<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1240525154261270346</id><updated>2011-04-21T17:09:34.652-07:00</updated><title type='text'>Identity Management</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://idmbyibo.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://idmbyibo.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ibO</name><uri>http://www.blogger.com/profile/00236659750629753380</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1240525154261270346.post-7721384159063551808</id><published>2007-07-31T02:42:00.000-07:00</published><updated>2007-07-31T02:43:37.187-07:00</updated><title type='text'>Identity Agent</title><content type='html'>&lt;p&gt;An &lt;b&gt;Identity Agent&lt;/b&gt; is a software application for user-centric identity  management. It&lt;/p&gt;  &lt;ul&gt; &lt;li&gt;Manages a consistent user experience for authentication (and in some cases  other kinds of interactions) with a Service Provider (also known as a Relying  Party)  &lt;/li&gt;&lt;li&gt;Provides a &lt;a title="User interface" href="/wiki/User_interface"&gt;user  interface&lt;/a&gt; called an "&lt;a title="I-Card" href="/wiki/I-Card"&gt;i-card&lt;/a&gt;  selector" which displays a set of alternative i-card icons from which the users  selects their preferred &lt;a title="I-card" href="/wiki/I-card"&gt;i-card&lt;/a&gt; when  authentication is required by a local application or Service Provider (e.g. a  web site's sign-in page)  &lt;/li&gt;&lt;li&gt;Provides a &lt;a title="User interface" href="/wiki/User_interface"&gt;user  interface&lt;/a&gt; to create new personal i-cards and/or manage them. This interface  is sometimes called an "&lt;a title="I-card" href="/wiki/I-card"&gt;i-card&lt;/a&gt; manager"  &lt;/li&gt;&lt;li&gt;Provides a local Security Token Service that is used to provide the security  tokens for personal (self-issued) &lt;a title="I-card" href="/wiki/I-card"&gt;i-cards&lt;/a&gt;  &lt;/li&gt;&lt;li&gt;Provides a user interface to import and export personal or managed i-card  files in standard file formats  &lt;/li&gt;&lt;li&gt;Is invoked by a browser extension or by a local rich client application  &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;An Identity Agent may also allow the user to manage (e.g. create, review,  update and delete cards within) their portfolio of i-cards.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1240525154261270346-7721384159063551808?l=idmbyibo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://idmbyibo.blogspot.com/feeds/7721384159063551808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1240525154261270346&amp;postID=7721384159063551808' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/7721384159063551808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/7721384159063551808'/><link rel='alternate' type='text/html' href='http://idmbyibo.blogspot.com/2007/07/identity-agent.html' title='Identity Agent'/><author><name>ibO</name><uri>http://www.blogger.com/profile/00236659750629753380</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1240525154261270346.post-635076244851221265</id><published>2007-07-27T20:59:00.000-07:00</published><updated>2007-07-27T21:15:36.358-07:00</updated><title type='text'>IDM Solutions</title><content type='html'>Solutions which fall under the category of Identity Management:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Management of Identities&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a title="Provisioning" href="http://en.wikipedia.org/wiki/Provisioning"&gt;&lt;span style="color:#999999;"&gt;Provisioning&lt;/span&gt;&lt;/a&gt;/De-provisioning of accounts&lt;br /&gt;&lt;a title="Workflow automation" href="http://en.wikipedia.org/wiki/Workflow_automation"&gt;&lt;span style="color:#cc0000;"&gt;Workflow automation&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a title="Delegated administration" href="http://en.wikipedia.org/wiki/Delegated_administration"&gt;&lt;span style="color:#ff6600;"&gt;Delegated administration&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a title="Password synchronization" href="http://en.wikipedia.org/wiki/Password_synchronization"&gt;&lt;span style="color:#ffcc33;"&gt;Password synchronization&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a title="Self Service Password Reset" href="http://en.wikipedia.org/wiki/Self_Service_Password_Reset"&gt;&lt;span style="color:#ffcc00;"&gt;Self Service Password Reset&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Access Control&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a class="new" title="Policy based access control" href="http://en.wikipedia.org/w/index.php?title=Policy_based_access_control&amp;action=edit"&gt;&lt;span style="color:#33cc00;"&gt;Policy based access control&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a title="Business" href="http://en.wikipedia.org/wiki/Business"&gt;&lt;span