by CIO Staff

Oracle Open Identity Protection Project Launched

Nov 29, 20063 mins

Oracle, working with other technology vendors, has launched an open-framework initiative to develop software to protect identity-related employee, customer and partner information, the company said Wednesday.

Oracle is inviting technology vendors and customers to review plans for the Identity Governance Framework (IGF) and contribute to key draft specifications, the company said in a news release. Five technology vendors, including CA, Sun Microsystems and Novell, have already reviewed a draft of the framework and plan to work with Oracle to develop full specifications, Oracle said.

The project, based on XML, comes as security vendors look for ways to help businesses and government agencies avoid adding to a rash of security breaches during the past two years. Oracle rolled out a piece of its own identity management software suite, called Oracle Identity Manager 10g R3, in May.

IGF will be designed to protect identity information as it flows across several applications, the company said. Identity-related information is often embedded in numerous applications across organizations, placing the information at risk and creating potential privacy violations, Oracle said.

The goal of IGF will be to establish a standard way of defining organization-wide policies to share sensitive personal information securely between applications, Oracle said.

Oracle understands the challenges its customers face in trying to manage and secure identity-related information and knows that it is increasingly important to establish policies regarding such information, said Hasan Rizvi, Oracle’s vice president of identity management and security products, in a statement.

Vendors and customers can currently review four components of IGF:

  • Client attribute requirement markup language (CARML), an XML-based declarative contract defined by application developers that informs deployment managers and service providers about the attribute usage requirements of an application.

  • Attribute authority policy markup language, a set of policy rules regarding the use of identity-related information from an identity source that allow these sources to specify constraints on use of provided data by applications.

  • CARML API, an application program interface that makes it easier for developers to write applications that consume and use identity-related data in a way that conforms to policies set around the use of such information.

  • Identity Service, a policy-secured service for accessing identity-related data from multiple identity sources.

Oracle has the project’s specifications posted at the IGF website.

-Grant Gross, IDG News Service (Washington Bureau)

Related Link:

  • Oracle Buys SPL WorldGroup for Public Sector Business

Check out our CIO News Alerts and Tech Informer pages for more updated news coverage.