Liberty Alliance, Microsoft Discuss Identity Protocols


Wed, January 10, 2007

CIO

The Liberty Alliance, a consortium working on policy and technology issues for identity management, is discussing with Microsoft (MSFT) how to reconcile their competing sets of protocols for secure Web transactions.

"We have finally put down the boxing gloves and are trying to figure out how to solve our customers’ problems," said Roger Sullivan, the newly elected president of the Liberty Alliance and vice president of Oracle’s (ORCL) identity management section.

The Liberty Alliance, whose participants include Hewlett-Packard (HPQ), Sun Microsystems (JAVA) and IBM (IBM), backs the ID-Web Services Framework (ID-WSF), a set of protocols for Web services. Microsoft supports another set, WS-Star.

The protocols are used for secure information exchanges over the Internet. Eventually, the standards will likely converge, Sullivan said. Microsoft has been "cordial" in discussions with the Liberty Alliance, he said.

"We believe the Web Services Framework from Liberty very well complements the WS-Star protocols," Sullivan said.

But two sets of standards create problems for enterprises that may have already invested in infrastructure, and enterprises may delay identity projects because of confusion, he said.

"We have customers who have deployed WSF, and we need to help them reconcile the two standards stacks so when convergence happens, it will be logical," Sullivan said.

Over the next year, that will mean working with vendors to ensure the transition is smooth and doesn’t jeopardize expensive software investments, Sullivan said.

The identity and access management field has been hampered in the past by competing standards protocols, according to a report released last month by analyst IDC.

However, with the protocol standards debate settling, IDC expects the revenue for identity technologies to rise from US$3 billion in 2005 to $5.1 billion in 2010.

A first step toward stability came in 2005, with the ratification of security assertion markup language (SAML) 2.0, an XML-based framework for exchanging identity information, IDC said. SAML 2.0 was backed by the Liberty Alliance and is now widely used in vendor products.

Standards-based secure Web transactions are seen as key to improving everything from the efficiency of how supply chains operate to simplifying authentication on multiple websites.

Organizations, however, are still working on the legal and liability issues surrounding the use of identity management technology. Sullivan said the Liberty Alliance will help by publicizing successful case studies.

Microsoft officials reached in London Wednesday morning could not immediately comment on the discussions.

-Jeremy Kirk, IDG News Service (London Bureau)

Check out our CIO News Alerts and Tech Informer pages for more updated news coverage.

As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center