<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-31038959</id><updated>2012-01-28T22:03:27.901-08:00</updated><category term='AAAAuthority'/><category term='PPPAM'/><category term='sudarshan'/><category term='444'/><category term='sunser'/><category term='CSSS'/><category term='GObama'/><category term='SSSAB'/><category term='InterwrokingIII'/><category term='AAAP'/><category term='IIIndia'/><category term='AAA6'/><category term='PPPPOsso'/><category term='EEExpress'/><category term='AAANY'/><category term='AAANM3'/><category term='netid09'/><category term='mmus'/><category term='mmm'/><category term='egovtelecom'/><category term='CCCCoalmine'/><category term='SSSolaris'/><category term='dc'/><category term='FCCCC'/><category term='IDCCCC'/><category term='AAANM2'/><category term='CCCCPD'/><category term='RRR'/><category term='ssscisco'/><category term='EEethics'/><category term='KeynoteSIM'/><category term='XACML_ABAC_project'/><category term='AAA7'/><category term='RRRatify'/><category term='CCCOracle'/><category term='SEI'/><category term='AAA4'/><category term='BBBasel'/><category term='AAApertio'/><category term='IIIPTV'/><category term='TTT39'/><category term='improveimp'/><category term='IIIO'/><category term='mmmtut'/><category term='idtrust2008'/><category term='DDDDesign'/><category term='AAAustin'/><category term='AAA5'/><category term='AdAA'/><category term='10GKGrad'/><category term='firstfew'/><category term='IIIDEA'/><category term='MMMobile'/><category term='FFFAM'/><category term='TTT2'/><category term='AOP'/><category term='DIM2008'/><category term='RRRRBAC'/><category term='TTT40'/><category term='IDTrust2009'/><category term='ll'/><category term='CFPTPC'/><category term='SSOS'/><category term='ravir'/><category term='CCContext'/><category term='memmom'/><category term='TTT3'/><category term='AAASOA'/><category term='SSSec'/><category term='CClientContext'/><category term='GGGen'/><category term='NSNGN'/><category term='SSSSec'/><category term='CCCB'/><category term='GGGain'/><category term='PPPairs'/><category term='CCCommunity'/><category term='SSSMS'/><category term='GGGloop'/><category term='BBBailout'/><category term='TTT1'/><category term='TTT41'/><category term='ddvi'/><category term='OrGRC'/><category term='PPPworkshop'/><category term='CCCdance'/><category term='nnnnetid'/><category term='SSStrategy'/><category term='sssdsee'/><category term='LLL'/><category term='wwwwebcast'/><category term='Keynote'/><category term='AAAObama'/><category term='ValidIII'/><category term='OOOpenet'/><category term='Keynotes'/><category term='ieccc'/><category term='IDXML'/><category term='midm'/><category term='AAAgate'/><category term='PPCP'/><category term='ppprivacy'/><category term='IIIITIL'/><category term='SSSriSri'/><category term='USAFRICA'/><category term='OpenSSOEEE'/><category term='LLLogic'/><category term='XiiML'/><category term='WWWash'/><category term='TTT26'/><category term='SOASIG'/><category term='SSSS'/><category term='RRRpolicy'/><category term='vvvesu'/><category term='RiskBAC'/><category term='HHHE'/><category term='AAAssurance'/><category term='CCClouds'/><category term='TTT35'/><category term='anand'/><category term='RRRl'/><category term='CASonacard'/><category term='TTT27'/><category term='IIIGRC'/><category term='TTT32'/><category term='LLLT'/><category term='ACMAC'/><category term='IDMunich'/><category term='SSStar'/><category term='ShankarTrinity'/><category term='TPPP'/><category term='AAAAlignment'/><category term='TTTax'/><category term='ABACRBAC'/><category term='cccautism'/><category term='OOOJava'/><category term='CCCV'/><category term='TTT28'/><category term='MMM2010'/><category term='AAAIDS'/><category term='ciscosun'/><category term='CCCtelcomysql'/><category term='TTTrans'/><category term='wwworkshop'/><category term='TTTb'/><category term='TTT33'/><category term='VVVFP'/><category term='CCCUC'/><category term='EMSXACML'/><category term='JGMMM'/><category term='TTTNXTComm08'/><category term='CCConv'/><category term='DIDW2008'/><category term='VVVolgenau'/><category term='sailfin'/><category term='netID'/><category term='CCCplaces'/><category term='TTT37'/><category term='TTT29'/><category term='mmmove'/><category term='sspot'/><category term='RRRBAC'/><category term='sssschool'/><category term='SSSweekend'/><category term='MMMunich'/><category term='SOASISec'/><category term='TTT38'/><category term='uuuam'/><category term='motodev'/><category term='LEEE'/><category term='analogies'/><category term='CCCCon'/><category term='IIIindigo'/><category term='evem'/><category term='DIM2010'/><category term='PPProtocols'/><category term='AAAAAA'/><category term='IIIPhone'/><category term='CCCMobile'/><category term='IIINHIN'/><category term='AAANM'/><category term='CCCGB'/><category term='CommcustCT'/><category term='cccc'/><category term='HHSS'/><category term='TTT19'/><category term='RRRaji'/><category term='DDDIDT'/><category term='CIA4CC'/><category term='RRRM'/><category term='DDDivide'/><category term='OpeningKeynote'/><category term='AAAUTHN'/><category term='idpbook'/><category term='idendev'/><category term='TTT36'/><category term='WWWin'/><category term='arjunaa'/><category term='hhssrs'/><category term='TTTotT'/><category term='TTTFTC'/><category term='TOLTTT'/><category term='SASSOSAML'/><category term='OOOpNGDC'/><category term='FFFGS'/><category term='cccmouli'/><category term='SSSOSession'/><category term='AAAservices'/><category term='AAAC'/><category term='TTT18'/><category term='TTTech'/><category term='IEEEIDM'/><category term='SIMSCWSSSO'/><category term='TTT17'/><category term='andreasfrank'/><category term='SSSworld'/><category term='MMMDM'/><category term='PPpermutation'/><category term='CCC'/><category term='bookatparis'/><category term='alignSOA'/><category term='SSSOA'/><category term='TTT16'/><category term='TTT21'/><category term='mtv'/><category term='IIWITU'/><category term='pppbook'/><category term='FFFISMA'/><category term='VVVpdc'/><category term='INIDIN'/><category term='IIIPP'/><category term='TTT15'/><category term='sun25'/><category term='TTTelco'/><category term='AAAMTune'/><category term='idenabledTA'/><category term='soaatsd'/><category term='TTT20'/><category term='FFFTNC'/><category term='SSSIDworld2010'/><category term='AAAF'/><category term='superG'/><category term='TTT14'/><category term='tmftmw'/><category term='RRRR'/><category term='IDPVC'/><category term='AAAJ1'/><category term='cccdc'/><category term='TTT31'/><category term='TTT22'/><category term='HHHitsp'/><category term='LLLGO'/><category term='RRRefuteUrRep'/><category term='JGD'/><category term='pppnortel'/><category term='Insights2Integration'/><category term='TTT30'/><category term='DDDMB'/><category term='LLLondon'/><category term='SSSHC'/><category term='CCCS'/><category term='chandrusss'/><category term='vaau'/><category term='IDTrustAAA'/><category term='FFFusion'/><category term='KKKishore'/><category term='KKKeynotes'/><category term='AAAplliance'/><category term='PPPbnm'/><category term='IDDev'/><category term='TTT13'/><category term='EEEdad'/><category term='MMMM'/><category term='SSSipDA'/><category term='CCCbook'/><category term='SunSAI'/><category term='TTTTokens'/><category term='TTT24'/><category term='TOGAF2008'/><category term='VDVVM'/><category term='CCComments'/><category term='TTT12'/><category term='CCCust'/><category term='TTTr'/><category term='PPProfile'/><category term='AAAIDMR'/><category term='NNNHT'/><category term='IIInt'/><category term='IIIIBI'/><category term='TTT8'/><category term='TTSCIT'/><category term='CCidC'/><category term='websense'/><category term='uva'/><category term='TTT11'/><category term='VVVAAU'/><category term='webCworkS'/><category term='SSOA'/><category term='trends'/><category term='carsandroads'/><category term='AAArjuna'/><category term='EEEID'/><category term='2020Cricket'/><category term='SSSwift'/><category term='TTT10'/><category term='eeeve'/><category term='WWWFI'/><category term='SSSL7'/><category term='IDMindsurty'/><category term='Policy 2010'/><category term='PPPID'/><category term='IIIImedia'/><category term='nnn'/><category term='WWW'/><category term='CCCpapers'/><category term='TTTT'/><category term='REREBE'/><category term='nnnb'/><category term='DIDW07SSS'/><category term='sunopenid'/><category term='CCCyber'/><category term='RRRepurcussions'/><category term='pppp'/><category term='EEEE'/><category term='GGGRC'/><category term='SSSumathi'/><category term='LLLon'/><category term='AAAmber'/><category term='TTT'/><category term='TTT9'/><category term='pb'/><category term='AAArjun'/><category term='RSRRR'/><category term='TenatSun'/><category term='stdatdc'/><category term='SSSOS'/><category term='CCContextMEP'/><category term='VVVV'/><category term='OCCC'/><category term='ideniptv'/><category term='VofVI'/><category term='VVVivek'/><category term='PPPat'/><category term='BBBOSSO'/><category term='IIITelco'/><category term='GoObama'/><category term='obamabiden'/><category term='SSSNAC'/><category term='AFandMe'/><category term='TTT5'/><category term='CCCConvergence'/><category term='IIIWarrior'/><category term='Net Dialogue'/><category term='DallasTM'/><category term='SABSA'/><category term='CIIII'/><category term='VZW'/><category term='worththewait'/><category term='LLLA'/><category term='IASAIDEA'/><category term='CMCC'/><category term='SunBWPPPP'/><category term='TTT4'/><category term='glimpse'/><category term='SSSFS'/><category term='CCCC1'/><category term='CCCM'/><category term='SSSOSSO'/><category term='PPProt'/><category term='idpbook2'/><category term='RAAA'/><category term='iiii'/><category term='UVAArc'/><category term='rbacjone'/><category term='TTT7'/><category term='ScottSS'/><category term='IDenabledSDP'/><category term='authnjsr279'/><category term='FFFED'/><category term='RRRBar'/><category term='glennbblog'/><category term='ccccMIT'/><category term='TTT6'/><category term='OOOut'/><category term='DrRimland'/><category term='IIITol'/><category term='savaje'/><category term='PPPGMU'/><category term='SSSolve'/><category term='XXXDI'/><category term='PEPPIP'/><category term='RARR'/><category term='SAAS'/><category term='drkalam'/><title type='text'>Identity Driven Enterprise (Security) Architecture (IDEAs!!)</title><subtitle type='html'>&amp;quot;The IDEA is to design systems that put the concepts of secure, distributed, open &amp;amp; controlled &amp;quot;digital identity&amp;quot; at the core of ESA.&amp;quot; IDEA enables an Identity Layer that securely exchanges the AuthN &amp;amp; AuthZ context, Network &amp;amp; Device context, User context and other contextual data for &amp;quot;Contextual Composition of Converged Services&amp;quot; - while adhering to pervasive policies and establishing (transactional) Trust Through Transparency.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default?start-index=101&amp;max-results=100'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>567</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-31038959.post-8623828480142129448</id><published>2012-01-28T21:45:00.000-08:00</published><updated>2012-01-28T22:03:27.933-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT41'/><title type='text'>Thoughts on Token Technology Trends- No: 41</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-nltlueEFVkw/TyTcYzy1EoI/AAAAAAAAENI/3dsfR1qWmcw/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-nltlueEFVkw/TyTcYzy1EoI/AAAAAAAAENI/3dsfR1qWmcw/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;This is a link to the &lt;a href="http://www.oasis-open.org/committees/download.php/44489/rakesh-talk-v1.pdf"&gt;presentation &lt;/a&gt;I gave to the Trust Elevation WG at OASIS, headed by Dr. Abbie Barbir.&amp;nbsp; I might extend the time frame to post the reminder 59 thoughts around token trends (not within the 100 days) to late 2012.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8623828480142129448?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8623828480142129448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8623828480142129448' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8623828480142129448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8623828480142129448'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2012_01_01_archive.html#8623828480142129448' title='Thoughts on Token Technology Trends- No: 41'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-nltlueEFVkw/TyTcYzy1EoI/AAAAAAAAENI/3dsfR1qWmcw/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-9095423354045931776</id><published>2012-01-28T21:42:00.000-08:00</published><updated>2012-01-28T21:42:37.041-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT40'/><title type='text'>Thoughts on Token Technology Trends- No: 40</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="separator" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-r70Uq6Yl1KM/TyTb30JbnCI/AAAAAAAAENA/mHGwe_2XNm0/s200/sts.jpg" width="200" /&gt;&lt;/div&gt;&lt;br /&gt;And also Microsoft supports a type of&lt;a href="http://en.wikipedia.org/wiki/Access_token"&gt; Access Tokens&lt;/a&gt; in its operating system.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-9095423354045931776?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/9095423354045931776/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=9095423354045931776' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/9095423354045931776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/9095423354045931776'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2012_01_01_archive.html#9095423354045931776' title='Thoughts on Token Technology Trends- No: 40'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-r70Uq6Yl1KM/TyTb30JbnCI/AAAAAAAAENA/mHGwe_2XNm0/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2717451600553987033</id><published>2012-01-28T21:27:00.000-08:00</published><updated>2012-01-28T21:27:38.881-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT39'/><title type='text'>Thoughts on Token Technology Trends- No: 39</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-JVd9tRCEzL0/TyTX4liji4I/AAAAAAAAEM4/h1DYnTOh6sY/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-JVd9tRCEzL0/TyTX4liji4I/AAAAAAAAEM4/h1DYnTOh6sY/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;In the Data Tokenization space -- we need to go beyond simple data element tokenization (such as SS# and PAN) and leverage a Data Tokenization Platform such as the &lt;a href="http://intelasip.nebrina.com/redfort/Expressway-Tokenization-Broker-Reduce-PCI-Scope/"&gt;Intel Token Broker&lt;/a&gt;. The idea is to have a tokenized representation of all "data" resource - which includes a table, a db or directory. See the demo and read the papers. Such Data STS are also integrated into XACML based entitlement systems (such as Axiomatics and Oracle EM).&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2717451600553987033?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2717451600553987033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2717451600553987033' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2717451600553987033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2717451600553987033'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2012_01_01_archive.html#2717451600553987033' title='Thoughts on Token Technology Trends- No: 39'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-JVd9tRCEzL0/TyTX4liji4I/AAAAAAAAEM4/h1DYnTOh6sY/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7798034125340976851</id><published>2012-01-28T21:21:00.000-08:00</published><updated>2012-01-28T21:21:09.387-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT38'/><title type='text'>Thoughts on Token Technology Trends- No: 38</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-cPAx1uNB6ks/TyTWvGucAzI/AAAAAAAAEMw/RcKy4_2P5nw/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-cPAx1uNB6ks/TyTWvGucAzI/AAAAAAAAEMw/RcKy4_2P5nw/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Of course when you have major mainframe applications and mainframe batch jobs still in production, we need to extend the legacy RACF authentication of such legacy systems and specialized implementation such as &lt;a href="http://www.csl-int.com/pages_docs/ezToken.pdf"&gt;eZtoken &lt;/a&gt;enables these tokenized representation.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7798034125340976851?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7798034125340976851/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7798034125340976851' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7798034125340976851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7798034125340976851'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2012_01_01_archive.html#7798034125340976851' title='Thoughts on Token Technology Trends- No: 38'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-cPAx1uNB6ks/TyTWvGucAzI/AAAAAAAAEMw/RcKy4_2P5nw/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-3370947086690205512</id><published>2012-01-28T21:17:00.000-08:00</published><updated>2012-01-28T21:17:08.792-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT37'/><title type='text'>Thoughts on Token Technology Trends- No: 37</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-VrGisrsZeu8/TyTVflvAERI/AAAAAAAAEMo/hGN7gK2Faiw/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-VrGisrsZeu8/TyTVflvAERI/AAAAAAAAEMo/hGN7gK2Faiw/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;While OATH tokens are Authentication tokens we also have &lt;a href="http://oauth.net/2/"&gt;OAUTH&lt;/a&gt; tokens as access tokens. Amongst Access tokens we can have tokens such as an RBACtoken or a XrML token that offers tokenized representation of access privileges for a user. Very useful when access decisions are taken for multiple distributed resources and in collaboration with multiple access tokens.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-3370947086690205512?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/3370947086690205512/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=3370947086690205512' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3370947086690205512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3370947086690205512'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2012_01_01_archive.html#3370947086690205512' title='Thoughts on Token Technology Trends- No: 37'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-VrGisrsZeu8/TyTVflvAERI/AAAAAAAAEMo/hGN7gK2Faiw/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-9030266167339155364</id><published>2011-11-13T05:17:00.000-08:00</published><updated>2011-11-13T05:17:47.191-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT36'/><title type='text'>Thoughts on Token Technology Trends- No: 36</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-P9XqLEc-D5o/Tr_DG5AaH7I/AAAAAAAAEL4/EXwsVL7YEzE/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-P9XqLEc-D5o/Tr_DG5AaH7I/AAAAAAAAEL4/EXwsVL7YEzE/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Another popular SAML token is the &lt;a href="http://docs.oasis-open.org/wss/v1.1/wss-v1.1-spec-os-SAMLTokenProfile.pdf"&gt;Web Service Security SAML toke&lt;/a&gt;n, which provides the capability to federate a Tokenized representation of a Web Service and the messages it contains. Majority of the STS (secure token services) support this profile, and it is very useful for XACML (policies) to inter-operate with WS-Policy as well. The WSS-SAML token acts as the identifier to align both policy space.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-9030266167339155364?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/9030266167339155364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=9030266167339155364' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/9030266167339155364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/9030266167339155364'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#9030266167339155364' title='Thoughts on Token Technology Trends- No: 36'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-P9XqLEc-D5o/Tr_DG5AaH7I/AAAAAAAAEL4/EXwsVL7YEzE/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4968878929946749024</id><published>2011-11-13T05:07:00.000-08:00</published><updated>2012-01-28T21:10:50.874-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT35'/><title type='text'>Thoughts on Token Technology Trends- No: 35</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="separator" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-t2PrFeyF5Aw/Tr_AsT-GyWI/AAAAAAAAELw/5dFZL1R2RiY/s200/sts.jpg" width="200" /&gt;&lt;/div&gt;&lt;br /&gt;Similar to the approach taken by the SPENGO effort in the past (negotiated authentication), OATH is another initiative that aligns a few Authentication methods and tokens, such as; Standalone OTP generators, Smart Cards, USB Key FOBs, Software tokens and Trusted Platform Module (TPM) tokens via client negotiated framework with STS (secure token services). The power of &lt;a href="http://www.openauthentication.org/webfm_send/13"&gt;OATH token&lt;/a&gt; is that it is a framework that is token agnostic and authN mechanism agnostic, and that it will have commercial implementations via Ping STS and others. Therefore if you see a OATH token in a STS representing a subject - you can expect that it is negotiated with the client application or application type before it is generated.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4968878929946749024?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4968878929946749024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4968878929946749024' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4968878929946749024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4968878929946749024'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#4968878929946749024' title='Thoughts on Token Technology Trends- No: 35'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-t2PrFeyF5Aw/Tr_AsT-GyWI/AAAAAAAAELw/5dFZL1R2RiY/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6761179847475882023</id><published>2011-11-13T04:57:00.000-08:00</published><updated>2011-11-13T04:57:27.126-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT24'/><title type='text'>Thoughts on Token Technology Trends- No: 34</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-XiyunVpAIbA/Tr-9khVJ3sI/AAAAAAAAELo/acWqZ9PLl6Q/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-XiyunVpAIbA/Tr-9khVJ3sI/AAAAAAAAELo/acWqZ9PLl6Q/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Integrating Tokens into a Map is one of the key functions of a STS (secure token service). STS can initiate tokens, translate tokens, transfer tokens, map tokens and more. Similar to how in the past we had a &lt;a href="http://www.secure-endpoints.com/talks/nist-pki-06-kerberos.pdf"&gt;Kerberos Token aligned with a PKI token&lt;/a&gt;, we also have extensions of Kerberos token to the browser world (SSO token) via the &lt;a href="http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-kerberos-browser-sso.pdf"&gt;SAML Kerberos WebSSO token&lt;/a&gt;. This is a very useful approach to authenticate applications (client applications and server applications) and can augment user level authentication and device authentication (such as OTP token and TPM token).&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6761179847475882023?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6761179847475882023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6761179847475882023' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6761179847475882023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6761179847475882023'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#6761179847475882023' title='Thoughts on Token Technology Trends- No: 34'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-XiyunVpAIbA/Tr-9khVJ3sI/AAAAAAAAELo/acWqZ9PLl6Q/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7581160960016169402</id><published>2011-11-12T08:28:00.000-08:00</published><updated>2011-11-12T08:41:14.450-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT33'/><title type='text'>Thoughts on Token Technology Trends- No: 33</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7UOx9qCnQYE/Tr6dsLZqqmI/AAAAAAAAELg/1DHU8Sk7Jws/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-7UOx9qCnQYE/Tr6dsLZqqmI/AAAAAAAAELg/1DHU8Sk7Jws/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Before we can delve into the various SAML token types (which are also referenced as SAML profiles) - its is also important to note that there are additional SSO tokens, such as OBtoken (Oblix tokens in Oracle Access Manager), SMtokens (Siteminder tokens), CDSSO tokens (Sun Java Systems Access Manager -now Oracle), TivoliAM token (IBM AM), WinSSO token (MS) and more. The past decade we have seen several thousand deployments of these software that are all part of the access manager space (not federation manager space that adds a SAML context for federation setup - primary function of an STS). Other than the OPenSSO project (which was a Sun Open Source project -that combined - Access Management, STS/Federation, Entitlement Management, etc., which is under Oracle now, I am not aware of any system that combines these areas together, unfortunately. They are treated as separate products.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7581160960016169402?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7581160960016169402/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7581160960016169402' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7581160960016169402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7581160960016169402'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#7581160960016169402' title='Thoughts on Token Technology Trends- No: 33'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-7UOx9qCnQYE/Tr6dsLZqqmI/AAAAAAAAELg/1DHU8Sk7Jws/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1059659396978289567</id><published>2011-11-12T08:22:00.000-08:00</published><updated>2011-11-12T08:22:56.022-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT32'/><title type='text'>Thoughts on Token Technology Trends- No: 32</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-rVhUXgwou28/Tr6cyrprx3I/AAAAAAAAELY/40i6rdo3TmY/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-rVhUXgwou28/Tr6cyrprx3I/AAAAAAAAELY/40i6rdo3TmY/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;SWIFT for Secure Widespread Identifiers for Federated Telecom, has also created the notion of a SWIFT Token with an emphasis on Aligning Attribute Authorities around&lt;a href="http://security.future-internet.eu/images/9/9f/Computer-Paper.pdf"&gt; a SWIFT token&lt;/a&gt;. Since telecom operators own the Access Networks and can bootstrap a mobile devise into the Access Network as part of an Admission process, SWIFT tokens as virtual identifiers to align attribute authority can come in very useful.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1059659396978289567?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1059659396978289567/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1059659396978289567' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1059659396978289567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1059659396978289567'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#1059659396978289567' title='Thoughts on Token Technology Trends- No: 32'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-rVhUXgwou28/Tr6cyrprx3I/AAAAAAAAELY/40i6rdo3TmY/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7742729304565786365</id><published>2011-11-12T08:16:00.000-08:00</published><updated>2011-11-12T08:16:34.634-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT31'/><title type='text'>Thoughts on Token Technology Trends- No: 31</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-NOtdQQXnvEk/Tr6YmrezIRI/AAAAAAAAELQ/xNU-AvWya5M/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-NOtdQQXnvEk/Tr6YmrezIRI/AAAAAAAAELQ/xNU-AvWya5M/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;One of the Key Tokens that is leveraged by a Application and/or Browsers to NEGOTIATE an Authentication Mechanism with the back-end server is &lt;a href="http://en.wikipedia.org/wiki/SPNEGO"&gt;SPENGO token&lt;/a&gt;. A &lt;a href="http://msdn.microsoft.com/en-us/library/ms995330.aspx"&gt;SPENGO &lt;/a&gt;Token, that can carry for example a Kerberos Token. Typical usage is an environment that needs negotiated authentication -when there is multiple authentication systems, SPENGO is used and is supported by majority of the Browser's including Google Chrome. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7742729304565786365?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7742729304565786365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7742729304565786365' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7742729304565786365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7742729304565786365'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#7742729304565786365' title='Thoughts on Token Technology Trends- No: 31'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-NOtdQQXnvEk/Tr6YmrezIRI/AAAAAAAAELQ/xNU-AvWya5M/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1044477945106695395</id><published>2011-11-08T18:18:00.000-08:00</published><updated>2011-11-08T18:22:53.740-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT30'/><title type='text'>Thoughts on Token Technology Trends- No: 30</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-wfdIANYRspU/TrniXI2XXGI/AAAAAAAAELI/bJQstRHIfo8/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-wfdIANYRspU/TrniXI2XXGI/AAAAAAAAELI/bJQstRHIfo8/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;One key differentiation between time based and event based OTP/Tokens (RSA Secure ID like systems are time based) - is that event based OTP tokens are also critical post-authentication -&lt;a href="http://www3.safenet-inc.com/blog/pdf/Time_vs_Event_Based_OTP.pdf"&gt; in session or in-transaction subject validation&lt;/a&gt;.