel2IYfWJfPbPsg=w125-h125" style="padding-right: 10px; float: left;"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="https://s2.googleusercontent.com/s2/favicons?domain=www.declineoftheempire.com" style="padding-right: 5px;"&gt;&lt;/img&gt; &lt;a href="http://www.declineoftheempire.com/2013/05/chinese-demand-peak-oil-and-realism.html"&gt;Chinese Demand, Peak Oil And Realism - Decline of the Empire »&lt;/a&gt;&lt;br&gt;&#xD;
This is the third and final day of my spring fundraiser. If you value this website, consider making a donation via the Donate (Paypal) button on this page, or by sending a check or money order to the PO Box I gave you in Tueday's post. Thanks â€” Dave [Tony Judt's book Ill Fares the Land] has a touch of prophecy in the authentic sense of that term. Prophecy is not about foretelling the future; it is about warning those in the present that unless th...&lt;br&gt;&#xD;
&lt;/div&gt;&lt;br&gt;&#xD;
[from: &lt;a href="https://plus.google.com/106416716945076707395/posts/5iLrteCpCGj"&gt;Google+ Posts&lt;/a&gt;]&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=i9RhF6-TM4A:QhV8zuGemLw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=i9RhF6-TM4A:QhV8zuGemLw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=i9RhF6-TM4A:QhV8zuGemLw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=i9RhF6-TM4A:QhV8zuGemLw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/i9RhF6-TM4A" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3568</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3567</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/F4peqtlFoGg/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: 16 May (tonight), MS Stubnitz, Canary Wharf, London for some Real time, Algorithmically Generated Techno...</title>
    
