Independent Identity


By tradition I give the closing keynote at Digital ID World. I've been doing that since 2002, when the show began. From the beginning I've had a case to make. I'm still making it.

The case is this:

  1. In a truly open and free marketplace, vendors in a category compete openly for a customer's business, based on information the customer supplies, at his or her discretion, to any or all of them. Customer data isn't all isolated in vendor silos, and customers aren't forced to go from one silo to another and interact separately with each vendor's exclusive CRM (Customer Relationship Management) system and its locked-up data.
  2. Customers won't have full power in the marketplace until they control their own data, and selectively make it available to vendors. Drummond Reed of Cordance and Identity Commons calls this CoRM, for Company Relationship Management.
  3. Powerful customers make markets grow. Customers with CoRM will blow the CRM blinders off vendors, and invite all kinds of entrepreneurship, differentiation and innovation.
  4. CoRM requires identity services that do not yet exist. Those services need to be part of the suite of open and free infrastructural architectures and building materials of the Net and the Web.

One reason is that the organizers know I risk being entertaining, which might keep some attendees from heading off early to planes and golf dates. But the main reason is that I reliably insist that identity is fundamentally a personal rather than a corporate issue, and that the only digital identity movement worthy of the name will grow up from individuals rather than down from big companies.

It's a fun gig, but by the middle of last year I had begun to lose faith that anything would ever grow up from the grass roots. Then I met Kaliya ("Identity Woman") Hamlin at a ball game. She introduced me to the folks at Identity Commons, and they gave me lots of fodder for my keynote. It went well, wrote that story up in "What's your i-Name?", my column for the January 2005 issue of Linux Journal. Here are some excerpts from the column that explain my case:

Even though the Net has enlarged and leveled the playing field we call the marketplace, customer reach still fails to exceed vendor grasp. Networked customers may get smarter faster than most vendors, as Cluetrain also said, but market power still is unbalanced in favor of vendors, and that's not good for either side...

Even on the customer side, the credit-card system alone is so familiar and so deeply ingrained in our culture, that it's hard to imagine life as a fully empowered customer. It's even harder to imagine a marketplace in which vendors compete to fulfill needs that customers themselves express.
Imagine walking up to the counter at a random coffee shop and presenting a card that lets the barista know you like double short decaf capuccinos. Or imagine a world where car rental agencies really do compete to provide you with the car you want and the options you want rather than Yet Another Chevy Cavalier, plus the usual up-sell for insurance and an extra tank of gas.
Imagine that same identity card--one you own, that contains secure pointers to whatever identity, preference, interaction history and relationship information you choose to accumulate and disclose, for your own or mutual purposes--letting the coffee shops on a road trip know you're coming.
We're not going to get that from vendors, for the same reason we didn't get Linux from vendors: Big suppliers in any category have trouble pioneering anything that's good for everybody and not only for them.

Since then the identity conversation has grown a lot more, um... interesting. Because the grass roots identity ideas that are getting the most attention and encouragement -- even from the Identity Commons people -- are coming from an unlikely place. Namely, Microsoft.

The most concrete product of those ideas is the Identity Metasystem. It is, by definition, not owned by Microsoft. The "meta" prefix in this case refers to inclusion. Above or around would be better synonymous prepositions than about (which is the approximate meaning of "meta" in metadata). While it may seem odd that Microsoft would suggest the need for a market solution they don't own, it's quite sensible to expect such a solution to come from Kim Cameron, architect of the identity metasystem.

Kim came to Microsoft by way of acquisition, when Microsoft bought Zoomit, a Toronto company specializing in the "metadirectory" field. I came to know Kim through Craig Burton of The Burton Group, back in the early 1990s. Craig saw non-interoperable directories as a problem that could only be solved by a system that was intentionally inclusive and respectful toward all of them. Her labeled the absent system a "metadirectory", and called for vendors to fill the market's need for one. Kim Cameron and Zoomit stepped forward and developed a metadirectory product, along with a lot of deep thinking about directories. During that time I became good friends with Kim, an an occasional consultant to Zoomit.

As it happened, Microsoft acquired Zoomit at about the time it was becoming clear that Microsoft was failing miserably with Passport, a centralized identity management system that had the misfortune of launching as part of an initiative that may have had the scariest name in Microsoft's history: "Hailstorm." (I wrote about Passport and Hailstorm in "Whose hand is that in your pocket", for the July 2001 Linux Journal.)