&amp;nbsp; These types of event token -- are extremely useful for context driven target rule sets, as a 2nd factor - contextual 2nd factor or 3rd factor. Note: Time, Event, USB, RFID, NFC and other related periphery tokens all-have influence over a device posture token and are all run time representation of a context (a set of attributes generated by a system post successful execution of a certain set of controls - in layer 1 to 7 of the OSI stack).&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1044477945106695395?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1044477945106695395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1044477945106695395' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1044477945106695395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1044477945106695395'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#1044477945106695395' title='Thoughts on Token Technology Trends- No: 30'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-wfdIANYRspU/TrniXI2XXGI/AAAAAAAAELI/bJQstRHIfo8/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-3893420109056864195</id><published>2011-11-08T18:12:00.000-08:00</published><updated>2011-11-08T18:12:05.318-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT29'/><title type='text'>Thoughts on Token Technology Trends- No: 29</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-rPzJiAmqWGU/TrngwQMFsMI/AAAAAAAAELA/4qJkV1h7wWI/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-rPzJiAmqWGU/TrngwQMFsMI/AAAAAAAAELA/4qJkV1h7wWI/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;One of the more commonly known and widespread usage of the term "tokens" is for the &lt;a href="http://www.rsa.com/node.aspx?id=1156"&gt;RSA secureid token.&lt;/a&gt; A device that generates a one time password - a "transient token" based on what you have and what you know "a PIN" - and can be augmented with axcionics like systems that add bio-metrics if needed. This is the type of token that increases the posture of a "subject: user + device"&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-3893420109056864195?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/3893420109056864195/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=3893420109056864195' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3893420109056864195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3893420109056864195'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#3893420109056864195' title='Thoughts on Token Technology Trends- No: 29'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-rPzJiAmqWGU/TrngwQMFsMI/AAAAAAAAELA/4qJkV1h7wWI/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1918224181724531663</id><published>2011-11-08T18:02:00.000-08:00</published><updated>2011-11-08T18:02:10.328-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT28'/><title type='text'>Thoughts on Token Technology Trends- No: 28</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-dfINRvhee88/TrnezxQfhhI/AAAAAAAAEK4/ALRYUmNraEY/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-dfINRvhee88/TrnezxQfhhI/AAAAAAAAEK4/ALRYUmNraEY/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Another influencer of the posture token (in terms of periphery token) is the &lt;a href="http://www.synometrix.com/RFID_waterproof_tokens_specification.shtml"&gt;RFID tokens or tags &lt;/a&gt;(in conjunction with USN tokens and NFC tokens).&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1918224181724531663?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1918224181724531663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1918224181724531663' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1918224181724531663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1918224181724531663'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#1918224181724531663' title='Thoughts on Token Technology Trends- No: 28'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-dfINRvhee88/TrnezxQfhhI/AAAAAAAAEK4/ALRYUmNraEY/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1566211349332969035</id><published>2011-11-08T17:59:00.000-08:00</published><updated>2011-11-08T17:59:30.623-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT27'/><title type='text'>Thoughts on Token Technology Trends- No: 27</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ZZaWNl4J0Vw/TrndNboDkHI/AAAAAAAAEKw/37zQox6FXsE/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-ZZaWNl4J0Vw/TrndNboDkHI/AAAAAAAAEKw/37zQox6FXsE/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Another such periphery token that can increase or decrease the integrity representing posture token is a &lt;a href="http://www.beyondlogic.org/usbnutshell/usb4.shtml"&gt;USB token&lt;/a&gt;. Non-provisioned adhoc USB tokens generated will basically reduce the posture tokens attribute value representations. However since these USB tokens themselves can be used as (&lt;a href="http://www.goldkey.com/"&gt;a pre provisioned initiating vector&lt;/a&gt;) secure storage of certificate/PKI, SIM, and other soft tokens - they can be added to the client device overall to increase the posture tokens attribute values. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1566211349332969035?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1566211349332969035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1566211349332969035' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1566211349332969035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1566211349332969035'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#1566211349332969035' title='Thoughts on Token Technology Trends- No: 27'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-ZZaWNl4J0Vw/TrndNboDkHI/AAAAAAAAEKw/37zQox6FXsE/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-3514743497957220107</id><published>2011-11-08T17:53:00.000-08:00</published><updated>2011-11-08T17:53:33.407-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT26'/><title type='text'>Thoughts on Token Technology Trends- No: 26</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-YJYur2Pjejg/TrncAYwxCsI/AAAAAAAAEKo/6d2DbZ2gOv4/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-YJYur2Pjejg/TrncAYwxCsI/AAAAAAAAEKo/6d2DbZ2gOv4/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Related to Posture Tokens that act as a runtime representation of validated and verified integrity attributes about a device and its connection, the contiguity and continuity of the integrity posture is not a given. Depending on the context and use case (application) the device is running the posture token will be re-aligned. Influencers of such posture tokens about lets say a mobile device are additional periphery contexts also represented by tokens. One such token is an&lt;a href="http://www.nfc-research.at/fileadmin/papers/2006/03/NFC_HGB_Science_Day_2006_Gerald_Madlmayr.pdf"&gt; NFC token.&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-3514743497957220107?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/3514743497957220107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=3514743497957220107' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3514743497957220107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3514743497957220107'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#3514743497957220107' title='Thoughts on Token Technology Trends- No: 26'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-YJYur2Pjejg/TrncAYwxCsI/AAAAAAAAEKo/6d2DbZ2gOv4/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2224192480296825873</id><published>2011-11-08T15:21:00.000-08:00</published><updated>2011-11-08T15:21:21.073-08:00</updated><title type='text'>Thoughts on Token Technology Trends- No: 25</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6aocjYWEQrU/Trm4JLf4GPI/AAAAAAAAEKg/9YboJnfIp_Y/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-6aocjYWEQrU/Trm4JLf4GPI/AAAAAAAAEKg/9YboJnfIp_Y/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;In conjunction with external entity posture (such as client devices) the perimeter PDP can also produce a &lt;a href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/product_data_sheet0900aecd805baef2_ps2706_Products_Data_Sheet.html"&gt;Network Threat Level Posture token &lt;/a&gt;- based on current Threats that are active. &lt;a href="http://us.trendmicro.com/us/about/threat-level/"&gt;Trendmicro like systems&lt;/a&gt; generate such threat level tokens - it can range from the access networks a perimeter network connects to (such as a mobile network), the enterprise network and the SP network (cloud SP). These types of tokens adds another layer of Intelligence to measuring an Integrity Level of an end to end Client to Service Connection. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2224192480296825873?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2224192480296825873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2224192480296825873' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2224192480296825873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2224192480296825873'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#2224192480296825873' title='Thoughts on Token Technology Trends- No: 25'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-6aocjYWEQrU/Trm4JLf4GPI/AAAAAAAAEKg/9YboJnfIp_Y/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5099153100707848840</id><published>2011-11-08T15:13:00.000-08:00</published><updated>2011-11-08T15:13:46.714-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT24'/><title type='text'>Thoughts on Token Technology Trends- No: 24</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-m-AACm08Dks/Trm14C3rJRI/AAAAAAAAEKY/kcaV5KO-9os/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-m-AACm08Dks/Trm14C3rJRI/AAAAAAAAEKY/kcaV5KO-9os/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Ultimately leveraging the path and packet tokenization and protocol and port tokenization - a comprehensive Perimeter PDP should generate &lt;a href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/PstrVal.pdf"&gt;Posture Tokens&lt;/a&gt; - that captures in Real Time the Integrity level of a device and its connection (client device and server device e2e). This in general should be generated post execution of all the control functions that are performed by; UTM -including Intrusion Detection and Prevention control functions, IP FW functions, VPN control functions, admission control functions, and more. The POSTURE TOKENS generated at Runtime is from a comprehensive combination perimeter PDP.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5099153100707848840?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5099153100707848840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5099153100707848840' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5099153100707848840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5099153100707848840'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#5099153100707848840' title='Thoughts on Token Technology Trends- No: 24'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-m-AACm08Dks/Trm14C3rJRI/AAAAAAAAEKY/kcaV5KO-9os/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6452600889590343643</id><published>2011-11-08T15:03:00.000-08:00</published><updated>2011-11-08T15:03:26.296-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT24'/><title type='text'>Thoughts on Token Technology Trends- No: 23</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-yEvJPAi9dD8/Trm0PZ6AROI/AAAAAAAAEKQ/nH2NeBcWkoo/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-yEvJPAi9dD8/Trm0PZ6AROI/AAAAAAAAEKQ/nH2NeBcWkoo/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Packet and Protocol Port (tokenized ports -NAT and PAT)&amp;nbsp; firewalls (a&lt;a href="http://csrc.nist.gov/publications/nistpubs/800-41-Rev1/sp800-41-rev1.pdf"&gt; farm of firewalls&lt;/a&gt;) generate path and packet tokens after protocol and port level rules are full enforced. This relates to Appliances such as Cisco ASA that sit on the Perimeter (DMZ) and functions a Packet FW, DPI, NAC, IDS/IPS and UTM all in one - concerted and co-ordinated to generate Posture Tokens -around the integrity of the device and the connection. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6452600889590343643?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6452600889590343643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6452600889590343643' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6452600889590343643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6452600889590343643'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#6452600889590343643' title='Thoughts on Token Technology Trends- No: 23'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-yEvJPAi9dD8/Trm0PZ6AROI/AAAAAAAAEKQ/nH2NeBcWkoo/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1868172334415307920</id><published>2011-11-08T14:56:00.000-08:00</published><updated>2011-11-08T15:05:42.901-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT22'/><title type='text'>Thoughts on Token Technology Trends- No: 22</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-52frT_aP-00/TrmyQK121SI/AAAAAAAAEKI/qqjbannPIhY/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-52frT_aP-00/TrmyQK121SI/AAAAAAAAEKI/qqjbannPIhY/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Token ring was a protocol that leveraged packet tokenization, and with &lt;a href="http://en.wikipedia.org/wiki/Token_bucket"&gt;MPLS token buckets&lt;/a&gt; are heavily utilized as well. The insertion of tokens within IPv6 packets allows for a rich set of capabilities around identification, authN and authZ of packets as well. Packet tokens augment Path tokens and are combined with protocol tokens to determine (policy based) posture tokens. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1868172334415307920?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1868172334415307920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1868172334415307920' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1868172334415307920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1868172334415307920'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#1868172334415307920' title='Thoughts on Token Technology Trends- No: 22'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-52frT_aP-00/TrmyQK121SI/AAAAAAAAEKI/qqjbannPIhY/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-958083401492314547</id><published>2011-11-08T14:50:00.000-08:00</published><updated>2011-11-08T14:50:10.263-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT21'/><title type='text'>Thoughts on Token Technology Trends- No: 21</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-htqaLitLASA/TrmxU9JenvI/AAAAAAAAEKA/ZRoDTuIxla0/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-htqaLitLASA/TrmxU9JenvI/AAAAAAAAEKA/ZRoDTuIxla0/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;The next 10 entries will revoke around the topics of DMZ perimeter PDP and network tokens, such as Path Tokens, Packet Tokens, Protocol Token, Posture tokens and the likes that in essence helps validate the integrity of a network connection, network session, device connection (both client and server devices) and more. See a well &lt;a href="http://www.nextgrid.org/download/Tokenbased-final.pdf"&gt;written paper here&lt;/a&gt;. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-958083401492314547?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/958083401492314547/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=958083401492314547' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/958083401492314547'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/958083401492314547'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#958083401492314547' title='Thoughts on Token Technology Trends- No: 21'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-htqaLitLASA/TrmxU9JenvI/AAAAAAAAEKA/ZRoDTuIxla0/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1578945947844150633</id><published>2011-11-08T06:49:00.000-08:00</published><updated>2011-11-08T14:36:15.486-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT20'/><title type='text'>Thoughts on Token Technology Trends- No: 20</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-7rIHmJATYn0/TrlAdggTjQI/AAAAAAAAEJ0/_DVus8O6AaE/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-7rIHmJATYn0/TrlAdggTjQI/AAAAAAAAEJ0/_DVus8O6AaE/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Along the lines of decoupling an Authentication Token from a STS SAML token, which is a key concept to digest, the idea behind adaptive authentication (&lt;a href="http://www.oracle.com/technetwork/middleware/id-mgmt/learnmore/oracle-ds-oaam-11gr1-173462.pdf?ssSourceSiteId=ocomen"&gt;such as OAAM&lt;/a&gt;) also is critical - since the set of subject tokens made necessary is dependent on the composite risk token associated with the resource consumed and the composite risk token associated with the subject as well. SO thus far we have covered Risk tokens, AuthN tokens, SAMLtokens, etc., in the 1st 20 entries. Now the focus will move on to a related area which is Network tokens and Integrity tokens and more. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1578945947844150633?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1578945947844150633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1578945947844150633' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1578945947844150633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1578945947844150633'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#1578945947844150633' title='Thoughts on Token Technology Trends- No: 20'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-7rIHmJATYn0/TrlAdggTjQI/AAAAAAAAEJ0/_DVus8O6AaE/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1773390156947754840</id><published>2011-11-08T06:43:00.000-08:00</published><updated>2011-11-08T14:36:47.862-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT19'/><title type='text'>Thoughts on Token Technology Trends- No: 19</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-4NuU9Z_jkUI/Trk_A3hpOkI/AAAAAAAAEJs/s7IB83Tg7zI/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-4NuU9Z_jkUI/Trk_A3hpOkI/AAAAAAAAEJs/s7IB83Tg7zI/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;In some cases innovative companies such as &lt;a href="http://www.axsionics.ch/tce/frame/main/420.htm"&gt;Axcionics generate all three token types (what you have, what you are and what you know) - SIM+OTP+BioMetric all in one to initiate a SAML Session&lt;/a&gt;. OpenSSO as &lt;a href="http://www.axsionics.ch/tce/frame/main/476.htm"&gt;an STS was integrated with Axionics&lt;/a&gt; as an Authentication mechanism as well. Hence a combination of tokens were generated at the get go and associated with a SAMLtoken in STS.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1773390156947754840?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1773390156947754840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1773390156947754840' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1773390156947754840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1773390156947754840'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#1773390156947754840' title='Thoughts on Token Technology Trends- No: 19'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-4NuU9Z_jkUI/Trk_A3hpOkI/AAAAAAAAEJs/s7IB83Tg7zI/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2942756863874697844</id><published>2011-11-08T06:32:00.000-08:00</published><updated>2011-11-08T14:37:01.274-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT18'/><title type='text'>Thoughts on Token Technology Trends- No: 18</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-jk0mxmYC4vw/Trk8hnP2BqI/AAAAAAAAEJk/erPAHOHW58o/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-jk0mxmYC4vw/Trk8hnP2BqI/AAAAAAAAEJk/erPAHOHW58o/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;If one can start with a hard token that represents an initiating vector and leverage some sort of biometric credentials (non intrusive) to authenticate a user, and bind the two tokens (or map the tokens with a SAMLtoken) using STS - one of the common ways to integrate and align to authenticated resources within an enterprise that has applications (application with a authN token) is via kerberos (common and popular). This is a key reason why we have &lt;a href="https://www.pingidentity.com/support-and-downloads/product-documentation/kerberos/1-0/loader.cfm?csModule=security/getfile&amp;amp;pageid=6086"&gt;SAMLkerberos profile and approaches to integration leveraging an STS.&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2942756863874697844?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2942756863874697844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2942756863874697844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2942756863874697844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2942756863874697844'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#2942756863874697844' title='Thoughts on Token Technology Trends- No: 18'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-jk0mxmYC4vw/Trk8hnP2BqI/AAAAAAAAEJk/erPAHOHW58o/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-8655987895622014023</id><published>2011-11-08T06:26:00.000-08:00</published><updated>2011-11-08T14:37:15.390-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT17'/><title type='text'>Thoughts on Token Technology Trends- No: 17</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-HlLAxKHBbGU/Trk69Mun2-I/AAAAAAAAEJc/gtJzsOc4RRs/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-HlLAxKHBbGU/Trk69Mun2-I/AAAAAAAAEJc/gtJzsOc4RRs/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Any hard token acting as the "initiating vector" allows for the STS to bind other token types to it. In general - when authenticating an entity - in this case a subject - similar to a hard token associated with a device (tamper resistant), a hard token associated with a human being is obviously Bio Metrics. The extensibility of the Biomentric AuthN tokens are also critical - such as DNA, fingerprint, facial recognition, retina, and more. Hence multiple Bio Metric token types should be generated by a platform for the right risk context. I am reminded of the&lt;a href="http://developers.sun.com/identity/reference/techart/bioauthentication.html"&gt; OpenSSO (STS) integration with Biobex&lt;/a&gt; for this purpose. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8655987895622014023?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8655987895622014023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8655987895622014023' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8655987895622014023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8655987895622014023'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#8655987895622014023' title='Thoughts on Token Technology Trends- No: 17'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-HlLAxKHBbGU/Trk69Mun2-I/AAAAAAAAEJc/gtJzsOc4RRs/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5890436280429105789</id><published>2011-11-08T06:18:00.000-08:00</published><updated>2011-11-08T14:37:28.537-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT16'/><title type='text'>Thoughts on Token Technology Trends- No: 16</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-muHjNIt34tI/Trk5qdYrDZI/AAAAAAAAEJU/07ylFCoaC28/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-muHjNIt34tI/Trk5qdYrDZI/AAAAAAAAEJU/07ylFCoaC28/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Similar to blog entry no 15, a TPM token can act as the initiating vector from which a SAMLtoken is generated by an STS and mapped to an OpenID token - like the &lt;a href="http://www.wave.com/news/press_archive/09/090915_id.wave.com.asp"&gt;one demo'd by wave technologies in 2009 at Digital ID world&lt;/a&gt;. This was an integrated demo using Ping STS. This same approach can be leveraged with any hardware token from CPU makers such as Intel and AMD. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5890436280429105789?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5890436280429105789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5890436280429105789' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5890436280429105789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5890436280429105789'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#5890436280429105789' title='Thoughts on Token Technology Trends- No: 16'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-muHjNIt34tI/Trk5qdYrDZI/AAAAAAAAEJU/07ylFCoaC28/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-510057320275721596</id><published>2011-11-08T06:14:00.000-08:00</published><updated>2011-11-08T14:37:36.708-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT15'/><title type='text'>Thoughts on Token Technology Trends- No: 15</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-HLhR7lLq_mk/Trk4eAZdH3I/AAAAAAAAEJM/WEH2YXdRUjU/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-HLhR7lLq_mk/Trk4eAZdH3I/AAAAAAAAEJM/WEH2YXdRUjU/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;One of the key forking factors for federation is the SIM card and the &lt;a href="http://www.w3.org/2011/identity-ws/papers/idbrowser2011_submission_20.pdf"&gt;GBA/GAA tokens that are generated by a the Mobile Operators&lt;/a&gt;. To a certain extent for enterprises that are extending their services to the mobile devices, this bootstrapping architecture and AKA/Digest +SIM based GAA allows for some level of device and user context that can be exchanged via SAMLtokens and STS, and augmented with additional authN tokens if needed.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-510057320275721596?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/510057320275721596/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=510057320275721596' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/510057320275721596'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/510057320275721596'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#510057320275721596' title='Thoughts on Token Technology Trends- No: 15'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-HLhR7lLq_mk/Trk4eAZdH3I/AAAAAAAAEJM/WEH2YXdRUjU/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2232934897312067410</id><published>2011-11-08T06:01:00.000-08:00</published><updated>2011-11-08T14:37:46.398-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT14'/><title type='text'>Thoughts on Token Technology Trends- No: 14</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-z3lERqbnS7A/Trk1SE2H3LI/AAAAAAAAEJE/HuBt0G7t_Tg/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-z3lERqbnS7A/Trk1SE2H3LI/AAAAAAAAEJE/HuBt0G7t_Tg/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Now that we know that there can exist multiple Authentication types represented as a AuthN token for a subject, in those scenarios where there is Federation involved we have to have a good understanding of STS (secure token services) and the &lt;a href="http://www.devproconnections.com/article/federated-security/generate-saml-tokens-using-windows-identity-foundation"&gt;SAMLtoken (aka SAMLartifact) it generates&lt;/a&gt;. With recent developments at OASIS you should also note that SAMLartifact can also carry a XACML decision token (i.e., an AuthZ token), more on AuthZ token for the another blog entry.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2232934897312067410?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2232934897312067410/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2232934897312067410' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2232934897312067410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2232934897312067410'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#2232934897312067410' title='Thoughts on Token Technology Trends- No: 14'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-z3lERqbnS7A/Trk1SE2H3LI/AAAAAAAAEJE/HuBt0G7t_Tg/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2529118768045428552</id><published>2011-11-08T05:50:00.000-08:00</published><updated>2011-11-08T14:37:58.873-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT13'/><title type='text'>Thoughts on Token Technology Trends- No: 13</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-C6kRETAftjc/Trky_oE-3kI/AAAAAAAAEI8/M5qPggtA_ns/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-C6kRETAftjc/Trky_oE-3kI/AAAAAAAAEI8/M5qPggtA_ns/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Toeknized representation of the audit trails are also anoher key perspective to keep in mind - to ensure full loop back - for traceability and observability. For example: &lt;a href="http://download.oracle.com/docs/cd/E19082-01/819-3321/6n5i4b7ug/index.html"&gt;Audit Tokens similar to the ones generated by Solaris&lt;/a&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2529118768045428552?