    <updated>2013-05-16T06:42:00Z</updated>
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;16 May (tonight), MS Stubnitz, Canary Wharf, London for some Real time, Algorithmically Generated Techno wholly or predominantly characterised by the emission of a succession of repetitive conditionals.&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://algorave.com/stubnitz2/" rel="nofollow"&gt;http://algorave.com/stubnitz2/&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://algorave.com/" rel="nofollow"&gt;http://algorave.com/&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://thenextweb.com/shareables/2013/05/11/algoraves-get-people-together-to-dance-to-music-generated-in-real-time-by-algorithms" rel="nofollow"&gt;http://thenextweb.com/shareables/2013/05/11/algoraves-get-people-together-to-dance-to-music-generated-in-real-time-by-algorithms&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://feedproxy.google.com/~r/TheNextWeb/~3/zsUdjhOM5tY/" rel="nofollow"&gt;http://feedproxy.google.com/~r/TheNextWeb/~3/zsUdjhOM5tY/&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a class="ot-anchor" href="http://boingboing.net/2013/05/11/algoraves-dancing-to-algorith.html" rel="nofollow"&gt;http://boingboing.net/2013/05/11/algoraves-dancing-to-algorith.html&lt;/a&gt;&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
Time to dust off the Music Tech dissertation and rhythm generator using Markoff Chains in the time domain.&lt;hr&gt;&lt;/hr&gt;&lt;div&gt;&lt;a href="http://algorave.com/stubnitz2/"&gt;&lt;img src="https://lh4.googleusercontent.com/proxy/gva0tXcK6GiHrW8EWJH4Xl6zeddm__NXUv7qHnnTRxALH2xpe3GN8bxBpr1Gkt7e3Vr0qysF_oxJ9w1tBwFi2bPUbGrY4do=w125-h125" style="padding-right: 10px; float: left;"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="https://s2.googleusercontent.com/s2/favicons?domain=algorave.com" style="padding-right: 5px;"&gt;&lt;/img&gt; &lt;a href="http://algorave.com/stubnitz2/"&gt;London (MS Stubnitz) Algorave on 16th May 2013 »&lt;/a&gt;&lt;br&gt;&#xD;
When: 7pm-11:30pm, Thursday 16 May 2013 Where: MS Stubnitz, Montgomery Street, Canary Wharf tube, London E14 9SB Tax: £9 advance tickets (or plenty on the door for £10) We're back on-board the MS S...&lt;br&gt;&#xD;
&lt;/div&gt;&lt;br&gt;&#xD;
[from: &lt;a href="https://plus.google.com/106416716945076707395/posts/DVRmSXGeDPm"&gt;Google+ Posts&lt;/a&gt;]&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=F4peqtlFoGg:G_mnGZ-Mgv4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=F4peqtlFoGg:G_mnGZ-Mgv4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=F4peqtlFoGg:G_mnGZ-Mgv4:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=F4peqtlFoGg:G_mnGZ-Mgv4:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/F4peqtlFoGg" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3567</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://self-issued.info/?p=1026</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/zR42iOxzu9k/" rel="alternate" type="text/html" />
    <link href="http://self-issued.info/?p=1026#comments" rel="replies" type="text/html" />
    <link href="http://self-issued.info/?feed=atom&amp;p=1026" rel="replies" type="application/atom+xml" />
    <title xml:lang="en-US">Mike Jones - Microsoft: OAuth 2.0 has won the 2013 European Identity Award</title>
    <summary xml:lang="en-US" type="html">I’m pleased to report that OAuth 2.0 has won the 2013 European Identity Award for Best Innovation/New Standard. I was honored to accept the award from Kuppinger Cole at the 2013 European Identity and Cloud Conference on behalf of all who contributed to creating the OAuth 2.0 standards [RFC 6749, RFC 6750] and who are [...]</summary>
    <content type="html" xml:lang="en-US">&lt;p&gt;&lt;span class="plain"&gt;&lt;img align="right" alt="OAuth logo" src="http://self-issued.info/images/oauth_logo_120x120.png"&gt;&lt;/img&gt;&lt;/span&gt;I’m pleased to report that OAuth 2.0 has won the 2013 European Identity Award for Best Innovation/New Standard.  I was honored to accept the award from Kuppinger Cole at the &lt;a href="http://www.id-conf.com/events/eic2013/"&gt;2013 European Identity and Cloud Conference&lt;/a&gt; on behalf of all who contributed to creating the OAuth 2.0 standards &lt;a href="http://tools.ietf.org/html/rfc6749"&gt;[RFC 6749&lt;/a&gt;, &lt;a href="http://tools.ietf.org/html/rfc6750"&gt;RFC 6750&lt;/a&gt;] and who are building solutions with them.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zR42iOxzu9k:Md-mzN9Egvw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zR42iOxzu9k:Md-mzN9Egvw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zR42iOxzu9k:Md-mzN9Egvw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=zR42iOxzu9k:Md-mzN9Egvw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/zR42iOxzu9k" height="1" width="1"/&gt;</content>
    <updated>2013-05-15T23:22:30Z</updated>
    <published>2013-05-15T17:23:44Z</published>
    <category scheme="http://self-issued.info" term="Events" />
    <category scheme="http://self-issued.info" term="OAuth" />
    <category scheme="http://self-issued.info" term="Specifications" />
    <author>
      <name>Mike Jones</name>
      <uri>http://self-issued.info/</uri>
    </author>
    <source>
      <id>http://self-issued.info/?feed=atom</id>
      <link href="http://self-issued.info" rel="alternate" type="text/html" />
      <link href="http://self-issued.info/?feed=atom" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Musings on Digital Identity</subtitle>
      <title xml:lang="en-US">Mike Jones: self-issued</title>
      <updated>2013-05-15T23:22:30Z</updated>
    </source>
  <feedburner:origLink>http://self-issued.info/?p=1026</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.discoveringidentity.com/?p=3679</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/mLXFG-m7PfI/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Oracle: Gartner: The Nexus of Forces – Social, Mobile, Cloud and Information</title>
    <summary type="html">Today I read a year-old document published by Gartner, entitled, “The Nexus of Forces: Social, Mobile, Cloud and Information.”  It explains the interaction among these market forces better than any single document I have read: Research over the past several years has identified the independent evolution of four powerful forces: social, mobile, cloud and information. [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://www.gartner.com/id=2049315" target="blank"&gt;&lt;img alt="GartnerNexus" border="0" height="296" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/GartnerNexus.png" style="float: right;" title="GartnerNexus.png" width="300"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt;Today I read a year-old document published by Gartner, entitled, “&lt;a href="http://www.gartner.com/id=2049315" target="blank"&gt;The Nexus of Forces: Social, Mobile, Cloud and Information&lt;/a&gt;.”  It explains the interaction among these market forces better than any single document I have read:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Research over the past several years has identified the independent evolution of four powerful forces: social, mobile, cloud and information. As a result of consumerization and the ubiquity of connected smart devices, people’s behavior has caused a convergence of these forces.&lt;/p&gt;&#xD;
&lt;p&gt;In the Nexus of Forces, &lt;strong&gt;&lt;em&gt;information&lt;/em&gt;&lt;/strong&gt; &lt;strong&gt;&lt;em&gt;is the context&lt;/em&gt;&lt;/strong&gt; for delivering enhanced social and mobile experiences. &lt;strong&gt;&lt;em&gt;Mobile devices&lt;/em&gt;&lt;/strong&gt; &lt;strong&gt;&lt;em&gt;are a&lt;/em&gt;&lt;/strong&gt; &lt;strong&gt;&lt;em&gt;platform&lt;/em&gt;&lt;/strong&gt; for effective social networking and new ways of work. &lt;strong style="font-style: italic;"&gt;S&lt;/strong&gt;&lt;strong&gt;&lt;em&gt;ocial links people&lt;/em&gt;&lt;/strong&gt; to their work and each other in new and unexpected ways.&lt;strong&gt;&lt;em&gt; Cloud enables delivery &lt;/em&gt;&lt;/strong&gt;of information and functionality to users and systems. The forces of the Nexus are intertwined to create a user-driven ecosystem of modern computing. (my emphasis added)&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;Excerpts from Gartner’s treatment of each of these areas include:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Social&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Social is one of the most compelling examples of how consumerization drives enterprise IT practices. It’s hard to think of an activity that is more personal than sharing comments, links and recommendations with friends. Nonetheless, enterprises were quick to see the potential benefits. Comments and recommendations don’t have to be among friends about last night’s game or which shoes to buy; they can also be among colleagues about progress of a project or which supplier provides good value. Consumer vendors were even quicker to see the influence — for good or ill — of friends sharing recommendations on what to buy.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Mobile&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Mobile computing is forcing the biggest change to the way people live since the automobile. And like the automotive revolution, there are many secondary impacts. It changes where people can work. It changes how they spend their day. Mass adoption forces new infrastructure. It spawns new businesses. And it threatens the status quo.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Cloud&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Cloud computing represents the glue for all the forces of the Nexus. It is the model for delivery of whatever computing resources are needed and for activities that grow out of such delivery. Without cloud computing, social interactions would have no place to happen at scale, mobile access would fail to be able to connect to a wide variety of data and functions, and information would be still stuck inside internal systems.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Information&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Developing a discipline of innovation through information enables organizations to respond to environmental, customer, employee or product changes as they occur. It will enable companies to leap ahead of their competition in operational or business performance.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;Gartner’s conclusion offers this challenge:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;The combination of pervasive mobility, near-ubiquitous connectivity, industrial compute services, and information access decreases the gap between idea and action. To take advantage of the Nexus of Forces and respond effectively, organizations must face the challenges of modernizing their systems, skills and mind-sets. Organizations that ignore the Nexus of Forces will be displaced by those that can move into the opportunity space more quickly — and the pace is accelerating.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;So, what does this mean for Identity and Access Management?  Just a few thoughts:&lt;/p&gt;&#xD;
&lt;ol&gt;&#xD;
&lt;li&gt;While “Social Identity” and “Enterprise Identity” are often now considered separately, I expect that there will be a convergence, or at least a close interoperation of, the two areas. The boundaries between work and personal life are being eroded, with work becoming more of an &lt;em&gt;activity&lt;/em&gt; and less of a &lt;em&gt;place&lt;/em&gt;.  The challenge of enabling and protecting the convergence of social and enterprise identities has huge security and privacy implications. &lt;/li&gt;&#xD;
&lt;li&gt;We cannot just focus on solving the IAM challenges of premised-based systems.  IAM strategies must accommodate cloud-based and premise-based systems as an integrated whole.  Addressing one without the other ignores the reality of the modern information landscape.&lt;/li&gt;&#xD;
&lt;li&gt;Mobile devices, not desktop systems, comprise the new majority of user information tools. IAM systems must address the fact that a person may have multiple devices and provide uniform means for addressing things like authentication, authorization, entitlement provisioning, etc. for use across a wide variety of devices.&lt;/li&gt;&#xD;
&lt;li&gt;We must improve our abilities to leverage the use of the huge amounts of information generated by mobile/social/cloud platforms, while protecting the privacy of users and the intellectual property rights of enterprises.&lt;/li&gt;&#xD;
&lt;li&gt;Emerging new computing paradigms designed to accommodate these converging forces, such as personal clouds, will require built-in, scalable, secure IAM infrastructure.&lt;/li&gt;&#xD;
&lt;li&gt;The Gartner Nexus doesn’t explicitly address the emergence of the Internet of Things, but IoT fits well within this overall structure.  The scope of IAM must expand to not only address the rapid growth of mobile computing devices, but the bigger virtual explosion of connected devices.&lt;/li&gt;&#xD;
&lt;/ol&gt;&#xD;
&lt;p&gt;We live in an interesting time. The pace of technological and social change is accelerating. Wrestling with and resolving IAM challenges across this rapidly changing landscape is critical to efforts to not only cope with but leverage new opportunities caused by these transformative forces.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=mLXFG-m7PfI:pTDH-7SkxNQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=mLXFG-m7PfI:pTDH-7SkxNQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=mLXFG-m7PfI:pTDH-7SkxNQ:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=mLXFG-m7PfI:pTDH-7SkxNQ:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/mLXFG-m7PfI" height="1" width="1"/&gt;</content>
    <updated>2013-05-15T22:58:29Z</updated>
    <category term="Identity" />
    <category term="Cloud" />
    <category term="Gartner" />
    <category term="Information" />
    <category term="Mobile" />
    <category term="Social" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Exploring the science and magic of Identity and Access Management</subtitle>
      <title>Discovering Identity</title>
      <updated>2013-05-22T15:02:14Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2013/05/15/gartner-the-nexus-of-forces-social-mobile-cloud-and-information/</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.gluu.org/blog/?p=813</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/Q82DyXpMYNw/" rel="alternate" type="text/html" />
    <title>Gluu: How &amp; Why Gluu’s open source authorization and authentication platform was chosen by Toshiba for new Cloud TV.</title>
    <summary type="html">Today, services like authorization and authentication are delivered via APIs: JSON / REST HTTP “endpoints.” Some of the most popular authentication API’s on the Internet are using different profiles of OAuth2. Because consolidation increases efficiency, Google, Microsoft, Yahoo, and others … &lt;span class="entry-more"&gt;&lt;a href="http://www.gluu.org/blog/how-why-gluus-open-source-authorization-and-authentication-platform-was-chosen-by-toshiba-for-new-cloud-tv/"&gt;Read more &amp;gt;&amp;gt;&lt;/a&gt;&lt;/span&gt;</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p dir="ltr"&gt;Today, services like authorization and authentication are delivered via APIs: JSON / REST HTTP “endpoints.” Some of the most popular authentication API’s on the Internet are using different profiles of OAuth2. Because consolidation increases efficiency, Google, Microsoft, Yahoo, and others came together to define one standard profile for OAuth 2.0 authentication: &lt;a href="http://gluu.org/resources/openid-connect"&gt;OpenID Connect&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;OpenID Connect documents a single profile of OAuth2 that can be used by any Internet domain.  &lt;strong&gt;One standard for domain authentication&lt;/strong&gt; will simplify security for application developers (web and mobile), make end users more secure, and enable easier integration of mobile devices and cloud agents.&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;&lt;a href="http://goo.gl/Z60me"&gt;See Toshiba Cloud TV in Action.&lt;/a&gt;  &lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;Specifically, OpenID Connect defines several endpoints to enable domains to offer : (1) user authentication; (2) client registration; (3) client authentication; (4) user claims; (5) client claims; and (6) discovery. Industry analysts are predicting that OpenID Connect is on a trajectory for significant adoption. The standard should be finalized by the end of 2013. Nat Sakimura (NTT) , Vice-Chairman of the OpenID Foundation, has said this about OpenID Connect: “&lt;a href="http://lists.openid.net/pipermail/openid-specs-ab/Week-of-Mon-20130513/003475.html"&gt;we are done apart from formalities.&lt;/a&gt;”&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;For reasons like these, Toshiba decided in 2012 to align with OpenID Connect. As Gluu’s open source “OX” platform performed well in the &lt;a href="http://goo.gl/9CdE6"&gt;OpenID Connect OpenID Provider (“OP”) Internop&lt;/a&gt;, Toshiba decided it was preferable to use OX rather than write their own implementation.&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;&lt;a href="http://self-issued.info/presentations/OpenID_Connect_Update_May_14_2013.pdf"&gt;Learn more about OpenID Connect via slides from Microsoft’s Michael B. Jones.&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;The partnership with Toshiba has driven the implementation of a number of features to the OX platform. For example, they wanted to build a &lt;strong&gt;highly available “cluster”&lt;/strong&gt; of authentication servers delivered across multiple geographic regions to ensure business continuity. This would enable Toshiba engineers to take a server out for maintenance, and just add it back later.&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;Toshiba has also been helpful with &lt;strong&gt;testing and benchmarking&lt;/strong&gt;. OX has been in production there since last year, so we have also been able to observe the behavior of the platform over time, while handling significant load.&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;Gluu has also built features to enable Toshiba to use the central publication of &lt;strong&gt;multi-party federation&lt;/strong&gt; metadata to enable globally delivered websites to trust identity providers in different regions (Japan, US, and Europe) without persisting any personally identifiable data outside of the region. Although JSON multiparty federation metadata is not currently a feature of OpenID Connect, Gluu has documented its implementation at the OpenID Foundation in the Emerging Work Section, and hopes it will be included in a subsequent release: &lt;a href="http://wiki.openid.net/w/page/59727624/Multi-Party%20Federations"&gt;http://wiki.openid.net/w/page/59727624/Multi-Party%20Federations&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p dir="ltr"&gt;Toshiba is keen to promote the OX open source platform within the &lt;a href="http://www.smarttv-alliance.org/"&gt;SmartTV Alliance&lt;/a&gt;, which is why they authorized the &lt;a href="http://goo.gl/31tFC"&gt;May 1, 2013 press release&lt;/a&gt;. Adoption of the OX open source platform will help members of the SmartTV Alliance collaborate on the development of an Internet scale, interoperable security infrastructure, a goal everyone wants to achieve.&lt;/p&gt;&#xD;
&lt;p&gt;Gluu provides services to companies that want to use the OX platform: &lt;strong&gt;Design, Build, Operate, and Transfer (DBOT)&lt;/strong&gt;.  We were able to help Toshiba engineers jumpstart their development effort and to provide some tactical feature enhancements in the open source project to support their rollout.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Q82DyXpMYNw:1ZxurHdwjFY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Q82DyXpMYNw:1ZxurHdwjFY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=Q82DyXpMYNw:1ZxurHdwjFY:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=Q82DyXpMYNw:1ZxurHdwjFY:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/Q82DyXpMYNw" height="1" width="1"/&gt;</content>
    <updated>2013-05-15T21:33:23Z</updated>
    <category term="Gluu" />
    <category term="OX" />
    <category term="application security" />
    <category term="cloud identity" />
    <category term="consumer authentication" />
    <category term="consumer facing authentication" />
    <category term="mobile authentication" />
    <category term="oauth 2.0" />
    <category term="openid connect" />
    <category term="single sign on" />
    <category term="sso" />
    <category term="strong authentication" />
    <category term="two-factor authentication" />
    <author>
      <name>Mike S.</name>
    </author>
    <source>
      <id>http://www.gluu.org/blog</id>
      <link href="http://www.gluu.org/blog/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.gluu.org/blog" rel="alternate" type="text/html" />
      <title>Gluu | Blog</title>
      <updated>2013-05-22T15:04:45Z</updated>
    </source>
  <feedburner:origLink>http://www.gluu.org/blog/how-why-gluus-open-source-authorization-and-authentication-platform-was-chosen-by-toshiba-for-new-cloud-tv/</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/eicaward2013_oauth</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/TfEFsU5baRk/eicaward2013_oauth" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: European Identity &amp; Cloud Award 2013: OAuth 2.0 - 70778</title>
    
