<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont)</title><link>http://www.communities.hp.com/online/blogs/mcm/default.aspx</link><description>Marco Casassa Mont’s “Research on Security and Identity Management” Blog. The focus of this blog is on trends, new technologies/solutions and innovative aspects of Security and Identity Management - in a variety of contexts. I am a researcher at HP Labs: I am very keen to explore and discuss technical and social aspects of Security and Identity Management that are going to affect individuals, enterprises and other organizations in the medium/long terms. What is the next big thing in this space?
</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/ResearchOnIdentityManagement" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>Security Trends Report by Microsoft and McAfee: Phishing Scams Relying More Heavily on Worms and Trojans</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/J3GYOinOCjc/118176.aspx</link><pubDate>Mon, 02 Nov 2009 18:04:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:118176</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118176.aspx#comments</comments><description>&lt;p&gt;Based on a recent &lt;a href="http://www.microsoft.com/security/portal/Threat/SIR.aspx"&gt;security trends report by Microsoft and MAfee&lt;/a&gt;, it looks like that social networks have been targeted with phishing scams and relying more heavily on worms and Trojans to attack computers. Rogue security software also remains a big issue.&lt;/p&gt;
&lt;p&gt;Some related articles on this topic can also be found &lt;a href="http://news.cnet.com/8301-27080_3-10387768-245.html?tag=newsEditorsPicksArea.0"&gt;here&lt;/a&gt; and &lt;a href="http://www.theregister.co.uk/2009/11/02/microsoft_security_report/"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=118176" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/J3GYOinOCjc" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/phishing+attacks/default.aspx">phishing attacks</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118176.aspx</feedburner:origLink></item><item><title>3rd PrivacyOS meeting</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/2lwOhDY0WPk/118175.aspx</link><pubDate>Mon, 02 Nov 2009 18:00:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:118175</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118175.aspx#comments</comments><description>&lt;p&gt;The 3&lt;sup&gt;rd&lt;/sup&gt; PrivacyOS meeting has taken place in Vienna, 26-27 October 2009.&lt;/p&gt;
&lt;p&gt;I attended, along with a few colleagues from HP Labs Bristol, the 3&lt;sup&gt;rd&lt;/sup&gt; PrivacyOS meeting, in Vienna. &lt;/p&gt;
&lt;p&gt;It has been a very interesting meeting, with presentations from various stakeholders of the privacy community and debates.&lt;/p&gt;
&lt;p&gt;A summary of presentations and related notes can be found &lt;a href="https://www.privacyos.eu/wiki/index.php/Main_Page"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=118175" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/2lwOhDY0WPk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/PrivacyOS/default.aspx">PrivacyOS</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118175.aspx</feedburner:origLink></item><item><title>Article - Malware is bound to hit smartphone devices as users do not consider security</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/L2q9x4V1Nrk/118174.aspx</link><pubDate>Mon, 02 Nov 2009 17:57:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:118174</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118174.aspx#comments</comments><description>&lt;p&gt;Interesting &lt;a href="http://www.scmagazineuk.com/Malware-is-bound-to-hit-smartphone-devices-as-users-do-not-consider-security/article/156858/"&gt;article&lt;/a&gt;, by Dan Raywood (called &amp;quot;Malware is bound to hit smartphone devices as users do not consider security&amp;quot;):&lt;/p&gt;
&lt;p&gt;&amp;quot;Smartphone attacks are likely to increase, as users are encouraged to take as much care with their device as with their PC. According to a report by CNN, smartphone security threats are likely to rise as the popularity of smartphones is on the rise and malware could be heading for them. ...&amp;quot;&lt;/p&gt;
&lt;p&gt;I believe this is a real threat.&amp;nbsp; At risk, among many, are business corporate executives and senior people relying in and using more and more smartphones as their core device for their communications, including handling emails and storing confidential data.&lt;/p&gt;
&lt;p&gt;I predict that more efforts (in terms of products, solutions, services) will be paid to address these issues, at least at a corporate level&amp;nbsp; ...