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2529118768045428552/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2529118768045428552' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2529118768045428552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2529118768045428552'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#2529118768045428552' title='Thoughts on Token Technology Trends- No: 13'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-C6kRETAftjc/Trky_oE-3kI/AAAAAAAAEI8/M5qPggtA_ns/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2125386977935757382</id><published>2011-11-08T05:42:00.000-08:00</published><updated>2011-11-08T14:38:08.128-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT12'/><title type='text'>Thoughts on Token Technology Trends- No: 12</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-3imxeynb9gI/Trkwt5UYyPI/AAAAAAAAEI0/_sTo70Ziloo/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-3imxeynb9gI/Trkwt5UYyPI/AAAAAAAAEI0/_sTo70Ziloo/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Similar to the composite subject risk token, systems are capable of generating composite Resource Risk token as well. &lt;a href="http://www.sailpoint.com/resources/risk-management.php"&gt;Darren Rolls the CTO of Sailpoint recently showed a demo&lt;/a&gt; that does risk ranking of resources based on multiple factors associated with the resource - including access review and access certification, the entitlements associated with the resource and more. The generated XML artifact about the risk rating of a resource can be tokenized - compressed, encrypted with metadata. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2125386977935757382?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2125386977935757382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2125386977935757382' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2125386977935757382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2125386977935757382'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#2125386977935757382' title='Thoughts on Token Technology Trends- No: 12'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-3imxeynb9gI/Trkwt5UYyPI/AAAAAAAAEI0/_sTo70Ziloo/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-3193626855715124939</id><published>2011-11-08T05:37:00.000-08:00</published><updated>2011-11-08T14:38:21.198-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT11'/><title type='text'>Thoughts on Token Technology Trends- No:11</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-K0bHw8c5I4g/TrkvrDT9LRI/AAAAAAAAEIs/gwPIUUtq1SU/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-K0bHw8c5I4g/TrkvrDT9LRI/AAAAAAAAEIs/gwPIUUtq1SU/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;There are two types of composite risk that can be calculated - one for a subject (typically a person - employee, partner, customer, etc.) - for example &lt;a href="http://www.securonix.com/user_behavior.htm"&gt;Securonix generates what they define as a SmartRanking&lt;/a&gt; artifact, which to me is a specialized XMLtoken representing the risk associated with a subject based on past and current behavior.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-3193626855715124939?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/3193626855715124939/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=3193626855715124939' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3193626855715124939'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3193626855715124939'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#3193626855715124939' title='Thoughts on Token Technology Trends- No:11'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-K0bHw8c5I4g/TrkvrDT9LRI/AAAAAAAAEIs/gwPIUUtq1SU/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4832010533183970981</id><published>2011-11-07T17:38:00.000-08:00</published><updated>2011-11-08T14:38:33.102-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT10'/><title type='text'>Thoughts on Token Technology Trends- No: 10</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-OZh_llF4o7w/TriGc1m6ihI/AAAAAAAAEIk/4oJctjncnDU/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-OZh_llF4o7w/TriGc1m6ihI/AAAAAAAAEIk/4oJctjncnDU/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Another interesting trend is the Data Tokenization space (&lt;a href="http://go.protegrity.com/tokenization-whitepaper-download.html"&gt;see paper&lt;/a&gt;). While data tokenization is to secure data (at rest and in transit) -the tokenized representation also has meta-data that classifies the data - such as PCI-DSS data, PII data, iTAR data and more. Which is also key to understand when we need to comply with regulatory requirements around data and data in the clouds! To me along with other firewall functions performed by a DB FW -this should be an add on capability. However today its typically an add on product.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4832010533183970981?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4832010533183970981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4832010533183970981' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4832010533183970981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4832010533183970981'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#4832010533183970981' title='Thoughts on Token Technology Trends- No: 10'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-OZh_llF4o7w/TriGc1m6ihI/AAAAAAAAEIk/4oJctjncnDU/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6047912853729616229</id><published>2011-11-07T17:30:00.000-08:00</published><updated>2011-11-08T14:38:52.019-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT9'/><title type='text'>Thoughts on Token Technology Trends- No: 9</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="separator" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-ACbSvQg3uAU/TriEEkz7S3I/AAAAAAAAEIc/BnSgGTCMPDE/s200/sts.jpg" width="200" /&gt;&lt;/div&gt;&lt;br /&gt;Another key technology trend in this space is DRM and rights management expressions using XrML and the resulting &lt;a href="http://xml.coverpages.org/WS-Security-XML-Tokens.pdf"&gt;XrML tokens&lt;/a&gt; (runtime licensing keys and artifact representing a resource access control function). This takes us to the topic of representing - rights, access, privileges, priority, entitlements and all AuthZ related functions as they relate to documents, databases, OS and applications + data - all expressed in Tokens - similar to XrML tokens - also allowing for&amp;nbsp; run-time representation of DAC, MAC, RBAC, DRM and more.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6047912853729616229?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6047912853729616229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6047912853729616229' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6047912853729616229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6047912853729616229'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#6047912853729616229' title='Thoughts on Token Technology Trends- No: 9'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-ACbSvQg3uAU/TriEEkz7S3I/AAAAAAAAEIc/BnSgGTCMPDE/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4889886675981068094</id><published>2011-11-07T17:20:00.000-08:00</published><updated>2011-11-08T14:39:04.329-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT8'/><title type='text'>Thoughts on Token Technology Trends- No: 8</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-KauMHjrIU1s/TriC8MTVdMI/AAAAAAAAEIU/Xb1ayGwrL8E/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-KauMHjrIU1s/TriC8MTVdMI/AAAAAAAAEIU/Xb1ayGwrL8E/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Another key technology trend in this space is the usage of Virtual Directory technology to create what is referred to as "computed tokens", such as &lt;a href="http://www.radiantlogic.com/products/radiantone-vds/"&gt;Radiant Logic&lt;/a&gt;. VDS technology allows for the aggregation of associated attributes into a virtual view. From this virtual view lets say we can see a 100 attributes - we can easily define that if we see 90% of attribute match create a Green Token - 70-90% match a blue token - 50-70% match an orange token and below 50% a red token - all of which are computed token types around an attribute set. This functionality of computed tokens is very critical to understand as well.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4889886675981068094?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4889886675981068094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4889886675981068094' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4889886675981068094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4889886675981068094'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#4889886675981068094' title='Thoughts on Token Technology Trends- No: 8'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-KauMHjrIU1s/TriC8MTVdMI/AAAAAAAAEIU/Xb1ayGwrL8E/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4297442969470784471</id><published>2011-11-07T17:16:00.000-08:00</published><updated>2011-11-08T14:39:24.816-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT7'/><title type='text'>Thoughts on Token Technology Trends- No: 7</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-B_x1HkkjoRQ/TriA5YJ1CxI/AAAAAAAAEIM/76eIQ6UydlU/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-B_x1HkkjoRQ/TriA5YJ1CxI/AAAAAAAAEIM/76eIQ6UydlU/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;One of they key value proposition of token typing is the fact that we also have the notion of a hard token and a soft token - a TPM (trusted platform module) or a SIM card can act as a Hard token with tamper resistant memory footprint and an identifier (unique to the device) which can act as the "Initiating vector" for storing other soft tokens and token types or combining the same if needed. This is a critical concept to understand in this space as well.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4297442969470784471?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4297442969470784471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4297442969470784471' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4297442969470784471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4297442969470784471'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#4297442969470784471' title='Thoughts on Token Technology Trends- No: 7'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-B_x1HkkjoRQ/TriA5YJ1CxI/AAAAAAAAEIM/76eIQ6UydlU/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-272196326614379448</id><published>2011-11-07T17:04:00.000-08:00</published><updated>2011-11-08T14:39:44.974-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT6'/><title type='text'>Thoughts on Token Technology Trends- No: 6</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-CNPVac5mWWk/Trh_M__1SHI/AAAAAAAAEIE/cRGMN7BVwFQ/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-CNPVac5mWWk/Trh_M__1SHI/AAAAAAAAEIE/cRGMN7BVwFQ/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;One of the extreme use cases according to some (not me) is to create an RBAC token or RBAC tokenization -- at runtime any tokenized artifact is a XML file with condensed attributes and meta-data. From that perspective RBAC profiles have been XML'ized for close to a decade now and therefore they can be tokenized as well into&lt;a href="http://accelconf.web.cern.ch/accelconf/ica07/PAPERS/TPPA04.PDF"&gt; RBAC tokens&lt;/a&gt;. These tokens unlike AuthN token are considered to be Access Tokens (and an RBACtoken type is only one amongst many in this space). Please read the paper in the link above that describes the usage of RBAC tokens. Note: at run time this XML artifact (an RBACtoken) is also encrypted -so secure exchange is possible.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-272196326614379448?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/272196326614379448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=272196326614379448' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/272196326614379448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/272196326614379448'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#272196326614379448' title='Thoughts on Token Technology Trends- No: 6'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-CNPVac5mWWk/Trh_M__1SHI/AAAAAAAAEIE/cRGMN7BVwFQ/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7004158365261409707</id><published>2011-11-07T16:51:00.000-08:00</published><updated>2011-11-08T14:39:59.168-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT5'/><title type='text'>Thoughts on Token Technology Trends- No: 5</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-DzN80oRpxPg/Trh6znYTo-I/AAAAAAAAEH8/6Z7zW1VCnkQ/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-DzN80oRpxPg/Trh6znYTo-I/AAAAAAAAEH8/6Z7zW1VCnkQ/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;One perceived definition of token or a&lt;a href="http://en.wikipedia.org/wiki/Security_token"&gt; "security token"&lt;/a&gt; is that it is an authentication token (like a OTP token, Biometric token, SmartCard token or Kerberos token, etc). In our 100 entry description of the technology trends in tokens, tokenization and STS - we take a broader picture around tokens that go FAR beyond what is traditionally understood as token (authN tokens) - based on the definitions and token type description in the previous 4 entries. AuthN tokens are a critical piece however if we take an basket of tokens - they would represent only 10 to 20% of the token types. This again has to be kept in mind BIG Time!!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7004158365261409707?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7004158365261409707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7004158365261409707' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7004158365261409707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7004158365261409707'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#7004158365261409707' title='Thoughts on Token Technology Trends- No: 5'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-DzN80oRpxPg/Trh6znYTo-I/AAAAAAAAEH8/6Z7zW1VCnkQ/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-8263292143940666223</id><published>2011-11-07T16:40:00.000-08:00</published><updated>2011-11-08T14:40:10.838-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT4'/><title type='text'>Thoughts on Token Technology Trends- No: 4</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-mdYa309ILxQ/Trh5KHsluxI/AAAAAAAAEH0/UDQ8N8Vj1HQ/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://1.bp.blogspot.com/-mdYa309ILxQ/Trh5KHsluxI/AAAAAAAAEH0/UDQ8N8Vj1HQ/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Tokens represent Assured Attributes -- i.e., The attributes are from authoritative sources validated by control functions performed prior to the token generation - for example; A posture token generated by a&lt;a href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/PstrVal.pdf"&gt; Cisco ASA solution&lt;/a&gt; is generated after the validation control function of&amp;nbsp; multiple attribute sets about a device. The same is TRUE for all Token Types - i.e., whether it is a AuthN token or Access Token or a SAML token it does not matter. Therefore one definition of a Token is that it is an "Active Abstraction of Assured Attributes". This understanding of a token is also very critical in terms of synergies and synthesis that it can bring to the table. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8263292143940666223?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8263292143940666223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8263292143940666223' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8263292143940666223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8263292143940666223'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#8263292143940666223' title='Thoughts on Token Technology Trends- No: 4'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-mdYa309ILxQ/Trh5KHsluxI/AAAAAAAAEH0/UDQ8N8Vj1HQ/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5084286492497101323</id><published>2011-11-07T16:20:00.000-08:00</published><updated>2011-11-08T14:40:21.726-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT3'/><title type='text'>Thoughts on Token Technology Trends- No: 3</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-NuhTrlyCgWo/Trh0FI-spuI/AAAAAAAAEHs/KxE5etT8zfI/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://3.bp.blogspot.com/-NuhTrlyCgWo/Trh0FI-spuI/AAAAAAAAEHs/KxE5etT8zfI/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Another key trend to be noted is that there are many many token types in play within an Enterprise Security Architecture, namely;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Public Tokens vs Private Tokens&lt;/li&gt;&lt;li&gt; Standardized Tokens vs non-Standardized Tokens (SAML vs proprietory tokens)&lt;/li&gt;&lt;li&gt;Authentication Tokens vs Access Tokens&lt;/li&gt;&lt;li&gt;Subject Tokens vs Resource Tokens&lt;/li&gt;&lt;li&gt;Integrity Tokens vs Trust Tokens &lt;/li&gt;&lt;li&gt;Computed Token Types (many)&lt;/li&gt;&lt;li&gt;Risk Tokens (for subjects and resources)&lt;/li&gt;&lt;li&gt;Transaction Token Types (such as SWIFT Tokens)&lt;/li&gt;&lt;li&gt;Network Token Types (such as Posture tokens and Path tokens)&lt;/li&gt;&lt;li&gt;Decision Tokens and Obligatory Tokens&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;I have listed nine token types here and there are many more. Each is a topic for an blog entry, but there should be clear understanding of what a token means and the types that they can belong to. An STS development kit should be robust enough to work with all these token types and more that can be custom defined.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5084286492497101323?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5084286492497101323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5084286492497101323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5084286492497101323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5084286492497101323'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#5084286492497101323' title='Thoughts on Token Technology Trends- No: 3'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-NuhTrlyCgWo/Trh0FI-spuI/AAAAAAAAEHs/KxE5etT8zfI/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7985123892859028454</id><published>2011-11-07T16:12:00.000-08:00</published><updated>2011-11-08T14:40:32.388-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT2'/><title type='text'>Thoughts on Token Technology Trends- No: 2</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-b-Eer4AjD9c/TrhzsuX3QPI/AAAAAAAAEHk/O9CgNXrD3wM/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://4.bp.blogspot.com/-b-Eer4AjD9c/TrhzsuX3QPI/AAAAAAAAEHk/O9CgNXrD3wM/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;The decoupling of Authentication and Sessions with &lt;a href="http://www.oracle.com/technetwork/middleware/id-mgmt/oraclestswhitepaper-403633.pdf"&gt;Secure Token Services, is a another key technology trend&lt;/a&gt;. We are all familiar with many authentication mechanisms that generate a token type (bio-metric token or a SIM token, etc) - these independent Authenticating systems that authenticate an entity (user, device or application./service) generates a Authentication Token post successful Authentication and traditionally this was tightly tied to SSO services -such as WinSSO and Kerb token or Siteminder SSO and LDAP AuthN, etc. With the recent trend in terms of STS development - the secure token service is the service that accepts these tokens, creates a session token and does mapping and translaton of Tokens. Hence this technology trend in terms of decoupling Authenticating systems and Secure Token Services is a Key underlying technology trend that is extremely important to understand, tokens, token types, tokenization process, STS and more.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7985123892859028454?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7985123892859028454/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7985123892859028454' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7985123892859028454'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7985123892859028454'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#7985123892859028454' title='Thoughts on Token Technology Trends- No: 2'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-b-Eer4AjD9c/TrhzsuX3QPI/AAAAAAAAEHk/O9CgNXrD3wM/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6428095987414046346</id><published>2011-11-07T16:03:00.000-08:00</published><updated>2011-11-08T14:40:42.792-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTT1'/><title type='text'>Thoughts on Token Technology Trends- No: 1</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-31XcJ8btALQ/TrhtL5ObDCI/AAAAAAAAEHc/K7cq2SihuXo/s1600/sts.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="127" src="http://2.bp.blogspot.com/-31XcJ8btALQ/TrhtL5ObDCI/AAAAAAAAEHc/K7cq2SihuXo/s200/sts.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;From this blog entry onwards I am challenging myself to post 100 entries and a 100 perspectives on Tokens, Tokenization and STS (Secure Token Services) - meaning each one is a unique perspective on this Technology Trend within the next 100 days !! So here it goes:&lt;br /&gt;&lt;br /&gt;I grew up in chennai india - where every time we walked up to our family doctors clinic - we were given a token (since there were several dozen patients waiting in line). This token was cryptic - in a sense - since its had numbers and colors and certain markings in it. As i learn't later in life - the colors depicted - whether you were really sick or was it something that can wait, whether you were man or a woman, aged or young and more. The numbers reflected you turn - and there were multiple queues. Also in certain cases - a patient would be given preference either because they come from a privileged family (special tokens) or if they had called in advance (we typically walked in hoping&amp;nbsp; to have a wait time of less than an hr). Taking this analogy; a token has 5 characteristics - True for the Token relating to the Technology Trend we'll be discuss in these blogs as well;&lt;br /&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Tokens represent an Attribute Set (token types) -compressed or condensed - for example Perimeter host admission control solutions validate 60+ attributes about a device and then create a posture token (3 or 4 types - that reflects the Attribute sets)&lt;/li&gt;&lt;li&gt; Tokens have some meta-data based on their characteristics (for example in the analogy above - green could mean sick boy, blue could mean sick girl, yellow sick adult man and red sick adult woman and more)&lt;/li&gt;&lt;li&gt;Tokens are Cryptic - meaning that if you are not briefed in advance - all the substance in the token will mean nothing to you (in our technology trend they are encrypted and compressed -secure exchange)&lt;/li&gt;&lt;li&gt;Tokens represent Attributes with some level of Assurance -Attribute Assurance - since they are based on successfull execution of some control function&lt;/li&gt;&lt;li&gt;Tokens are generated at run time and have real time characteristics of a state of an Entity (entity can be subject or a resource or an action or condition) - real time representation of entities.&lt;/li&gt;&lt;/ul&gt;This is the basis for all the next 99 entries and therefore - it is imperative to&amp;nbsp; DIGEST this understanding of what Token represents!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6428095987414046346?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6428095987414046346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6428095987414046346' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6428095987414046346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6428095987414046346'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_11_01_archive.html#6428095987414046346' title='Thoughts on Token Technology Trends- No: 1'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-31XcJ8btALQ/TrhtL5ObDCI/AAAAAAAAEHc/K7cq2SihuXo/s72-c/sts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2594631827286265258</id><published>2011-10-13T15:56:00.000-07:00</published><updated>2011-10-13T15:56:23.074-07:00</updated><title type='text'>Architecurual Alignment with Access Control</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-36-urhs-wqM/TpdoP4j42WI/AAAAAAAAEHE/0fWb5_66pBY/s1600/XACML.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://2.bp.blogspot.com/-36-urhs-wqM/TpdoP4j42WI/AAAAAAAAEHE/0fWb5_66pBY/s200/XACML.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;I just completed my CISSP training last week and it was very interesting to note that amongst the 10 modules - Access Control is one and it includes - all three areas of IAM, "Identification", "Authentication" and "Authorization". If Authorization decisions at run time are also leveraging audit data (historical behaviors for example" - then we might add the topic of Audit as well to the overall Access CONTROL space. To me that leads to XACML:&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;as the extensible XML based AC policy language,&amp;nbsp;&lt;/li&gt;&lt;li&gt;the framework (PEP, PDP, PIP, PMP, etc),&amp;nbsp;&lt;/li&gt;&lt;li&gt;the XACML request response paradigm (interfaces and integration),&amp;nbsp;&lt;/li&gt;&lt;li&gt;the XACML profiles (such as RBAC profile) and,&lt;/li&gt;&lt;li&gt; the SAML2XACML artifact that allows for the alignment of Authentication to Authorization at run time. &lt;/li&gt;&lt;/ul&gt;Just like how we saw the ID Federation (SAML) take off this past decade (2000-2010), this decade is the XACML decade&amp;nbsp; (2011-2020). If we view; applications plus services as one set of resources and data plus documents as another set of resources - the systems protecting apps/services are;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;XML firewalls (and we have support from IBM, Intel, Layer7 and majority of the vendors in this space that support XACML estensions&lt;/li&gt;&lt;li&gt;RBAC systems (majority of the RBAC implementations extend via XACML-RBAC profiles)&lt;/li&gt;&lt;li&gt;and Composite Risk Rating Engines (such as Sailpoint and Securonix) that generate XML artifacts that gets passed to a XACML PDP as a PIP&lt;/li&gt;&lt;/ul&gt;On the Data and Documentation side, we have an interesting scenario of some XACML vendors; the Top 5 being;&lt;br /&gt;Axiomatic&lt;br /&gt;Bitkoo&lt;br /&gt;IBM&lt;br /&gt;Oracle, and,&lt;br /&gt;Nextlabs&lt;br /&gt;&lt;br /&gt;beginning to support DB Firewalls and DRM systems(using XACML as a policy expression language)  (plus integration into DLP).&lt;br /&gt;&lt;br /&gt;All the NEP's (such as Cisco and Juniper) have the opportunity to create a specialized Network (perimeter) PDP - that unifies (UTM) - Deep Packet Inspection, with Packet FW, with Network Admission Controls and Intrusion Detection Systems - and generate Network Threat and Device Integrity Information (acting as a PIP) to the Enterprise Data+App PDP. This approach kinda ensures the REALIZATION of the Vision established by XACML as a Pervasive Policy Paradigm for an Enterprise Security Architecture !!&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2594631827286265258?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2594631827286265258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2594631827286265258' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2594631827286265258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2594631827286265258'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_10_01_archive.html#2594631827286265258' title='Architecurual Alignment with Access Control'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-36-urhs-wqM/TpdoP4j42WI/AAAAAAAAEHE/0fWb5_66pBY/s72-c/XACML.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5031899738597466590</id><published>2011-04-23T19:28:00.000-07:00</published><updated>2011-04-23T19:28:44.266-07:00</updated><title type='text'>The AAA Aligned to AAA</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="separator" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-Nw1WkDD_iZs/TbOERtdKwHI/AAAAAAAAEEc/cPvHcGMWIg0/s1600/ibmesa.jpg" /&gt;&lt;/div&gt;I remember reviewing this IBM&lt;a href="http://www.freebookzone.com/goto.php?bkcls=rb_rbdft&amp;amp;bkidx=95&amp;amp;lkidx=1"&gt; redbook on ESA &lt;/a&gt;a few years back and thinking about how an IAM (identity and access management) stack play's an important and critical role for Enterprise Security Architecture. I've just started a few weeks back at the Bank of America as a VP., Sr. IAM Architect in the Enterprise Security Architecture group. An amazing organization with a number of enterprise scale security projects going on (Six Sigma Security). I will have very little time to blog moving forward. My 1st paper at the organization along with a few others talks to the AAA behind AAA from Radius to an Integrated IDM Infrastructure. RADIUS was good a few decades back when we had a few remote dial up users and with almost all (employees, customers and suppliers) users in today's cloud, outsourced and highly mobile environments,&amp;nbsp; is remote and mobile accessing services under varying conditions (context), accessing services from a cloud data centers managed by operations outsourced to Asia and more., makes an Integrated IDM Infrastructure even more critical for distributed systemic security services;&lt;br /&gt;&lt;br /&gt;AAA behind AAA:&lt;br /&gt;Admission Control (Analysis, Acceptance and then Admission)&lt;br /&gt;Authentication (Authenticity of credentials, Adaptive AuthN, etc)&lt;br /&gt;Assertion (Assertion of tokens including authN Attestation and authN Assurance)&lt;br /&gt;(all three making up the 1st A)&lt;br /&gt;Attribute Aggregation (Assimilation of pre-authN, post AuthN, pre-AuthZ Attributes) &lt;br /&gt;Authorization (entitlement data, privileges, permissions and more)&lt;br /&gt;Access Control (run-time RBAC, ABAC, Risk, context driven, etc)&lt;br /&gt;(all three making up the 2nd A)&lt;br /&gt;Activity Monitoring (end to end log based RT monitoring)&lt;br /&gt;Accounting (metering, measuring and billing)&lt;br /&gt;Auditing (compliance reporting and certification)&lt;br /&gt;(all three make up the 3rd A)&lt;br /&gt;&lt;br /&gt;The paper will have functional decomposition of each of the 9 A's, inter-relationships between them, flow diags, etc. An amazing place to work at, an amazing area to focus on (IAM and ESA), an amazing team to work with.. Its going to be the best years of my career!