    <updated>2013-05-15T18:25:04Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:08Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;European Identity Award 2013 for „Best Innovation/New Standard in Information Security”: A new standard that rapidly gained momentum and plays a central role for future concepts of Identity Federation and Cloud Security.&lt;/p&gt;&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/eicaward2013_oauth"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/TfEFsU5baRk" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=TfEFsU5baRk:a5tdgkPdKr8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=TfEFsU5baRk:a5tdgkPdKr8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=TfEFsU5baRk:a5tdgkPdKr8:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=TfEFsU5baRk:a5tdgkPdKr8:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/TfEFsU5baRk" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/eicaward2013_oauth</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/eicaward2013_vwfs</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/dVX1raXi8IU/eicaward2013_vwfs" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: European Identity &amp; Cloud Award 2013: Volkswagen Financial Services AG - 70775</title>
    
    <updated>2013-05-15T18:23:30Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Special Award 2013 for „Bridging the organizational gap between Business and IT”: A project that was far above average when it comes to Business/IT Alignment, by successfully setting up a framework of guidelines and policies plus the required organizational entities and rolling this out into a global organization.&lt;/p&gt;&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/eicaward2013_vwfs"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/dVX1raXi8IU" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dVX1raXi8IU:umYOaFL8sdE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dVX1raXi8IU:umYOaFL8sdE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dVX1raXi8IU:umYOaFL8sdE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=dVX1raXi8IU:umYOaFL8sdE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/dVX1raXi8IU" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/eicaward2013_vwfs</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/eicaward2013_swissre</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/H51SLH6OV6c/eicaward2013_swissre" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: European Identity &amp; Cloud Award 2013:  Swiss Reinsurance Company Ltd - 70774</title>
    
    <updated>2013-05-15T18:22:10Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:07Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;European Identity Award 2013 in category „Best Access Governance and Intelligence Project”: Holistic IAM/IAG approach following new architectural concepts and enabling Dynamic Authorization Management based on business rules.&lt;/p&gt;&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/eicaward2013_swissre"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/H51SLH6OV6c" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=H51SLH6OV6c:SZMNkWrVw0E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=H51SLH6OV6c:SZMNkWrVw0E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=H51SLH6OV6c:SZMNkWrVw0E:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=H51SLH6OV6c:SZMNkWrVw0E:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/H51SLH6OV6c" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/eicaward2013_swissre</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/eicaward2013_schindler</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/-aPR_M_sY_A/eicaward2013_schindler" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: European Identity &amp; Cloud Award 2013: Schindler Informatik AG - 70771</title>
    
    <updated>2013-05-15T18:21:06Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Special Award 2013 for „Rapid Re-Design and Re-Implementation of the Entire IAM”: Moving from a traditional, Active Directory-centric environment to full HR integration on a global scale and full support for automated provisioning, based on a clearly defined roadmap for further improvement.&lt;/p&gt;&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/eicaward2013_schindler"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/-aPR_M_sY_A" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-aPR_M_sY_A:tgrjirWQHeU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-aPR_M_sY_A:tgrjirWQHeU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-aPR_M_sY_A:tgrjirWQHeU:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=-aPR_M_sY_A:tgrjirWQHeU:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/-aPR_M_sY_A" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/eicaward2013_schindler</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/eicaward2013_deutschebank</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/ADi-cRFlEV0/eicaward2013_deutschebank" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: European Identity &amp; Cloud Award 2013: Deutsche Bank AG - 70772</title>
    
    <updated>2013-05-15T18:18:12Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:07Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;European Identity Award 2013 in category „Best Access Governance and Intelligence Project”: Implementing cross-divisional SoD rules on a global scale at business level, with full integration into the existing Access Governance solution.&lt;/p&gt;&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/eicaward2013_deutschebank"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/ADi-cRFlEV0" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ADi-cRFlEV0:bul0O2kYEsA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ADi-cRFlEV0:bul0O2kYEsA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ADi-cRFlEV0:bul0O2kYEsA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=ADi-cRFlEV0:bul0O2kYEsA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/ADi-cRFlEV0" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/eicaward2013_deutschebank</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/articles/award2013</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/EKW_gPzWGZU/award2013" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: European Identity &amp; Cloud Awards 2013</title>
    
    <updated>2013-05-15T18:06:28Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; Am heutigen Abend verlieh die Analystengruppe KuppingerCole im Rahmen der siebten European Identity &amp;amp; Cloud Conference (EIC) in unterschiedlichen Kategorien den European Identity &amp;amp; Cloud Award 2013. Dieser Award zeichnet herausragende Projekte und Initiativen in den Bereichen Identity &amp;amp; Access Management (IAM), GRC (Governance, Risk Management and Compliance) und Cloud Security aus. Nominiert waren zahlreiche Projekte, die im Laufe der letzten 12 Monate von Anwenderunternehmen und Herstellern...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/articles/award2013"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/EKW_gPzWGZU" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=EKW_gPzWGZU:30e1S5FB51A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=EKW_gPzWGZU:30e1S5FB51A:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=EKW_gPzWGZU:30e1S5FB51A:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=EKW_gPzWGZU:30e1S5FB51A:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/EKW_gPzWGZU" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/articles/award2013</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3566</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/kZ7GBcIMatY/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: Google All Access. "Radio Without Rules", Music streaming $9.99 pm, $7.99 pm early adopters. 30 days ...</title>
    
    <updated>2013-05-15T16:56:00Z</updated>
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Google All Access. "Radio Without Rules", Music streaming $9.99 pm, $7.99 pm early adopters. 30 days free. An extension to Google Music allowing clever playlists and instant access to any track in Google's library. Along with some more smarts for exploring based on your listening and library habits. USA Today. Other countries rolling out "soon".&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
No thanks. I've already got 30k tracks in my personal collection.&lt;br&gt;&#xD;
[from: &lt;a href="https://plus.google.com/106416716945076707395/posts/TNugk6cUjG4"&gt;Google+ Posts&lt;/a&gt;]&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=kZ7GBcIMatY:pfMqhIFfqxA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=kZ7GBcIMatY:pfMqhIFfqxA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=kZ7GBcIMatY:pfMqhIFfqxA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=kZ7GBcIMatY:pfMqhIFfqxA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/kZ7GBcIMatY" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3566</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>8d07cc69-a460-48f1-844d-25b05ba87317:10583</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/bxlbc0fG0k0/bring-your-own-identity-the-rise-of-the-user.aspx" rel="alternate" type="text/html" />
    <title>CA on Security Management: Bring Your Own Identity: the Rise of the User</title>
    
    <updated>2013-05-14T20:01:00Z</updated>
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/BYOD/default.aspx" term="BYOD" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Facebook/default.aspx" term="Facebook" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Google/default.aspx" term="Google" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Identity+and+Access+Management/default.aspx" term="Identity and Access Management" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Identity+Assurance+Framework/default.aspx" term="Identity Assurance Framework" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/identity+federation/default.aspx" term="identity federation" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/linkedin/default.aspx" term="linkedin" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/social+media/default.aspx" term="social media" /><feedburner:origlink>http://community.ca.com/blogs/iam/archive/2013/05/14/bring-your-own-identity-the-rise-of-the-user.aspx</feedburner:origlink>
    <author>
      <name>Henk van der Heijden</name>
    </author>
    <source>
      <id>http://community.ca.com/blogs/iam/default.aspx</id>
      <logo>http://www.ca.com/images/global/logo_172900.gif</logo>
      <link href="http://community.ca.com/blogs/iam/default.aspx" rel="alternate" type="text/html" />
      <link href="http://feeds.ca.com/CS_CAIAMBlog" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Insight and opinion on the world of security management. Visit often for commentary on security industry issues around identity and access management, data protection, advanced authentication, single sign-on and access management, cloud security and more.</subtitle>
      <title>Security Management</title>
      <updated>2013-05-15T16:02:18Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Social media is fast becoming the identity mechanism of choice to log into popular sites and company information. Looking to find the right music on Spotify? Want to connect with the world’s professionals on LinkedIn? You can now simply log in via your Facebook account. The UK Government may even soon allow citizens to use their social media identity to access public services safely and securely...&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
 &lt;img height="1" src="http://feeds.feedburner.com/~r/CS_CAIAMBlog/~4/Uy-xX4tiU8k" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=bxlbc0fG0k0:wEXCIaD4KVU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=bxlbc0fG0k0:wEXCIaD4KVU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=bxlbc0fG0k0:wEXCIaD4KVU:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=bxlbc0fG0k0:wEXCIaD4KVU:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/bxlbc0fG0k0" height="1" width="1"/&gt;</content><feedburner:origLink>http://feeds.ca.com/~r/CS_CAIAMBlog/~3/Uy-xX4tiU8k/bring-your-own-identity-the-rise-of-the-user.aspx</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>8d07cc69-a460-48f1-844d-25b05ba87317:10582</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/9uTagtCOb3A/supporting-industry-standards.aspx" rel="alternate" type="text/html" />
    <title>CA on Security Management: Supporting Industry Standards</title>
    