&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=118174" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/L2q9x4V1Nrk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/smartphones/default.aspx">smartphones</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/malware/default.aspx">malware</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118174.aspx</feedburner:origLink></item><item><title>Update about TSB UK EnCoRe Project – Ensuring Consent and Revocation</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/ZxL7w3ks_9o/118173.aspx</link><pubDate>Mon, 02 Nov 2009 17:54:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:118173</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118173.aspx#comments</comments><description>&lt;p&gt;The 5&lt;sup&gt;th&lt;/sup&gt; Quarter Summary of EnCoRe (&lt;a href="http://www.encore-project.info/"&gt;http://www.encore-project.info&lt;/a&gt;) R&amp;amp;D activities in the space of Consent and Revocation management is now available online at: &lt;a href="http://www.encore-project.info/press_archive/Q5%20summary.pdf"&gt;http://www.encore-project.info/press_archive/Q5%20summary.pdf&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;In addition, a new &amp;quot;service&amp;quot; has been launched, about &amp;quot;Latest EnCoRe Tidbits&amp;quot; aiming at providing links to snippets of news related to consent and revocation: &lt;a href="http://www.encore-project.info/news.html#story1"&gt;http://www.encore-project.info/news.html#story1&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;More to come. Enjoy.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=118173" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/ZxL7w3ks_9o" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118173.aspx</feedburner:origLink></item><item><title>Research on Security and Identity Management   </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/DPO9q8S69S4/116411.aspx</link><pubDate>Fri, 09 Oct 2009 17:22:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:116411</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116411.aspx#comments</comments><description>&lt;p&gt;The time has come to update the topic (and focus) of this blog. &lt;/p&gt;
&lt;p&gt;In the last few years my R&amp;amp;D work and research at HP Labs has been involving a variety of aspects, including security, identity management and privacy.&lt;/p&gt;
&lt;p&gt;Most of my posts have actually been reflecting this - hence my decision to update my blog. Hope this will further increase the community of people that are interested and follow my blog.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=116411" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/DPO9q8S69S4" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/security/default.aspx">security</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116411.aspx</feedburner:origLink></item><item><title>New W3C PLING General Phone Call – 14 October 2009, 12:00 UTC    </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/isURfxaSyZo/116410.aspx</link><pubDate>Fri, 09 Oct 2009 17:20:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:116410</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116410.aspx#comments</comments><description>&lt;p&gt;The next W3C Policy Language Interest Group (PLING) general meeting is going to happen on October, 14&lt;sup&gt;th&lt;/sup&gt; - 12:00 UTC.&lt;/p&gt;
&lt;p&gt;Topics to be discussed include: (1) Best practices for privacy awareness; (2) web policy language working group proposal.&lt;/p&gt;
&lt;p&gt;Please consider attending.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=116410" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/isURfxaSyZo" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/W3C+PLING/default.aspx">W3C PLING</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116410.aspx</feedburner:origLink></item><item><title>Article – Phishing or not, leaked passwords show lazy habits  </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/v6E7ASl8LsQ/116409.aspx</link><pubDate>Fri, 09 Oct 2009 17:18:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:116409</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116409.aspx#comments</comments><description>&lt;p&gt;This article, called &lt;a href="http://news.cnet.com/8301-27080_3-10371499-245.html?tag=newsEditorsPicksArea.0"&gt;Phishing or not, leaked passwords show lazy habits&lt;/a&gt;, by Elinor Mills, is quite interesting.&lt;/p&gt;
&lt;p&gt;It is not a novelty the fact that there are bad practices when dealing with passwords - but it is also true that people are usually good at making risk assessments and judge which level of protection to choose, depending on the value of the asset to protect ...&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=116409" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/v6E7ASl8LsQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/password+phishing/default.aspx">password phishing</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116409.aspx</feedburner:origLink></item><item><title>3rd PrivacyOS Conference, Vienna, 25-27 October 2009  </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/caa4mAwQhVY/116047.aspx</link><pubDate>Mon, 28 Sep 2009 16:43:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:116047</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/29/116047.aspx#comments</comments><description>&lt;p&gt;The Third PrivacyOS conference is going to take place in Vienna, 25-27 October 2009:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.amiando.com/3rdprivacyos.html"&gt;http://www.amiando.com/3rdprivacyos.html&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;quot;The third PrivacyOS Conference focuses on &amp;quot;rising awareness - functions and impact of data protection&amp;quot;. &lt;/p&gt;