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5031899738597466590?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5031899738597466590/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5031899738597466590' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5031899738597466590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5031899738597466590'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2011_04_01_archive.html#5031899738597466590' title='The AAA Aligned to AAA'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Nw1WkDD_iZs/TbOERtdKwHI/AAAAAAAAEEc/cPvHcGMWIg0/s72-c/ibmesa.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1835319677961676064</id><published>2010-09-29T03:36:00.000-07:00</published><updated>2010-09-29T03:36:13.895-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OCCC'/><title type='text'>Oracle'c Cloud Computing Center</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_RI178MJjsuE/TKMSi_-49mI/AAAAAAAAEBE/x4A7XuLmNTQ/s1600/cloud-feature-bg.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_RI178MJjsuE/TKMSi_-49mI/AAAAAAAAEBE/x4A7XuLmNTQ/s1600/cloud-feature-bg.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Last week at OOW I had the chance to present "Context Aware Security for Cloud Control and Compliance" along with some friends at Verizon. It was an Amazing week since Oracle announced an array of products and solutions in support of our &lt;a href="http://www.oracle.com/us/technologies/cloud/index.htm"&gt;Cloud Computing Strategy.&lt;/a&gt; From &lt;a href="https://event.on24.com/eventRegistration/EventLobbyServlet?target=registration.jsp&amp;amp;eventid=244865&amp;amp;sessionid=1&amp;amp;key=7C946C00C82CA0F93EA4E95A5A6BA196&amp;amp;partnerref=ohm&amp;amp;sourcepage=register"&gt;ExaLogic EC&lt;/a&gt; -the cloud in a box solution for IAAS, PAAS and SAAS, to the next generation of &lt;a href="http://www.oracle.com/us/products/database/database-machine/index.html"&gt;ExaData&lt;/a&gt; for Storage AAS and DB AAS, to the &lt;a href="http://www.oracle.com/us/corporate/features/sparc-t3-feature-173454.html"&gt;Niagara T3 CMT processors&lt;/a&gt; and systems based on T3 (ideally suited for Cloud Security and Control Applications - that are &lt;a href="http://www.oracle.com/technetwork/server-storage/solarisstudio/documentation/oss-parallel-programs-170709.pdf"&gt;parallel in nature&lt;/a&gt; -see paper). There are a &lt;a href="http://www.oracle.com/us/technologies/cloud/index.htm"&gt;number of excellent papers and webcasts here&lt;/a&gt; that discuss everything cloud;&lt;br /&gt;Cloud Strategy&lt;br /&gt;Cloud Computing and EA&lt;br /&gt;Cloud Management&lt;br /&gt;Cloud API&lt;br /&gt;Public vs Private Clouds&lt;br /&gt;and more..&lt;br /&gt;&lt;br /&gt;My next dozen plus blog entries will be around "Context Aware Security for Cloud Control &amp;amp; Compliance". &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1835319677961676064?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1835319677961676064/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1835319677961676064' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1835319677961676064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1835319677961676064'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_09_01_archive.html#1835319677961676064' title='Oracle&apos;c Cloud Computing Center'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/TKMSi_-49mI/AAAAAAAAEBE/x4A7XuLmNTQ/s72-c/cloud-feature-bg.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4136416045704827247</id><published>2010-07-01T06:51:00.000-07:00</published><updated>2010-07-07T21:37:52.975-07:00</updated><title type='text'>The Intersection of IDM and IN</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_RI178MJjsuE/TCybF0oPNJI/AAAAAAAAD_w/1UjDQi_Tlck/s1600/mobilecloud.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="117" src="http://1.bp.blogspot.com/_RI178MJjsuE/TCybF0oPNJI/AAAAAAAAD_w/1UjDQi_Tlck/s200/mobilecloud.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;My 2nd paper is around the integration and intersection of different Intelligence data both Network facing, IT facing and Business facing around a common identity management layer. Mobile Cloud Operators have unique advantages in the Cloud Control and Compliance space due to the visibility and transparency they have on both ends. Here is a nice writeup on the &lt;a href="http://www.itbusinessedge.com/cm/community/features/guestopinions/blog/the-intersection-of-business-intelligence-and-identity-management-identity-governance/?cs=39024"&gt;Intersection of IDM and BI&lt;/a&gt; from a GRC perspective. Oracle with its complimentary solutions around an Integrated Identity Infrastructure that includes DB Security, MDM, GRC, BI and NI products is again well positioned here. Its already possible to Integrate Network Intelligence and Business Intelligence with a common Identity Infrastructure today (to a certain extent) and since the Cloud Paradigm converges and collapses the Business and Network layer into ONE, any Cloud Initiative will require this end to end IN integration. This approach is also facilitated by SEIM software (such as the ones from our partner LogLogic) that collects Logs end to end and applies Logic on top for Security Events and Information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4136416045704827247?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4136416045704827247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4136416045704827247' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4136416045704827247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4136416045704827247'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_07_01_archive.html#4136416045704827247' title='The Intersection of IDM and IN'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/TCybF0oPNJI/AAAAAAAAD_w/1UjDQi_Tlck/s72-c/mobilecloud.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-237535883554331087</id><published>2010-07-01T06:39:00.000-07:00</published><updated>2010-07-01T06:39:14.879-07:00</updated><title type='text'>Charging for Cloud Computing Services</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_RI178MJjsuE/TCyXSrKnNYI/AAAAAAAAD_o/PuDrOMqYVTw/s1600/mobilecloud.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="117" src="http://4.bp.blogspot.com/_RI178MJjsuE/TCyXSrKnNYI/AAAAAAAAD_o/PuDrOMqYVTw/s200/mobilecloud.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Oracle is a market leader in terms of Integrated Identity Infrastructure Implementations in Telco's (mobile operators) worldwide. These Telco's are all gearing up for Mobile Cloud Computing initiatives.. I just delivered a Keynote at the SIMposium 2010 in Rome yesterday and folks here clearly view SIM+SCWS+Secure Contained Client Code+JC 3.0 as a PEP (policy enforcement point and a programmable end point) as the ideal Cloud Client. Another important perspective when offering SAAS, PAAS, IAAS, etc., is the flexible, open, robust charging and billing models that are required for all the IP Cloud Services. Here is an &lt;a href="http://bit.ly/dj2kld"&gt;excellent presentation via webex&lt;/a&gt; from Paul and Elisabeth on how well Oracle's BRM is positioned for these large scale Cloud Initiatives from a Charging and BRM perspective - and how well they can support different business models and revenue recognition models. I am working on a series of 5 papers (that would eventually transition into my "Identity and Trust" book on - Cloud Control and Compliance with a number of Industry coauthors) and the 1st one is on the significance and importance of an Integrated ID Infrastructure from a charging and billing perspective for Cloud Services. The obvious ones are;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Mediation between Operator as an IDP and ASP/SAAS as a SP is facilitated with federation&lt;/li&gt;&lt;li&gt;Revenue Assurance is aligned to ID Assurance levels&lt;/li&gt;&lt;li&gt;Mobile wallet is a PEP for a PDP&lt;/li&gt;&lt;li&gt;Fraud Detection &amp;amp; Risk Based AC for Billing - Transaction level AAA&lt;/li&gt;&lt;li&gt;Pre-pay, post pay, pay per use and other pricing models - aligned to Roles and Responsibilities&lt;/li&gt;&lt;li&gt;Integration with AAA, Radius, Diameter, etc&lt;/li&gt;&lt;li&gt;Access Control - DRM -content/IPTV/services tied back to payments&lt;/li&gt;&lt;li&gt;Log Data from III for non-repudiation and assurance&lt;/li&gt;&lt;li&gt;Consolidated Converged Charging is USER/ID Centric&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-237535883554331087?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/237535883554331087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=237535883554331087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/237535883554331087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/237535883554331087'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_07_01_archive.html#237535883554331087' title='Charging for Cloud Computing Services'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/TCyXSrKnNYI/AAAAAAAAD_o/PuDrOMqYVTw/s72-c/mobilecloud.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2008633989557058692</id><published>2010-06-06T18:52:00.000-07:00</published><updated>2010-12-03T16:53:42.666-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCCV'/><title type='text'>A Critical Cloud Control partner -Vordel</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_RI178MJjsuE/TPmRBZ9t2fI/AAAAAAAAEBQ/xVLlPpwiizM/s1600/vordel_hp_master_slice2_02.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="72" src="http://1.bp.blogspot.com/_RI178MJjsuE/TPmRBZ9t2fI/AAAAAAAAEBQ/xVLlPpwiizM/s200/vordel_hp_master_slice2_02.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://www.vordel.com/oracle/"&gt;Vordel, Oracle's key partner for Cloud Control &amp;amp; Compliance&lt;/a&gt; area, did an excellent presentation at Telco Cloud 2010 last week, and will be at the E-Identity event next week as well. Check out the joint presentations and white papers, discussing the integration between Vordel's Cloud Control product Oracle's Identity Infrastructure products, Oracle DB and Oracle's Enterprise Manager. There are both common Telco and NEP customers who will benefit hugely with this Integrated Approach for their Cloud Control Initiatives!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2008633989557058692?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2008633989557058692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2008633989557058692' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2008633989557058692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2008633989557058692'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_06_01_archive.html#2008633989557058692' title='A Critical Cloud Control partner -Vordel'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/TPmRBZ9t2fI/AAAAAAAAEBQ/xVLlPpwiizM/s72-c/vordel_hp_master_slice2_02.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6363976986626759026</id><published>2010-06-03T08:31:00.000-07:00</published><updated>2010-06-03T08:33:04.845-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCC'/><title type='text'>Cloud Computing Conference</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.iir-telecoms.com/appdata/event/cloud/logo_homepage.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="55" src="http://www.iir-telecoms.com/appdata/event/cloud/logo_homepage.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Another &lt;a href="http://www.iir-telecoms.com/event/cloud"&gt;Telco Cloud Services event in London the week of June 15th&lt;/a&gt;. The original one was scheduled for April and was later postponed to June (due to volcanic ash).. An amazing amount of momentum from Operators such as BT and FT in terms of starting Cloud Initiatives and a great lineup of NEP's to support the operators including Cisco, ALU, NEC and others.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6363976986626759026?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6363976986626759026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6363976986626759026' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6363976986626759026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6363976986626759026'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_06_01_archive.html#6363976986626759026' title='Cloud Computing Conference'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5040909158875714656</id><published>2010-05-24T20:30:00.000-07:00</published><updated>2010-05-25T18:41:09.085-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CIA4CC'/><title type='text'>CIA for Cloud Computing</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_RI178MJjsuE/S_s-wHmYExI/AAAAAAAAD5Y/pgOTwUMgWQw/s1600/logo.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="55" src="http://2.bp.blogspot.com/_RI178MJjsuE/S_s-wHmYExI/AAAAAAAAD5Y/pgOTwUMgWQw/s200/logo.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Oracle announced the acquisition of &lt;a href="http://www.secerno.com/"&gt;Secreno&lt;/a&gt; a Database Firewall software company, a few days back. An excellent acquisition that compliments &lt;a href="http://www.oracle.com/database/database-vault.html"&gt;Data Vault&lt;/a&gt; , &lt;a href="http://www.oracle.com/enterprise_manager/data-masking.html"&gt;Data Masking&lt;/a&gt; and other related Security solutions from Oracle, that are key enablers of Data level security in a Cloud Model. From my perspective similar to the application (XML) firewall solutions from our partners such as &lt;a href="http://www.layer7tech.com/"&gt;Layer 7&lt;/a&gt; and &lt;a href="http://vordel.com/"&gt;Vordel&lt;/a&gt;, along with traditional &lt;a href="http://en.wikipedia.org/wiki/Firewall_%28computing%29"&gt;Network Firewalls&lt;/a&gt;, the combination of these firewalls integrated and aligned to an Identity Stack (i.e., they are session aware, white listed, id context aware,&amp;nbsp; integrity checks, assurance level aware, and more), offers the defense in depth for cloud services. If this is one area of alignment, the other perspective is the alignment of network integrity, with code integrity (apps and VM) and data integrity, plus device integrity with an Identity Stack, to meet QOS and SLA requirements of a Managed Cloud Service provider. Taking this approach we can address the CIA (confidentiality, integrity and availability) for Cloud Computing. The availability aspect goes beyond disaster recovery and traditional HA designs to include - &lt;a href="http://identity-centric-architecture.blogspot.com/search?q=SCIT"&gt;self cleansing intrusion tolerant (SCIT)&lt;/a&gt; based specialized VM's that are tightened, tweaked and tuned to offer specific services. A clean and tolerant VM executing my service for my given session and recycled when my session terminates (hence again integrated to the ID stack). Within my one authenticated session I could invoke multiple federated VM sessions that execute services on my behalf and are terminated (based on the security sensitivity of the service consumed) when my user level session terminates. This approach introduces true Mobility to Cloud Computing that covers User Mobility, Device Mobility, Session Mobility, Network Mobility and Service Mobility!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Systemic Security (Services) for Cloud Computing is achieved only when there is intelligent&lt;br /&gt;linkage between all security systems with a core Identity Infrastructure.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5040909158875714656?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5040909158875714656/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5040909158875714656' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5040909158875714656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5040909158875714656'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_05_01_archive.html#5040909158875714656' title='CIA for Cloud Computing'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S_s-wHmYExI/AAAAAAAAD5Y/pgOTwUMgWQw/s72-c/logo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5359446509775411332</id><published>2010-05-24T09:11:00.000-07:00</published><updated>2010-05-24T09:11:03.114-07:00</updated><title type='text'>Mobility Context, Cloud Mobility and MAAS</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_RI178MJjsuE/S_qjMaYz8hI/AAAAAAAAD5M/RKVFMb9_jQw/s1600/cloudmob_banner_bg.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="42" src="http://1.bp.blogspot.com/_RI178MJjsuE/S_qjMaYz8hI/AAAAAAAAD5M/RKVFMb9_jQw/s200/cloudmob_banner_bg.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Similar to the description given by &lt;a href="http://www.maas360.com/fiberlink/en-US/mobilityAsAService/"&gt;MAAS here&lt;/a&gt;, the flexibility offered by Cloud Computing and Cloud Service when married with the Mobility aspects (anytime, anywhere, any device), Identity, Policy, Security, Control, Compliance, Session, Trust, and other related IDM services becomes a CENTRAL enabler on both fronts (on the Infrastructure and Service side and the mobile broadband access network side as well).. Informa is putting together a great event in &lt;a href="http://www.cloud-mobility.com/"&gt;September 2010&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5359446509775411332?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5359446509775411332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5359446509775411332' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5359446509775411332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5359446509775411332'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_05_01_archive.html#5359446509775411332' title='Mobility Context, Cloud Mobility and MAAS'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/S_qjMaYz8hI/AAAAAAAAD5M/RKVFMb9_jQw/s72-c/cloudmob_banner_bg.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6377739146544105659</id><published>2010-05-23T15:18:00.000-07:00</published><updated>2010-05-23T15:31:59.264-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCClouds'/><title type='text'>Cloud Control and Compliance</title><content type='html'>&lt;div class="separator" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="103" src="http://3.bp.blogspot.com/_RI178MJjsuE/S_mqXbfi3KI/AAAAAAAAD5E/QptiQUdR-bQ/s200/cloudtelcofixe.jpg" width="200" /&gt;&lt;/div&gt;June is a hectic month for me.. Two keynotes and a presentation plus panel participation. The 1st one is at Paris for the Telco Cloud event, directly relevant to the work we are doing at Oracle as an NEP partner of companies such as Cisco, Ericsson, Juniper and others around "&lt;a href="http://www.upperside.fr/cloudtelco2010/cloudtelco2010program.htm"&gt;Cloud Control and Compliance&lt;/a&gt;". My presentation will reflect the alliance and partnership that we have with Cisco and specific ISV partners, in this space. The 2nd presentation is the Closing Keynote "&lt;a href="http://www.revolutionevents.plus.com/eema/index.htm"&gt;Identity, Policy and Context for Cloud Services&lt;/a&gt;" at eema IDM event in London the 2nd week of June. The 3rd one is an Opening Keynote the last week of June in Rome at the &lt;a href="http://www.simposiumglobal.com/"&gt;SIMposium 2010&lt;/a&gt; around the topics of SIM, JavaCard 3, SCWS (smart card web server), Integrated ID stack and more.. (Bootstrapping the mobile with Cloud Services). The &lt;a href="http://www.clickgreen.org.uk/news/international-news/121349-ash-cloud-forecast-confirms-a-clear-travel-week-as-volcano-remains-quiet.html"&gt;Clouds will hopefully cooperate&lt;/a&gt;!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6377739146544105659?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6377739146544105659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6377739146544105659' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6377739146544105659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6377739146544105659'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_05_01_archive.html#6377739146544105659' title='Cloud Control and Compliance'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/S_mqXbfi3KI/AAAAAAAAD5E/QptiQUdR-bQ/s72-c/cloudtelcofixe.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2380712648331006339</id><published>2010-04-20T06:42:00.000-07:00</published><updated>2010-04-20T07:03:34.429-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AAAssurance'/><title type='text'>Asserting Attributes for Assurance</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/identity"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 133px; height: 18px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S82v5Nmk7uI/AAAAAAAAD2M/f1pWmw_1a9E/s200/oralogo_small.gif" alt="" id="BLOGGER_PHOTO_ID_5462215320509148898" border="0" /&gt;&lt;/a&gt;One of the core areas where the Alignment of Attribute Authorities is imperative is the area where the attributes are asserted for changing assurance levels, pre-authentication and post authentication for Attribute Based Access Control. If one's identity is a "Construct of Credentials within a Context" that construct of credentials (an assimilation of attributes or credentials) can vary from simply leveraging SIM like authentication, SIM plus a Location Attribute, SIM plus a location and a PIN, SIM plus a location and a PIN plus voice, SIM plus a location and a PIN plus voice plus a Attribute Authority validating citizenship, and more. The Attribute Authorities are asserting attributes as authoritative sources of those attributes, such as a mobile operator and a device location, a Device Reputation Authority and the attributes pertaining to the device capabilities, a 3rd party Attribute Authority asserting prior institutional decisions taken about a user, etc. etc,. These attribute authorities are also viewed as federated databases (large and high throughput) that can exchange attributes securely at lightning speeds. This alignment of attribute authorities in network can also be viewed as;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The NG IP Intelligence Layer between the User &amp;amp; the Services/Content he/she consumes&lt;/li&gt;&lt;li&gt;A more advanced Context Layer for contextual composition of all IP services&lt;/li&gt;&lt;li&gt;The Identity, Policy + Control Layer - since control is for an identity and abides by policies&lt;/li&gt;&lt;li&gt;A meta layer - that can host mapping profiles and an abstracted set of information&lt;/li&gt;&lt;li&gt;A more advanced &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/SSSAB"&gt;routing, switching, bridging, gateway-ing, repeating, accelerating layer&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;This is the area where Oracle's collaboration with ISV and NEP (such as Cisco, Ericsson and NSN) will benefit the communication, media and entertainment industry.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2380712648331006339?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2380712648331006339/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2380712648331006339' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2380712648331006339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2380712648331006339'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_04_01_archive.html#2380712648331006339' title='Asserting Attributes for Assurance'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S82v5Nmk7uI/AAAAAAAAD2M/f1pWmw_1a9E/s72-c/oralogo_small.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7770893190753529310</id><published>2010-04-06T14:11:00.001-07:00</published><updated>2010-04-06T15:37:11.122-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='GGGRC'/><title type='text'>Genesis for Global eGovernance</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://egov.epfl.ch/"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 82px; height: 23px;" src="http://3.bp.blogspot.com/_RI178MJjsuE/S7ujmND9qAI/AAAAAAAAD0Y/KnrPDdhQuC0/s200/epfl_logo.gif" alt="" id="BLOGGER_PHOTO_ID_5457135250226128898" border="0" /&gt;&lt;/a&gt;&lt;a href="http://www.oracle.com/us/solutions/corporate-governance/index.htm"&gt;GRC (governance, risk management and compliance) programs&lt;/a&gt; typically leverage an Integrated Identity Infrastructure along with the People, Processes and Technologies that go with it. To me the trends towards technology based transnational transparency initiatives, including the many Transparency programs put in place by the Obama Administration, will be the &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/obamabiden"&gt;Genesis towards a Global e-Governance&lt;/a&gt; model, that will encourage more open, participative and collaborative environment for &lt;a href="http://www.dni.gov/nic/PDF_2025/2025_Global_Trends_Final_Report.pdf"&gt;Governance&lt;/a&gt;. This is the topic of my 4th book "Identity and Transparency" the Genesis for Global eGovernance (2012). I am truly amazed at the pace at which this administration (including the CIO Vivek Kundra and CTO Aneesh Chopra) is putting in place major &lt;a href="http://blog.sunlightfoundation.com/taxonomy/term/vivek-kundra/"&gt;transparency programs&lt;/a&gt;, both national and trans-national.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7770893190753529310?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7770893190753529310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7770893190753529310' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7770893190753529310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7770893190753529310'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_04_01_archive.html#7770893190753529310' title='Genesis for Global eGovernance'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/S7ujmND9qAI/AAAAAAAAD0Y/KnrPDdhQuC0/s72-c/epfl_logo.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4083357564987964706</id><published>2010-04-06T13:59:00.000-07:00</published><updated>2010-04-06T14:08:27.896-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pppp'/><title type='text'>Prosperity Phenomenon - a Paradigm of the Past</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_RI178MJjsuE/S7ug9fHsedI/AAAAAAAAD0Q/Ks3rtYMtDaU/s1600/oneworld.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 69px; height: 69px;" src="http://3.bp.blogspot.com/_RI178MJjsuE/S7ug9fHsedI/AAAAAAAAD0Q/Ks3rtYMtDaU/s200/oneworld.jpg" alt="" id="BLOGGER_PHOTO_ID_5457132351675726290" border="0" /&gt;&lt;/a&gt;After posting my blog entry on Africa - I was wondering why we face these economic cycles within nations and why cant there be prosperity in a global scale. After all one's prosperity is highly intertwined and interlinked with others prosperity (new markets, increased specializations and efficiency in resource consumption and more)..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.huffingtonpost.com/sri-sri-ravi-shankar/values-elusive-reality_b_526793.html?ref=fb&amp;amp;src=sp"&gt;" History has shown us that when some parts of the world prosper, others  often don't. For instance, in the 1600, when India and China were  thriving, Europe was at a low; when Europe was on top of the world, Asia  was down; when Europe and Asia were on the decline, the United States  was on the rise; and while the rest of the world is still struggling to  recover from the recession, Brazil, India and China seem to be forging  ahead. However, we need work together to make this phenomenon, where one  region prospers at the cost of another, a paradigm of the past. In  today's globalized world, international borders are porous, and the  inter-connectedness and inter-dependence of countries and regions is  obvious. The nature of today's challenges requires us to unite across  the world to come up with common solutions".&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;In this &lt;a href="http://www.dni.gov/nic/PDF_2025/2025_Global_Trends_Final_Report.pdf"&gt;highly globalized world&lt;/a&gt; - the genesis for global e governance will be the trend towards a technology based transnational transparency.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4083357564987964706?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4083357564987964706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4083357564987964706' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4083357564987964706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4083357564987964706'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_04_01_archive.html#4083357564987964706' title='Prosperity Phenomenon - a Paradigm of the Past'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/S7ug9fHsedI/AAAAAAAAD0Q/Ks3rtYMtDaU/s72-c/oneworld.