    <updated>2013-05-14T18:07:00Z</updated>
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/forrester/default.aspx" term="forrester" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Open+Group/default.aspx" term="Open Group" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/OpenID/default.aspx" term="OpenID" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/security+management/default.aspx" term="security management" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/single+sign-on/default.aspx" term="single sign-on" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/SPML/default.aspx" term="SPML" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/SSO/default.aspx" term="SSO" /><feedburner:origlink>http://community.ca.com/blogs/iam/archive/2013/05/14/supporting-industry-standards.aspx</feedburner:origlink>
    <author>
      <name>Chris Wraight</name>
    </author>
    <source>
      <id>http://community.ca.com/blogs/iam/default.aspx</id>
      <logo>http://www.ca.com/images/global/logo_172900.gif</logo>
      <link href="http://community.ca.com/blogs/iam/default.aspx" rel="alternate" type="text/html" />
      <link href="http://feeds.ca.com/CS_CAIAMBlog" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Insight and opinion on the world of security management. Visit often for commentary on security industry issues around identity and access management, data protection, advanced authentication, single sign-on and access management, cloud security and more.</subtitle>
      <title>Security Management</title>
      <updated>2013-05-15T16:02:18Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;On May 7, Andras Cser of Forrester Research, Inc. posted a thought-provoking blog entry entitled “XACML is Dead” which postulated that there wasn’t any future for XACML. &#xD;
&#xD;
At CA Technologies we have long supported a broad range of industry standards such as LDAP, X.509, WS-Federation, SAML, WS-Security, REST, SPML as well as more recent standards like OpenID, OpenID Connect and OAuth, thereby...&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
 &lt;img height="1" src="http://feeds.feedburner.com/~r/CS_CAIAMBlog/~4/n_Q1oxjvjfo" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=9uTagtCOb3A:saIlG5KlK5M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=9uTagtCOb3A:saIlG5KlK5M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=9uTagtCOb3A:saIlG5KlK5M:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=9uTagtCOb3A:saIlG5KlK5M:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/9uTagtCOb3A" height="1" width="1"/&gt;</content><feedburner:origLink>http://feeds.ca.com/~r/CS_CAIAMBlog/~3/n_Q1oxjvjfo/supporting-industry-standards.aspx</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.mythics.com/blog/do-you-have-a-contingency-plan-for-your-critical-it-infrastructure</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/-SYG6ZdEWYk/do-you-have-a-contingency-plan-for-your-critical-it-infrastructure" rel="alternate" type="text/html" />
    <title>Mythics: Do You Have a Contingency Plan for Your Critical IT Infrastructure?</title>
    
    <updated>2013-05-14T17:42:00Z</updated>
    <source>
      <id>http://www.mythics.com/blog</id>
      <author>
        <name>Mythics</name>
      </author>
      <link href="http://www.mythics.com/blog" rel="alternate" type="text/html" />
      <link href="http://www.mythics.com/rss/blog/" rel="self" type="application/rss+xml" />
      <rights>Copyright 2013</rights>
      <title>Mythics Blog</title>
      <updated>2013-05-22T15:04:41Z</updated>
    </source>
  <content type="html">&lt;p&gt;Summer is coming, which means the hurricane, tornado season is here. Do you have a contingency plan for your critical IT infrastructure? If so, is…&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-SYG6ZdEWYk:bh9cMArFEFQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-SYG6ZdEWYk:bh9cMArFEFQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=-SYG6ZdEWYk:bh9cMArFEFQ:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=-SYG6ZdEWYk:bh9cMArFEFQ:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/-SYG6ZdEWYk" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.mythics.com/blog/do-you-have-a-contingency-plan-for-your-critical-it-infrastructure</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://self-issued.info/?p=1021</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/BEmtbCh-9UY/" rel="alternate" type="text/html" />
    <link href="http://self-issued.info/?p=1021#comments" rel="replies" type="text/html" />
    <link href="http://self-issued.info/?feed=atom&amp;p=1021" rel="replies" type="application/atom+xml" />
    <title xml:lang="en-US">Mike Jones - Microsoft: OpenID Connect Update Presentation</title>
    <summary xml:lang="en-US" type="html">I’ve posted the OpenID Connect Update presentation that I gave today during the OpenID Workshop at the European Identity and Cloud Conference. It’s available in PowerPoint and PDF formats.</summary>
    <content type="html" xml:lang="en-US">&lt;p&gt;&lt;span class="plain"&gt;&lt;img align="right" alt="OpenID logo" src="http://self-issued.info/images/openid-logo.png"&gt;&lt;/img&gt;&lt;/span&gt;I’ve posted the OpenID Connect Update presentation that I gave today during the &lt;a href="http://www.id-conf.com/events/eic2013-openid"&gt;OpenID Workshop&lt;/a&gt; at the &lt;a href="http://www.id-conf.com/events/eic2013/"&gt;European Identity and Cloud Conference&lt;/a&gt;.  It’s available in &lt;a href="http://self-issued.info/presentations/OpenID_Connect_Update_May_14_2013.pptx"&gt;PowerPoint&lt;/a&gt; and &lt;a href="http://self-issued.info/presentations/OpenID_Connect_Update_May_14_2013.pdf"&gt;PDF&lt;/a&gt; formats.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=BEmtbCh-9UY:w6qvxBmogrQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=BEmtbCh-9UY:w6qvxBmogrQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=BEmtbCh-9UY:w6qvxBmogrQ:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=BEmtbCh-9UY:w6qvxBmogrQ:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/BEmtbCh-9UY" height="1" width="1"/&gt;</content>
    <updated>2013-05-14T16:06:56Z</updated>
    <published>2013-05-14T16:05:36Z</published>
    <category scheme="http://self-issued.info" term="Events" />
    <category scheme="http://self-issued.info" term="OpenID" />
    <author>
      <name>Mike Jones</name>
      <uri>http://self-issued.info/</uri>
    </author>
    <source>
      <id>http://self-issued.info/?feed=atom</id>
      <link href="http://self-issued.info" rel="alternate" type="text/html" />
      <link href="http://self-issued.info/?feed=atom" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Musings on Digital Identity</subtitle>
      <title xml:lang="en-US">Mike Jones: self-issued</title>
      <updated>2013-05-15T23:22:30Z</updated>
    </source>
  <feedburner:origLink>http://self-issued.info/?p=1021</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/advisorynote_bigdatasmartdata70750140513</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/D2-F307cXQE/advisorynote_bigdatasmartdata70750140513" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Advisory Note: From Big Data to Smart Information - 70750</title>
    
    <updated>2013-05-14T15:21:48Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Big Data is characterized by three properties: there is now an enormous quantity of data which exists in a wide variety of forms and is being generated very quickly. However, the term “Big Data” is as much a reflection of the limitations of the current technology as it is a statement on the quantity, speed or variety of data. The term Big Data needs to be understood as data which has greater quantity, variety or speed than can be comfortably processed using the technology that...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/advisorynote_bigdatasmartdata70750140513"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/D2-F307cXQE" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=D2-F307cXQE:SyhgiQM6onk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=D2-F307cXQE:SyhgiQM6onk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=D2-F307cXQE:SyhgiQM6onk:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=D2-F307cXQE:SyhgiQM6onk:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/D2-F307cXQE" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/advisorynote_bigdatasmartdata70750140513</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/executiveview_stewardship7074414052013</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/_-iKdkxOEPY/executiveview_stewardship7074414052013" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Executive View: Big Data and Information Stewardship - 70744</title>
    
    <updated>2013-05-14T12:23:11Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Big Data provides many opportunities to solve emerging business challenges and Big Data technologies can create business value. However Big Data also creates security challenges that need to be considered by organizations adopting or using Big Data techniques and technologies. This paper outlines the information security risks involved in Big Data and recommends the responses to these based on the concepts of information stewardship and information centric security...&lt;/p&gt;&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/executiveview_stewardship7074414052013"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/_-iKdkxOEPY" width="1"&gt;&lt;/img&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_-iKdkxOEPY:C62jV6Rel6Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_-iKdkxOEPY:C62jV6Rel6Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=_-iKdkxOEPY:C62jV6Rel6Q:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=_-iKdkxOEPY:C62jV6Rel6Q:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/_-iKdkxOEPY" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/executiveview_stewardship7074414052013</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/advisorynote_lidmanagementcontrol70745140513</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/zUDyGkfiqHk/advisorynote_lidmanagementcontrol70745140513" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Advisory Note: Life Management Platforms: Control and Privacy for Personal Data - 70745</title>
    
