{"id":1049,"date":"2009-06-09T11:33:06","date_gmt":"2009-06-09T19:33:06","guid":{"rendered":"\/?p=1049"},"modified":"2009-06-10T07:10:17","modified_gmt":"2009-06-10T15:10:17","slug":"definitions-for-a-common-identity-framework","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=1049","title":{"rendered":"Definitions for a Common Identity Framework"},"content":{"rendered":"<p>The <a href=\"\/wp-content\/images\/2009\/06\/UserCentricIdentityMetasystem.html\" class=\"broken_link\">Proposal for a Common Identity Framework<\/a> begins\u00a0by explaining the\u00a0termnology it uses.\u00a0\u00a0This wasn&#39;t intended to open up old wounds or provoke ontological\u00a0debate.\u00a0\u00a0We just wanted\u00a0to reduce ambiguity about what we actually mean to say\u00a0in the rest of the paper.\u00a0\u00a0To do this,\u00a0we did think very carefully about what we were going to call things, and tried to be very precise about our use of terms.<\/p>\n<p>The paper presents its definitions in alphabetical order to faciliate lookup while reading the proposal, but I&#39;ll group them differently here to facilitate discussion.<\/p>\n<p>Let&#39;s start with the series of definitions pertaining to claims.\u00a0 It is key to the document that claims are assertions by one subject about another subject that are &#8220;in doubt&#8221;.\u00a0\u00a0This is a fundamental\u00a0notion\u00a0since\u00a0it leads to an understanding\u00a0that one of the\u00a0basic services of a multi-party model\u00a0must be\u00a0&#8220;Claims Approval&#8221;.\u00a0\u00a0The simple assumption by systems that assertions <em>are true<\/em> &#8211;\u00a0in other words the failure\u00a0to factor out &#8220;approval&#8221; as a separate service &#8211; has lead to conflation and insularity in earlier systems.<\/p>\n<ul>\n<li><strong>Claim:<\/strong>\u00a0 an assertion made by one subject about itself or another subject that a relying party considers to be \u201cin doubt\u201d until it passes \u201cClaims Approval\u201d<\/li>\n<li><strong>Claims Approval:<\/strong> The process of evaluating a set of claims associated with a security presentation to produce claims trusted in a specific environment so it can used for automated decision making and\/or mapped to an application specific identifier.<\/li>\n<li><strong>Claims Selector:<\/strong>\u00a0 A software component that gives the user control over the production and release of sets of claims issued by claims providers.\u00a0<\/li>\n<li><strong>Security Token:<\/strong>\u00a0 A set of claims.<\/li>\n<\/ul>\n<p>The concept of claims provider is presented in relation to &#8220;registration&#8221; of subjects.\u00a0 Then claims are divided into two broad categories:\u00a0 primordial and substantive&#8230;<\/p>\n<ul>\n<li><strong>Registration:<\/strong>\u00a0 The process through which a primordial claim is associated with a subject so that a claims provider can subsequently issue a set of claims about that subject.<\/li>\n<li><strong>Claims Provider:<\/strong>\u00a0 An individual, organization or service that:<\/li>\n<\/ul>\n<ol style=\"margin-left: 60px;\">\n<li>Registers subjects and associates them with primordial claims, with the goal of subsequently exchanging their primordial claims for a set of substantive claims about the subject that can be presented at a relying party; or<\/li>\n<li>Interprets one set of substantive claims and produces a second set (this specialization of a claims provider is called a claims transformer).\u00a0 A claims set produced by a claims provider is not a primordial claim.<\/li>\n<\/ol>\n<ul>\n<li><strong>Claims Transformer:<\/strong>\u00a0 A claims provider that produces one set of substantive claims from another set.<\/li>\n<\/ul>\n<p>To understand this better let&#39;s look\u00a0at\u00a0what\u00a0we mean\u00a0by\u00a0 &#8220;primordial&#8221; and &#8220;substantive&#8221; claims.\u00a0 The word\u00a0&#8220;primordial&#8221; may\u00a0seem a strange at first, but\u00a0its use\u00a0will be seen to be\u00a0rewardingly precise:\u00a0 <em>Constituting the beginning or starting point, from which something else is derived or developed, or on which something else depends. (OED)\u00a0.<\/em><\/p>\n<p>As will become clear, the\u00a0claims-based model\u00a0works through the\u00a0use of &#8220;Claims Providers&#8221;.\u00a0 In the most basic case, subjects\u00a0prove\u00a0to\u00a0a claims provider that they are\u00a0an entity it has registered, and\u00a0then the claims provider makes\u00a0&#8220;substantive&#8221; claims about them.\u00a0 The subject proves that it is\u00a0the registered entity\u00a0by using a &#8220;primordial&#8221; claim &#8211; one which is thus the beginning or starting point, and from which the provider&#39;s substantive claims are derived.\u00a0 So our definitions\u00a0are the following:\u00a0<\/p>\n<ul>\n<li><strong>Primordial Claim:<\/strong> A proof \u2013 based on secret(s) and\/or biometrics \u2013 that only a single subject is able to present to a specific claims provider for the purpose of being recognized and obtaining a set of substantive claims.<\/li>\n<li><strong>Substantive claim:<\/strong>\u00a0 A claim produced by a claims provider \u2013 as opposed to a primordial claim.<\/li>\n<\/ul>\n<p>Passwords and secret keys are therefore examples of &#8220;primordial&#8221; claims, whereas SAML tokens and X.509 certificates (with DNs and the like) are examples of substantive claims.\u00a0<\/p>\n<p>Some will say, &#8220;Why don&#39;t\u00a0you just use the word\u00a0&#8216;credential'&#8221;?\u00a0\u00a0\u00a0The answer is simple.