style="color:#00cccc;"&gt;Enterprise&lt;/span&gt;&lt;/a&gt;/Legacy &lt;a title="Single signon" href="http://en.wikipedia.org/wiki/Single_signon"&gt;&lt;span style="color:#3366ff;"&gt;Single Sign On&lt;/span&gt;&lt;/a&gt; (SSO) and &lt;a title="Single signout" href="http://en.wikipedia.org/wiki/Single_signout"&gt;&lt;span style="color:#6633ff;"&gt;Single Signout&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#6633ff;"&gt;&lt;br /&gt;&lt;/span&gt;Web Single Sign On (SeoS)&lt;br /&gt;&lt;a class="new" title="Reduced Sign On" href="http://en.wikipedia.org/w/index.php?title=Reduced_Sign_On&amp;amp;action=edit"&gt;&lt;span style="color:#cc33cc;"&gt;Reduced Sign On&lt;/span&gt;&lt;/a&gt; &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Directory Services&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Identity Repository (directory services for administration of user account attributes)&lt;br /&gt;&lt;a title="Metadata" href="http://en.wikipedia.org/wiki/Metadata"&gt;&lt;span style="color:#999999;"&gt;Metadata&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#999999;"&gt; &lt;/span&gt;&lt;a title="Replication" href="http://en.wikipedia.org/wiki/Replication"&gt;&lt;span style="color:#999999;"&gt;Replication&lt;/span&gt;&lt;/a&gt;/Synchronization&lt;br /&gt;Directory Virtualization (virtual directory)&lt;br /&gt;&lt;a title="E-business" href="http://en.wikipedia.org/wiki/E-business"&gt;&lt;span style="color:#cc0000;"&gt;e-business&lt;/span&gt;&lt;/a&gt; scale directory systems&lt;br /&gt;&lt;a class="new" title="Next generation system" href="http://en.wikipedia.org/w/index.php?title=Next_generation_system&amp;action=edit"&gt;&lt;span style="color:#ff6600;"&gt;Next generation systems&lt;/span&gt;&lt;/a&gt; - &lt;a title="CADS" href="http://en.wikipedia.org/wiki/CADS"&gt;&lt;span style="color:#ffcc33;"&gt;CADS&lt;/span&gt;&lt;/a&gt; and CADS SDP &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Other categories&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a title="Role-based access control" href="http://en.wikipedia.org/wiki/Role-based_access_control"&gt;&lt;span style="color:#ffcc00;"&gt;Role-based access control&lt;/span&gt;&lt;/a&gt; (RBAC)&lt;br /&gt;&lt;a title="Federated identity" href="http://en.wikipedia.org/wiki/Federated_identity"&gt;&lt;span style="color:#33cc00;"&gt;Federation&lt;/span&gt;&lt;/a&gt; of user access rights on web applications across otherwise untrusted networks&lt;br /&gt;&lt;a class="new" title="Directory enabled networking" href="http://en.wikipedia.org/w/index.php?title=Directory_enabled_networking&amp;amp;action=edit"&gt;&lt;span style="color:#00cccc;"&gt;Directory enabled networking&lt;/span&gt;&lt;/a&gt; and &lt;a title="802.1x" href="http://en.wikipedia.org/wiki/802.1x"&gt;&lt;span style="color:#3366ff;"&gt;802.1X EAP&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#3366ff;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Standards Initiatives&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a class="external text" title="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=" href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security/" rel="nofollow"&gt;&lt;span style="color:#6633ff;"&gt;SAML&lt;/span&gt;&lt;/a&gt; - An industry consortium&lt;br /&gt;&lt;a class="external text" title="http://www.projectliberty.org/" href="http://www.projectliberty.org/" rel="nofollow"&gt;&lt;span style="color:#cc33cc;"&gt;Project Liberty&lt;/span&gt;&lt;/a&gt; - An industry consortium&lt;br /&gt;&lt;a class="external text" title="http://shibboleth.internet2.edu/" href="http://shibboleth.internet2.edu/" rel="nofollow"&gt;&lt;span style="color:#999999;"&gt;Shibboleth&lt;/span&gt;&lt;/a&gt; - Identity standards targeted towards educational environments.&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1240525154261270346-635076244851221265?l=idmbyibo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://idmbyibo.blogspot.com/feeds/635076244851221265/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1240525154261270346&amp;postID=635076244851221265' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/635076244851221265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/635076244851221265'/><link rel='alternate' type='text/html' href='http://idmbyibo.blogspot.com/2007/07/idm-solutions.html' title='IDM Solutions'/><author><name>ibO</name><uri>http://www.blogger.com/profile/00236659750629753380</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1240525154261270346.post-620303257289335634</id><published>2007-07-24T05:43:00.000-07:00</published><updated>2007-07-24T05:48:35.067-07:00</updated><title type='text'>Definition of Identity Management</title><content type='html'>&lt;p&gt;Identity management (ID management) is a broad administrative area that deals with identifying individuals in a system (such as a country, a network, or an enterprise) and controlling their access to resources within that system by associating user rights and restrictions with the established identity. The driver licensing system is a simple example of identity management: drivers are identified by their license numbers and user specifications (such as "can not drive after dark") are linked to the identifying number.