    <updated>2013-05-14T12:19:15Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Life Management Platforms will change the way individuals deal with sensitive information like their health data, insurance data, and many other types of information – information that today frequently is paper-based or, when it comes to personal opinions, only in the mind of the individuals. They will enable new approaches for privacy and security-aware sharing of that information, without the risk of losing control of that information. A key concept is “informed pull”...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/advisorynote_lidmanagementcontrol70745140513"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/zUDyGkfiqHk" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zUDyGkfiqHk:0F0ZEROW0Do:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zUDyGkfiqHk:0F0ZEROW0Do:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zUDyGkfiqHk:0F0ZEROW0Do:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=zUDyGkfiqHk:0F0ZEROW0Do:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/zUDyGkfiqHk" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/advisorynote_lidmanagementcontrol70745140513</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://blog.bavoderidder.com/?p=424</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/MmI-3464LtU/" rel="alternate" type="text/html" />
    <title>Bavo De Ridder: Conceptual, Logical and Physical</title>
    <summary type="html">In his article “ArchiMate from a data modelling perspective” Bas van Gils from BiZZdesign talks about the difference between conceptual, logical and physical levels of abstraction. This distinction is very often used in (enterprise) IT architecture but is often also poorly understood, defined or applied. Bas refers to the TOGAF/IAF definitions: TOGAF seems to follow [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;In his article “&lt;a href="http://www.bizzdesign.com/blog/archimate-from-a-data-modelling-perspective/"&gt;ArchiMate from a data modelling perspective&lt;/a&gt;” &lt;a href="https://twitter.com/basvg"&gt;Bas van Gils&lt;/a&gt; from &lt;a href="http://www.bizzdesign.com/"&gt;BiZZdesign&lt;/a&gt; talks about the difference between conceptual, logical and physical levels of abstraction. This distinction is very often used in (enterprise) IT architecture but is often also poorly understood, defined or applied.&lt;/p&gt;&#xD;
&lt;p&gt;Bas refers to the TOGAF/IAF definitions:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;TOGAF seems to follow the interpretation close to Capgemini’s IAF where conceptual is about “what”, logical is about “how” and physical is about “with what”. In that case, conceptual/logical appears to map on the architecture level, whereas physical seems to map on the design/ implementation level. All three are somewhat in line but in practice we still see people mix-and-match between abstraction levels.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&#xD;
&lt;p&gt;I am not a fan of the above. It is one of those definitions that tries to explain a concept by using specific words in the hope to evoke a shared emotion. Needless to say, this type of definition is at the heart of many open ended and often very emotional online discussions.&lt;/p&gt;&#xD;
&lt;p&gt;Conceptual, logical and physical are most often related to the idealization – realization spectrum of abstraction. This spectrum abstracts ‘things’ by removing elements relating to the realization of the ‘thing’. Opposite, the spectrum elaborates ‘things’ by adding elements related to a specific realization. You can say that a conceptual model contains less elements related to a realization compared to a logical model. You can also say that a physical model contains more elements related to a realization when compared to a logical model.&lt;/p&gt;&#xD;
&lt;p&gt;In other words, conceptual, logical and physical are relative to each other. They don’t point to a specific abstraction. For that you need to specify more information on exactly what kind of elements of realizations you want to abstract away at each level of abstraction.&lt;/p&gt;&#xD;
&lt;p&gt;The most commonly used reference model for using these three levels is as follows:&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;&lt;strong&gt;Conceptual&lt;/strong&gt;. All elements related to an implementation with an Information System are abstracted away.&lt;/li&gt;&#xD;
&lt;li&gt;&lt;strong&gt;Logical&lt;/strong&gt;. A realization with an Information System is not abstracted away anymore. All elements related to a technical implementation of this Information System are abstracted away.&lt;/li&gt;&#xD;
&lt;li&gt;&lt;strong&gt;Physical&lt;/strong&gt;. A technical realization is assumed and not abstracted away anymore.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;That is the only way to define the levels conceptual, logical and physical: define what type of realization-related elements are abstracted away at each level. You can never assume everyone uses the same reference model. You either pick an existing one (e.g. &lt;a href="http://en.wikipedia.org/wiki/Zachman_Framework"&gt;Zachman Framework&lt;/a&gt;) or define your own.&lt;/p&gt;&#xD;
&lt;p&gt;Saying that conceptual is “what”, logical is “how” and physical is “with what” is confusing to say the least. Especially if you know that in the Zachman Framework “how” and “what” are even orthogonal to “conceptual” and “logical”.&lt;/p&gt;&#xD;
&lt;p&gt;At first it is not easy to define a conceptual model without referring to an Information System. For instance any referral to lists, reports or querying assumes an Information System and is in fact already at the logical model.&lt;/p&gt;&#xD;
&lt;p&gt;A misunderstanding I often hear is that people assume that conceptual means (a lot) less detail compared to logical. That’s not true. A conceptual model can consist of as many models and pages of text as a logical model. In reality, conceptual models are often more limited but I only have to point to the many failed IT projects due to too little detail at the conceptual model. It’s just wrong.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=MmI-3464LtU:sPhNC9ZSmjs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=MmI-3464LtU:sPhNC9ZSmjs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=MmI-3464LtU:sPhNC9ZSmjs:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=MmI-3464LtU:sPhNC9ZSmjs:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/MmI-3464LtU" height="1" width="1"/&gt;</content>
    <updated>2013-05-14T11:40:23Z</updated>
    <category term="Architecture" />
    <author>
      <name>Bavo De Ridder</name>
    </author>
    <source>
      <id>http://blog.bavoderidder.com</id>
      <link href="http://blog.bavoderidder.com/?feed=rss2" rel="self" type="application/atom+xml" />
      <link href="http://blog.bavoderidder.com" rel="alternate" type="text/html" />
      <subtitle>Bavo De Ridder's blog: software architecture, software engineering, security and anything else worthwhile.</subtitle>
      <title>Ruminations on Architecture and Security</title>
      <updated>2013-05-16T19:33:03Z</updated>
    </source>
  <feedburner:origLink>http://blog.bavoderidder.com/?p=424</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.discoveringidentity.com/?p=3677</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/dW3EfQf56fo/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Oracle: Google or Giggle?</title>
    <summary type="html">Which type of glasses do you prefer?</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Which type of glasses do you prefer?&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.gocomics.com/frankandernest/2013/05/14" target="blank"&gt;&lt;img alt="Frankandearnest 130514" border="0" height="175" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/frankandearnest-130514.png" style="display: block; margin-left: auto; margin-right: auto;" title="frankandearnest-130514.png" width="580"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dW3EfQf56fo:d3dNfcyzFpA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dW3EfQf56fo:d3dNfcyzFpA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dW3EfQf56fo:d3dNfcyzFpA:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=dW3EfQf56fo:d3dNfcyzFpA:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/dW3EfQf56fo" height="1" width="1"/&gt;</content>
    <updated>2013-05-14T11:30:23Z</updated>
    <category term="Humor" />
    <category term="Social Media" />
    <category term="Frank and Ernest" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Exploring the science and magic of Identity and Access Management</subtitle>
      <title>Discovering Identity</title>
      <updated>2013-05-22T15:02:14Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2013/05/14/google-or-giggle/</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.discoveringidentity.com/?p=3675</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/MAyb1AHxHyY/" rel="alternate" type="text/html" />
    <title>Mark Dixon - Oracle: All in a Day’s Work – In Orbit</title>
    <summary type="html">I love this photo of Chris Cassidy, one of our great NASA astronauts, at work.     The NASA web site explains: Repairing the Station in Orbit Expedition 35 Flight Engineers Chris Cassidy (pictured) and Tom Marshburn (out of frame) completed a spacewalk at 2:14 p.m. EDT May 11, 2013 to inspect and replace a pump controller box on the [...]</summary>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;I love this photo of &lt;a href="http://en.wikipedia.org/wiki/Christopher_Cassidy" target="blank"&gt;Chris Cassidy&lt;/a&gt;, one of our &lt;a href="http://www.jsc.nasa.gov/Bios/" target="blank"&gt;great NASA astronauts&lt;/a&gt;, at work.  &lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.nasa.gov/multimedia/imagegallery/image_feature_2507.html" target="blank"&gt;&lt;img alt="Astronaut" border="0" height="512" src="http://www.discoveringidentity.com/wp-content/uploads/2013/05/astronaut.jpg" style="display: block; margin-left: auto; margin-right: auto;" title="astronaut.jpg" width="580"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p&gt; &lt;/p&gt;&#xD;
&lt;p&gt;The &lt;a href="http://www.nasa.gov/multimedia/imagegallery/image_feature_2507.html" target="blank"&gt;NASA web site&lt;/a&gt; explains:&lt;/p&gt;&#xD;
&lt;blockquote&gt;&#xD;
&lt;p&gt;Repairing the Station in Orbit Expedition 35 Flight Engineers Chris Cassidy (pictured) and Tom Marshburn (out of frame) completed a spacewalk at 2:14 p.m. EDT May 11, 2013 to inspect and replace a pump controller box on the International Space Station’s far port truss (P6) leaking ammonia coolant. The two NASA astronauts began the 5-hour, 30-minute spacewalk at 8:44 a.m.&lt;/p&gt;&#xD;
&lt;p&gt;A leak of ammonia coolant from the area near or at the location of a Pump and Flow Control Subassembly was detected on Thursday, May 9, prompting engineers and flight controllers to begin plans to support the spacewalk. The device contains the mechanical systems that drive the cooling functions for the port truss.&lt;/p&gt;&#xD;
&lt;/blockquote&gt;&#xD;
&lt;p&gt;What a thrill it must be for these guys!&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=MAyb1AHxHyY:KcL5ZOKd3qE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=MAyb1AHxHyY:KcL5ZOKd3qE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=MAyb1AHxHyY:KcL5ZOKd3qE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=MAyb1AHxHyY:KcL5ZOKd3qE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/MAyb1AHxHyY" height="1" width="1"/&gt;</content>
    <updated>2013-05-14T02:32:11Z</updated>
    <category term="Space Travel" />
    <category term="Astronaut" />
    <category term="Space" />
    <author>
      <name>Mark Dixon</name>
    </author>
    <source>
      <id>http://www.discoveringidentity.com</id>
      <link href="http://www.discoveringidentity.com/feed/" rel="self" type="application/atom+xml" />
      <link href="http://www.discoveringidentity.com" rel="alternate" type="text/html" />
      <subtitle>Exploring the science and magic of Identity and Access Management</subtitle>
      <title>Discovering Identity</title>
      <updated>2013-05-22T15:02:14Z</updated>
    </source>
  <feedburner:origLink>http://www.discoveringidentity.com/2013/05/13/all-in-a-days-work-in-orbit/</feedburner:origLink></entry>

