trust frameworks explained

19
Trust Frameworks Explained (in 20 minutes or less) Andrew Hughes [email protected] KantaraInitiative.org

Upload: kantarainitiative

Post on 20-Jan-2017

121 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Trust Frameworks Explained

Trust Frameworks Explained (in 20 minutes or less)

Andrew Hughes [email protected]

KantaraInitiative.org

Page 2: Trust Frameworks Explained

WHAT IS A DIGITAL IDENTITY TRUST FRAMEWORK?

Explaining Digital Trust Frameworks in 20 minutes or less

Page 3: Trust Frameworks Explained

Fun and Exciting!

Page 4: Trust Frameworks Explained

Current Work Creating a Pan-Canadian Trust Framework for the

Digital Identification & Authentication Council of Canada (DIACC)

Stakeholders include: federal & provincial governments; financial institutions; telecom providers; credit bureaus; identity networks / hubs; credential managers, others

Wildly divergent needs, expectations and operational modes

Page 5: Trust Frameworks Explained

What is a Digital Identity Trust Framework?

“Digital Identity”• Identity: A reference or designation used to

distinguish a unique and particular individual, organization or device.

• Trusted Digital Identity: ‘a trusted electronic representation of who I am.’

“Framework”• Digital Identity Trust Frameworks define

the ‘rules of the road’ for interactions between organizations when handling identity, authentication and authorization. Often, these Frameworks form the basis of agreements and contracts.

Page 6: Trust Frameworks Explained

Functions The DIACC Framework covers

Person Identity Proofing (Registration Authorities) Credential Management Authorization policy (PDP) Access control (PEP) Authentication of Credentials (Verifier) Establishment of government authoritative identity

records

Page 7: Trust Frameworks Explained

WHY USE A DIGITAL IDENTITY TRUST FRAMEWORK?

Page 8: Trust Frameworks Explained

A reason for a framework?

To make negotiating agreements easier

Page 9: Trust Frameworks Explained

Reasons for Frameworks STANDARDIZATION of identity, authentication &

access control processes and technologies within a trust community

LESSEN BURDEN by amalgamating published standards to reduce burden of adopters to know all the standards

Framework Profile creation process captures community-specific details, regulated requirements – GOVERNED by a designated body

Assessment & conformance approach will acknowledge and use PRIOR USE and certifications

Page 10: Trust Frameworks Explained

How?

Framework

Contracts and Agreements

StandardsRegulationsLaws

Framework Profile

Page 11: Trust Frameworks Explained

Some Details

Page 12: Trust Frameworks Explained

Digital Trust Framework Elements

Roles & Responsibilities

Page 13: Trust Frameworks Explained

Digital Trust Framework Elements

Business functions & Expected Processes

Page 14: Trust Frameworks Explained

Digital Trust Framework Elements

Processes & Criteria (proof of ‘sameness’ and ‘equivalency’)

Page 15: Trust Frameworks Explained

Digital Trust Framework Elements

Library of Profiles

Page 16: Trust Frameworks Explained

Tools and Rules Technical protocols Software / servers Cryptography Communication

protocols Standards

Policies for proof of

identity; ‘Levels’ of certainty

Privacy policy Operations practices Designated authorities

Page 17: Trust Frameworks Explained

The Future Possibilities Model contract clauses Automation for contracts Addition of new roles, responsibilities, business

functions Build a library of framework profiles

Page 18: Trust Frameworks Explained

Now what?Join us in innovating and verifying trusted identity solutions for the world Kantara Initiative members include global experts from industry and

government in the fields: Identity assurance Privacy Security Policy Information systems assessment

Join. Innovate. Trust. Visit.:

KantaraInitiative.org

Page 19: Trust Frameworks Explained

Join. Innovate. Trust.General Inquiries: [email protected]

[email protected]