SUBSCRIBE

Identity federation is vital for survival of Canadian organizations, conference told

Canada Post is willing to do something few Canadian retailers do: Federate an identity service with other firms. Itโ€™s something more organizations here are going to have to do, an identity conference was warned Wednesday, or theyโ€™ll be crushed by online competitors.

Graeme Gibson, Canada Post
Graemeย Gordon

โ€œThereโ€™s a freight train comingโ€ in ecommerce led by Google, Apple and others, said Graeme Gordon, the post officeโ€™s vice-president of digital channels โ€œand if we donโ€™t get ahead of it itโ€™s going to run us over.โ€

That was one of the messages that came out from the annual IdentityNorth conference in Toronto, which drew about 150 retailers, government officials, software developers, service providers and researchers to talk about problems and solutions in digital identity and authorization.

Itโ€™s more than doing away with passwords. The number of public and private sector online transactions expand every year and will continue, with the public demanding easier ways of doing things besides going to stores and government offices to pay for goods or to prove their identities, age or residency.

So, the conference heard, people might want to open a bank account online by using a cellphone without going to a branch, or a province might want to hold an online public consultation on a controversial issue but wants to digitally verify participants actually live in the community without exposing their full address.

But what is still needed, conference experts said, are secure ways governments, banks, telcos, utilities and others can securely share customer personal information โ€“ and, ideally, giving customers the ability to approve the use of their information from various sources at various times to limit exposure of their personal data.

For example, one speaker asked, when trying to get into a bar why should a person show their driverโ€™s licence, which includes a home address, when all that is needed is proof of age? Why canโ€™t a digital piece of information be pulled from a government database along with a photo on the personโ€™s cellphone to show proof of age?

Many are hoping work being done by the Digital ID and Authorization Council of Canada (DIACC), a public-private partnership building on the work of the federal Pan-Canadian Trust Framework, a digital identity and authentication management architecture will point the way for organizations to create platforms to expand opportunities in the global digital economy.

On Monday DIACC released its second proof of concept white paper, showing how an online service that would verify an individualโ€™s place of residence would work. IT was a follow-up to the release last year of a strategy paper.

DIACC chair Dave Nikolejsin, who is also deputy minister of B.C.โ€™s ministry of natural gas development, told one panel that the industry needs to more to live demonstrations to show the concepts work. โ€œHistorically Canada bad at moving ahead before itโ€™s totally safe,โ€ he said. โ€œLetโ€™s not start with health care, the stakes stakes are too high.โ€ But, he said, there must be some โ€œsafe areasโ€ where an organization could โ€œpush the boundariesโ€ฆ.Itโ€™s time to get on with some things.โ€

Canada Post, for one, is ready to integrate its FlexDelivery service for sending third party customersโ€™ purchases to the nearest post office for pickup, Gordon told the conference. which saves a buyer from going to a retail store. But customers have to register for the service. They can do it on the Canada Post Web site, but better would be to register on the retailerโ€™s Web site through a link, trusting the retailerโ€™s customer identification process. Through federation this would be done behind the scenes linking to the post office. The key is the customer doesnโ€™t leave the retailerโ€™s site, giving the treasured seamless experience.

โ€œSo in the end I end up with more revenue, more knowledge of my customers,โ€ Gordon said in an interview. โ€œCustomers end up with a better experience and the retailers benefit because theyโ€™ve been able to offer a service delivering [products] to other places easily.โ€

But, he warned, big service providers like Google are already working hard on federation. In this country โ€œfederation is in its infancy and weโ€™re falling behind,โ€ he said.

Telus is another company hoping to take the plunge. Lloyd Switzer, the carrierโ€™s senior vice-president for network transformation, told the conference it has developed an identity validation system allowing a subscriber to create a bank account through a mobile device, with the bank trusting the carrier to identify the person through an identity score (Switzer didnโ€™t detail, but it would be easy to infer that, for example, the person has had the same phone number and same address for X years and paid their bills for Y years, therefore has a high identity score). The score โ€“ not personal information โ€“ is transmitted to the bank. For every bank transaction the accountโ€™s identity is approved the same way.

This guarding of privacy is crucial to the future of e-business, Ann Cavoukian, head of Ryerson Universityโ€™s privacy and big data institute, told the conference. Privacy isnโ€™t a barrier, it should be a positive that will work for organizations, and gain a competitive advantage. It will not stand in the way of business goals and objectives.

However, Canadian Kim Cameron, a Microsoft identity architect who created the seven laws of identity, warned CIOs thereโ€™s an urgent need to professionalize application identity management.

Too many firms try to create their own identity regimes rather than use well built systems including cloud-based ones. These home-built systems are often the ones that are most vulnerable to hackers, he said.

Attackers are โ€œfully professionalized,โ€ often having more PhDs working for them than big software companies. โ€œWe need ways to fight back.โ€ he said. โ€œWe have ways, because if we put together all the knowledge of these attackers we can understand what theyโ€™re doing, the patterns.โ€

For some the golden ideal is to somehow link the many trusted parties with pieces of identity โ€“ such as banks, telecos, governments, credit scoring firms โ€“ into one ecosystem. Greg Wolfond, CEO of Torontoโ€™s SecureKey Technologies, said his company is working on a solution where users can pull and mix attributes for identification and authorization as needed from their smart phonesโ€“ approving one bundle of ID for getting into a bar, another for approving your childโ€™s participation in a minor league hockey team, another for logging into your financial advisorโ€™s Web site, another for approving a donation to a charity.

The concept would be built on the blockchain technology behind digital currencies that includes security, privacy and usability.

Every use of ID is done with user approval โ€“ or, as Wolfond says, โ€œweโ€™ve Uberized the experience.โ€

Today, he said, too much relies on paper. For example, a school emails a permission form for a parent to fill out mail in a cheque so their child can go on a field trip. โ€œThis is ridiculous. Itโ€™s 2016. Why canโ€™t I say โ€˜I agree to the terms and conditions,โ€™ my bank app digitally signs it [to verify] and then go to the bank app and digitally move the money to the school account.โ€

The model wouldnโ€™t have a broker in the middle handling transactions.

He didnโ€™t give a timeline on when it might be realized.

(Earlier version of this story incorrectly identified Canada Postโ€™s vice-president of digital channels. His name is Graeme Gordon. We regret this mistake)

Tech Jobs

Categories