  <entry xml:lang="en-US">
    <id>http://www.xmlgrrl.com/blog/?p=3009</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/ZpYlAlcMsyo/" rel="alternate" type="text/html" />
    <link href="http://www.xmlgrrl.com/blog/2013/05/13/new-modern-authorization-systems-and-xacml/#comments" rel="replies" type="text/html" />
    <link href="http://www.xmlgrrl.com/blog/2013/05/13/new-modern-authorization-systems-and-xacml/feed/atom/" rel="replies" type="application/atom+xml" />
    <title xml:lang="en-US">Eve Maler: New: Modern authorization systems and XACML</title>
    <summary type="html" xml:lang="en-US">&lt;p&gt;Over on the Forrester blogs, I &lt;a href="http://blogs.forrester.com/eve_maler/13-05-13-the_mobile_cloud_axis_needs_a_modern_authorization_system_xacml_3_isnt_it"&gt;take a look&lt;/a&gt; at XACML, advocating that it needs to refactor heavily to meet mobile/cloud authorization policy needs. &lt;a href="http://kantarainitiative.org/confluence/display/uma/Case+Study%3A+Access+Management+2.0+for+the+Enterprise"&gt;UMA&lt;/a&gt; as a potential enterprise “access management 2.0″ solution makes an appearance as well. Quoting the post: “Would an XACML.next that concentrates on ‘growing the pie’ for declarative authorization policy be valuable? Would an integration of web and post-web access management help you achieve your goals?” If you have thoughts on this, check out the post  […]&lt;br&gt; &lt;a class="read_more" href="http://www.xmlgrrl.com/blog/2013/05/13/new-modern-authorization-systems-and-xacml/"&gt;Read more&lt;/a&gt;&lt;/p&gt;</summary>
    <content type="html" xml:lang="en-US">&lt;p&gt;Over on the Forrester blogs, I &lt;a href="http://blogs.forrester.com/eve_maler/13-05-13-the_mobile_cloud_axis_needs_a_modern_authorization_system_xacml_3_isnt_it"&gt;take a look&lt;/a&gt; at XACML, advocating that it needs to refactor heavily to meet mobile/cloud authorization policy needs. &lt;a href="http://kantarainitiative.org/confluence/display/uma/Case+Study%3A+Access+Management+2.0+for+the+Enterprise"&gt;UMA&lt;/a&gt; as a potential enterprise “access management 2.0″ solution makes an appearance as well. Quoting the post: “Would an XACML.next that concentrates on ‘growing the pie’ for declarative authorization policy be valuable? Would an integration of web and post-web access management help you achieve your goals?” If you have thoughts on this, check out the post and let me know…&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ZpYlAlcMsyo:g3wUZDzS9ac:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ZpYlAlcMsyo:g3wUZDzS9ac:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=ZpYlAlcMsyo:g3wUZDzS9ac:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=ZpYlAlcMsyo:g3wUZDzS9ac:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/ZpYlAlcMsyo" height="1" width="1"/&gt;</content>
    <updated>2013-05-13T23:53:26Z</updated>
    <published>2013-05-13T23:53:26Z</published>
    <category scheme="http://www.xmlgrrl.com/blog" term="Forrester" />
    <category scheme="http://www.xmlgrrl.com/blog" term="ProtectServe" />
    <category scheme="http://www.xmlgrrl.com/blog" term="Security/identity" />
    <category scheme="http://www.xmlgrrl.com/blog" term="XML" />
    <category scheme="http://www.xmlgrrl.com/blog" term="UMA" />
    <category scheme="http://www.xmlgrrl.com/blog" term="XACML" />
    <author>
      <name>Eve</name>
      <uri>http://www.xmlgrrl.com</uri>
    </author>
    <source>
      <id>http://www.xmlgrrl.com/blog/feed/atom/</id>
      <link href="http://www.xmlgrrl.com/blog" rel="alternate" type="text/html" />
      <link href="http://www.xmlgrrl.com/blog/feed/atom/" rel="self" type="application/atom+xml" />
      <subtitle xml:lang="en-US">Tangled musings on identity, privacy, trust, and suchlike</subtitle>
      <title xml:lang="en-US">Pushing String</title>
      <updated>2013-05-13T23:53:26Z</updated>
    </source>
  <feedburner:origLink>http://www.xmlgrrl.com/blog/2013/05/13/new-modern-authorization-systems-and-xacml/</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/trendreports_2013_2014iam_iag70782130513</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/3nCm1dL73Hg/trendreports_2013_2014iam_iag70782130513" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Advisory Note: Top Trends 2013-2014 IAM/IAG, Cloud, Privacy - 70782</title>
    
    <updated>2013-05-13T20:14:48Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;As in the past years, KuppingerCole has worked out the Top Trends in IAM/IAG (Identity and Access Management/Governance), Cloud Computing, and Information Protection and Privacy. The most important trends are the massive increase in demand for support of the “Extended Enterprise” in IAM/IAG, the cloud stratification in various layers, increasing threats imposed by the rise of cybercrime, and the emergence of Life Management Platforms. In the following sections, we name the five...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/trendreports_2013_2014iam_iag70782130513"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/3nCm1dL73Hg" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3nCm1dL73Hg:vpaA0g8jUFU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3nCm1dL73Hg:vpaA0g8jUFU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=3nCm1dL73Hg:vpaA0g8jUFU:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=3nCm1dL73Hg:vpaA0g8jUFU:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/3nCm1dL73Hg" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/trendreports_2013_2014iam_iag70782130513</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/advisoryreportiam_iag707491352013</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/zPX0fNedWFw/advisoryreportiam_iag707491352013" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Advisory Note: Typical Risks and Pitfalls for IAM and IAG projects - 70749</title>
    
    <updated>2013-05-13T20:10:17Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Identity and Access Management (IAM) is a holistic approach to managing identities (both internal and external) and their access within an organisational framework. The key benefit to the business should be to enable people to do their jobs more effectively. If deployed correctly, IAM can help achieve this in a multitude of different ways for different departments and roles within them; internal staff and external partners and customers. However, this also makes it a complex issue which...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/advisoryreportiam_iag707491352013"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/zPX0fNedWFw" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zPX0fNedWFw:4-xPFMmfjHE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zPX0fNedWFw:4-xPFMmfjHE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=zPX0fNedWFw:4-xPFMmfjHE:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=zPX0fNedWFw:4-xPFMmfjHE:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/zPX0fNedWFw" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/advisoryreportiam_iag707491352013</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>8d07cc69-a460-48f1-844d-25b05ba87317:10574</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/glFbzdZ27IA/identity-centric-security.aspx" rel="alternate" type="text/html" />
    <title>CA on Security Management: Identity-centric Security</title>
    
    <updated>2013-05-13T14:20:00Z</updated>
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/advanced+authentication/default.aspx" term="advanced authentication" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/authentication/default.aspx" term="authentication" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Cloud+Security/default.aspx" term="Cloud Security" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Identity+Management/default.aspx" term="Identity Management" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/SaaS+Security/default.aspx" term="SaaS Security" />
    <category scheme="http://community.ca.com/blogs/iam/archive/tags/Security/default.aspx" term="Security" /><feedburner:origlink>http://community.ca.com/blogs/iam/archive/2013/05/13/identity-centric-security.aspx</feedburner:origlink>
    <author>
      <name>Sumner Blount</name>
    </author>
    <source>
      <id>http://community.ca.com/blogs/iam/default.aspx</id>
      <logo>http://www.ca.com/images/global/logo_172900.gif</logo>
      <link href="http://community.ca.com/blogs/iam/default.aspx" rel="alternate" type="text/html" />
      <link href="http://feeds.ca.com/CS_CAIAMBlog" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>Insight and opinion on the world of security management. Visit often for commentary on security industry issues around identity and access management, data protection, advanced authentication, single sign-on and access management, cloud security and more.</subtitle>
      <title>Security Management</title>
      <updated>2013-05-15T16:02:18Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;The “good old days” are gone forever.  &#xD;
&#xD;
Those were the days when IT environments were more predictable and easier to control. The user population and their access patterns were more easily defined. Stick a firewall in front of key systems, create some controls around who can access what, and you’re done. &#xD;
&#xD;
The world is far different now. The headlong march towards the cloud has made the...&lt;br&gt;&#xD;
&lt;br&gt;&#xD;
 &lt;img height="1" src="http://feeds.feedburner.com/~r/CS_CAIAMBlog/~4/bW3sWCOVGg8" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=glFbzdZ27IA:oPs_Emrvqc8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=glFbzdZ27IA:oPs_Emrvqc8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=glFbzdZ27IA:oPs_Emrvqc8:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=glFbzdZ27IA:oPs_Emrvqc8:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/glFbzdZ27IA" height="1" width="1"/&gt;</content><feedburner:origLink>http://feeds.ca.com/~r/CS_CAIAMBlog/~3/bW3sWCOVGg8/identity-centric-security.aspx</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://blogs.forrester.com/9260 at http://blogs.forrester.com</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/VG30jMyZc6Q/13-05-13-the_mobile_cloud_axis_needs_a_modern_authorization_system_xacml_3_isnt_it" rel="alternate" type="text/html" />
    <title>Eve Maler - Forrester: The Mobile-Cloud Axis Needs A Modern Authorization System. XACML 3 Isn’t It</title>
    