&lt;p&gt;Participants are invited to join the Austrian Big Brother Awards Gala on the evening of the 25&lt;sup&gt;th&lt;/sup&gt; of October and to discuss about privacy issues or their experiences in this field. The conference provides a unique opportunity to articulate and exchange best practices, challenges and solutions in privacy and data protection on the 26th and 27th of October. &lt;/p&gt;
&lt;p&gt;The conference primarily addresses legal and technical IT experts, interested manufacturers of IT products or services as well as data protection authorities. All persons interested in privacy or data protection aspects are welcome to register for the event. &amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=116047" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/caa4mAwQhVY" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/PrivacyOS/default.aspx">PrivacyOS</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/29/116047.aspx</feedburner:origLink></item><item><title>Workshop on Access Control (and Privacy) Application Scenarios </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/gY0ff4rh9tU/116046.aspx</link><pubDate>Mon, 28 Sep 2009 16:37:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:116046</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/29/116046.aspx#comments</comments><description>&lt;p&gt;Please consider submitting a position paper at the W3C Workshop on Access Control (and Privacy) Application Scenarios, by October 23&lt;sup&gt;rd&lt;/sup&gt;:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.w3.org/2009/policy-ws/cfp.html" title="http://www.w3.org/2009/policy-ws/cfp.html"&gt;http://www.w3.org/2009/policy-ws/cfp.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;W3C invites people to participate in a Workshop on Access Control Application Scenarios on 17-18 November 2009 in Luxembourg. This Workshop is intended to explore evolving application scenarios for access control technologies, such as XACML. Results from a number of recent European research projects in the grid, cloud computing, and privacy areas show overlapping use cases for these technologies that extend beyond classical intra-enterprise applications. The Workshop, co-financed by the European Commission 7th framework program via the PrimeLife project, is free of charge and open to anyone, subject to review of their statement of interest and space availability. &lt;/p&gt;
&lt;p&gt;The workshop is intended to discuss issues around access control in very wide sense, encompassing conditions and rules derived from the fact of accessing information. Topics that might serve as appropriate discussion points for position papers include, but are not limited to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;interaction between access control and privacy policies &lt;/li&gt;
&lt;li&gt;language extensions to connect access control languages to novel types of credentials &lt;/li&gt;
&lt;li&gt;large-scale cloud and grid computing use cases for access control technologies &lt;/li&gt;
&lt;li&gt;policy management &lt;/li&gt;
&lt;li&gt;mechanisms for controlling progressive disclosure of information by user agents and servers &lt;/li&gt;
&lt;li&gt;the emerging role of trust delegation and supportive mechanisms in cloud computing, grid, and Web use cases &lt;/li&gt;
&lt;li&gt;mechanisms for richer user control over downstream data controllers &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The workshop will examine experiences and recent research results in these areas, their need for agreed semantics, the need for extensions to existing access control languages, and perhaps for radically new approaches.&lt;/p&gt;
&lt;p&gt;Position papers are due 23 October. See the call for participation for more information.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; my original HP blog can be found &lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt;&amp;nbsp; ---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=116046" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/gY0ff4rh9tU" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/access+contol/default.aspx">access contol</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/29/116046.aspx</feedburner:origLink></item><item><title>Interesting article – “Phishing Fraud hits two year high” </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/A7ywtwh2aTk/116045.aspx</link><pubDate>Mon, 28 Sep 2009 16:34:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:116045</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/29/116045.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://www.theregister.co.uk/2009/09/28/phishing_fraud_trends/"&gt;http://www.theregister.co.uk/2009/09/28/phishing_fraud_trends/&lt;/a&gt; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;quot;Phishing attacks reached a record high during the second quarter of 2009, with 151,000 unique attacks, according to a study by brand reputation firm MarkMonitor. ...&amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=116045" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/A7ywtwh2aTk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/phishing/default.aspx">phishing</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/29/116045.aspx</feedburner:origLink></item><item><title>On Enterprise Security Playbooks</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/zDNiI2fkPN8/110323.aspx</link><pubDate>Tue, 08 Sep 2009 16:25:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:110323</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/09/110323.aspx#comments</comments><description>&lt;p&gt;I am interested in getting a few real-world examples of enterprise &amp;quot;Security Playbooks&amp;quot; and explore them.&lt;/p&gt;