At Microsoft Kim quickly took an interest in identity as an issue, and began thinking about using a "meta" approach that would open a whole new marketplace, for Microsoft and everybody else. Craig Burton took a natural interest in Kim's identity work at Microsoft, and told me he thought it had the potential to fulfill the grass-roots growth scenario I had been calling for at each of my DIDW keynotes.

So I made sure, at DIDW, that Kim got to connect with the other grass-roots advocates attending the conference: Drummond Reed, Fen LaBalme, Mark LeMaitre, Kaliya Hamlin, Jan Hauser and Owen Davis of Identity Commons (and also, for several on that list, of Seattle-based Cordance); Dick Hardt of Sxip, Marc Canter (currently of Broadband Mechanics, but perhaps best known as a founder of Macromind, which later became Macromedia) and Phil Windley of Brigham Young University (also former CIO of Utah and the author of a book from O'Reilly on digital identity). All are open source and open standards advocates, and all consider open source involvement essential to the success of whatever it was Kim and Microsoft had in the works, which still wasn't clear at the time.

The group hit it off. A number of meetings followed in Seattle, between various parties in the last two paragraphs. Craig Burton flew up from Scottsdale for some of them as well.

Kim also began publishing his Identity Weblog (at identityblog.com) right after DIDW, gradually posting Seven Laws of Identity. He did this on the installment plan, to give everybody time to talk about each one before moving on to the next. His First Law appeared on November 16, and his Seventh Law appeared on March, 2005. Here's how Kim explained them, as he rolled them out on the IdentityBlog:

(These) define the set of "objective" dynamics that constrain the definition of an identity system capable of being widely enough accepted that it can enable distributed computing on a universal scale.  It is essential that we change the identity conversation enough that its laws are no longer argued as "moral imperatives", but rather as explanations of dynamics which must be mastered to craft such a universal system. 

  1. The Law of Control: 
    Technical identity systems MUST only reveal information identifying a user with the user's consent.
  2. The Law of Minimal Disclosure
    The solution which discloses the least identifying information is the most stable, long-term solution.
  3. The Law of Fewest Parties
    Technical identity systems MUST be designed so the disclosure of identifying information is limited to parties having a necessary and justifiable place in a given identity relationship.
  4. The Law of Directed Identity
    A universal identity system MUST support both "omnidirectional" identifiers for use by public entities and "unidirectional" identifiers for use by private entities, thus facilitating discovery while preventing unnecessary release of correlation handles.
  5. The Law of Pluralism: 
    A universal identity system MUST channel and enable the interworking of multiple identity technologies run by multiple identity providers.
  6. The Law of Human Integration: 
    The universal identity system MUST define the human user to be a component of the distributed system, integrated through unambiguous human-machine communications mechanisms offering protection against identity attacks.
  7. The Law of Harmonious Contextual Autonomy
    The unifying identity metasystem MUST facilitate negotiation between relying party and user of the specific identity and its associated encoding such that the unifying system presents a harmonious technical and human interface while permitting the autonomy of identity in different contexts.

The names of the laws have changed somewhat in the months since they were first published. For example, in Microsoft's official Laws of Identity paper, the laws are expressed as topical headings. (In my keynote at DIDW in April 2005 I suggested that Kim adopt the speech of a burning bush, and say "Thou shalt..." and "Thou shalt not...")

The Laws had two obvious puproses. The first was, explicitly, to guide development in an emerging marketplace. The second was, implicitly, to make sure his employer didn't make exactly the kind of market-dominating moves everybody naturally expected.

In November, Marc and Kim blogged back and forth about what Craig Burton delicately characterized in his own blog as "the benefits and dangers of doing business with Microsoft". Craig explained,

Marc contends that people don't want to get locked into standards owned by Microsoft or Sun. Kim wants to look beyond the past and create a "big bang" of distributed computing that would eclipse the petty Microsoft bashing. In Marc's defense, Microsoft is an unabashed bully. The leaders of Microsoft--Bill Gates and Steve Ballmer--lead the bully behaviour. I have personal experience of this behaviour from both of them. Microsoft doesn't and isn't going to play fair anytime in the future--in general.

