These are my raw notes put here for reference purposes.
–
Attendees
- Peter A
- Mary R
- Ian G
- Gerry B
- others
What is mean by identity oracle?
* An oracle provides an answer to a question but not a specific attribute
** If you ask an Oracle, is Peter over 21 it says yes. It does not hand back an attribute – birthdate
Peter: The Federal Govt is authoritative for very few attributes – State Dept – passport #, citizenship. State govt are authoritative for driver’s license number. SSA for SSN.
eVerfify is an example of an oracle, says Gerry.
Peter – what will drive this is the requirement for LOA3 credentials needed to access to medical records.
P – “We do not have an attribute infrastructure.” A lot of attributes are simply issued via IdP’
I – our examples so far have shown organizations that are authoritative for identifiers but not attributes
P – raises need for back end attribute exchange
Gerry – Problem with authoritative attribute provides is that the PDP makes a decision as to what is truly authoritative for a given context. Authoritative data source must provide SLA or MOU so that relying party can establish trust.
P – BAE is 1/2 of the equation and attribute provider (market?) is the other half
A – is there a business model for attribute providers? Continue reading "Notes from the “Government as Identity Oracle” session at IIW East"...
what others say