&lt;p&gt;What is an enterprise Security Playbook? It is the &amp;quot;outcome&amp;quot; of organisation&amp;#39;s scenario planning and security risk assessment exercises, describing what should be done in presence of specific events and threats, for given contexts.&lt;/p&gt;
&lt;p&gt;A security playbook can relate both to current and foreseeable situations where decisions must be taken by one or more &amp;quot;decision makers&amp;quot; and courses of actions carried out by specific people.&lt;/p&gt;
&lt;p&gt;Why are &amp;quot;security playbooks&amp;quot; important? They are strategic for organisations as they synthesize what has to be done in critical situations (and who has to carry out actions) when very little time is allowed for debates and reactions.&lt;/p&gt;
&lt;p&gt;Interestingly enough, &amp;quot;playbooks&amp;quot; are available in many fields, related to traditional business risk management (in case of faults, natural disasters, etc.).&lt;/p&gt;
&lt;p&gt;I am interested in learning more about enterprise playbook that specifically focus on &amp;quot;IT security and cybercrime&amp;quot; aspects: I am wondering if any public template, example or guideline has ever been produced. I struggled to find anything really relevant ...&lt;/p&gt;
&lt;p&gt;I am also interested in better understanding what the implications are in the IAM space, which impact playbooks have on people, IAM processes and related IT operations ...&lt;/p&gt;
&lt;p&gt;Any input or links would be greatly appreciated.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=110323" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/zDNiI2fkPN8" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Playbook/default.aspx">Security Playbook</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/09/110323.aspx</feedburner:origLink></item><item><title>On my Experience in Using Twitter …</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/WURdb_jZcnI/110320.aspx</link><pubDate>Tue, 08 Sep 2009 16:22:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:110320</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>3</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/09/110320.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;ve now been using &lt;a href="http://twitter.com/MCasassaMont"&gt;my Twitter account&lt;/a&gt; for a few months, in order to provide quick updates about my work and activities.&lt;/p&gt;
&lt;p&gt;My overall experience is positive. The 140 chars limitation is actually a pros, imposing some discipline on what to say and focus. &lt;/p&gt;
&lt;p&gt;I have used Twitter many times to complement my blogging activities, to provide short pointers to blog posts of interest, to a wide community of followers.&lt;/p&gt;
&lt;p&gt;I noticed that the communities operating in Twitter are nowadays much more active and dynamic than the ones operating in the traditional blogging space. &lt;/p&gt;
&lt;p&gt;But this is just based on my personal experience and discussed topics ...&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=110320" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/WURdb_jZcnI" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Twitter/default.aspx">Twitter</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/09/110320.aspx</feedburner:origLink></item><item><title>W3C Policy Languages Interest Group (PLING) - Public Teleconference - 09 September 2009 – 12:00 AM (UTC) </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/x_zvfgSZvlQ/110318.aspx</link><pubDate>Tue, 08 Sep 2009 16:19:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:110318</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/09/110318.aspx#comments</comments><description>&lt;p&gt;The next &lt;a href="http://www.w3.org/Policy/pling/wiki/Main_Page"&gt;W3C Policy Languages Interest Group&lt;/a&gt; (PLING) public teleconference is going to be held on 09 September 2009, at 12:00 AM (UTC).&lt;/p&gt;
&lt;p&gt;Among many other topics, the agenda includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;PLING Note on &lt;a href="http://www.w3.org/Policy/pling/wiki/PLINGNOTEBestPracticesForPrivacyAwareness" title="http://www.w3.org/Policy/pling/wiki/PLINGNOTEBestPracticesForPrivacyAwareness"&gt;Best Practices for Privacy Awareness&lt;/a&gt;. See &lt;a href="http://www.w3.org/TR/geolocation-API/" title="http://www.w3.org/TR/geolocation-API/"&gt;W3C GeoLocation API WD&lt;/a&gt; and &lt;a href="http://www.mozilla.com/en-US/firefox/geolocation/" title="http://www.mozilla.com/en-US/firefox/geolocation/"&gt;FireFox Location-Aware Browsing&lt;/a&gt; for inspiration&lt;/li&gt;