Perspective: Craig fought Microsoft, head to head, at Novell in the 1980s. And usually won. One high-level Microsoft executive told me years later that Craig was perhaps the only executive at a competing company that truly unerstood how to compete and win against Microsoft. Craig continues,

I say "in general" for a reason. There are good people with vision and integrity at Microsoft. Kim Cameron is one of those people. You can't go wrong working with Kim. Further, it is just ludicrous to think that Microsoft is of one voice and has an overarching plan with which to rule everything always and forever... I have said before to Kim that working at Microsoft is like working inside 10 tornadoes. I am changing that to a thousand tornadoes. Each tornado (or hailstorm if you like) has its own path, thinking and objective. They seldom cross paths and are too busy dealing with the issues at hand to even talk to each other. Microsoft is a thousand tornadoes deep.

Microsoft bashing aside, when two people like Marc and Kim get together and collaborate, expect good things to happen that go beyond the history of giants--even the giant of all time--Microsoft.

Through November and December, I

None of the points I've made so far are new. In fact, I've made them in my closing keynotes at every Digital Identity World (DIDW) since the first one in 2002. My most recent DIDW keynote was in May, 2005, and I said it again there too.

But this time there was a difference. This time we had signs of progress. Big ones. Interested individuals and organizations were now meeting, publishing, working on products and protocols, finding and implementing useful standards, and adjusting work already in progress. An informal group had gathered around a shared belief that the world needed a new class of identity services that carried such adjectives as "grass roots", "lightweight", "user-centric", "next-generation", "independent", "human origin", "bottom-up", "distributed" and "individual".

The first Independent Identity meetings took place at the DIDW/2004, which was held last October in Denver.

At an Identity Commons BoF (Birds of a Feather) session, Drummond Reed of Cordance (and a winner of DIDW's first award, in 2002, for the XRI/XDI standard) suggested the need for CoRM, or "Company Relationship Managment": an ability by customers to manage relationships with multiple companies, and to support the safe and selective sharing of identity-related data with those companies for mutually agreeable purposes. This, we agreed, would be far better for the marketplace than the silo'd marketing machinery in every vendor's Customer Relationship Management (CRM) system.

We also agreed that CoRM-enabled customers in open markets would be a Good Thing for vendors as well. Customer relationships would be two way, not one-way. And they would provide vendors with much more useful data than silo'd CRM systems would ever allow -- much as the open Internet is better for everybody's business than the closed LANs and online services we had back in the 80s and early 90s. Many rich, interesting and useful customer relationships would be possible. Better products and services would follow. Vendor differentiation and specialization would increase, as resourceful sources of supply began to follow independent forms of demand.

In addition to Identity Commons, several other parties joined a series of subsequent conversations at DIDW, a In part this was a reaction to heavy conversation around

So instead I'll

To some degree all these adjectives were equal-and-opposite reactions to domination of DIDW's stage by large technology companies and preoccupation with identity problems shared by the customers of those companies. Issues included the usual: trust, privacy, authentication, single-sign-on, PKI, standards and compliance, combating fraud, distributed directories, RFID, and managing all the above. But the biggest buzzword at the conference was "federation". In an IT Conversations interview, Eric Norlin of Ping Identity Corp. (disclosure: I'm on the company's advisory board) called federation a "concept" or an "approach" that "leaves the distributed environment as it is, but seeks to let the end user link together those pieces and still have control over their privacy, what gets shared, and how. The Liberty Alliance spec, he says, "is purposefully designed to be opaque. (It) tries to accomplish one thing... to allow one end user to link one account to another account. But in order to protect the privacy of the end user... neither side of that account -- either Company A or Company B --would know who the end user is that is being passed between them. In other words, in oeder to find that it was me that was linking between Companies A and B, they would actually have to go outside of the specification through a backchannel. So the specification puposefully makes it hard to violate someone's privacy."

I've summarized this as "large companies having safe sex using customer data". This is less fair than funny, but it accurately characterizes federation as a big company concern. While federation might protect customers and provide them with certain benefits, it is essentially a silo-to-silo "solution." So far.