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4620175418423862017</id><published>2010-03-31T19:28:00.000-07:00</published><updated>2010-03-31T19:36:57.655-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DIM2010'/><title type='text'>DIM 2010 - CFP open Colocated with CCS2010</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www2.pflab.ecl.ntt.co.jp/dim2010/"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 47px; height: 46px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S7QFSPXZDXI/AAAAAAAAD0I/l52uqZygfDM/s200/acmlogo.png" alt="" id="BLOGGER_PHOTO_ID_5454990859572940146" border="0" /&gt;&lt;/a&gt;As a proud lifetime member of ACM (almost 5 years now), it gives me great pleasure to provide this pointer to this upcoming ACM event - &lt;a href="http://www2.pflab.ecl.ntt.co.jp/dim2010/"&gt;DIM 2010&lt;/a&gt;; topics include:&lt;br /&gt;&lt;br /&gt;&lt;div style="width: 50%; float: left;"&gt; &lt;ul&gt;&lt;li&gt;Identity management for cloud computing&lt;/li&gt;&lt;li&gt;Identity management for critical infra&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Identity assurance&lt;/li&gt;&lt;li&gt;Identity governance&lt;/li&gt;&lt;li&gt;Attribute aggregation&lt;/li&gt;&lt;li&gt;Identity in service-oriented architecture&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Anonymity and pseudonymity&lt;/li&gt;&lt;li&gt;Accountability in identity management&lt;/li&gt;&lt;li&gt;Identity management APIs&lt;/li&gt;&lt;li&gt;IDM in ubiquitous and mobile computing&lt;/li&gt;&lt;li&gt;Reputation and incentive systems&lt;/li&gt;&lt;li&gt;Privacy-enhanced identity management&lt;/li&gt;&lt;li&gt;Identity-based access control&lt;/li&gt;&lt;li&gt;Identity discovery&lt;/li&gt;&lt;li&gt;Identity theft prevention&lt;/li&gt;&lt;li&gt;User-centric identity management&lt;/li&gt;&lt;li&gt;User experience models and integrity&lt;/li&gt;&lt;li&gt;Standardization of IDM and policies thereof, standards harmonization&lt;/li&gt;&lt;li&gt;Case studies and lessons from large scale deployment&lt;/li&gt;&lt;li&gt;Vulnerabilities, threat analysis and risk assessment of IDM  solutions (e.g., threat of malware affecting identity theft)&lt;/li&gt;&lt;li&gt;Analysis of differences between requirements for consumer and  enterprise IDM&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style="width: 50%; float: right;"&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4620175418423862017?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4620175418423862017/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4620175418423862017' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4620175418423862017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4620175418423862017'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_03_01_archive.html#4620175418423862017' title='DIM 2010 - CFP open Colocated with CCS2010'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S7QFSPXZDXI/AAAAAAAAD0I/l52uqZygfDM/s72-c/acmlogo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7263607726590554007</id><published>2010-03-16T18:24:00.000-07:00</published><updated>2010-03-16T19:18:31.409-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='USAFRICA'/><title type='text'>United States of Africa (Aligned with APAC and Americas)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.amazon.com/Africa-Rising-Million-African-Consumers/dp/0132339420/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1268788943&amp;amp;sr=8-1"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 75px; height: 75px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/S6AvjR8twWI/AAAAAAAADz8/o9PrfPunOm0/s200/ARising.jpg" alt="" id="BLOGGER_PHOTO_ID_5449407832278286690" border="0" /&gt;&lt;/a&gt;I reviewed a well written story and article in Fortune Magazine this week about the potential for the African Sub continent, that also had a quote about this 2008 Vijay Mahajan's book. Population exceeding a Billion, GDP exceeding a Trillion, huge land mass that is more than the land occupied by China, Europe and USA combined and all the natural resources that go along with it. The 1st thought that ran through my mind is how all the 50+ countries in this beautiful continent can come together as another&lt;a href="http://en.wikipedia.org/wiki/United_States_of_Africa"&gt; USA (United States of Africa).&lt;/a&gt;. also amongst the top 10 economies of the world. Similar to the strengths in the Union that is found in the EU or the US of A (America), there are huge synergies and power that comes with the Union and Federation of these 50+ countries in Africa. All the 50 plus nations combined can leverage common standards around commerce and cooperation.  Of course tourism is another huge industry opportunity as well.. from the Pyramids in the Egypt to the Safaris in Tanzania, Beaches in South Africa to the Kilimanjaro mountains and the Madagascar. I am going to get this book to read for my next flight. All 50+ nations can come together for a 1Billion+ African Identity Initiative as well (similar to the &lt;a href="http://uidai.gov.in/documents/Creating_a_unique_identity_for_every_resident_in_India.pdf"&gt;UIDAI project for the 1+ Billion citizens/residents of India&lt;/a&gt;).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7263607726590554007?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7263607726590554007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7263607726590554007' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7263607726590554007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7263607726590554007'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_03_01_archive.html#7263607726590554007' title='United States of Africa (Aligned with APAC and Americas)'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/S6AvjR8twWI/AAAAAAAADz8/o9PrfPunOm0/s72-c/ARising.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5458314809716720410</id><published>2010-03-08T05:45:00.001-08:00</published><updated>2010-03-08T05:47:19.041-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MMM2010'/><title type='text'>Must Attend event in May at Munich</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.id-conf.com/events/eic2010/agenda"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 22px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S5T_l_4y_SI/AAAAAAAADzM/qSbz6dIBGcg/s200/eic2010banner.jpg" alt="" id="BLOGGER_PHOTO_ID_5446258877667671330" border="0" /&gt;&lt;/a&gt;A premier IDM and GRC event in May 2010. Registration is OPEN!! Do not Miss it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5458314809716720410?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5458314809716720410/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5458314809716720410' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5458314809716720410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5458314809716720410'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_03_01_archive.html#5458314809716720410' title='Must Attend event in May at Munich'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S5T_l_4y_SI/AAAAAAAADzM/qSbz6dIBGcg/s72-c/eic2010banner.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6940540851534366004</id><published>2010-03-02T05:27:00.000-08:00</published><updated>2010-03-02T05:32:16.218-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CFPTPC'/><title type='text'>CFP - IEEE CS - Securing the Converged Mobile Internet</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://scmi2010.kt.agh.edu.pl/#home"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 25px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S40SfiYEAxI/AAAAAAAADys/lwSjG5xzF1E/s200/seccm.png" alt="" id="BLOGGER_PHOTO_ID_5444027857573774098" border="0" /&gt;&lt;/a&gt;Call for Papers Open for this very interesting IEEE Computer Society event on "&lt;a href="http://scmi2010.kt.agh.edu.pl/#home"&gt;Securing the Converged Mobile Internet&lt;/a&gt;".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6940540851534366004?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6940540851534366004/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6940540851534366004' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6940540851534366004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6940540851534366004'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_03_01_archive.html#6940540851534366004' title='CFP - IEEE CS - Securing the Converged Mobile Internet'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S40SfiYEAxI/AAAAAAAADys/lwSjG5xzF1E/s72-c/seccm.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-601018899762406897</id><published>2010-02-22T17:46:00.000-08:00</published><updated>2010-02-22T19:11:35.134-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AAAC'/><title type='text'>ABAC is Adaptive Access Control</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_RI178MJjsuE/S4MztSyi3fI/AAAAAAAADvQ/ZnnkGzZmq8U/s1600-h/OAAM2.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 74px; height: 55px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/S4MztSyi3fI/AAAAAAAADvQ/ZnnkGzZmq8U/s200/OAAM2.jpg" alt="" id="BLOGGER_PHOTO_ID_5441249628024659442" border="0" /&gt;&lt;/a&gt;I am working with a CEO/CTO of a start up ISV partner of Oracle, who is building a niche Trust (IDBE) functionality, on top of an &lt;a href="http://www.oracle.com/us/products/middleware/identity-management/index.htm"&gt;Integrated Identity Infrastructure from Oracle&lt;/a&gt;. We might get a chance to deliver some information on this strategic initiative as a Keynote soon. I also had a con call with the VP of product management for the &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_RI178MJjsuE/S4Mz24LTrwI/AAAAAAAADvY/YGaDdf33cSU/s1600-h/OAAM.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 74px; height: 54px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S4Mz24LTrwI/AAAAAAAADvY/YGaDdf33cSU/s200/OAAM.gif" alt="" id="BLOGGER_PHOTO_ID_5441249792679456514" border="0" /&gt;&lt;/a&gt;Identity Stack today with respect to a NEP/OEM integration. With STS (secure token services) and Fedlet integrated into the Oracle Stack (&lt;a href="http://www.oracle.com/technology/products/id_mgmt/pdf/idm_tech_wp_11g_r1.pdf"&gt;see latest Feb 2010 paper&lt;/a&gt;), there are some amazing values offered in just the integration of these components. I might also get a chance to deliver a Integrated ID Infrastructure, workshop at&lt;a href="http://www.pcw.co.uk/vnunet/news/2241280/bt-unveils-managed-security"&gt; BT in London in 2010.&lt;/a&gt; A chapter in the upcoming book "Identity and Context" covers the topic of an Integrated Identity Infrastructure leveraged for Context Aware Security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-601018899762406897?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/601018899762406897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=601018899762406897' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/601018899762406897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/601018899762406897'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#601018899762406897' title='ABAC is Adaptive Access Control'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/S4MztSyi3fI/AAAAAAAADvQ/ZnnkGzZmq8U/s72-c/OAAM2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2143915942059072426</id><published>2010-02-17T06:48:00.001-08:00</published><updated>2010-02-17T06:54:58.059-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OrGRC'/><title type='text'>Get Connected at GSMI's GRC Summit</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.thegrcsummit.com/agenda.php"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 150px; height: 36px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S3wBzwLAbBI/AAAAAAAADvI/Fln3Reb4iKE/s200/grcsummit" alt="" id="BLOGGER_PHOTO_ID_5439224438572739602" border="0" /&gt;&lt;/a&gt;Excellent event to learn all about end to end Governance, Risk Management and Compliance (GRC initiatives). With the acquisition of Amberpoint and it Agile Governance System, Oracle has a very comprehensive and compelling end to end &lt;a href="http://www.oracle.com/us/corporate/press/041986"&gt;solution to address GRC&lt;/a&gt; (IT governance, Application/Business Governance and Enterprise Governance).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2143915942059072426?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2143915942059072426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2143915942059072426' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2143915942059072426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2143915942059072426'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#2143915942059072426' title='Get Connected at GSMI&apos;s GRC Summit'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S3wBzwLAbBI/AAAAAAAADvI/Fln3Reb4iKE/s72-c/grcsummit' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5809443230078923467</id><published>2010-02-11T09:13:00.000-08:00</published><updated>2010-02-11T17:46:45.052-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cccc'/><title type='text'>CIO Council on Credentialing -ICAM</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_RI178MJjsuE/S3Q7Ul4nhRI/AAAAAAAADvA/uD33xolXDvc/s1600-h/idmbigpic.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 68px; height: 51px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S3Q7Ul4nhRI/AAAAAAAADvA/uD33xolXDvc/s200/idmbigpic.jpg" alt="" id="BLOGGER_PHOTO_ID_5437035875096036626" border="0" /&gt;&lt;/a&gt;Comprehensive Coverage of &lt;a href="http://www.idmanagement.gov/documents/FICAM_Roadmap_Implementation_Guidance.pdf"&gt;Identity Credentialing and Access Management&lt;/a&gt;, by the CIO council, in the latest report. After all Digital Identity is defined as a &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/CCCM"&gt;"Construct of Credentials for a Given Context"&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5809443230078923467?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5809443230078923467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5809443230078923467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5809443230078923467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5809443230078923467'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#5809443230078923467' title='CIO Council on Credentialing -ICAM'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S3Q7Ul4nhRI/AAAAAAAADvA/uD33xolXDvc/s72-c/idmbigpic.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-457291730916954589</id><published>2010-02-10T08:37:00.000-08:00</published><updated>2010-02-10T08:56:43.895-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cccc'/><title type='text'>Conextual Composition &amp; Convergent Charging</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/convergin/convergin-general-presentation.pdf"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 67px; height: 49px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S3LhD-7-k8I/AAAAAAAADu4/tT-c5yIj7do/s200/convergin.gif" alt="" id="BLOGGER_PHOTO_ID_5436655158740030402" border="0" /&gt;&lt;/a&gt;Wow - the&lt;a href="http://www.oracle.com/convergin/index.html"&gt; Global Communications Business Unit at Oracle&lt;/a&gt; is moving at Lightning speed. We just announced the acquisition of Convergin (a JEE/SCIM based Service Broker), that can compose converged services and handle complex charging model (prepay, post-pay, pay-per-use, etc.). Also read the new Oracle sponsored paper on &lt;a href="https://www.formrouter.net/forms@ORCL/048959.pdf"&gt;Converging on the Customer&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-457291730916954589?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/457291730916954589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=457291730916954589' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/457291730916954589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/457291730916954589'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#457291730916954589' title='Conextual Composition &amp; Convergent Charging'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S3LhD-7-k8I/AAAAAAAADu4/tT-c5yIj7do/s72-c/convergin.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5521039421252532695</id><published>2010-02-08T06:16:00.001-08:00</published><updated>2010-02-08T06:30:01.278-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AAAmber'/><title type='text'>Agile Application Governance Across All Platforms</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://amberpoint.com/platforms/platform_oracle.shtml"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 71px; height: 55px;" src="http://3.bp.blogspot.com/_RI178MJjsuE/S3Ac5fFTAlI/AAAAAAAADuw/FLtu3xbM1f8/s200/AP_for_Oracle300.jpg" alt="" id="BLOGGER_PHOTO_ID_5435876524158026322" border="0" /&gt;&lt;/a&gt;Given the solid integration that's already in place as an &lt;a href="http://amberpoint.com/platforms/platform_oracle.shtml"&gt;ISV partner for Oracle Fusion Middleware&lt;/a&gt;, todays news on &lt;a href="http://finance.yahoo.com/news/OracleR-Buys-iw-3438586922.html?x=0&amp;amp;.v=1"&gt;Oracle's Acquisition of Amberpoint&lt;/a&gt; should come in as very &lt;a href="http://www.oracle.com/amberpoint/index.html"&gt;good news&lt;/a&gt; for our common &lt;a href="http://amberpoint.com/casestudies/telecom.shtml"&gt;Telco install base&lt;/a&gt; (such as BT, Orange and Telcom Italia). Amberpoint is &lt;a href="http://www.amberpoint.com/products/standards.shtml"&gt;standards based&lt;/a&gt; that includes XACML.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5521039421252532695?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5521039421252532695/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5521039421252532695' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5521039421252532695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5521039421252532695'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#5521039421252532695' title='Agile Application Governance Across All Platforms'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/S3Ac5fFTAlI/AAAAAAAADuw/FLtu3xbM1f8/s72-c/AP_for_Oracle300.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2004962894574085861</id><published>2010-02-07T18:42:00.001-08:00</published><updated>2010-02-07T18:47:09.402-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RRRl'/><title type='text'>Reducing Risk and Revenue Losses</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_RI178MJjsuE/S296PjgN9QI/AAAAAAAADuo/wFadDySSKZU/s1600-h/customer-hub-large.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 76px; height: 66px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/S296PjgN9QI/AAAAAAAADuo/wFadDySSKZU/s200/customer-hub-large.gif" alt="" id="BLOGGER_PHOTO_ID_5435697682906477826" border="0" /&gt;&lt;/a&gt;Excellent paper that talks to the integration points between an Integrated Identity Infrastructure and &lt;a href="http://www.oracle.com/industries/communications/bill-rev-ready-wp.pdf"&gt;Revenue Assurance&lt;/a&gt;. I will hopefully get to present on the topic of "Identity, Policy and Context for Revenue Assurance" at this &lt;a href="http://www.billingworldexpo.com/2010/"&gt;upcoming local event&lt;/a&gt; on OSS/BSS.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2004962894574085861?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2004962894574085861/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2004962894574085861' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2004962894574085861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2004962894574085861'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#2004962894574085861' title='Reducing Risk and Revenue Losses'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/S296PjgN9QI/AAAAAAAADuo/wFadDySSKZU/s72-c/customer-hub-large.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6185527865866819484</id><published>2010-02-07T18:15:00.000-08:00</published><updated>2010-02-07T18:25:11.580-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCConv'/><title type='text'>Identity, Policy &amp; Context Centric Convergence</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_RI178MJjsuE/S290Cgi2GbI/AAAAAAAADug/dMKQvRreMTU/s1600-h/swift.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 63px; height: 47px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S290Cgi2GbI/AAAAAAAADug/dMKQvRreMTU/s200/swift.jpg" alt="" id="BLOGGER_PHOTO_ID_5435690861704124850" border="0" /&gt;&lt;/a&gt;Excellent paper by SWIFT on &lt;a href="http://www.ist-swift.org/component/option,com_docman/task,doc_download/gid,20/Itemid,37/"&gt;"Identity as the Convergence Layer",&lt;/a&gt; which implies, Identity (authN authorities), Policy (authZ authorities) and Context (attribute authorities) as the layer that enables Customer or User Centric Convergence.&lt;br /&gt;&lt;br /&gt;The 5 industry standards initiatives around Identity for Communications Convergence includes;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.tmforum.org/IdentityManagement/7306/home.html"&gt;TMF Identity for NGOSS (IPSF also folded in)&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.itu.int/ITU-T/worksem/ngn/200612/index.html"&gt;ITU T work on Identity and Security for Telco&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://xml.coverpages.org/ETSI-IdM.html"&gt;ETSI for Identity and Profile Management&lt;/a&gt; (GUP, SUP, DUP, etc.)&lt;/li&gt;&lt;li&gt;&lt;a href="http://kantarainitiative.org/confluence/display/telcoid/Charter"&gt;Kantara WG on Telco IDM&lt;/a&gt; (and historical work done by Liberty Alliance)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.ist-swift.org/content/view/13/29/"&gt;SWIFT's work on Use Cases&lt;/a&gt; around IDM for NGN including Policies and Context&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6185527865866819484?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6185527865866819484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6185527865866819484' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6185527865866819484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6185527865866819484'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#6185527865866819484' title='Identity, Policy &amp; Context Centric Convergence'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S290Cgi2GbI/AAAAAAAADug/dMKQvRreMTU/s72-c/swift.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6584493659479812249</id><published>2010-02-07T17:05:00.000-08:00</published><updated>2010-02-07T17:53:37.857-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCCOracle'/><title type='text'>Customer's Context Centric Convergence &amp; Consolidation</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/us/industries/communications/018751.htm"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 69px; height: 60px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/S29jo0SAhJI/AAAAAAAADuY/jAlQR4r8NUU/s200/customer-hub-large.gif" alt="" id="BLOGGER_PHOTO_ID_5435672828139570322" border="0" /&gt;&lt;/a&gt;The more I learn around the value proposition that Oracle offers to the Telco Industry, the more I am excited to be working in the &lt;a href="http://www.oracle.com/us/industries/communications/018751.htm"&gt;Communication Global Business Unit&lt;/a&gt;. Through its massive set of acquisitions for the Telco vertical and the Identity Infrastructure space Oracle offers a big piece of the solution sets that would be required by the Carriers in this industry who are essentially facing three large scale challenges  (given the Convergence around IP - wireless+wireline convergence, Network+IT convergence, Voice+Data+Video convergence, Device Convergence, etc., and the massive transformation we see with a Global Broadband Wireless deployments), which include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Enabling &lt;a href="http://www.oracle.com/industries/communications/enable-convergence.html"&gt;Next Generation Service and Content Delivery&lt;/a&gt; (converged and contextual - relevant to each and every unique subscriber/customer needs)&lt;/li&gt;&lt;li&gt;Improve &lt;a href="http://www.oracle.com/industries/communications/improve-compliance.html"&gt;Cost Control and Compliance&lt;/a&gt; (heavily leveraging an Identity Infrastructure and containing costs both on the IT and Network side)&lt;/li&gt;&lt;li&gt;Drive &lt;a href="http://www.oracle.com/industries/communications/drive-customer-centric.html"&gt;Customer Centric Information Architecture&lt;/a&gt; (based on SOA)&lt;/li&gt;&lt;/ul&gt;Other than the &lt;a href="http://www.oracle.com/industries/communications/oracle-communications-services-delivery.html"&gt;software infrastructure products&lt;/a&gt; (communications SDP) that heavily integrate with a &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/IIIO"&gt;common identity infrastructure&lt;/a&gt;, for the infrastructure services it has to offer; all three major Applications offered for this vertical also leverage this common identity infrastructure in a very big way:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Billing and &lt;a href="http://www.oracle.com/industries/communications/communications-billing-revenue-management.html"&gt;Revenue Assurance&lt;/a&gt; heavily rely on an Identity Infrastructure as described in &lt;a href="http://www.oracle.com/industries/communications/bill-rev-ready-wp.pdf"&gt;this paper &lt;/a&gt;(including Risk BAC, Logging, Auditing, etc.)&lt;/li&gt;&lt;li&gt;The &lt;a href="http://www.oracle.com/industries/communications/oracle-communications-service-fulfillment-suite.html"&gt;OSS stack&lt;/a&gt; also leverages the Authentication and Authorization functions for Unified Operator Management (as elaborated by TMF)&lt;/li&gt;&lt;li&gt;The &lt;a href="http://www.oracle.com/master-data-management/cdh.html"&gt;Oracle Customer Hub&lt;/a&gt; for a 360 degree view of a Customer, for compliance and better customer service and more (integration with Unified Profile, Virtual Directory, HSS and more)&lt;/li&gt;&lt;/ul&gt;The best part is now all this can be combined with Sun's Open Telecom Platform offerings that are ATCA, SAF and other industry standards compliant HW infrastructure and Expertise in integrating with NEP's network facing systems around IMS, WiMAX, LTE, CCSF, HSS, PSCF, etc., making it a phenomenal story - especially when Telco are geared up to deliver &lt;a href="http://www.tmforum.org/ManagingCloudServices/8006/home.html"&gt;Managed Cloud offerings&lt;/a&gt;!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6584493659479812249?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6584493659479812249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6584493659479812249' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6584493659479812249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6584493659479812249'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#6584493659479812249' title='Customer&apos;s Context Centric Convergence &amp; Consolidation'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/S29jo0SAhJI/AAAAAAAADuY/jAlQR4r8NUU/s72-c/customer-hub-large.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-9199325625137720826</id><published>2010-02-02T14:39:00.000-08:00</published><updated>2010-02-02T15:02:32.600-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCCOracle'/><title type='text'>Contextual Composition of Converged Services</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.context.futuretext.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 69px; height: 100px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S2ip00NeRDI/AAAAAAAADuQ/J5dNE1uLYbE/s200/cover.jpg" alt="" id="BLOGGER_PHOTO_ID_5433779675255948338" border="0" /&gt;&lt;/a&gt;Its great to learn more about Oracle's &lt;a href="http://www.oracle.com/industries/communications/productmaps.html"&gt;Converged Communications products&lt;/a&gt;, this week. Starting with the SDP platform that include &lt;a href="http://www.oracle.com/industries/communications/oracle-communications-services-delivery.html"&gt;Converged Communications Server (JEE, SIP Container, IMS/NGIN/WS Server, etc), Communication Services Gatekeeper (parlayX gateway, SLA/QOS Policy enforcer, etc) and the new Communications Media and Advertising Server&lt;/a&gt;, OSS/BSS Servers (end to end from Service Activation to Service Retirement), Media and Entertainment Services, GRC for Telco and an ATCA+SAF compliant Carrier Grade Framework. An awesome product line!! No wonder Telco's &lt;a href="http://www.oracle.com/us/corporate/press/044198"&gt;worldwide choose Oracle&lt;/a&gt;. Now with the Sun acquisition, every Telco I've worked with in the past 10 years (from an ID Stack perspective) - Telstra in Australia to Telus in Canada, Telcel in Mexico to Verizon in US, Vodafone in Europe to Reliance in India, Vimplecom in Moscow to China Mobile in Beijing can leverage the &lt;a href="http://identity-centric-architecture.blogspot.com/search?q=converged"&gt;Identity, Policy and Context layer&lt;/a&gt; to Deliver Revenue generating NG converged communication services and cloud services!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-9199325625137720826?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/9199325625137720826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=9199325625137720826' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/9199325625137720826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/9199325625137720826'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#9199325625137720826' title='Contextual Composition of Converged Services'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S2ip00NeRDI/AAAAAAAADuQ/J5dNE1uLYbE/s72-c/cover.