Technology Review - Published By MIT
Advertisement

March/April 2006

Universal Authentication

Continued from page 1

By David Talbot

smaller text tool iconmedium text tool iconlarger text tool icon

While some U.S. universities have been using Shibboleth since 2003, adoption of the system grew rapidly in 2005. It's now used at 500-plus sites worldwide, including educational systems in Australia, Belgium, England, Finland, Denmark, Germany, Switzerland, and the Netherlands; even institutions in China are signing on. Also in late 2005, Internet2 announced Shibboleth's interoperability with a Microsoft security infrastructure called the Active Directory Federation Service.

Critically, the system is moving into the private sector, too. The science and medical division of research publishing conglomerate Reed Elsevier has begun granting university-based subscribers access to its online resources through Shibboleth, rather than requiring separate, Elsevier-specific logins. And Cantor has forged ties with the Liberty Alliance, a consortium of more than 150 companies and other institutions dedicated to creating shared identity and authentication systems.

With Cantor's help, the alliance, which includes companies such as AOL, Bank of America, IBM, and Fidelity Investments, is basing the design of its authentication systems on a common standard known as SAML. The alliance, Cantor says, was "wrestling with lots of the same hard questions that we were, and we were starting to play in the same kind of territories. Now there is a common foundation....we're trying to make it ubiquitous." With technical barriers overcome, the companies can now roll out systems as their business needs dictate.

Of course, Cantor is not the only researcher, nor Shibboleth the only technology, in the field of Internet authentication. In 1999, for instance, Microsoft launched its Passport system, which let Windows users access any participating website using their e-mail addresses and passwords. Passport, however, encountered a range of security and privacy problems.

But thanks to the efforts of the Shibboleth team and the Liberty Alliance, Web surfers could start accessing multiple sites with a single login in the next year or so, as companies begin rolling out interoperable authentication systems.

OTHER PLAYERS
Universal Authentication

Stefan Brands -- Cryptology, identity management, and authentication technologies
McGill University

Kim Cameron -- "InfoCard" system to manage and employ a range of digital identity information
Microsoft, Redmond, WA

Robert Morgan -- "Person registry" that gathers identity data from source systems; scalable authentication infrastructure
University of Washington

Tony Nadalin -- Personal-identity software platform
IBM, Armonk, NY

Home page image courtesy of Bryan Christie Design.

Comments

  • Double-edge sword
    "Worse, the diversity of authentication systems increases the chances that somewhere, your privacy will be compromised, or your identity will be stolen."

    Single sign-on means that losing your password will have greater implication than before. Is there any way of overcome this problem ?
    Rate this comment: 12345
    Guest (chuan)
    04/27/2006
    Posts:1
    • [no subject]
      Single sign-on doesn't imply passwords. Stronger authentication is the best way to deal with the single credential problem. Also, note that most non-technical users just reuse the same passwords everywhere, making the exposure very similar with or without SSO.
      Rate this comment: 12345
      Guest (Scott Cantor)
      04/27/2006
      Posts:1
  • Outside Academia
    When I log in to a commercial account -- for example a brokerage account or my mortgage records -- they need to know a lot more than that I am registered at a particular university. How does this system apply outside the academic world?
    Rate this comment: 12345
    Guest (farang)
    05/01/2006
    Posts:1
    • [no subject]
      Any number of attributes (name, account numbers, etc) about a user can be sent along to the service provider.  You are not limited to simply affiliation-type data.
      Rate this comment: 12345
      Guest (Will Norris)
      05/22/2006
      Posts:1
  • False confidence
    Any system that produces a sense of enhanced confidence in its reliability will cause greater difficulties to the person whose identity is compromised. it is human nature.  However, since most people only use a few passwords over and over again, single-signing is not inherently more insecure. to believe it can't be hacked is naive. See http://rfidanalysis.org/
    Rate this comment: 12345
    Guest (threemallards)
    05/15/2006
    Posts:1
  • Universal Identity and NetAlter
    NetAlter is developing an Alternative to the Internet and one of the key features is the concept of Universal Identity that will access multiple services and applications. However there is a minor difference in that the user gets to decide if he or she wants one single ID or seperate IDs. And even if the user creates seperate ID, all of these will have reference to the Universal ID that is provided at the time of registration with NetAlter (which ofcourse is free to end users)
    Rate this comment: 12345
    Guest (Gurudatt Shenoy)
    08/04/2006
    Posts:1
  • Not even geographic knowledge
    "Australia, Belgium, England, Finland" the poor author does not even have basic geographic knowledge that the UK is 4 countries not just England. It is like saying "Ohio" when you mean USA. If he can't get that even right, I would not even bother with the rest of article.
    Rate this comment: 12345

    OsamaBinLade...
    11/11/2006
    Posts:1

Technology Review Magazine

The Knowledge
Biotechnology’s advance presents dark possibilities. Terrorists can develop biological weapons. Worse, the life sciences could give malefactors the ability to manipulate fundamental life processes -- and even affect human behavior.

FEATURES

10 Emerging Technologies
This year, our list of technologies that are worth keeping an eye on is particularly wide ranging -- but all of our picks are ready to have a big impact on business, medicine and culture.
The Fountain of Health
Antiaging researchers aren’t likely to find ways to extend life anytime soon. But their work could provide a powerful approach to treating the many diseases of old age.

Read more articles from this Issue

NOTEBOOKS FORWARD Q&A PHOTO ESSAY REVIEWS HACK DEMO
Archives MIT News Subscribe Contact

Log In

Forgot your password?     Register »
Advertisement

Videos

The Marcellus Shale Gas Rush
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.