    <updated>2013-05-13T13:48:27Z</updated>
    <category scheme="http://blogs.forrester.com/category/oauth" term="OAuth" />
    <category scheme="http://blogs.forrester.com/security_and_risk" term="Security and Risk" />
    <category scheme="http://blogs.forrester.com/category/uma" term="UMA" />
    <category scheme="http://blogs.forrester.com/category/xacml" term="XACML" />
    <category scheme="http://blogs.forrester.com/category/access_control" term="access control" />
    <category scheme="http://blogs.forrester.com/category/authorization" term="authorization" />
    <author>
      <name>Eve Maler</name>
    </author>
    <source>
      <id>http://blogs.forrester.com/eve_maler</id>
      <link href="http://blogs.forrester.com/eve_maler" rel="alternate" type="text/html" />
      <link href="http://blogs.forrester.com/eve_maler/feed" rel="self" type="application/rss+xml" />
      <title>Eve Maler's blog</title>
      <updated>2013-05-22T15:02:25Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://blogs.forrester.com/andras_cser"&gt;Andras Cser&lt;/a&gt; probed a sore spot in IAM last week with his post, "&lt;a href="http://blogs.forrester.com/andras_cser/13-05-07-xacml_is_dead"&gt;XACML Is Dead.&lt;/a&gt;" It's a necessary conversation (though I did see a glint in his eye at the &lt;a href="http://www.forrester.com/marketing/events/bt-forum-2013-in-review.html"&gt;Forrester BT Forum&lt;/a&gt; after he pressed Publish!). Our Q3 2012 Identity Standards &lt;a href="http://www.forrester.com/TechRadar+For+Security+Pros+Zero+Trust+Identity+Standards+Q3+2012/fulltext/-/E-RES80522"&gt;TechRadar&lt;/a&gt; showed that &lt;strong&gt;XACML has already crested the peak of its moderate success trajectory&lt;/strong&gt;, heading for decline. We haven't seen its business value-add or ecosystem grow since then, despite the publication of XACML 3.0 and a few other bright spots, such as Axiomatics' recent &lt;a href="http://axiomatics.com/news/175-leading-independent-authorization-solution-provider-axiomatics,-secures-$6-5-million-funding.html"&gt;funding round&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;It's not that we &lt;em&gt;don't&lt;/em&gt; need an interoperable solution for finer-grained access control. But the world's demands for loosely coupled identity and access systems have gotten...well, more demanding. &lt;strong&gt;The solution needs to be friendly&lt;/strong&gt; to open web API security and management. It needs to be friendly to mobile developers. And it most certainly needs to be prepared to tackle the hard parts of integrating authorization with truly heterogeneous cloud services and applications, where business partners aren't just enterprise clones, but may be tiny and resource-strapped. This admittedly gets into business rather than technical challenges, but &lt;strong&gt;every ounce of technical friction makes success in the business realm less likely.&lt;/strong&gt;&lt;/p&gt;&lt;a class="node_read_more" href="http://blogs.forrester.com/eve_maler/13-05-13-the_mobile_cloud_axis_needs_a_modern_authorization_system_xacml_3_isnt_it" title="Read the rest of 'The Mobile-Cloud Axis Needs A Modern Authorization System. XACML 3 Isn’t It'."&gt;Read more&lt;/a&gt;&lt;div class="categories"&gt;&lt;h3&gt;Categories:&lt;/h3&gt;&lt;ul class="links"&gt;&lt;li class="taxonomy_term_9566 first"&gt;&lt;a alt="See other content with this tag." href="http://blogs.forrester.com/category/oauth" rel="tag" title="See other content with this tag."&gt;OAuth&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;li class="taxonomy_term_10509"&gt;&lt;a alt="See other content with this tag." href="http://blogs.forrester.com/category/uma" rel="tag" title="See other content with this tag."&gt;UMA&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;li class="taxonomy_term_10510"&gt;&lt;a alt="See other content with this tag." href="http://blogs.forrester.com/category/xacml" rel="tag" title="See other content with this tag."&gt;XACML&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;li class="taxonomy_term_10508"&gt;&lt;a alt="See other content with this tag." href="http://blogs.forrester.com/category/access_control" rel="tag" title="See other content with this tag."&gt;access control&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;li class="taxonomy_term_10507 last"&gt;&lt;a alt="See other content with this tag." href="http://blogs.forrester.com/category/authorization" rel="tag" title="See other content with this tag."&gt;authorization&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VG30jMyZc6Q:O29OhVXUYto:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VG30jMyZc6Q:O29OhVXUYto:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=VG30jMyZc6Q:O29OhVXUYto:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=VG30jMyZc6Q:O29OhVXUYto:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/VG30jMyZc6Q" height="1" width="1"/&gt;</content><feedburner:origLink>http://blogs.forrester.com/eve_maler/13-05-13-the_mobile_cloud_axis_needs_a_modern_authorization_system_xacml_3_isnt_it?cm_mmc=RSS-_-BT-_-59-_-blog_2681</feedburner:origLink></entry>

  <entry>
    <id>http://blogs.kuppingercole.com/kuppinger/2013/05/13/another-dead-body-in-it-or-is-xacml-still-alive/</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/y0uWCv8JGek/" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Another dead body in IT? Or is XACML still alive?</title>
    
    <updated>2013-05-13T10:48:46Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:06Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt; &lt;br&gt;&lt;br&gt;&lt;p&gt;Since my colleague Craig Burton has declared that &lt;a href="http://blogs.kuppingercole.com/burton/2012/09/19/saml-is-dead-long-live-saml/"&gt;SAML is dead&lt;/a&gt;, it seems to be in vogue among analysts to take the role of the public medical officer and to diagnose the death of standards or even &lt;a href="http://blogs.kuppingercole.com/kuppinger/2013/02/28/do-we-need-to-kill-iam-to-save-it/"&gt;IAM&lt;/a&gt; (Identity and Access Management) in general. Admittedly, the latter case was not about diagnosing the death but proposing to kill IAM, but that does not change much. The newest in this series of dead bodies is XACML, &lt;a href="http://blogs.forrester.com/andras_cser/13-05-07-xacml_is_dead"&gt;according to another Industry Analyst&lt;/a&gt;. So we are surrounded by dead corpses now, or maybe by living zombies. But is that really true? My colleague Craig Burton titled his blog – for a very good reason – “SAML is Dead! Long Live SAML!” That is fundamentally different from saying “XACML is dead”.&lt;/p&gt;&#xD;
&lt;p&gt;There are a lot of good answers from experts such as &lt;a href="http://blogs.gartner.com/ian-glazer/2013/05/09/anyone-can-kill-off-a-protocol-a-k-a-xacml-isnt-dead/"&gt;Ian Glazer&lt;/a&gt;, &lt;a href="http://analyzingidentity.com/2013/05/08/xacml-alive-and-well/"&gt;Gerry Gebel&lt;/a&gt; (OK, he might be a little biased being the President of Axiomatics Americas), or &lt;a href="http://dannythorpe.com/2013/05/08/xacml-is-dead-long-live-xacml/"&gt;Danny Thorpe&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;I am clearly not suspicious being the enthusiastic XACML evangelist wearing blinders. Just ask some of the Axiomatics guys – we had many controversial discussions over the years. However, for me it is clear that neither Dynamic Authorization Management in general nor XACML in particular are dead.&lt;/p&gt;&#xD;
&lt;p&gt;What puzzled me most in this blog post was that part of the initial sentence:&lt;/p&gt;&#xD;
&lt;p&gt;&lt;i&gt;XACML … is largely dead or will be transformed into access control&lt;/i&gt;&lt;/p&gt;&#xD;
&lt;p&gt;OK, “access control”. XACML is access control. Access control is everything around authentication and authorization. So what does this mean? I just do not understand that sentence, sorry. XACML is a part of the overall Access Control story.&lt;/p&gt;&#xD;
&lt;p&gt;From my perspective, the two most important concepts within access control are Dynamic Authorization Management and &lt;a href="http://blogs.kuppingercole.com/kearns/2013/05/07/when-three-as-are-better-than-four/"&gt;Risk-/Context-Based Access Control&lt;/a&gt; (i.e. both Authentication and Authorization). The latter only will work with Dynamic Authorization Management in place. When we know about the context and the risk and make authorization decisions based on that, then we need systems that externalize authorization and rely on rules that can take the context into account.&lt;/p&gt;&#xD;
&lt;p&gt;The challenge with Dynamic Authorization Management, i.e. technologies implemented in a variety of products such as the Axiomatics Policy Server, the Oracle Entitlements Server, the IBM Security Policy Manager, Quest APS, and many others, is that it requires changes in both application code and the mindset of software developers and architects. That is a long journey. On the other hand we see some increase in acceptance and use of such technologies. Notably, Dynamic Authorization Management is not new. You will find such concepts dating back to the mid ‘70s in mainframe environments, and IBM’s good old RACF can be consider an early example for that.&lt;/p&gt;&#xD;
&lt;p&gt;You still can argue that Dynamic Authorization Management is alive but XACML as the most important standard around it is dead. There are good arguments against that, and I will not repeat what the others mentioned above have said. You might discuss where to use XACML and where to rely on proprietary technology. However, do you really want to lock in your entire application landscape into a proprietary Dynamic Authorization Management technology of a single vendor? That would be a nightmare. You need to isolate your applications from the Dynamic Authorization Management system in use, and a standard helps in doing that. Just think about being locked into proprietary interfaces for all of your applications using a specific Dynamic Authorization Management system for the next 30, 40 or more years.&lt;/p&gt;&#xD;
&lt;p&gt;XACML even is the better choice for COTS applications. They can rely on a standard, instead of every vendor building proprietary connectors. Most vendors will do that for Microsoft SharePoint, because SharePoint is so important. But that is the exception, not the rule. And deducing from the fact that vendors support SharePoint with proprietary interfaces (instead of using XACML) that XACML is dead is just a wrong deduction. The problem in that case is not XACML but the SharePoint security model that clearly is not the best I have ever seen (to say the least). XACML is of value. Standards are of value. And I believe you would need much better reasons to diagnose the death of standards.&lt;/p&gt;&#xD;
&lt;p&gt;To learn more about the real trends in IAM, IAG, Cloud Security, and many other topics, just visit the &lt;a href="http://www.id-conf.com/"&gt;EIC 2013&lt;/a&gt; that starts on Tuesday, May 14&lt;sup&gt;th&lt;/sup&gt;.&lt;/p&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/y0uWCv8JGek" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=y0uWCv8JGek:erj10p-_Fcw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=y0uWCv8JGek:erj10p-_Fcw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=y0uWCv8JGek:erj10p-_Fcw:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=y0uWCv8JGek:erj10p-_Fcw:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/y0uWCv8JGek" height="1" width="1"/&gt;</content><feedburner:origLink>http://blogs.kuppingercole.com/kuppinger/2013/05/13/another-dead-body-in-it-or-is-xacml-still-alive/</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/advisorynote_cloudprovideselect7074213513</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/w1YKEzCWtX0/advisorynote_cloudprovideselect7074213513" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Advisory Note: Selecting your cloud provider - 70742</title>
    