Liberty Alliance isn't the only consortium devoted to federation. The other big one is WS-I (where WS stands for Web Services). WS-I was founded by Microsoft, IBM and Verisign. Liberty Alliance was initiated by Sun, partly in response to Microsoft's Passport, which was part of a scary-sounding initiative called "Hailstorm". Liberty gathered pretty much everybody not in the WS-I -- though many companies belong to both. For most of DIDW's history, the Liberty Alliance has had the higher profile.

In DIDW/2005, held this past April in San Francisco, Liberty's profile dropped almost to zero. I'm not sure why, or if it matters, beyond the degree to which the grass roots movement -- which I'll call Independent Identity -- adopts standards gleaned from the WS-I library. This appears likely, since it was in that library that Kim Cameron, chief Identity Architect at Microsoft, found what he needed to structure what he calls the "identity metasystem."

This is a system that, by definition, is not owned in any way by Microsoft. The "meta" prefix in this case refers to inclusion. Above or around would be better synonymous prepositions than about (which is the approximate meaning of meta in metadata).

In fact, little or none of your customer data belongs to you, or is in your control. It belongs to the silo owners. To suppliers. It's data about you as Thrifty, Hertz, or Avis customer. Not as a rental car customer.

In other words, there is no such thing as a customer in the market for rental cars. Unless you understand that market to consist of a silo cluster surrounded by no open space at all.

Which is exactly what we do. We've been defining markets (actually, categories) as collections of vendor offerings for a dozen decades or more. We regard our silo memberships as a grace at best and an annoyance at worst. But in either case we frame our understanding in terms provided by the supply side. Our demand is not sovereign. Our choices are not free, because they between silos, and the offerings inside each silo.

Nothing clarifies the problem here more than a customer-side look at what we euphemistically call a Customer Relationship Management (CRM) system. Wikipedia says CRMs "enable organizations to better serve their customers through the introduction of reliable processes and procedures for interacting with those customers". But what kind of interaction are we talking about? Wikipedia explains,

The operational part of CRM typically involves three general areas of business: Enterprise Marketing Automation (EMA), Sales Force Automation (SFA) and Customer Service and Support (CSS). EMA provides information about the business environment, including competitors, industry trends, and macroenviromental variables. SFA automates some of the company's sales and sales force management functions; for example, keeping track of customer preferences, buying habits, and demographics, as well as sales staff performance. CSS automates some service requests, complaints, product returns, and information requests.

Many call centers use CRM software to store all of their customer's details. When a customer calls, the system can be used to retrieve and store information relevant to the customer. By serving the customer quickly and efficiently, and also keeping all information on a customer in one place, a company aims to make cost savings, and also encourage new customers.

Whatever its virtues, CRM is, at its heart, silo maintenance. Walled gardening.

Then imagine you want to buy something. Say it's a piece of . You make your attentions known to the set of mer

Characters

Conversation on phone

Organizations

Vendors/Products

Meetings

Timelines

Kim's Laws:

(These) define the set of "objective" dynamics that constrain the definition of an identity system capable of being widely enough accepted that it can enable distributed computing on a universal scale.  It is essential that we change the identity conversation enough that its laws are no longer argued as "moral imperatives", but rather as explanations of dynamics which must be mastered to craft such a universal system. 

  1. The Law of Control: 
    Technical identity systems MUST only reveal information identifying a user with the user's consent.  (Starts here...)\
  2. The Law of Minimal Disclosure
    The solution which discloses the least identifying information is the most stable, long-term solution.  (Starts here...)
  3. The Law of Fewest Parties
    Technical identity systems MUST be designed so the disclosure of identifying information is limited to parties having a necessary and justifiable place in a given identity relationship.  (Starts here...)
  4. The Law of Directed Identity
    A universal identity system MUST support both "omnidirectional" identifiers for use by public entities and "unidirectional" identifiers for use by private entities, thus facilitating discovery while preventing unnecessary release of correlation handles.   (Starts here...)
  5. The Law of Pluralism: 
    A universal identity system MUST channel and enable the interworking of multiple identity technologies run by multiple identity providers.  (Starts here...)
  6. The Law of Human Integration: 
    The universal identity system MUST define the human user to be a component of the distributed system, integrated through unambiguous human-machine communications mechanisms offering protection against identity attacks.  (Starts here...)
  7. The Seventh Law: The Law of Harmonious Contextual Autonomy
    Yada. (Starts here...)