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2183734490939400011</id><published>2010-02-02T13:02:00.000-08:00</published><updated>2010-02-02T13:16:07.761-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='KeynoteSIM'/><title type='text'>Secure SIM and SSO based Payment Services</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.simposiumglobal.com/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 55px; height: 63px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/S2iS5acp9sI/AAAAAAAADuI/gzfSEcVVNCQ/s200/sim2010.png" alt="" id="BLOGGER_PHOTO_ID_5433754465472214722" border="0" /&gt;&lt;/a&gt;My &lt;a href="http://www.simalliance.org/SITEFORUM?t=/contentManager/selectCatalog&amp;amp;e=UTF-8&amp;amp;i=1185787014303&amp;amp;l=0&amp;amp;ParentID=1260895140076&amp;amp;active=no2"&gt;Keynote with Hadi Nahari, Principal Architect at Paypal&lt;/a&gt; is confirmed for april 2010. The POC will continue with an Oracle+Sun ID Stack.. We will present on the requirements and key metrics around performance and scalability that resulted in a proposed Solution Architecture (300 mill+ subscribers, 1 mill policies, 1+ billion attributes, etc.).. This will be my first as an Oracle employee!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2183734490939400011?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2183734490939400011/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2183734490939400011' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2183734490939400011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2183734490939400011'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#2183734490939400011' title='Secure SIM and SSO based Payment Services'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/S2iS5acp9sI/AAAAAAAADuI/gzfSEcVVNCQ/s72-c/sim2010.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-257606627947575990</id><published>2010-02-01T12:17:00.000-08:00</published><updated>2010-02-01T12:44:26.285-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TTTelco'/><title type='text'>Top Twenty Telco - Trust Oracle+Sun</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/us/industries/communications/index.htm"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 93px; height: 75px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S2c3ENkQgYI/AAAAAAAADuA/wcV__e10vYQ/s200/orsun" alt="" id="BLOGGER_PHOTO_ID_5433372020946534786" border="0" /&gt;&lt;/a&gt;In the 10 years I was with Sun roughly 1/2 was on leading and consulting on Telco projects worldwide as a Lead Architect (including Telcel in Mexico, Vodafone in Europe, Cingular in US and more) that included integrated EBPP, mobileSOA, ID infrastructure and more, the reminder 1/2 was in SW Sales Org focusing on Identity Infrastructure (US, Canada and LA.). I am glad I will continue playing a LEAD role in Oracle Global Telco Unit reporting direct to a VP. My roles and responsibilities will include;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Acting as the GO TO GUY for Integrated ID Infra for Global Telco Deals.&lt;/li&gt;&lt;li&gt;Representing Oracle Comms at ITU, TMF, GSM, and other Industry Events, etc.&lt;/li&gt;&lt;li&gt;Integrating ID Infra for the Telco Vertical Solutions (Market Requirements, etc.).&lt;/li&gt;&lt;li&gt;Interfacing with different Product specific Product Managers for alignment.&lt;/li&gt;&lt;li&gt;Working closely with Sales/ISV/SI partner Teams focused on Telco a/c's.&lt;/li&gt;&lt;/ul&gt;Plus more... I already know the strengths that Sun brings to this Telco Industry, and combined with Oracle we will have solid momentum as Telco's roll out 4G &amp;amp; IMS worldwide and integrate Web 2.0 and Comms 2.0 services via a Common Identity, Policy and Context layer. Looking forward to the next 10 years at Oracle!! Its going to be AWESOME!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-257606627947575990?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/257606627947575990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=257606627947575990' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/257606627947575990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/257606627947575990'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_02_01_archive.html#257606627947575990' title='Top Twenty Telco - Trust Oracle+Sun'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S2c3ENkQgYI/AAAAAAAADuA/wcV__e10vYQ/s72-c/orsun' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-3539072344516942238</id><published>2010-01-31T17:22:00.000-08:00</published><updated>2010-01-31T17:42:35.503-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ScottSS'/><title type='text'>Legend - Leadership Lecture</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.youtube.com/watch?v=DnhXfxy-MQY"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 67px; height: 53px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S2Ys27sOVrI/AAAAAAAADt4/cl2t6hUecQo/s200/srisri.jpg" alt="" id="BLOGGER_PHOTO_ID_5433079322716821170" border="0" /&gt;&lt;/a&gt;I was listening to Sri Sri's lecture at Wharton that was given in early 2009 for students and I thought about his "12 Qualities of Good Leadership" (that was emailed to me this weekend):&lt;br /&gt;&lt;br /&gt;The first major aspect of good leadership is letting go of control. Are you in control when you’re sleeping or when you’re dreaming? No! Are you in control of any other function in your body? Your heart is pumping all by itself. Your liver functions by itself. The food you stuff in the stomach gets digested all by itself. Do you have any control over them? Are you in control of the Sun and Moon moving around the globe or even the globe rotating on itself? Are you in control of the thoughts that come into your head? So, when you realize you really do not have any control over all major things that are happening in you life, you’ll stand up and laugh. “Oh, what am I thinking, am I in control of something?” Then you will realize that the idea that you are in control is an illusion. And then you relax. And that relaxed state is called surrender.&lt;br /&gt;&lt;br /&gt;What is surrender? A state of mind, where you are absolutely at home, totally relaxed — with no fear, anxiety, burden or problem. That state is called surrender. Surrender is our very nature; you don’t have to do it. When you are in your natural state of childlike innocence, you are already in a state of surrender. When you cannot surrender, then you make effort, and effort makes you surrender. So when you say, “I cannot relax”, I will say, “Ok, hold your fists tight and tight and tight.” Then, when I ask you to make it tighter and you cannot do that, what do you do? Being tired, you just drop. This is coming to the other end with effort! For a leader, it is also important to be in the present moment.&lt;br /&gt;&lt;br /&gt;So, what are the qualities of good leadership? How can you be a dynamic, confident and enthusiastic leader?&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;The first quality of leadership is to set an &lt;span style="font-weight: bold;"&gt;example&lt;/span&gt;. A leader doesn’t just order things; he does it so that others can do it.&lt;/li&gt;&lt;li&gt;Second aspect is that a leader takes good care of those whom he is leading.&lt;/li&gt;&lt;li&gt;Third aspect is that he doesn’t create followers. &lt;span style="font-weight: bold;"&gt;A good leader creates leaders&lt;/span&gt;. And then chain action happens. A leader should delegate responsibility.&lt;/li&gt;&lt;li&gt;The fourth quality is that a leader &lt;span style="font-weight: bold;"&gt;does not depend on authority&lt;/span&gt;. He just does a thing, whether authority is invested or not. It comes by itself.&lt;/li&gt;&lt;li&gt;The fifth aspect of leadership is that he does not worry about position. The respect that you gain through virtue is very different from the respect you gain through the position. The respect you get through a position is short-lived and temporary. But the respect that you gain just because of your smile, your attitude, your virtues are there with you all the time. You may be a chairman of this committee, a president of that committee, or you are barrister here or governor of that state — these are all momentary, temporary. They come and they go. And the respect you get because of this position is not genuine, it is not from the heart, it is not true. But the respect you gain because you are a nice person, is genuine, it lasts long. It is spontaneous.&lt;/li&gt;&lt;li&gt;The sixth quality is that a &lt;span style="font-weight: bold;"&gt;leader is alert and when challenges come&lt;/span&gt;, he is not disturbed. A good leader is one who does not drop things when challenges appear.&lt;/li&gt;&lt;li&gt;The seventh quality of a good leader is one who does not care for comfort, but &lt;span style="font-weight: bold;"&gt;who stretches himself beyond the comfort zone.&lt;/span&gt; Anything creative, dynamic and great can happen only when you stretch beyond your comfort zone where we are often struck. We think we cannot do something: just make an effort and put one step ahead, and you will find that that you are expanding your comfort zone. Creativity transcends your comfort zone. Or, when you step out of the comfort zone, your creativity comes into play.&lt;/li&gt;&lt;li&gt;The eighth aspect is, a leader should not mix head and heart. If you mix head and heart, you are in a mess! When you have to work, you work with commitment and you live with your head. In life, in situations other than when you are working, listen to your heart.&lt;/li&gt;&lt;li&gt;The ninth quality of a good leader is that &lt;span style="font-weight: bold;"&gt;he should be multidimensional and see from the other’s point of view&lt;/span&gt;. Put yourself in other person’s shoes, look from the other person’s point of view.&lt;/li&gt;&lt;li&gt;The tenth aspect is that the leader doesn’t depend on one-sided information. When you get some news from one side, don’t take any decision or conclusion till you hear from the other side also. Leader should be a good communicator.&lt;/li&gt;&lt;li&gt;The eleventh is that a leader should have a direct approach.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Twelfth quality of a good leader is not to judge oneself. You have this tendency of judging yourself, “Am I good? I’m no good.” The self-judgment is an obstruction. Stop doing that. Don’t judge yourself. When you judge yourself, you are judging others also. Then you oscillate like a pendulum. If you feel you’re good, then you are saying that others are not so good. So when you find that others are good, and then you feel that you are no good, you blame yourself. Judgment is very similar to self-blame and blaming others. We have to get out of this vicious circle of self-judgment. That is also the state of surrender. When you have surrendered to the Divine that means that you no longer judge yourself. Self-Judgment is not necessary. A child is so innocent, why? Because the child doesn’t judge itself.&lt;/li&gt;&lt;/ol&gt;In my mind I thought about the Legendary Leadership offered by Scott Mcnealy the last 27 years..   always as an example - any major high profile project or meeting I go to - would have been preceded by Scott Mcnealy and the customers CIO, CTO or CEO meeting- I've run into him many times at the EBC, and I in fact got a call from him just before my presentation at Nextcom in 2008. Scott is well known for creating Leaders (more than 100 CEO's in the industry will trace their time back to him).&lt;br /&gt;&lt;br /&gt;He ensured that Sun's IP (intellectual property), products and majority of the people were taken care off - with the Oracle Acquisition.. (the best alternative to Sun going it alone). I truly believe that Sun, its Industry changing technology, products and people will do extremely well within Oracle, since the combined entity is a bigger force that can tackle competitors in an industry that is consolidating rapidly... He has done amazing things including promoting eco friendly computing, supporting global education and more.. He is a LEGEND since he also had the courage to give up control.. (the 1st quality of leadership) for the larger good that it can do!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-3539072344516942238?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/3539072344516942238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=3539072344516942238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3539072344516942238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3539072344516942238'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#3539072344516942238' title='Legend - Leadership Lecture'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S2Ys27sOVrI/AAAAAAAADt4/cl2t6hUecQo/s72-c/srisri.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5191090821371887971</id><published>2010-01-28T04:57:00.000-08:00</published><updated>2010-01-28T05:04:47.834-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OOOJava'/><title type='text'>Java ONE merged into Oracle Open World</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/us/openworld/018162.htm"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 21px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S2GKBCcOSkI/AAAAAAAADtw/HFZ9oUMS2E0/s200/oow_header_09.gif" alt="" id="BLOGGER_PHOTO_ID_5431774376025279042" border="0" /&gt;&lt;/a&gt;Given the popularity of Java ONE and the huge successes of Oracle Openworld in 2009, this year in 2010 the combined event will be unprecedented!! Registration is open!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5191090821371887971?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5191090821371887971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5191090821371887971' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5191090821371887971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5191090821371887971'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#5191090821371887971' title='Java ONE merged into Oracle Open World'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S2GKBCcOSkI/AAAAAAAADtw/HFZ9oUMS2E0/s72-c/oow_header_09.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6878758028771535250</id><published>2010-01-27T17:38:00.000-08:00</published><updated>2010-01-27T17:43:49.654-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SOASIG'/><title type='text'>SOA SIG Scheduled for Next Month</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://natcapoug.org/sst_NATCAPOUG/index.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 69px; height: 69px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S2DrIe_87UI/AAAAAAAADto/xtBwKO170pA/s200/logo.gif" alt="" id="BLOGGER_PHOTO_ID_5431599681601596738" border="0" /&gt;&lt;/a&gt;The National Capital Oracle User Group has a SOA special interest group, and I'll be presenting on "Identity, Policy and Context for Cloud Services" next month, to this group. It will be a great way to meet Oracle customers local to the DC area!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6878758028771535250?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6878758028771535250/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6878758028771535250' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6878758028771535250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6878758028771535250'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#6878758028771535250' title='SOA SIG Scheduled for Next Month'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S2DrIe_87UI/AAAAAAAADto/xtBwKO170pA/s72-c/logo.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6924946800761830691</id><published>2010-01-25T14:48:00.000-08:00</published><updated>2010-01-28T17:27:40.392-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IIIO'/><title type='text'>Whats an Integrated Identity Infrastructure</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://www.eiseverywhere.com/ehome/index.php?eventid=8165&amp;amp;tabid=4650&amp;amp;"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 273px; height: 32px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/S14fz-fBLJI/AAAAAAAADtY/l4OwcrtYgwY/s200/cso" alt="" id="BLOGGER_PHOTO_ID_5430813178462284946" border="0" /&gt;&lt;/a&gt;Now that the EU has approved and Sun as an entity has merged with Oracle, I decided to post an entry of what an &lt;a href="http://blogs.sun.com/identity/entry/integrated_identity_infrastructure"&gt;Integrated Identity Infrastructure&lt;/a&gt; means to me..&lt;br /&gt;&lt;br /&gt;At a high level it implies a:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;integrated system of Identity Services that are based on a common technology platform (similar to Sun's and Oracle ID services running on a JEE application platform),&lt;br /&gt;&lt;/li&gt;&lt;li&gt;interfaces are based on common standards such as SAML, XACML, SPML, XML, etc.,&lt;br /&gt;&lt;/li&gt;&lt;li&gt;the integrated architecture is based on reusable services (aka autonomous Service Building Blocks) that can be called upon when needed, and reusable by all IP (internet protocol) services (web services, communication services, VOIP, IPTV, web 2.0, etc.)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;acting as a common user centric intelligence and instrumentation layer across all services (PAAS, SAAS, IAAS -  cloud infrastructure services)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;plug-able - meaning modular in nature (supporting multiple authN module, policy modules, log/event modules, reporting/analysis modules and more)&lt;/li&gt;&lt;li&gt;integrated with other Security Tools (such as XML FW, DLP, IRM, and more)&lt;/li&gt;&lt;li&gt;integrated in all layers (App, DB, MW, OS/VM, Clouds, etc) and all tiers (device, networks, and data centers)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Specifically these include;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Authentication Services (reusable authN types) for Apps, Users, OS, etc. linked to Federation Services via AuthN context&lt;/li&gt;&lt;li&gt;Web Services Security integrated (message level security) with Transport and Session layer security&lt;br /&gt;&lt;/li&gt;&lt;li&gt; AuthN context acting as a condition for ABAC and XACML PDP&lt;/li&gt;&lt;li&gt;RBAC PDP acting as a PIP for a XACML PDP&lt;/li&gt;&lt;li&gt;Risk based PDP acting as PIP for a XACML PDP&lt;/li&gt;&lt;li&gt;Logs from PEP, PDP, PIP, PCCP, etc., exchanged with an external SIEM tool for live monitoring and management&lt;/li&gt;&lt;li&gt;IDM based Service and Attribute provisioning (at design time) used by Access Management at run time&lt;/li&gt;&lt;li&gt;Role (and role manager based) based provisioning of Attributes and Services that align with Business Processes&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Adaptive AuthN rules enforced based on Resource Accessed and ABAC&lt;/li&gt;&lt;li&gt;ID Attributes Aggregated for ID Analytics and Reporting&lt;/li&gt;&lt;li&gt;Identity, Attribute and Policy repositories integrated via Virtual Directory (and Unified Profiles)&lt;/li&gt;&lt;li&gt;ID Vetting and ID Proofing processes mapped and aligned to provisioning processes&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Assurance Levels as Attributes exchanged based on AuthN context, ID proofing/vetting, Reputation and more.&lt;/li&gt;&lt;li&gt;Common Management tools across all Identity System services&lt;/li&gt;&lt;li&gt;Embed able PEP/PDP on devices/clients, Services, Equipment and more&lt;/li&gt;&lt;li&gt;IRM and DLP instrumented with the identity intelligence layer&lt;/li&gt;&lt;li&gt;Identity and Policy services integrated into Context Engines&lt;/li&gt;&lt;li&gt;Session Oriented integration between Network and Service Sessions&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;and many more.. I can count at least a 100 touch points between different components of an Identity Infrastructure based on work we've done the past 4 to 5 years. Check out the event agenda that CSO is hosting and presented by Oracle.&lt;br /&gt;&lt;br /&gt;BTW: Oracle and Sun are in the leaders quadrant of many analysts reports -- and now we become one indomitable force in the Identity Space (with Sun ID Stack integrated into Fusion Middle ware).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6924946800761830691?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6924946800761830691/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6924946800761830691' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6924946800761830691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6924946800761830691'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#6924946800761830691' title='Whats an Integrated Identity Infrastructure'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/S14fz-fBLJI/AAAAAAAADtY/l4OwcrtYgwY/s72-c/cso' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1160941808828145648</id><published>2010-01-25T08:40:00.000-08:00</published><updated>2010-01-25T08:45:08.562-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSStrategy'/><title type='text'>Oracle+Sun Strategy (SW+HW)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/webapps/events/EventsDetail.jsp?p_eventId=108481&amp;amp;src=6806472&amp;amp;src=6806472&amp;amp;Act=22"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 71px; height: 58px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S13JhLDKuRI/AAAAAAAADtQ/wWbs4IEfv30/s200/osun" alt="" id="BLOGGER_PHOTO_ID_5430718297417627922" border="0" /&gt;&lt;/a&gt;Join in on &lt;a href="http://www.oracle.com/webapps/events/EventsDetail.jsp?p_eventId=108481&amp;amp;src=6806472&amp;amp;src=6806472&amp;amp;Act=22"&gt;wednesday this week!!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1160941808828145648?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1160941808828145648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1160941808828145648' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1160941808828145648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1160941808828145648'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#1160941808828145648' title='Oracle+Sun Strategy (SW+HW)'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S13JhLDKuRI/AAAAAAAADtQ/wWbs4IEfv30/s72-c/osun' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2185354545052848025</id><published>2010-01-18T16:57:00.000-08:00</published><updated>2010-01-18T17:04:41.005-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCCbook'/><title type='text'>Call for Chapters - Excellent Opportunity to Contribute</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.acsu.buffalo.edu/%7Emaheshth/CFC.pdf"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 19px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S1UEvU5jeHI/AAAAAAAADtI/wtRowlC6D0g/s200/ubitLogo.jpg" alt="" id="BLOGGER_PHOTO_ID_5428250136975472754" border="0" /&gt;&lt;/a&gt;&lt;a href="http://www.acsu.buffalo.edu/%7Emaheshth/CFC.pdf"&gt;A book edited by Dr. Raj Sharman, Dr. Sanjukta Das Smith and Manish Gupta&lt;/a&gt; State University of New York, Buffalo, NY, USA. To be published by IGI Global.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2185354545052848025?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2185354545052848025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2185354545052848025' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2185354545052848025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2185354545052848025'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#2185354545052848025' title='Call for Chapters - Excellent Opportunity to Contribute'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S1UEvU5jeHI/AAAAAAAADtI/wtRowlC6D0g/s72-c/ubitLogo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7899286513086803577</id><published>2010-01-18T16:50:00.000-08:00</published><updated>2010-01-18T16:54:50.687-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCidC'/><title type='text'>Charter and Committee proposed for "Identity in the Clouds"</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://xml.coverpages.org/Identity-Clouds-Proposal.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 13px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S1UCQobm5GI/AAAAAAAADtA/gJSJCulRYFA/s200/oasis-banner.png" alt="" id="BLOGGER_PHOTO_ID_5428247410619376738" border="0" /&gt;&lt;/a&gt;Out of scope are topics such as &lt;a href="http://xml.coverpages.org/Identity-Clouds-Proposal.html"&gt;Access Control, API's and protocols.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7899286513086803577?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7899286513086803577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7899286513086803577' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7899286513086803577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7899286513086803577'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#7899286513086803577' title='Charter and Committee proposed for &quot;Identity in the Clouds&quot;'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S1UCQobm5GI/AAAAAAAADtA/gJSJCulRYFA/s72-c/oasis-banner.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-8502548861364961657</id><published>2010-01-15T20:42:00.000-08:00</published><updated>2010-01-18T14:27:12.074-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IIINHIN'/><title type='text'>Integrated Identity Infrastructure for NHIN</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://meeting-reg.com/hhiesummit/agenda.php"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 139px; height: 29px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S1FEQmBQ2eI/AAAAAAAADs4/-_qSxj_ZrRY/s200/CCCHC.jpg" alt="" id="BLOGGER_PHOTO_ID_5427194077832600034" border="0" /&gt;&lt;/a&gt;Check out the agenda for this &lt;a href="https://meeting-reg.com/hhiesummit/agenda.php"&gt;event next week&lt;/a&gt;. I am reminded of&lt;a href="http://www.cs.virginia.edu/%7Ebjg5x/SACMATPaper.doc"&gt; &lt;/a&gt;&lt;a href="http://www.cs.virginia.edu/%7Ebjg5x/SACMATPaper.doc"&gt;this paper &lt;/a&gt;on XACML, RBAC, etc., for HC Use Cases.. Access Management, Federation Management, ID Management, Role Management, Entitlement Management, Risk Management, SEIM, Compliance Management, Auditing &amp;amp; Reporting Management, all in all an Integrated Identity Infrastructure is required for such large scale initiatives such as NHIN. The Keynote Speaker is &lt;a href="http://www.input.com/corp/events_conference/FedFocus10_bio-vskaran.cfm"&gt;Vish Shankaran&lt;/a&gt; Program Director, Office of National Coordinator/HHS, NHIN.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8502548861364961657?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8502548861364961657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8502548861364961657' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8502548861364961657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8502548861364961657'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#8502548861364961657' title='Integrated Identity Infrastructure for NHIN'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S1FEQmBQ2eI/AAAAAAAADs4/-_qSxj_ZrRY/s72-c/CCCHC.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4459776507429033788</id><published>2010-01-14T14:46:00.000-08:00</published><updated>2010-01-15T19:36:56.794-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCCUC'/><title type='text'>Covering collaborative real world use cases</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_RI178MJjsuE/S0-fdeTZf9I/AAAAAAAADsw/3JltgbRjkKM/s1600-h/safe_image.php.jpeg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 73px; height: 64px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S0-fdeTZf9I/AAAAAAAADsw/3JltgbRjkKM/s200/safe_image.php.jpeg" alt="" id="BLOGGER_PHOTO_ID_5426731404704186322" border="0" /&gt;&lt;/a&gt;In both my upcoming &lt;span style="font-weight: bold;"&gt;Keynotes &lt;/span&gt;I am collaborating with a customer or a potential customer to join me to discuss the use cases made possible with OpenSSO. At the SIMposium 2010 it is with Paypal (and mobile payment services) where SIM authN, SCWS and OpenSSO XACML based ABAC is covered for risk sensitive mobile payment apps. Its also in collaboration with Mobile Operators -- where the mobile operator acts as the 1st Authenticating Authority and Attribute Authority, with the Payment SP acting as a Authorizing Authority and Attribute Authority (plus as 2nd level Authenticating Authority when needed), leveraging distributed Authorities and allowing many possible ABAC scenarios.&lt;br /&gt;&lt;br /&gt;At MISC 2010 I will go over the Integration of &lt;a href="http://developer.webex.com/c/document_library/get_file?folderId=22041&amp;amp;name=DLFE-1704.pdf"&gt;Cisco's Webex&lt;/a&gt; with OpenSSO and a use case around initiating a webex session from within facebook (logged in and accessed from an iPhone or a Touch Screen client) and collaborating with a set of online facebook friends belonging to a group without having to login again, and exchanging docs, pictures, and other objects based on attributes and tags associated with these objects. For example, if you had a collaborative session with all Alumni of your 1986 High School and are  planning a 25th year anniversary event in 2011 plus a fundraiser for a cause, in conjunction with the anniversary - you do it with facebook, flickr and webex.. All the friends are in facebook, flickr has images of past get-to-gethers + some info on the fundraiser project and webex allows for secure collaboration for planning purposes - even though the class of 86 is all over the world (India, Dubai, Canada, UK, US, Europe, etc)..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4459776507429033788?