\u00a0 We\u00a0avoided \u201ccredential\u201d precisely because people use it to mean <em>both<\/em> the primordial claim (e.g. a secret key) and the substantive claim (e.g. a certificate or signed statement).\u00a0\u00a0\u00a0This conflation makes it unsuitable for\u00a0expressing the distinction between primordial and substantive, and this distinction is essential to properly factoring the services in the model.<\/p>\n<p>There are a number of definitions pertaining to subjects, persons\u00a0and identity itself:<\/p>\n<ul>\n<li><strong>Identity:<\/strong>\u00a0 The fact of being what a person or a thing is, and the characteristics determining this.<\/li>\n<\/ul>\n<p>This definition of identity is quite different from the definition that conflates identity and &#8220;identifier&#8221; (e.g. <a href=\"mailto:kim@foo.bar\">kim@foo.bar<\/a> being called an identity).\u00a0 Without clearing up this confusion, nothing can be understood.\u00a0\u00a0 Claims are the way of\u00a0communicating what a person or thing is &#8211; different from being that person or thing.\u00a0 An identifier is one possible claim content.<\/p>\n<p>We also distinguish between a &#8220;natural person&#8221;, a &#8220;person&#8221;, and a &#8220;persona&#8221;, taking into account input from the legal and policy community:<\/p>\n<ul>\n<li><strong>Natural person:<\/strong>\u00a0 A human being&#8230;<\/li>\n<li><strong>Person:<\/strong>\u00a0 an entity recognized by the legal system.\u00a0 In the context of eID, a person who can be digitally identified.<\/li>\n<li><strong>Persona:<\/strong>\u00a0 A character deliberately assumed by a natural person<\/li>\n<\/ul>\n<p>A &#8220;subject&#8221; is much broader, including things like services:<\/p>\n<ul>\n<li><strong>Subject:<\/strong>\u00a0 The consumer of a digital service (a digital representation of a natural or juristic person, persona, group, organization, software service or device) described through claims.<\/li>\n<\/ul>\n<p>And what about user?<\/p>\n<ul>\n<li><strong>User:<\/strong>\u00a0 a natural person who is represented by a subject.<\/li>\n<\/ul>\n<p>The entities that depend on identity are called relying parties:<\/p>\n<ul>\n<li><strong>Relying party:<\/strong>\u00a0 An individual, organization or service that depends on claims issued by a claims provider about a subject to control access to and personalization of a service.<\/li>\n<li><strong>Service:<\/strong>\u00a0 A digital entity comprising software, hardware and\/or communications channels that interacts with subjects.<\/li>\n<\/ul>\n<p>Concrete services that interact with subjects (e.g. digital entities) are not to be confused with the abstract services that constitute our model:<\/p>\n<ul>\n<li><strong>Abstract services:<\/strong>\u00a0 Architectural components that deliver useful services and can be described through high level goals, structures and behaviors.\u00a0 In practice, these abstract services are refined into concrete service definitions and instantiations.<\/li>\n<\/ul>\n<p>Concrete digital services, including both relying parties and claims providers, operate on the behalf of some &#8220;person&#8221; (in the sense used here of legal persons including organizations).\u00a0 This implies operations and administration:<\/p>\n<ul>\n<li><strong>Administrative authority:<\/strong>\u00a0 An organization responsible for the management of an administrative domain.<\/li>\n<li><strong>Administrative domain:<\/strong>\u00a0 A boundary for the management of all business and technical aspects related to:<\/li>\n<\/ul>\n<ol style=\"margin-left: 60px;\">\n<li>A claims provider;<\/li>\n<li>A relying party; or<\/li>\n<li>A relying party that serves as its own claims provider\u00a0<\/li>\n<\/ol>\n<p>There are several definitions that are necessary to understand how different pieces of the model fit together:<\/p>\n<ul>\n<li><strong>ID-data base:<\/strong>\u00a0 A collection of application specific identifiers used with automatic claims approval<\/li>\n<li><strong>Application Specific Identifier (ASID):<\/strong>\u00a0 An identifier that is used in an application to link a specific subject to data in the application.<\/li>\n<li><strong>Security presentation:<\/strong>\u00a0 A set consisting of elements like knowledge of secrets, possession of security devices or aspects of administration which are associated with automated claims approval.\u00a0 These elements derive from technical policy and legal contracts of a chain of administrative domains.<\/li>\n<li><strong>Technical Policy:<\/strong>\u00a0 A set of technical parameters constraining the behavior of a digital service and limited to the present tense.<\/li>\n<\/ul>\n<p>And finally, there is\u00a0the definition of <strong>what we mean by user-centric<\/strong>.\u00a0\u00a0Several colleagues have pointed out\u00a0that the word &#8220;user-centric&#8221; has been used recently to justify all kinds of schemes that usurp the autonomy of the user.\u00a0 So we want to be very precise about what we mean in this paper:<\/p>\n<ul>\n<li><strong>User-centric:<\/strong>\u00a0 Structured so as to allow users to conceptualize, enumerate and control their relationships with other parties, including the flow of information.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>We presented our definitions to achieve clarity, not to provoke ontological debate&#8230;<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[37,70,6,8,5],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1049"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1049"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1049\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}