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;In an IT network, identity management software is used to automate administrative tasks, such as resetting user passwords. Enabling users to reset their own passwords can save significant money and resources, since a large percentage of help desk calls are password-related. Password synchronization (p-synch) enables a user to access resources across systems with a single password; a more advanced version called single signon enables synchronization across applications as well as systems.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;In an enterprise setting, identity management is used to increase security and productivity, while decreasing cost and redundant effort. Standards such as Extensible Name Service (&lt;a class="inline" href="http://searchwebservices.techtarget.com/sDefinition/0,,sid26_gci913099,00.html"&gt;XNS&lt;/a&gt;) are being developed to enable identity management both within the enterprise and beyond.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;In a wider context, industry groups such as the World Wide Web Consortium (&lt;a class="inline" href="http://searchwebservices.techtarget.com/sDefinition/0,,sid41_gci213331,00.html"&gt;W3C&lt;/a&gt;) and &lt;a class="inline" href="http://searchoracle.techtarget.com/sDefinition/0,,sid_gci212708,00.html"&gt;The Open Group&lt;/a&gt; are developing standards that would enable global identity management, in which each individual would be uniquely identified, and all applicable data would be linked to that identity. A position paper on the W3C Web site, Requirements for a Global Identity Management Service, maintains that establishing global identity management is crucial for the development of the Web and &lt;a class="inline" href="http://searchwebservices.techtarget.com/sDefinition/0,,sid26_gci750567,00.html"&gt;Web services&lt;/a&gt;. The W3C position paper stipulates, among other things, that such a system that must be universally portable and interoperable; that it must support unlimited identity-related &lt;a class="inline" href="http://searchwebservices.techtarget.com/sDefinition/0,,sid26_gci214608,00.html"&gt;attribute&lt;/a&gt;s; that it must provide adequate mechanisms for privacy and accountability; and that it must be overseen by an independent governing authority.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1240525154261270346-620303257289335634?l=idmbyibo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://idmbyibo.blogspot.com/feeds/620303257289335634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1240525154261270346&amp;postID=620303257289335634' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/620303257289335634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/620303257289335634'/><link rel='alternate' type='text/html' href='http://idmbyibo.blogspot.com/2007/07/definition-of-identity-management.html' title='Definition of Identity Management'/><author><name>ibO</name><uri>http://www.blogger.com/profile/00236659750629753380</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1240525154261270346.post-5847939839029589054</id><published>2007-07-20T04:32:00.000-07:00</published><updated>2007-07-20T04:34:46.606-07:00</updated><title type='text'>Emerging Fundamental Points of IDM</title><content type='html'>&lt;p&gt;IdM provides a significantly greater opportunity to an online business beyond the process of authenticating and authorizing users via cards, tokens and &lt;a title="Web" href="http://en.wikipedia.org/wiki/Web"&gt;&lt;span style="color:#666666;"&gt;web&lt;/span&gt;&lt;/a&gt; access control systems.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;User-based IdM is evolving from &lt;a title="Username" href="http://en.wikipedia.org/wiki/Username"&gt;&lt;span style="color:#990000;"&gt;username&lt;/span&gt;&lt;/a&gt;/&lt;a title="Password" href="http://en.wikipedia.org/wiki/Password"&gt;&lt;span style="color:#cc6600;"&gt;password&lt;/span&gt;&lt;/a&gt; and web access control systems to those that embrace preferences, &lt;a title="Parental control" href="http://en.wikipedia.org/wiki/Parental_control"&gt;&lt;span style="color:#cc9933;"&gt;parental controls&lt;/span&gt;&lt;/a&gt;, entitlements, policy-based &lt;a title="Routing" href="http://en.wikipedia.org/wiki/Routing"&gt;&lt;span style="color:#999900;"&gt;routing&lt;/span&gt;&lt;/a&gt;, presence and loyalty schemes.