idtrust.xml.org - Online community for identify and trusted infrastructure standards
Welcome to IDtrust XML.org. This is the official community gathering place and information resource for identify and trusted infrastructure standards. The site is hosted by the OASIS IDtrust Member Section, a group that encourages new participation from developers and users. This is a community-driven site, and the public is encouraged to contribute content.

  • NetworkWorld: Internet Identity Workshop throws up the question of what's next in identity?
  • PingFederate Web Services Provides WS-Trust Security Token Service (STS)
  • CNET: Expect More PKI in 2008
  • Symmetric Key Management System (SKMS)

    Symmetric Key Management Systems address the need to improve the way that enterprises manage symmetric keys over their lifecycle.

    read more

  • Symmetric Cryptography Authentication

    While not as popular as public key methods, there are strong mechanisms for establishing authenticity through symmetric cryptography. If Alice and Bob know they have a reliable and unique shared secret (symmetric) key, then the ability for either of them to sensibly decrypt a message with that key provides strong evidence that the encrypted message came from the other party. Defence methods like the Fortezza card uses symmetric authentication in this way.

    NEEDS MORE DETAIL

  • Two Factor Authentication

    Setting aside the fact that smartcards and other cryptographic devices constitute "two factor" authentication, the term is often used to refer to a large class of personal authentication devices that generate a pass phrase or other login code, used to access online resources. There are three important sub-classes:

    Time Syncronised One Time Password: every thirty seconds or so, the device generates a fresh pseudo random one time password. The pseudo random number generator is seeded uniquely for each specific device.

    read more

  • Policy Frameworks for Trust & Identity
    Government authentication policy

    There are several policy approaches to authentication, in principle, which tend to vary from one jurisdiction to another according to political philosophy.

    read more

  • Regulatory Approaches to Trust & Identity

     

    A taxonomy of e-signature regulatory models

     

    There are three different types of electronic signature legislation worldwide, offering different degrees of legal certainty with respect to security technology, and fundamental trade-offs with respect to freedom of choice.

    read more

  • Fundamentals of Identity & Authentication

    The OASIS IDtrust Member Section was formed in 2006, partly on top of the erstwhile PKI Forum and OASIS PKI Member Section, in response to an intensifying yet broadening interest amongst businesses and vendors in the tpics of "identity" and "trust". In this we are probably paralleling the "Identity 2.0" movement.

    read more

  • Other Identity Technologies

    A number of mechanisms apart from PKI may be used to authenticate people and entities online.