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4459776507429033788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4459776507429033788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4459776507429033788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4459776507429033788'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#4459776507429033788' title='Covering collaborative real world use cases'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S0-fdeTZf9I/AAAAAAAADsw/3JltgbRjkKM/s72-c/safe_image.php.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7778604553601735449</id><published>2010-01-13T12:19:00.000-08:00</published><updated>2010-01-13T12:26:56.425-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSSIDworld2010'/><title type='text'>Speaker Submissions Open- IDWorld Summit 2010</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.idworldabudhabi.com/index.php?id=callforpapersad10"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 49px; height: 65px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/S04rNQ1UzsI/AAAAAAAADso/bYviVrVvi8w/s200/IAD10_Brochure.jpg" alt="" id="BLOGGER_PHOTO_ID_5426322107884949186" border="0" /&gt;&lt;/a&gt;Transportation, Asset Tracking, Near Field Communications, Citizen ID, Postal Innovation.. all of &lt;a href="http://www.idworldabudhabi.com/index.php?id=1480"&gt;which requires the mobility context... &lt;/a&gt;Excellent opportunities for Mobile Operators to collaborate with transportation/logistics services, asset tracking services, and more..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7778604553601735449?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7778604553601735449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7778604553601735449' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7778604553601735449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7778604553601735449'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#7778604553601735449' title='Speaker Submissions Open- IDWorld Summit 2010'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/S04rNQ1UzsI/AAAAAAAADso/bYviVrVvi8w/s72-c/IAD10_Brochure.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-3383011331735272809</id><published>2010-01-03T18:02:00.000-08:00</published><updated>2010-01-03T18:10:47.160-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Policy 2010'/><title type='text'>Policy 2010: Call for Papers for this Prestigious IEEE event</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="Duminda%20Wijesekera,%20%20George%20Mason%20University,%20USA"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 73px; height: 34px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/S0FMax3tjhI/AAAAAAAADsA/WnJW-Q9qoIo/s200/GMU.jpg" alt="" id="BLOGGER_PHOTO_ID_5422699449278107154" border="0" /&gt;&lt;/a&gt;&lt;a href="http://www.policy-workshop.org/cfp.html"&gt;Location Fairfax and Venue GMU &lt;/a&gt;-- perfect!! Call for papers open now - if you are working on XACML and distributed system or network policies this is the event for you. Dr. Duminda Wijesekera,  &lt;i&gt;George Mason    University, USA,&lt;/i&gt; is the Chair this year. Just completed the 1st draft of a paper titled "Constraints and Context for Cloud Infrastructure Services" based on XACML policies.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-3383011331735272809?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/3383011331735272809/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=3383011331735272809' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3383011331735272809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3383011331735272809'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2010_01_01_archive.html#3383011331735272809' title='Policy 2010: Call for Papers for this Prestigious IEEE event'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/S0FMax3tjhI/AAAAAAAADsA/WnJW-Q9qoIo/s72-c/GMU.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1451269437524737497</id><published>2009-12-26T09:06:00.000-08:00</published><updated>2009-12-26T10:20:38.925-08:00</updated><title type='text'>NHIN - National HI Network</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.connectopensource.org/display/NHINR21/OpenSSO+Policy+Engine"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 36px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SzZC-9mUyII/AAAAAAAADro/oeE0QZ5Dy8k/s200/NHINR21.png" alt="" id="BLOGGER_PHOTO_ID_5419592851041601666" border="0" /&gt;&lt;/a&gt;Along with the NHIN initiative that leverages OpenSSO's XACML policy engine, I am aware of one other large scale initiative that will also leverage OpenSSO's policy engine (will blog more about this in 2010). The 9 areas where OpenSSO excels in terms of scalability for these Policy/XACML deployments are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Indexed Policies&lt;/li&gt;&lt;li&gt;Cached Policies&lt;/li&gt;&lt;li&gt;Leveraging the underlying Directory Replication Mechanisms&lt;/li&gt;&lt;li&gt;Pre Fetch (post AuthN rules) and event based Policy retrievals/caching&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Parallel Evaluations of Policy Set (policy combination's, conflict resolutions, referrals, etc)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Vertical and Horizontal Scaling (within and between nodes)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Tuned for 256 Thread CMT(Niagara 2, 2+ and 3)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;High Speed Attribute Authorities (like Oracle DB Appliances)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Highly Distributed Architecture (Embedded (edge/devices), Co-located (with HSS) and Central (master PDP) ).&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Note:  The PIP is primarily used for accessing patient consent information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1451269437524737497?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1451269437524737497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1451269437524737497' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1451269437524737497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1451269437524737497'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_12_01_archive.html#1451269437524737497' title='NHIN - National HI Network'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SzZC-9mUyII/AAAAAAAADro/oeE0QZ5Dy8k/s72-c/NHINR21.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-8298127660769741487</id><published>2009-12-23T18:49:00.001-08:00</published><updated>2009-12-23T19:02:12.659-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCCpapers'/><title type='text'>Catalyst Conference Call for Papers</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.catalyst.burtongroup.com/EU10/index.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 31px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/SzLW4PaUbqI/AAAAAAAADrg/-NLkGVO1NXE/s200/HeaderBG.jpg" alt="" id="BLOGGER_PHOTO_ID_5418629563378069154" border="0" /&gt;&lt;/a&gt;The call for papers has been extended to Jan 2010 for this important Catalyst event in April. I just noticed this extension at &lt;a href="http://identityblog.burtongroup.com/bgidps/"&gt;Gerry Gebel's blog.&lt;/a&gt; I met Gerry at NetID 2009 and he was kind enough to share some material around "Identity and the Relationship Layer" parts of which I will include and reference in the "Identity and Context" book. I will miss this event, since its the same week as SIMposium 2010. Hopefully I'll make it to the &lt;a href="http://www.catalyst.burtongroup.com/"&gt;July event at California&lt;/a&gt;. Excellent events and a great agenda - dont miss this if you get a chance!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8298127660769741487?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8298127660769741487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8298127660769741487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8298127660769741487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8298127660769741487'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_12_01_archive.html#8298127660769741487' title='Catalyst Conference Call for Papers'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/SzLW4PaUbqI/AAAAAAAADrg/-NLkGVO1NXE/s72-c/HeaderBG.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5123466688315936407</id><published>2009-12-11T19:27:00.000-08:00</published><updated>2009-12-11T20:02:18.819-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WWW'/><title type='text'>What a Wonderful World</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://en.wikipedia.org/wiki/Sam_Cooke"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 82px; height: 85px;" src="http://3.bp.blogspot.com/_RI178MJjsuE/SyMN08_yLEI/AAAAAAAACyE/rT_M1qfR1c4/s200/SCooke.jpg" alt="" id="BLOGGER_PHOTO_ID_5414186380407483458" border="0" /&gt;&lt;/a&gt;Instead of having the final exam (for ISA562)on Monday the 14th Dec, due to some travel commitments, myself and two other students decided to do the finals today! The exam preparation was intent - we had to cover BellLapuda, Biba and Lattice models, plus topics on encryption, DiffeHellman, RSA, DES, 3DES, AES, hash algorithms, PKI, Certs, signatures, and more. It felt good when the exam was completed. Now along with the faculty and fellow student I plan to work on 3 new papers:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Constraints and Contextual Policies (XACML) for Cloud Computing (IAAS)&lt;/li&gt;&lt;li&gt;Composition and Choreography of Cryptographic functions using XACML (federation  of Symmetric, Asymmetric, Elliptic, Quantum and their combination of crypto functions)&lt;/li&gt;&lt;li&gt;XACML Policies for Privileged Account Permissions (OS, VM and Hypervisor Admin Accounts)&lt;/li&gt;&lt;/ol&gt;The 1st paper by dec 20th and the other 2 for spring 2010. On my commute back home from School switched on the radio to merge into this Sam Cooke's excellent song, where the lyrics had a special meaning for me!! After next week California trip - its definitely party time - movies with the kids, WII with Arjun, several holiday parties and more!!&lt;br /&gt;&lt;br /&gt;It was a perfect day and time to here this Song!! Came home and searched for Sam Cooke's CD..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5123466688315936407?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5123466688315936407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5123466688315936407' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5123466688315936407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5123466688315936407'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_12_01_archive.html#5123466688315936407' title='What a Wonderful World'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/SyMN08_yLEI/AAAAAAAACyE/rT_M1qfR1c4/s72-c/SCooke.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-3094625525790781032</id><published>2009-12-09T18:10:00.000-08:00</published><updated>2009-12-09T18:39:04.417-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HHHE'/><title type='text'>Honored, Humbled and Highly Excited</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://simalliance.org/servlets/sfs?t=/contentManager/selectCatalog&amp;amp;e=UTF-8&amp;amp;i=1185787014303&amp;amp;l=0&amp;amp;active=SFP&amp;amp;ParentID=201"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 106px; height: 38px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SyBZG5Ti6TI/AAAAAAAACx8/QahYHjlhPhw/s200/SIM_banner2010.jpg" alt="" id="BLOGGER_PHOTO_ID_5413424727096224050" border="0" /&gt;&lt;/a&gt;I am delighted and excited about 2010. Other than the &lt;span style="font-weight: bold; font-style: italic;"&gt;Keynote &lt;/span&gt;at MISC 2010 (London) on "Mobile - Connectivity and Context Convergence", I'll deliver another &lt;span style="font-weight: bold; font-style: italic;"&gt;Keynote&lt;/span&gt; on "Mobile Payments - SIM for Secure Service Access" at SIMposium 2010 (Rome). The first one is around Attribute Alignment and Aggregation for Social Apps (such as facebook and flickr - imagine Yahoo federating facebook with your flickr albums!! - for example the week I'm in London my facebook friends in london with our joint pictures taken during trips at flickr shows up in my iPhone) delivered to the mobile in a context. The second one is on the relevance of SIM and Javacard 3.0 for NG client devices, IMS and NGN and specifically for Mobile SOA - with mobile payments as an important service example. Aligning Payment SP's with Mobile Operators AuthN and Attributes - OpenSSO integrating with IMS/HSS and SIM/cert authN, plus JavaCard 3, and AuthZ based on Attributes (constraints and conditions XACML). With this trend of Keynote invites, I think I'll stick to 3 or 4 keynotes per year from 2010. There are 2 more tentative Keynote's lined up for 2010 already. I am honored with the recognition given for my work and books by these organizing bodies and humbled by the fantastic opportunities I've had working on key projects, topics and areas around Integrated Identity Infrastructure solutions, giving the experience and exposure to learn more and more (its a never ending story)..   BTW: The SIM/JC 3.0 and ABAC/XACML is based on a POC and a potential project which will involve the LARGEST ever XACML based Policy Engine deployment in the World till date (300+ million subscribers, 5000+ policies, integration with RiskBAC and RoleBAC, etc.)..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-3094625525790781032?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/3094625525790781032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=3094625525790781032' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3094625525790781032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/3094625525790781032'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_12_01_archive.html#3094625525790781032' title='Honored, Humbled and Highly Excited'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SyBZG5Ti6TI/AAAAAAAACx8/QahYHjlhPhw/s72-c/SIM_banner2010.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-909041595528125531</id><published>2009-11-24T08:41:00.000-08:00</published><updated>2009-11-24T10:32:13.179-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCCMobile'/><title type='text'>Mobile - Connectivity &amp; Context Convergence</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.miscforum.eu/misc2010/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 55px; height: 82px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SwwMrmNT05I/AAAAAAAACx0/i0z4U4ZoQ24/s200/misc2010-picture.jpg" alt="" id="BLOGGER_PHOTO_ID_5407711195695403922" border="0" /&gt;&lt;/a&gt;I am once again delighted to be giving a Keynote on "Mobile - Connectivity &amp;amp; Context Convergence" at MISC 2010 in London, covering the topic of Context Convergence (Attribute Aggregation) from a Mobile Operator perspective. As Wireless operators such as Verizon Wireless, AT&amp;amp;T, T-Mobile and Telus Mobility are investing in high speed wireless (4G networks), the mobile broadband connectivity (anywhere, any device paradigm) leads to the idea of reaching out to any service and any content from the mobile. However this also implies adhering to the pervasive set of policies and attribute alignment and aggregation -- for the next level of IN implementation- a convergence of MobileIN, NGIN, IN, AIN, InternetIN, IMS Attributes, Service Attributes, IPTV Attributes and more..  My presentation is on the 3rd book "Identity and Context" as well as 5 or more POC's that we are doing with Mobile Operators and Web2.0 companies (using OpenSSO)!! The agenda is packed with workshops, presentations, tutorials on - SAML, Federation, XACML and Attribute Exchange.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-909041595528125531?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/909041595528125531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=909041595528125531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/909041595528125531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/909041595528125531'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_11_01_archive.html#909041595528125531' title='Mobile - Connectivity &amp; Context Convergence'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SwwMrmNT05I/AAAAAAAACx0/i0z4U4ZoQ24/s72-c/misc2010-picture.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2837902636014395621</id><published>2009-11-17T14:14:00.000-08:00</published><updated>2009-11-17T17:35:28.865-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SIMSCWSSSO'/><title type='text'>SIM, SmartCard, SCWS and SSO</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://simalliance.org/servlets/sfs?t=/contentManager/selectCatalog&amp;amp;e=UTF-8&amp;amp;i=1185787014303&amp;amp;l=0&amp;amp;active=SFP&amp;amp;ParentID=201"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 112px; height: 40px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SwMhviPo8JI/AAAAAAAACxs/2NOUHBqmzz4/s200/SIM_banner2010.jpg" alt="" id="BLOGGER_PHOTO_ID_5405201078304698514" border="0" /&gt;&lt;/a&gt;I was reminded of Ajit Jaokar's writeup from futuretext on &lt;a href="http://opengardensblog.futuretext.com/archives/2008/10/scws_sim_as_the.html"&gt;SIM and SCWS&lt;/a&gt; and its implications for Carrier Cloud Computing, a while back, and the blog entry by &lt;a href="http://www.coresecuritypatterns.com/blogs/?p=1267"&gt;Ramesh on JavaCard 3.0&lt;/a&gt; which is a SIM and SCWS implementation in Java, when I saw the call for papers for SIMPosium 2010 by the &lt;a href="http://simalliance.org/servlets/sfs?i=1185787014303&amp;amp;b=1185787014303&amp;amp;t=/Default/gateway&amp;amp;xref="&gt;SIM Alliance&lt;/a&gt;. It is indeed amazing to see how these synergies are taking shape for systemic security in the network:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;We have had the opportunity to integrate OpenSSO with multiple NEP's IMS implementation  of &lt;a href="http://download.java.net/mobileembedded/developerdays/2008/TS-20-JMEIDS-final.pdf"&gt;GBA and GAA&lt;/a&gt; (which leverage SIM and AKA)&lt;/li&gt;&lt;li&gt;Advances in JavaCard 3.0 with a SCWS allows for embedding PEP/PDP that pertains to devices at the device itself (supporting the Centralized. Co-located and Embedded &lt;a href="http://blogs.sun.com/ideas/entry/xacml_declarative_access_control"&gt;XACML models in OpenSSO&lt;/a&gt;) - multiple ISV integration&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.context.futuretext.com/"&gt;Contextual Data exchanged by local PIP&lt;/a&gt; (policy information points) and federated (linked) PIP's via OpenSSO for 5 context areas (imagine the power of enforcing energy efficiency via sensors and XACML)&lt;/li&gt;&lt;li&gt;OpenSSO and its Services acting as the foundation set of Service for &lt;a href="http://de.sun.com/sunnews/events/2008/SOA_Discovery_Day/pdf/04_SOA%20Service_Creation.pdf"&gt;Mobile SOA, which can leverage SIM and SCWS&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Integrating Web 2.0 and Web Services as compo-sable applications and services in a user centric and device agnostic manner&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2837902636014395621?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2837902636014395621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2837902636014395621' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2837902636014395621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2837902636014395621'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_11_01_archive.html#2837902636014395621' title='SIM, SmartCard, SCWS and SSO'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SwMhviPo8JI/AAAAAAAACxs/2NOUHBqmzz4/s72-c/SIM_banner2010.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6773838638445508435</id><published>2009-10-24T08:15:00.000-07:00</published><updated>2009-10-24T08:19:33.105-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='XACML_ABAC_project'/><title type='text'>Giving a Guest Lecture at GMU</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://policy.futuretext.com"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 63px; height: 91px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/SuMaPpsed-I/AAAAAAAACws/nO-tBMZ7Ui0/s200/cover2.jpg" alt="" id="BLOGGER_PHOTO_ID_5396185634712745954" border="0" /&gt;&lt;/a&gt;As part of the coursework for ISA 562 - students have to do a XACML project (20% of grade). I am totally excited about being invited to give a guest lecture on XACML and ABAC to the 50+ students in this class. It is going to be fun!! I will also cover 5 sample XACML projects - one in Health Care, one in eGov, one in Edu, one in Telco and one in E-Biz. Plus 5 reference papers -one for each project.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6773838638445508435?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6773838638445508435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6773838638445508435' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6773838638445508435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6773838638445508435'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_10_01_archive.html#6773838638445508435' title='Giving a Guest Lecture at GMU'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/SuMaPpsed-I/AAAAAAAACws/nO-tBMZ7Ui0/s72-c/cover2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1077849389942038823</id><published>2009-10-24T08:01:00.000-07:00</published><updated>2009-10-24T08:22:20.566-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DDDMB'/><title type='text'>Disclosure, Deception and Disruption</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://nob.cs.ucdavis.edu/book/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 73px; height: 92px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/SuMW9ANgbMI/AAAAAAAACwk/jF5UmY63VjM/s200/cover-large.jpg" alt="" id="BLOGGER_PHOTO_ID_5396182015804468418" border="0" /&gt;&lt;/a&gt;The main textbook covered in the &lt;a href="http://cs.gmu.edu/programs/phd"&gt;ISA 562 course&lt;/a&gt; is this excellent book written by Matt Bishop. In the very 1st chapter he covers the three main areas of security in terms of Confidentiality, Integrity &amp;amp; Availability (CIA) and how they are threatened by Disclosure (such as snooping, wiretapping, etc.), Deception (spoofing, masquerading, etc.) and Disruption (DOS attacks, Delay attacks, etc) - threat techniques. We have so far covered the 1st chapter, Access Control Matrix, Take-Grant Models, RBAC, XACML and other policy topics in class (+ 2 home works and one exam). This Book is a must for all Security Professionals (and course).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1077849389942038823?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1077849389942038823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1077849389942038823' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1077849389942038823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1077849389942038823'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_10_01_archive.html#1077849389942038823' title='Disclosure, Deception and Disruption'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/SuMW9ANgbMI/AAAAAAAACwk/jF5UmY63VjM/s72-c/cover-large.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6563245538785619086</id><published>2009-10-22T13:55:00.000-07:00</published><updated>2009-10-22T14:00:49.673-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IIITelco'/><title type='text'>Insights into Innovations for Telco's</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/us/corporate/press/Spokespeople/016266"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 40px; height: 57px;" src="http://2.bp.blogspot.com/_RI178MJjsuE/SuDG39cos5I/AAAAAAAACwU/457in-DNaI0/s200/bg.jpg" alt="" id="BLOGGER_PHOTO_ID_5395531018279629714" border="0" /&gt;&lt;/a&gt;Bhaskar Gorti delivering a &lt;a href="http://www.iec.org/events/2008/sofnet/keynotes/keynote_gorti_view.asp"&gt;Keynote &lt;/a&gt;&amp;amp; having a chat at &lt;a href="http://www.youtube.com/watch?v=QN8V8xEgErY"&gt;OOW&lt;/a&gt;. Focusing on Comms, Media and Entertainment for more than a decade now, I like the idea of Identity, Policy, Context enabled (Communication embedded) Business Processes and Workflows - Context will drive a number of innovation Apps and Services from a Carrier Cloud!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6563245538785619086?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6563245538785619086/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6563245538785619086' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6563245538785619086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6563245538785619086'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_10_01_archive.html#6563245538785619086' title='Insights into Innovations for Telco&apos;s'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RI178MJjsuE/SuDG39cos5I/AAAAAAAACwU/457in-DNaI0/s72-c/bg.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-6203371226130263502</id><published>2009-10-19T08:43:00.000-07:00</published><updated>2009-10-19T08:56:08.267-07:00</updated><title type='text'>Federal Identity Interop and Initiatives</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://guest.cvent.com/Events/Info/Agenda.aspx?i=ff08e778-cf2f-415b-91a2-4a20bb68a769"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 25px;" src="http://3.bp.blogspot.com/_RI178MJjsuE/StyJvPIIjLI/AAAAAAAACwM/pzMdPfYJE44/s200/smartcards.gif" alt="" id="BLOGGER_PHOTO_ID_5394337898290515122" border="0" /&gt;&lt;/a&gt;Excellent &lt;a href="http://guest.cvent.com/Events/Info/Agenda.aspx?i=ff08e778-cf2f-415b-91a2-4a20bb68a769"&gt;Agenda at the Annual Smart Cards in Government&lt;/a&gt; event, to be held next week. Includes NIST, FIPS, ISO/IEC, Trust Levels in AuthN, Kantara, and many more.. Great opportunity if you are local!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-6203371226130263502?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/6203371226130263502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=6203371226130263502' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6203371226130263502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/6203371226130263502'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_10_01_archive.html#6203371226130263502' title='Federal Identity Interop and Initiatives'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/StyJvPIIjLI/AAAAAAAACwM/pzMdPfYJE44/s72-c/smartcards.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5387896807274924591</id><published>2009-10-15T12:51:00.000-07:00</published><updated>2009-10-15T13:35:24.834-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AAAplliance'/><title type='text'>Attribute Authority Appliances</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/us/corporate/press/036544"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 104px; height: 30px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/Std9lD7vGjI/AAAAAAAACwE/B5gazJD6iuU/s200/OracleSun.jpg" alt="" id="BLOGGER_PHOTO_ID_5392917154463947314" border="0" /&gt;&lt;/a&gt;The first part of this week I watched majority of the&lt;a href="http://www.oracle.com/us/openworld/034626.htm"&gt; Oracle Open World Keynotes &lt;/a&gt;(including Larry Ellison, Scott Mcnealy, Thomas Kurian, S. Gopalkrishnan (CEO Infosys) and many others). There were a number of fantastic news:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Continued Commitment to Sun Technologies&lt;/li&gt;&lt;li&gt;World record &lt;a href="http://www.oracle.com/us/corporate/press/036544"&gt;TPC-C benchmarks on Oracle Sun/DB appliance&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Communication enabled Business Processes&lt;/li&gt;&lt;li&gt;The &lt;a href="http://www.oracle.com/features/exadatachallenge.html"&gt;10 million dollar challenge&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Oracle Enterprise Manager updates&lt;/li&gt;&lt;/ul&gt;This new &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/SSSAB"&gt;DB appliance is directly relevant&lt;/a&gt; for many projects that are building Attribute Authorities (which augment AuthN and AuthZ Authorities in Federated Systems), for its superior performance and throughput achieved. Other than direct Identity Centric Attributes, there are many Industry Specific Attribute Authorities that need to federate Attributes (such as the &lt;a href="http://www.context.futuretext.com/"&gt;mobile or telecom industry, enterprises in health care, finance, education, govt, etc., social networks and more&lt;/a&gt;..). We are working on multiple OpenSSO projects where the ID repository plug-in is used to connect to MySQL and Oracle Databases to federate appropriate attributes for the appropriate context (in conjunction with a &lt;a href="http://www.policy.futuretext.com/"&gt;XACML entitlement engine&lt;/a&gt; that enforces the respective policies). There is a whole set of &lt;a href="http://www.oracle.com/database/exadata.html"&gt;amazing technology behind this appliance&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I also saw the demo of business processes that spanned HR, CRM, Supply Chain, wherein Identity enabled Communications was embedded into these services as part of the demo (which I thought was cool). Remember every call, connection and collaboration is made for a context.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5387896807274924591?