    The full list.

    Craig's posts

    The law of pluralism is contrary to the laws of customer control. Let's be clear, the law of pluralism requires operating system independence--by definition. This means the Microsoft Identity Archtiect is calling for a system that is not necissarily Windows centric by design. This--of course--is the only way such a system can really work--but consider the implications.
    A cross platfrom identity metasystem is sun-spot hot and--with the other laws being discussed here--changes everything.

    Kim conversation:

    When do you ever want identity information given out about you, when you're not there? What is the use case where I want my identity informatino to be given out by a robot? It's when I'm doing somethig that I come into a context where in return for some benefit I want to give some personal information out.

    Can you give me some examples of cases when informatoin is given out when

    Where does this type of thinking come from? It comes from people who do servers. It's an "If all you have is a hammer, then everything looks like a nail" thing.

    With this Laws thing, I'm putting people at the center of the framework. People who don't believe that individuals belong in the center of identity can't really assail the position.

    I'm not saying that their technology isn't useful. but it has to be the person's, the individual's decision, about what identity information is right in a given context.

    It's a quetion of what serves what.

    Nothing wrong with that, until you consider the absence of something: Your ability to present yourself as a customer to all the agencies at once, so they can compete for your business.

    We all have a bunch of identities... Most of us don't usually think about it. They could be anything from your record at the ss administration... to a credit card number to Microsoft passport to your account at Amazon.com. So digital identity is becoming widely recognized as a distributed environment with a bunch of little pieces that end up identifying an individual.

    The distributed nature (of identity) leads to certain problems. How is it we allow the end user -- be they an employee or an investor or a partner or a customer -- to actually have some sort of virtualized control over these distributed bits of digital identity? There are two broad solutions to that. One is to build something centralized: a great database in the sky. Larry Ellison's dream, right? We get a national ID program and everything goes into an Oracle database. The second approach, and the one that seems to be gaining in popularity, is federation. This approach leaves the distributed environment as it is, but seeks to let the end user link together those pieces and still have control over their privacy, what gets shared, and how.

    The obviouis example of this is the whole Passport (vs.) Liberty Alliance thing that happened. Micrsoft came out with Passport, a centralized system... Then Sun formed the Liberty Alliance (which has) grown up around this concept of federation, mostly because companies generally don't like the idea of sharing their customer data with other companies, even if it's companies providing an identity service to them, like a Passport.

    So, federation seeks to leave the distrubuted environment as it is and still attain the advantages and benefits of what would normally be a centralized database. The Liberty technology... is purposefully designed to be opaque. So the Liberty Alliance spec tries to accomplish one thing... to allow one end user to link one account to another account. But in order to protect the privacy of the end user... neither side of that account -- either Company A or Company B --would know who the end user is that is being passed between them. In other words, in oerder to find that it was me that was linking between Companies A and B, they would actually have to go outside of the specification through a backchannel. So the specification puposefully makes it hard to violate someone's privacy.

    Like Kim, I considered RSS (Really Simple Syndication) a good model of an internet service that grew to ubiquity from grass roots efforts. I also noted that a virtue of RSS was, as the initials said, simplicity. Dave Winer responded,

    Doc Searls... offered RSS and podcasting as examples of technologies that were simple, therefore successful, and suggests that identity, if it were to be approached the same way, might have similar success. Bzzzt. Wrong. RSS was not easy, it was hard, for exactly the same reasons identity is hard. Too many cooks spoil the broth. Two ways to do identity is one too many.

    Politics spoiled identity, and would have spoiled RSS had the major players not converged on RSS 2.0. The difference this time was that there was a Switzerland, me, to guide RSS through its gauntlet, and I clearly wasn't in bed with any of the major publishers or vendors. The Harvard connection didn't hurt because it's a highly respected university that hadn't been involved in tech standards. Had identity had that kind of champion-ship it might not be the mess it is today.

    So I suggested, in a post on IT Garage, that

    Grounds for Identity, November 2002: http://www.linuxjournal.com/article/6382

    What's our i-Name? November 2002: http://www.linuxjournal.com/article/7888

    Dave Winer: Last Week's Gillmor Gang. http://archive.scripting.com/2004/12/25#lastWeeksGillmorGang