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;IdM provides the focus to deal with system-wide data quality and &lt;a title="Data integrity" href="http://en.wikipedia.org/wiki/Data_integrity"&gt;&lt;span style="color:#009900;"&gt;integrity&lt;/span&gt;&lt;/a&gt; issues often encountered by fragmented databases and &lt;a class="new" title="Workflow process" href="http://en.wikipedia.org/w/index.php?title=Workflow_process&amp;action=edit"&gt;&lt;span style="color:#339999;"&gt;workflow processes&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;IdM embraces what the user actually gets in terms of products and services and how and when they do that. Therefore IdM applies to the products and services of an organization such as health, media, insurance, travel or government services, as well as how these products are provisioned and assigned to (or removed from) "entitled" users.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;IdM can deliver a single customer view that includes their presence and location, single product and services and single IT infrastructure and network views to the respective parties and therefore IdM is related intrinsically to information engineering and information security and privacy.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;IdM covers the machinery (system infrastructure components) that delivers such services because a user's service could be assigned to: a particular network technology; content title; usage rights; media server; mail server; soft switch; voice mail box; product catalogue set; security domain; billing system; &lt;a title="Customer relationship management" href="http://en.wikipedia.org/wiki/Customer_relationship_management"&gt;&lt;span style="color:#3333ff;"&gt;CRM&lt;/span&gt;&lt;/a&gt; or &lt;a title="Help desk" href="http://en.wikipedia.org/wiki/Help_desk"&gt;&lt;span style="color:#6600cc;"&gt;help desk&lt;/span&gt;&lt;/a&gt; and so on.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Critical to IdM projects are considerations of the online services of an organization (what are the users logging on to) and how are they managed from an internal perspective and the customer self care perspective.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1240525154261270346-5847939839029589054?l=idmbyibo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://idmbyibo.blogspot.com/feeds/5847939839029589054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1240525154261270346&amp;postID=5847939839029589054' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/5847939839029589054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/5847939839029589054'/><link rel='alternate' type='text/html' href='http://idmbyibo.blogspot.com/2007/07/emerging-fundamental-points-of-idm.html' title='Emerging Fundamental Points of IDM'/><author><name>ibO</name><uri>http://www.blogger.com/profile/00236659750629753380</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1240525154261270346.post-6273856088071230937</id><published>2007-07-19T07:06:00.000-07:00</published><updated>2007-07-19T07:26:52.959-07:00</updated><title type='text'>IDM - Three Perspectives</title><content type='html'>In the real world context of engineering online systems, identity management can be given three perspectives:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The pure identity paradigm - creation, management and deletion of identities without regard to access or entitlements;&lt;br /&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The user access (log-on) paradigm - a &lt;a title="Smart card" href="http://en.wikipedia.org/wiki/Smart_card"&gt;&lt;span style="color:#cc9933;"&gt;smart card&lt;/span&gt;&lt;/a&gt; and its associated data that a customer uses to log on to a service or services (a traditional view);&lt;br /&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The service paradigm - a system that delivers personalized, role-based, online, on-demand, multimedia (content), presence-based services to users and their devices.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;-The User Access Paradigm-&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;Identity Management in the user "log on" perspective would be an integrated system of &lt;a title="Business process" href="http://en.wikipedia.org/wiki/Business_process"&gt;&lt;span style="color:#999900;"&gt;business processes&lt;/span&gt;&lt;/a&gt;, policies and technologies that enable organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access. It represents a category of interrelated solutions that are employed to administer &lt;a title="Authentication" href="http://en.wikipedia.org/wiki/Authentication"&gt;&lt;span style="color:#009900;"&gt;user authentication&lt;/span&gt;&lt;/a&gt;, &lt;a title="Access rights" href="http://en.wikipedia.org/wiki/Access_rights"&gt;&lt;span style="color:#339999;"&gt;access rights&lt;/span&gt;&lt;/a&gt;, access restrictions, account profiles, &lt;a title="Password" href="http://en.wikipedia.org/wiki/Password"&gt;&lt;span