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5387896807274924591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5387896807274924591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5387896807274924591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5387896807274924591'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_10_01_archive.html#5387896807274924591' title='Attribute Authority Appliances'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/Std9lD7vGjI/AAAAAAAACwE/B5gazJD6iuU/s72-c/OracleSun.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-4188802178099448540</id><published>2009-09-28T07:12:00.000-07:00</published><updated>2009-09-28T07:22:24.434-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CCContextMEP'/><title type='text'>Carrier Network &amp; Corporate Network Context</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://weblogs.java.net/blog/spericas/archive/2008/07/sun_java_mobile.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 78px; height: 45px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SsDEvB11N2I/AAAAAAAACvc/bWv5ADtAHII/s200/2-tier.gif" alt="" id="BLOGGER_PHOTO_ID_5386521466562230114" border="0" /&gt;&lt;/a&gt;This perspective of adding &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/RRRRBAC"&gt;ABAC (conditions and constraints) to an already implemented RBAC&lt;/a&gt; project is exactly what we are doing with an Enterprise (a large financial institution) that is taking it's home grown Industry specific applications (originally written for the client server model and later to the web) to the Mobile world with the help of a specific Wireless Carrier and Sun's &lt;a href="http://docs.sun.com/app/docs/coll/1780.1"&gt;Mobile Enterprise Platform&lt;/a&gt;. Existing RBAC implementation is augmented with ABAC (Aligning the Enterprise Context with the Mobility Context) so these mobile apps can now be delivered by adhering to the different policy domains (privacy policies, QOS policies and more) and leveraging the appropriate context.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-4188802178099448540?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/4188802178099448540/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=4188802178099448540' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4188802178099448540'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/4188802178099448540'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#4188802178099448540' title='Carrier Network &amp; Corporate Network Context'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SsDEvB11N2I/AAAAAAAACvc/bWv5ADtAHII/s72-c/2-tier.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-5885009174316492559</id><published>2009-09-28T05:25:00.001-07:00</published><updated>2009-09-28T06:50:12.688-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RRRRBAC'/><title type='text'>RBAC0, RBAC1, RBAC2 &amp; RBAC3</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_RI178MJjsuE/SsCrgoa_QcI/AAAAAAAACvU/RZA4IiYBXqk/s1600-h/RBAC3.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 79px; height: 59px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SsCrgoa_QcI/AAAAAAAACvU/RZA4IiYBXqk/s200/RBAC3.gif" alt="" id="BLOGGER_PHOTO_ID_5386493731429892546" border="0" /&gt;&lt;/a&gt;Our last lecture at GMU was all about &lt;a href="http://en.wikipedia.org/wiki/Role-based_access_control"&gt;RBAC&lt;/a&gt;. I've always known that there were several iterations of &lt;a href="http://csrc.nist.gov/groups/SNS/rbac/faq.html"&gt;RBAC &lt;/a&gt;from RBAC0 to RBAC3 -- with Role Hierarchy and Constraints, yet I got more clarity in terms of its developments after the lecture. RBAC0 was the base model, RBAC1 had role hierarchies and RBAC2 had constraints ( &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_RI178MJjsuE/SsCraCzSfaI/AAAAAAAACvM/CfE1yfDt0UI/s1600-h/RBAC3w.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 73px; height: 55px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/SsCraCzSfaI/AAAAAAAACvM/CfE1yfDt0UI/s200/RBAC3w.gif" alt="" id="BLOGGER_PHOTO_ID_5386493618252053922" border="0" /&gt;&lt;/a&gt;in parallel paths), RBAC3 combined both hierarchies and constraints together. It should be noted that &lt;a href="http://en.wikipedia.org/wiki/XACML" title="XACML"&gt;XACML&lt;/a&gt; as an Attribute Based Access Control (ABAC) model also incorporates RBAC. We could have a RBAC based PDP within an Enterprise that gets its conditions and constraints (attributes) from a XACML PDP, &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/AAA7"&gt;unique to each authenticated session&lt;/a&gt;. Of course there is more to &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/VVVAAU"&gt;Role Management&lt;/a&gt; than just AC, it is intertwined with your business processes, IT processes, provisioning and more. We need the Cars, Trains and the Planes and Boats..  BTW: My good friend Babak from Axiomatic's emailed me about this &lt;a href="http://www.kuppingercole.com/events/n40063"&gt;webinar tomorrow&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-5885009174316492559?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/5885009174316492559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=5885009174316492559' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5885009174316492559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/5885009174316492559'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#5885009174316492559' title='RBAC0, RBAC1, RBAC2 &amp; RBAC3'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SsCrgoa_QcI/AAAAAAAACvU/RZA4IiYBXqk/s72-c/RBAC3.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7777410575403746975</id><published>2009-09-11T18:46:00.000-07:00</published><updated>2009-09-13T10:38:08.244-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='KKKeynotes'/><title type='text'>Keeping a tab on my Keynotes and Key Patents</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.google.com/patents/about?id=mZafAAAAEBAJ&amp;amp;dq=Rakesh+Radhakrishnan"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 153px; height: 31px;" src="http://3.bp.blogspot.com/_RI178MJjsuE/Sqr9sn5M4YI/AAAAAAAACuE/mnBxV2GGC7I/s200/patent_search_logo_sm.gif" alt="" id="BLOGGER_PHOTO_ID_5380391647912452482" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;I will revisit this blog entry as I make progress with new Keynotes and Patents (on behalf of Sun Microsystems). There are 2 more patent apps and 3/4 more keynotes planned (2010):&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Patents:&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.google.com/patents/about?id=kOGJAAAAEBAJ&amp;amp;dq=Rakesh+Radhakrishnan"&gt;Technology Architecture Patent&lt;/a&gt; (SOA, SAN, ACA, etc.)&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.google.com/patents/about?id=mZafAAAAEBAJ&amp;amp;dq=Rakesh+Radhakrishnan"&gt;Container Alignment Engine&lt;/a&gt; (ID&amp;amp;Attr driven Alignment)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.google.com/patents/about?id=il-XAAAAEBAJ&amp;amp;dq=Rakesh+Radhakrishnan"&gt;App Infrastructure Sec Techniques&lt;/a&gt; (Aligned with IDS)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://identity-centric-architecture.blogspot.com/search?q=disclosure"&gt;Correlated ID Context for Vertical Integration&lt;/a&gt; (Defensive Disclosure)&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Keynotes:&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.pes.edu/mcnc/icemc2/icemc2_advance_program.pdf"&gt;ICEM2&lt;/a&gt; -- Bangalore 2007 - International Conference on Embedded Mobile Communication and Computing. Title: "Identity and Security for NGN"&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.upperside.fr/soa2007/soa2007program.htm#day2"&gt;SOA Telecom&lt;/a&gt; -- Paris 2007 - Service Oriented Architecture for Telecom. Title: "ICA Aligning SOA and NGN"&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://middleware.internet2.edu/idtrust/2008/slides/01-radhakrishnan-identity-policy.pdf"&gt;IDTrust&lt;/a&gt; -- DC 2008 - OASIS Symposium on Identity and Trust. Title: "Identity and Policy for Security, Trust and Privacy"&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computas.de/agenda.pdf"&gt;NetID&lt;/a&gt; -- Berlin 2009 -- Identity, Trust, Privacy and Security in Europe. Title: "Identity and Context"&lt;/li&gt;&lt;li&gt;&lt;a href="http://www2.pflab.ecl.ntt.co.jp/dim2009/keynote_rakesh.html"&gt;DIM&lt;/a&gt; -- Chicago 2009 -- ACM Digital Identity Management. Title: "Identity and Context for a Changing World"&lt;/li&gt;&lt;/ul&gt;Other Significant ones:&lt;br /&gt;&lt;a href="http://archive.opengroup.org/events/q405/radhakrishnan-papers.htm"&gt;&lt;br /&gt;Open Group SOA&lt;/a&gt; -- Houston 2005 - &lt;a href="http://www.outlookseries.com/RADIO/Sun_Microsystems.htm"&gt;Aligning Architectural Approaches (WS Incite Award)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://archive.opengroup.org/events/q105/radhakrishnan-rangarajan.htm"&gt;Open Group IDM&lt;/a&gt;  -- SFO 2005 - &lt;a href="http://archive.opengroup.org/events/q105/index.htm"&gt;Identity enabled Network (Trailbalzer Award)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://archive.opengroup.org/events/q106/rakesh.htm"&gt;Open Group ADM&lt;/a&gt; -- Barcelona 2006 - &lt;a href="http://www.p3i-inc.com/data/newsdetail_2.pdf"&gt;Aligning ADM and ADDM (SEI Award)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://events.oasis-open.org/home/forum/2008/workshopspeakerprofiles#rakesh"&gt;OASIS ID Workshop&lt;/a&gt; -- London 2008 - Embedding ID Policy &lt;a href="http://events.oasis-open.org/home/forum/2008/workshopspeakerprofiles#rakesh"&gt;(Above &amp;amp; Beyond Award)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.projectliberty.org/news_events/events/webcast_identity_enables_mobility_with_security_ica_aligning_soa_with_ngn"&gt;Liberty Alliance WC&lt;/a&gt; -- Web 2007 &amp;amp; 08 -- &lt;a href="http://www.projectliberty.org/liberty/content/view/full/181/%28offset%29/30"&gt;ID Sec&lt;/a&gt; and &lt;a href="http://www.projectliberty.org/resource_center/presentations_webcasts/webcast_liberty_alliance_identity_enabled_policy_orchestration"&gt;ID Policy&lt;/a&gt; (webcast audio)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7777410575403746975?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7777410575403746975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7777410575403746975' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7777410575403746975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7777410575403746975'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#7777410575403746975' title='Keeping a tab on my Keynotes and Key Patents'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/Sqr9sn5M4YI/AAAAAAAACuE/mnBxV2GGC7I/s72-c/patent_search_logo_sm.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-8608885878116648655</id><published>2009-09-11T16:41:00.000-07:00</published><updated>2009-09-11T17:14:57.932-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IDPVC'/><title type='text'>ID Proofing, ID Verification &amp; ID Credentialing</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.anakam.com/Company/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 113px; height: 27px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/SqrgYlDKt_I/AAAAAAAACt8/gCCIJ-dy0B4/s200/anakam.gif" alt="" id="BLOGGER_PHOTO_ID_5380359417714358258" border="0" /&gt;&lt;/a&gt;Anakam is one of the OpenSSO and Sun IDM ISV partner who has integrated their Solution Set around proofing, vetting/verification, credentialing, etc., very relevant for a lot of eGov initiative (as part of the Registration and Provisioning processes involved in a project). A topic I will cover at the &lt;a href="http://events.oasis-open.org/home/forum/2009/schedule"&gt;IDM event&lt;/a&gt; along with &lt;span style="color: rgb(51, 51, 51);"&gt;Badri Sriraman, Chief Architect &amp;amp; Development Manager, Identity &amp;amp; Credentialing, &lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;from Unisys, in a few weeks. &lt;a href="http://www.sun.com/software/identity/find_partner.jsp"&gt;Brent Williams (CTO) of Anakam &lt;/a&gt;will also present at the event.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8608885878116648655?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8608885878116648655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8608885878116648655' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8608885878116648655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8608885878116648655'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#8608885878116648655' title='ID Proofing, ID Verification &amp; ID Credentialing'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/SqrgYlDKt_I/AAAAAAAACt8/gCCIJ-dy0B4/s72-c/anakam.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-8750203768032808033</id><published>2009-09-11T15:08:00.001-07:00</published><updated>2009-09-11T15:19:37.493-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CClientContext'/><title type='text'>Cheng on Client Context based Authentication</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://developers.sun.com/identity/reference/techart/ipresenvauthopensso.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 40px; height: 40px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SqrKe8Yw_tI/AAAAAAAACt0/l7r4lXGZWwA/s200/bio_qingwen_cheng.jpg" alt="" id="BLOGGER_PHOTO_ID_5380335337802366674" border="0" /&gt;&lt;/a&gt;It is one thing to support multiple &lt;a href="http://docs.sun.com/app/docs/doc/820-3740/ggkxe?a=view"&gt;Authentication Context (such as SmartCard and Mobile Contract) &lt;/a&gt;and &lt;a href="http://docs.sun.com/app/docs/doc/820-3740/ggkxe?a=view"&gt;another thing to support multiple AuthN types&lt;/a&gt; (such as Role based and Realm based). There could be rules that also take into account the client context information such as IP Address, IP Address ranges, private and public IP addresses, client environment (browser, iphone), device type and more. We are working on a POC that does exactly that for a customer who takes the client context into account for the authentication mechanism to use and respectively deliver post authN rules based content. Excellent writeup, very timely and useful by &lt;a href="http://developers.sun.com/identity/reference/techart/ipresenvauthopensso.html"&gt;Cheng and team&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8750203768032808033?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8750203768032808033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8750203768032808033' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8750203768032808033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8750203768032808033'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#8750203768032808033' title='Cheng on Client Context based Authentication'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SqrKe8Yw_tI/AAAAAAAACt0/l7r4lXGZWwA/s72-c/bio_qingwen_cheng.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-8344751995982579641</id><published>2009-09-10T19:03:00.000-07:00</published><updated>2009-09-12T20:04:21.535-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TenatSun'/><title type='text'>Ten Tremendous and Terrific Years</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_RI178MJjsuE/SqmwVso2N-I/AAAAAAAACts/P2GlaU6urUs/s1600-h/DSC08117.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 66px; height: 50px;" src="http://4.bp.blogspot.com/_RI178MJjsuE/SqmwVso2N-I/AAAAAAAACts/P2GlaU6urUs/s200/DSC08117.JPG" alt="" id="BLOGGER_PHOTO_ID_5380025116676995042" border="0" /&gt;&lt;/a&gt;I still remember the day I started at Sun 10 years ago in September 1999. Since starting at School in the Summer of 1990 to do my Masters at ODU, I had been working on Sparc Systems in the School Labs with what was known as SunOS. I was a hands on administrator fixing issues and managing a group of workstations. After graduating in 92 I landed up as a Systems Analyst (with limited programming work- perl, sed, awk, grep, etc), and then a Systems Administrator, later a DB Admin, and finally a Peoplesoft Architect, before joining Sun (approximately 2 years in each area- giving me the foundation to become a Systems/IT Architect). My boss in my previous job asked me -- if you had a choice of picking your Company, who would you go work for (since I landed up with my permanent residency and was about to complete the 4 year program/contract with them). Instantly my answer was Sun Microsystems, and voila I was part of the company with Ray Metzger as my 1st boss (in Sun PS). The very 1st day at Sun, I get a call asking me to book a flt that night to Las Vegas -- the Advanced Internet Practice (under Dan Berg) was having a group meeting and I was asked to join them (my 1st trip to Vegas). This was at the hotel Paris (which was just inaugurated that Summer). The 1st 4+ years at Sun PS was awesome. I had fun doing projects for Telco's in Cananda, US and Latin America (including Mexico, Argentina and Brazil). Around the end of 2002 I decided to specialize (from generic IT/Systems Architect) in Identity related projects - since we had just released the 1st Identity Server product (based on the Liberty Alliance specs that came out in 2001). This was based on my new boss then (Ron Schmidt) recommendations and what Dr. James Baty mentioned in a CETC/CEC event in 2002. Luckily I worked on a 6 month PS project for a Wireless Company in Seattle (that was migrating from  Odyssey 1 to 2 - the name of the Architecture Initiative), with an Oblix implementation for IDS and a SOA as the Target Architecture (one phenomenal project ). That helped me transition to Software Sales and Services working on projects (POC, pilots and proto-types) primarily focusing on the NEP market (such as Nortel, Cisco, Moto, Ericsson and Siemens). This exposure resulted in a bunch of papers I wrote around "Identity enabled Networks" - which was compiled into the 1st book in 2006 (also supported by Shawn Malaney my boss then). Between 05 and 09 I also acted as the Technology Lead (1st Telco and then for OpenSSO) primarily capturing Market requirements and relaying them to product engineering (at CEC/SEC meetings in Santa Clara). Since 2004/05 I started working with many ISV's (Bonsai, Pronto, Openwave, etc.) and Sun Telco customers as well (such as Verizon, AT&amp;amp;T, Telus Mobility, etc.).. moving on to publish this series of books, and getting more industry exposure (working with TMF coop on SSO, ITU-FG on IDM for NGN, Liberty Alliance ID Assurance programs, and more). In ten years I've had 5 managers (that includes Ken English plus Dennis Mastin) and all 5 of them were true leaders!! fully supporting and encouraging individuals like me.&lt;br /&gt;&lt;br /&gt;Amazing ride, a royal ride from Paris in Vegas the 1st week at Sun to Rio in Vegas (for DIDW 09 and Kantara) next week (sept 14th - which happens to me my B'day as well).&lt;br /&gt;&lt;br /&gt;I love this Company for 5 things unique to Sun;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;A company that is brimming with technology Innovation and encourages innovation from all&lt;/li&gt;&lt;li&gt;A company that has been an Industry Leader in terms of inventions (Java, Niagara, SunSpot, etc.)&lt;/li&gt;&lt;li&gt;A management that believes in Instrumenting a culture of team work and fearless courage&lt;/li&gt;&lt;li&gt;Colleagues who are genuinely interested in working towards solving customer problems&lt;/li&gt;&lt;li&gt;and &lt;a href="http://identity-centric-architecture.blogspot.com/search/label/SunSAI"&gt;Last but not the Least a Corporate Culture to Give and Volunteer&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;I will cherish this Award, the Sun PIN and the Mongoose Bicycle (recognition award).. Similar to the thousands of employees who have completed 10 or more years.. We all got a lot from this company -- a productive atmosphere, training, exposure to high profile projects, visibility, and a solid amount of experience!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-8344751995982579641?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/8344751995982579641/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=8344751995982579641' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8344751995982579641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/8344751995982579641'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#8344751995982579641' title='Ten Tremendous and Terrific Years'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RI178MJjsuE/SqmwVso2N-I/AAAAAAAACts/P2GlaU6urUs/s72-c/DSC08117.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-1170081984364115269</id><published>2009-09-10T18:15:00.000-07:00</published><updated>2009-09-10T18:35:43.048-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SunSAI'/><title type='text'>Sun is Shaping a Sustainable Future</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.ccsforum.org/"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 39px; height: 115px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/SqmlVm1_kqI/AAAAAAAACtk/yJUnuAeEE8g/s200/text.jpg" alt="" id="BLOGGER_PHOTO_ID_5380013020493615778" border="0" /&gt;&lt;/a&gt;I noticed this upcoming event on &lt;a href="http://www.ccsforum.org/about_us.html"&gt;Corporate Culture and Ethics&lt;/a&gt; a few months back, a forum organized by &lt;a href="http://pathwaypaved4peace.blogspot.com/"&gt;IAHV &lt;/a&gt;(AOL sister organization) since I am a IAHV volunteer as well. As I'm completing 10 years at Sun Microsystems (next week), I nominated Sun Microsystem's (recently acquired by Oracle) &amp;amp; its chairman Scott McNealy - for their role played in corporate culture of volunteering and giving -- that has taken shape in  the recent years based on a number of community programs that leverage Technology.&lt;br /&gt;&lt;br /&gt;This culture is both top-down and bottom-up -- with support from Chairman of the company &lt;a href="http://www.curriki.org/xwiki/bin/view/Main/WebHome"&gt;"Scott Mcnealy" and his pet project&lt;/a&gt; Curriki is an online environment created to support the development and  free distribution of world-class educational materials to anyone who  needs them, to many grass roots level folks such as Betsy Hansen and her work at  &lt;a href="http://www.horse-power.org/"&gt;&lt;span style="text-decoration: underline;"&gt;horsepower&lt;/span&gt;&lt;/a&gt; along with &lt;a href="http://www.sun.com/aboutsun/comm_invest/25yrs.html"&gt;many such volunteers.&lt;/a&gt; With an outstanding Business Conduct - Sun was named One of the Worlds  most &lt;a href="http://www.sun.com/aboutsun/media/features/ethical/"&gt;Ethical companies recently.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Sun's technology has been leveraged by many community based  collaboration projects that aim to address issues and concerns around housing/shelter, education, transparency and more,  such as; &lt;a href="http://www.architectureforhumanity.org/"&gt;&lt;span style="text-decoration: underline;"&gt;architecture for humanity&lt;/span&gt;&lt;/a&gt; a collaborative community based  tool that helps design low cost homes for countries in Asia and Africa. This includes programs to address the  world's hardest problems, including &lt;a href="http://www.blogger.com/%3Chttp://www.data.org/%3E"&gt;DATA &lt;/a&gt;(Debt,  Aids, Trade, Africa), the &lt;a href="http://www.blogger.com/%3Chttp://www.one.org/%3E"&gt;ONE &lt;/a&gt;Campaign , Make &lt;a href="http://www.blogger.com/%3Chttp://www.makepovertyhistory.org/%3E"&gt; Poverty&lt;/a&gt; History , Oxfam , Architecture for Humanity, and others.&lt;br /&gt;&lt;br /&gt;Sun's worldwide volunteer week programs and digital divide programs have  made tremendous impacts globally:&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.sun.com/aboutsun/foundation/init_employees.jsp"&gt;http://www.sun.com/aboutsun/foundation/init_employees.jsp&lt;/a&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.sun.com/aboutsun/foundation/volunteer_programs.jsp"&gt;http://www.sun.com/aboutsun/foundation/volunteer_programs.jsp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Majority of the Sun employees and senior management I know are  volunteering in one form or another -- especially since Sun as a Corporate entity works with its employees to pursue the goals  of their choice -- one employee may be passionate about fighting cancer  programs,&lt;br /&gt;another about volunteering for digital divide, and so on -- and they may  pursue those through their own community effort and with the support from Sun, Catalyzing the initiatives with their combined efforts..&lt;br /&gt;&lt;br /&gt;As an employee who is completing 10 great years at Sun, and as Sun is celebrating 27 years - I wanted to share  my experience and understanding of how Sun Creates this Culture of  Volunteering --leveraging technology and community based tools. I got reminded about this today since I got an email about &lt;a href="http://www.sunacademic.com/"&gt;Sun's SAI!!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I hope Sun Microsystems as a corporate entity and Scott Mcnealy as the Chairman get to win this Award this year!! It will be a well deserved RECOGNITION!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-1170081984364115269?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/1170081984364115269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=1170081984364115269' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1170081984364115269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/1170081984364115269'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#1170081984364115269' title='Sun is Shaping a Sustainable Future'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/SqmlVm1_kqI/AAAAAAAACtk/yJUnuAeEE8g/s72-c/text.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-2161051146554573712</id><published>2009-09-10T17:12:00.000-07:00</published><updated>2009-09-18T12:13:08.846-07:00</updated><title type='text'>Sustained Spending on Sun Sparc and Solaris</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/features/suncustomers.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 49px; height: 75px;" src="http://3.bp.blogspot.com/_RI178MJjsuE/SqmWMlI5NrI/AAAAAAAACtc/QKAO0sjc4z8/s200/sun_customers_lg.gif" alt="" id="BLOGGER_PHOTO_ID_5379996372742780594" border="0" /&gt;&lt;/a&gt;I spoke to a few large Sun Telco shops..about &lt;a href="http://www.oracle.com/features/suncustomers.html"&gt;this Advt&lt;/a&gt;. This is very good news for them. Also watch out for &lt;a href="http://www.theregister.co.uk/2008/06/23/sun_niagara_k2/"&gt;Niagara 3&lt;/a&gt; (16 core 16 thread per core = 256 cpu threads)!! Ideal processor for large scale Identity Providers (who handle federation, authN, policies and context).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-2161051146554573712?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/2161051146554573712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=2161051146554573712' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2161051146554573712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/2161051146554573712'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#2161051146554573712' title='Sustained Spending on Sun Sparc and Solaris'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RI178MJjsuE/SqmWMlI5NrI/AAAAAAAACtc/QKAO0sjc4z8/s72-c/sun_customers_lg.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31038959.post-7895198099917652760</id><published>2009-09-09T11:17:00.000-07:00</published><updated>2009-09-09T11:33:01.080-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSSSec'/><title type='text'>Secure Span for SOA Security</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://developers.sun.com/identity/reference/techart/xmlgatewayopensso.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 70px; height: 37px;" src="http://1.bp.blogspot.com/_RI178MJjsuE/Sqfxb_KASnI/AAAAAAAACtU/goqSx63GR2k/s200/figure1.png" alt="" id="BLOGGER_PHOTO_ID_5379533743029504626" border="0" /&gt;&lt;/a&gt;With the first cut of &lt;a href="http://blogs.sun.com/docteger/entry/opensso_entitlements_service_overview"&gt;OpenSSO entitlement services&lt;/a&gt; released as part of an express release, one can easily see how existing implementations can leverage OpenSSO as a Policy Admin/Mgmt Point (PMP) and a PDP that integrates with multiple types of PEP's (such as run time policy enforcement engine from Layer 7) and other specialized PDP's. Very relevant for&lt;a href="http://www.layer7tech.com/main/#"&gt; Cloud Computing Control&lt;/a&gt;. When everything eventually ends up in the clouds, IaaS, SaaS, PaaS, S(ec)aaS, and more -- policies in conjunction with attribute authorities aka PIP (SLA as well) becomes pervasive.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31038959-7895198099917652760?l=identity-centric-architecture.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identity-centric-architecture.blogspot.com/feeds/7895198099917652760/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31038959&amp;postID=7895198099917652760' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7895198099917652760'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31038959/posts/default/7895198099917652760'/><link rel='alternate' type='text/html' href='http://identity-centric-architecture.blogspot.com/2009_09_01_archive.html#7895198099917652760' title='Secure Span for SOA Security'/><author><name>Rakesh</name><uri>http://www.blogger.com/profile/05795934513331666808</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://photos1.blogger.com/blogger/7954/3341/1600/rk01%20027.0.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RI178MJjsuE/Sqfxb_KASnI/AAAAAAAACtU/goqSx63GR2k/s72-c/figure1.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