&lt;li&gt;&lt;a href="http://dev.w3.org/html5/spec/Overview.html#licensing-works" title="http://dev.w3.org/html5/spec/Overview.html#licensing-works"&gt;HTML 5 Licensing Works&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Proposal for a new Web Policy Language Working Group&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Please consider attending this teleconference.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=110318" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/x_zvfgSZvlQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/W3C+PLING/default.aspx">W3C PLING</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/09/09/110318.aspx</feedburner:origLink></item><item><title>Good R&amp;D Progress in the Space of Identity (and Security) Analytics</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/qKHHjqVTy4A/104920.aspx</link><pubDate>Tue, 25 Aug 2009 12:11:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:104920</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104920.aspx#comments</comments><description>&lt;p&gt;Good progress has been&amp;nbsp;made in the R&amp;amp;D space of Identity Analytics at HP Labs (in the broader context of Security Analytics).&lt;/p&gt;
&lt;p&gt;Various IAM case studies have been explored, investigating how event-driven probabilistic modelling, coupled with economic studies, can be used to help decision makers&amp;nbsp; to make decision on investments, identify suitable metrics &amp;amp; policies, better understand the impact of choices, trade-offs and risk implications.&lt;/p&gt;
&lt;p&gt;We got a few papers accepted in international conferences, in particular at IEEE Policy 2009 Symposium, Trust Economics 2009 Workshop and IEEE MetriSec 2009 - covering various IAM aspects.&lt;/p&gt;
&lt;p&gt;A few HP Labs Technical Reports are now publicly available:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-173.html"&gt;HPL-2009-173&lt;/a&gt; &lt;i&gt;Adrian Baldwin, Marco Casassa Mont, David Pym, Simon Shiu &lt;/i&gt;- System Modelling for Economic Analysis of Security Investments: A Case Study in Identity and Access Management&amp;nbsp;- HPL-2009-173&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-142.html"&gt;HPL-2009-142&lt;/a&gt; &lt;i&gt;Yolanta Beres, Marco Casassa Mont, Jonathan Griffin, Simon Shiu &lt;/i&gt;- Using Security Metrics Coupled with Predictive Modelling and Simulation to Assess Security Processes&amp;nbsp;- HPL-2009-142&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-138.html"&gt;HPL-2009-138&lt;/a&gt; &lt;i&gt;Anna Squicciarini, Marco Casassa Mont, &lt;/i&gt;&lt;i&gt;Sathya Dev Rajasekaran - &lt;/i&gt;Towards an Analytic Approach to Evaluate Enterprises&amp;#39; Risk Exposure to Social Networks&amp;nbsp;- HPL-2009-138&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-57.html"&gt;HPL-2009-57&lt;/a&gt; &lt;i&gt;Marco Casassa Mont, Adrian Baldwin, Simon Shiu &lt;/i&gt;- Identity Analytics - User provisioning Case Study: Using Modelling and Simulation for Policy Decision Support - HPL-2009-57, 2009 &lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-56.html"&gt;HPL-2009-56&lt;/a&gt; &lt;i&gt;Adrian Baldwin, Marco Casassa Mont, Simon Shiu &lt;/i&gt;- Using Modelling and Simulation for Policy Decision Support in Identity Management - HPL-2009-56, 2009 &lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;HPL-2008-&lt;/a&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;84&lt;/a&gt; &lt;i&gt;Marco Casassa Mont, Adrian Baldwin, Simon Shiu &lt;/i&gt;- On Identity Analytics: Setting the Context- HPL-2008-84, 2008&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I am looking for input and feedback, in particular additional case studies where to apply our approach and techniques. &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=104920" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/qKHHjqVTy4A" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104920.aspx</feedburner:origLink></item><item><title>Serving in the Technical Program Committee of International Conferences</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/RUlNPhzA2hE/104919.aspx</link><pubDate>Tue, 25 Aug 2009 12:06:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:104919</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104919.aspx#comments</comments><description>&lt;p&gt;This year I have been serving as a member of many Technical Program Committees, in various International (IEEE, ACM, etc.)&amp;nbsp; Conferences, including: &lt;a href="http://www.acsac.org/"&gt;ACSAC 2009&lt;/a&gt;,&amp;nbsp; &lt;a href="http://ieee-biometrics.org/bids2009/"&gt;IEEE BIDS 2009&lt;/a&gt;,&amp;nbsp; &lt;a href="http://sesar.dti.unimi.it/InSPEC2009/"&gt;IEEE InSpec 2009&lt;/a&gt;, &lt;a href="http://www2.pflab.ecl.ntt.co.jp/dim2009/"&gt;ACM DIM 2009&lt;/a&gt;, &lt;a href="http://www.icsi.berkeley.edu/icsc/"&gt;IEEE ICSC 2009&lt;/a&gt;, &lt;a href="http://www.icsd.aegean.gr/trustbus2009/"&gt;TrustBus 2009 &lt;/a&gt;and &lt;a href="http://www.iaria.org/conferences2009/ComICIMP09.html"&gt;ICIMP 2009&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I found this experience very rewarding. Despite the need to allocate some amount of time for peer reviewing papers, this really provides good overviews of the state-of-art of research (and applied research) in the field of interest - in my case security, identity management and privacy.&lt;/p&gt;
&lt;p&gt;I would encourage the members of this community in having a similar role, especially the ones interested in R&amp;amp;D and research.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=104919" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/RUlNPhzA2hE" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Conferences/default.aspx">Security Conferences</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104919.aspx</feedburner:origLink></item></channel></rss>