    <updated>2013-05-13T06:58:46Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:07Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;The ready availability of cloud services has made it easy for employees and associates to obtain and use these services without consideration of the potential impact on the organization. Therefore, in order to ensure good governance over the use of cloud services, it is imperative that organizations create and communicate a policy for their acquisition and use. This should be supported by a simple, fast and reliable risk based process for cloud service procurement and complemented by...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/advisorynote_cloudprovideselect7074213513"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/w1YKEzCWtX0" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=w1YKEzCWtX0:hwePVcNyoY8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=w1YKEzCWtX0:hwePVcNyoY8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=w1YKEzCWtX0:hwePVcNyoY8:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=w1YKEzCWtX0:hwePVcNyoY8:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/w1YKEzCWtX0" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/advisorynote_cloudprovideselect7074213513</feedburner:origLink></entry>

  <entry>
    <id>http://www.kuppingercole.com/report/advisorynotematuritylevel707381352013</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/fU2MZrUXY-4/advisorynotematuritylevel707381352013" rel="alternate" type="text/html" />
    <title>Kuppinger Cole: Advisory Note: Maturity Level Matrixes for Identity and Access  - 70738</title>
    
    <updated>2013-05-13T06:53:19Z</updated>
    <source>
      <id>http://www.kuppingercole.com</id>
      <author>
        <name>Kuppinger Cole</name>
      </author>
      <link href="http://www.kuppingercole.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/kuppingercole" rel="self" type="application/rss+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>KuppingerCole News</subtitle>
      <title>KuppingerCole</title>
      <updated>2013-05-22T15:03:07Z</updated>
    </source>
  <content type="html">In &lt;a href="http://www.kuppingercole.com"&gt;KuppingerCole&lt;/a&gt; &lt;br&gt;&lt;br&gt; &lt;p&gt;Most large organizations and a significant number of medium-sized organizations have heavily invested in IAM (Identity and Access Management) and IAG (Identity and Access Governance) during the past few years. Some projects went well; others did not deliver as expected. But even organizations that run successful IAM/IAG projects are challenged by new evolutions, such as the increasing relevance of the “Computing Troika” of Cloud Computing, Mobile Computing, and Social Computing...&lt;br&gt;&lt;a href="http://www.kuppingercole.com/report/advisorynotematuritylevel707381352013"&gt;more&lt;/a&gt;&lt;img height="1" src="http://feeds.feedburner.com/~r/kuppingercole/~4/fU2MZrUXY-4" width="1"&gt;&lt;/img&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=fU2MZrUXY-4:p0EK0iDEXQs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=fU2MZrUXY-4:p0EK0iDEXQs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=fU2MZrUXY-4:p0EK0iDEXQs:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=fU2MZrUXY-4:p0EK0iDEXQs:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/fU2MZrUXY-4" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.kuppingercole.com/report/advisorynotematuritylevel707381352013</feedburner:origLink></entry>

  <entry>
    <id>http://blog.aniljohn.com/2013/05/how-to-visualize-access-control-use-cases</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/dDMVp255Tec/how-to-visualize-access-control-use-cases.html" rel="alternate" type="text/html" />
    <title>Anil John: HOW TO Visualize Access Control Use Cases</title>
    <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Identity, authentication, attribute management and authorization domain experts tend to seek clear distinctions between each of those facets. The operational folks who actually deal with these issues often blur the boundaries between them. This blog post shows an example of laying out access control use cases from an operational perspective that I found rather educational.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;With the current buzz around mobility and BYOD, there is sometimes a belief that the infrastructure and choices that exist today will have to be completely re-done in order to accommodate new devices. While I am not sure about that, I recently saw a public NASA ICAM presentation that outlined a framework for how to look at access control from an operational perspective that I found relevant.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;I've kept the concept, but changed some of the details for the sake of clarity:&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&lt;img class="scale-with-grid" src="http://blog.aniljohn.com/img/access_mgmt_requirements.png" style="display: block; margin-left: auto; margin-right: auto;"&gt;&lt;/img&gt;&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;The key to the above visualization is to know that no one does credentialing and authentication for its own sake but as a means to an end to manage access to a system or resource. From an operational perspective, it allows for calling out an end to end process using natural language; &lt;em&gt;"A person who is anonymous, using an organization managed PC, on the organization's network, wants to access administrator level functions during normal business hours"&lt;/em&gt;.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;You can then lay out the use case variations using a tabular format:&lt;/p&gt;&#xD;
&#xD;
&lt;table class="table table-bordered"&gt;&#xD;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Use Case&lt;/th&gt;&lt;th&gt;Applicability&lt;/th&gt;&lt;th&gt;Priority&lt;/th&gt;&lt;th&gt;Criteria A&lt;/th&gt;&lt;/tr&gt;&#xD;
&lt;tr&gt;&#xD;
&lt;td&gt;10.10.10.10.10&lt;/td&gt;&#xD;
&lt;td&gt;NO&lt;/td&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;/tr&gt;&#xD;
&lt;tr&gt;&#xD;
&lt;td&gt;30.10.10.10.10&lt;/td&gt;&#xD;
&lt;td&gt;YES&lt;/td&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;/tr&gt;&#xD;
&lt;tr&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;td&gt;...&lt;/td&gt;&#xD;
&lt;/tr&gt;&#xD;
&lt;/tbody&gt;&lt;/table&gt;&#xD;
&#xD;
&#xD;
&lt;p&gt;It immediately gives you a way to articulate possibilities that may or may not apply to you; &lt;em&gt;What if it was a Smartphone instead of the PC? What if the connection is from the Internet? etc.&lt;/em&gt; It also provides you insights into what aspects change, what aspects still remain the same.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;Do you have any pointers to frameworks like these that help to clarify choices people need to make regarding access controls?&lt;/p&gt;&#xD;
&lt;hr&gt;&lt;/hr&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;img height="1" src="http://feeds.feedburner.com/~r/AnilJohn/~4/jvpRDTfH5As" width="1"&gt;&lt;/img&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dDMVp255Tec:3DuUS9ct-Fo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dDMVp255Tec:3DuUS9ct-Fo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=dDMVp255Tec:3DuUS9ct-Fo:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=dDMVp255Tec:3DuUS9ct-Fo:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/dDMVp255Tec" height="1" width="1"/&gt;</content>
    <updated>2013-05-12T18:40:00Z</updated>
    <published>2013-05-12T18:40:00Z</published><feedburner:origlink>http://blog.aniljohn.com/2013/05/how-to-visualize-access-control-use-cases.html</feedburner:origlink>
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
    <source>
      <id>http://blog.aniljohn.com/</id>
      <icon>http://blog.aniljohn.com/img/favicon.ico</icon>
      <logo>http://lh4.googleusercontent.com/-bdzCv-OkbiM/UN3mPNGG7QI/AAAAAAAAAUk/iADZchWRUXc/s800/aniljohnblog.png</logo>
      <author>
        <name>Anil John</name>
        <email>noreply@aniljohn.com</email>
        <uri>http://www.aniljohn.com/</uri>
      </author>
      <link href="http://blog.aniljohn.com" rel="alternate" type="text/html" />
      <link href="http://feeds.feedburner.com/AnilJohn" rel="self" type="application/atom+xml" />
      <link href="http://pubsubhubbub.appspot.com/" rel="hub" type="text/html" />
      <subtitle>On Architecture, Digital Security, Privacy...</subtitle>
      <title>Anil John | Blog</title>
      <updated>2013-05-20T11:34:42Z</updated>
    </source>
  <feedburner:origLink>http://feedproxy.google.com/~r/AnilJohn/~3/jvpRDTfH5As/how-to-visualize-access-control-use-cases.html</feedburner:origLink></entry>

  <entry xml:lang="en">
    <id>http://www.voidstar.com/node.php?id=3565</id>
    <link href="http://feedproxy.google.com/~r/PlanetIdentity/~3/FRjVsVXgr4I/node.php" rel="alternate" type="text/html" />
    <title>Julian Bond: Read this and be inspired.</title>
    
    <updated>2013-05-10T19:54:00Z</updated>
    <category term="bicycles" />
    <source>
      <id>http://www.voidstar.com/module.php?mod=blog</id>
      <author>
        <name>Julian Bond</name>
      </author>
      <link href="http://www.voidstar.com/module.php?mod=blog" rel="alternate" type="text/html" />
      <link href="http://www.voidstar.com/module.php?mod=blog&amp;op=feed&amp;voidstar=62498a27d91d27f31507a91f1929033a" rel="self" type="application/rss+xml" />
      <rights>Kopyleft. All rights reversed. Public domain. Do what you like with it.</rights>
      <subtitle>Recently updated blogs.</subtitle>
      <title>Voidstar: blog</title>
      <updated>2013-05-22T15:03:19Z</updated>
    </source>
  <content type="html">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Read this and be inspired. &lt;a href="http://www.electricbike.com/dogmans-tale/"&gt;http://www.electricbike.com/dogmans-tale/&lt;/a&gt;&lt;hr&gt;&lt;/hr&gt;Dogman's Tale  »&lt;br&gt;&#xD;
When I started chatting on the internet, I wanted a screen name to protect my identity. So I chose Dogman because I am part dog, I speak dog fluently, and I have always had a pack of dogs around ...&lt;br&gt;&#xD;
&lt;br&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=FRjVsVXgr4I:8opsRlO7ny0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=FRjVsVXgr4I:8opsRlO7ny0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/PlanetIdentity?a=FRjVsVXgr4I:8opsRlO7ny0:I2FUP0JpNAM"&gt;&lt;img src="http://feeds.feedburner.com/~ff/PlanetIdentity?i=FRjVsVXgr4I:8opsRlO7ny0:I2FUP0JpNAM" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PlanetIdentity/~4/FRjVsVXgr4I" height="1" width="1"/&gt;</content><feedburner:origLink>http://www.voidstar.com/node.php?id=3565</feedburner:origLink></entry>
</feed>