style="color:#3333ff;"&gt;passwords&lt;/span&gt;&lt;/a&gt;, and other attributes supportive of users' roles/ profiles on one or more applications or systems. &lt;/p&gt;&lt;span style="color:#000000;"&gt;&lt;strong&gt;-The Service Paradigm-&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;In the service paradigm perspective, where organizations are evolving their systems to the converged services world, the scope of identity management becomes much larger and its application more critical. The scope of identity management includes all the resources of the company that are used to deliver online services. This includes devices, network equipment, servers, portals, content, applications and products as well as a user's credentials, address books, preferences, entitlements and telephone numbers. See &lt;a title="Service Delivery Platform" href="http://en.wikipedia.org/wiki/Service_Delivery_Platform"&gt;&lt;span style="color:#6600cc;"&gt;Service Delivery Platform&lt;/span&gt;&lt;/a&gt; and &lt;a title="Directory service" href="http://en.wikipedia.org/wiki/Directory_service"&gt;&lt;span style="color:#993399;"&gt;Directory service&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Today many organizations are facing a major clean-up in their systems to bring identity coherence to their world. This coherence is required in order to deliver unified services to very large numbers of users on demand - cheaply and with security and single customer view facilities.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1240525154261270346-6273856088071230937?l=idmbyibo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://idmbyibo.blogspot.com/feeds/6273856088071230937/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1240525154261270346&amp;postID=6273856088071230937' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/6273856088071230937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/6273856088071230937'/><link rel='alternate' type='text/html' href='http://idmbyibo.blogspot.com/2007/07/idm-three-perspectives.html' title='IDM - Three Perspectives'/><author><name>ibO</name><uri>http://www.blogger.com/profile/00236659750629753380</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1240525154261270346.post-7613975775439792980</id><published>2007-07-19T06:59:00.000-07:00</published><updated>2007-07-19T07:27:38.211-07:00</updated><title type='text'>Identity management</title><content type='html'>&lt;span style="color:#000000;"&gt;In &lt;/span&gt;&lt;a title="Information system" href="http://en.wikipedia.org/wiki/Information_system"&gt;&lt;span style="color:#009900;"&gt;information systems&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000000;"&gt;, identity management, sometimes referred to as identity management systems, is the management of the &lt;/span&gt;&lt;a title="Digital identity" href="http://en.wikipedia.org/wiki/Digital_identity"&gt;&lt;span style="color:#339999;"&gt;identity&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000000;"&gt; &lt;/span&gt;&lt;a title="Life cycle" href="http://en.wikipedia.org/wiki/Life_cycle"&gt;&lt;span style="color:#3333ff;"&gt;life cycle&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000000;"&gt; of entities (subjects or objects) during which: &lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;"&gt;&lt;p&gt;&lt;br /&gt;1. the identity is established: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;a name (or number) is connected to the subject or object; &lt;/li&gt;&lt;br&gt;&lt;br /&gt;&lt;li&gt;the identity is re-established: a new or additional name (or number) is connected to the subject or object; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;2. the identity is described: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;one or more attributes which are applicable to this particular subject or object may be assigned to the identity; &lt;/li&gt;&lt;br&gt;&lt;br /&gt;&lt;li&gt;the identity is newly described: one or more attributes which are applicable to this particular subject or object may be changed; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;3. the identity is destroyed.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1240525154261270346-7613975775439792980?l=idmbyibo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://idmbyibo.blogspot.com/feeds/7613975775439792980/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1240525154261270346&amp;postID=7613975775439792980' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/7613975775439792980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1240525154261270346/posts/default/7613975775439792980'/><link rel='alternate' type='text/html' href='http://idmbyibo.blogspot.com/2007/07/identity-management.html' title='Identity management'/><author><name>ibO</name><uri>http://www.blogger.com/profile/00236659750629753380</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
