Privacy & Federated Authentication and Identity Management in The
Total Page:16
File Type:pdf, Size:1020Kb
Nederlandse Organisatie voor toegepast-natuurwetenschappelijk onderzoek / Netherlands Organisation for Applied Scientific Research Brassersplein 2 P.O. Box 5050 2600 GB Delft The Netherlands TNO report T +31 15 285 70 00 F +31 15 285 70 57 [email protected] Privacy & federated authentication and identity management in the infoservice society Date 1 October 2007 Author(s) Gabriela Bodea & Marc van Lieshout Assignor TNO Reviewer Dr.Ir. J.G.E. Olk, TNO ICT Project number 035.31600 Report number 34564 Classification report Title FAIM deliverable: Privacy & federated authentication and identity management in the infoservice society Number of pages 54 (incl. appendices) Number of appendices 5 All rights reserved. No part of this report may be reproduced and/or published in any form by print, photoprint, microfilm or any other means without the previous written permission from TNO. All information which is classified according to Dutch regulations shall be treated by the recipient in the same way as classified information of corresponding value in his own country. No part of this information will be disclosed to any third party. In case this report was drafted on instructions, the rights and obligations of contracting parties are subject to either the Standard Conditions for Research Instructions given to TNO, or the relevant agreement concluded between the contracting parties. Submitting the report for inspection to parties who have a direct interest is permitted. © 2007 TNO Nederlandse Organisatie voor toegepast-natuurwetenschappelijk onderzoek / Netherlands Organisation for Ap plied Scientific Research Brassersplein 2 Abstract P.O. Box 5050 2600 GB Delft The Netherlands T +31 15 285 70 00 F +31 15 285 70 57 [email protected] The present paper examines some of the privacy issues re lated to forms of federated authentication and identity management (FAIM) employed in the delivery of electronic services (mainly of the government). The paper should be read as a merely exploratory exercise. It starts by defining bri efly the context in which current forms of federated authentication and identity ma nagement (FAIM) are being employed. For this purpose, a new concept has been introduced, that of the infoservice society. Subsequently, the paper takes a closer look at the situation in three countries: the Netherlands, Austria and the United States. The brief inventory of developments in the three countries will be used to distil some insights into related privacy issues, formulate conclusions and policy recommendations. TTNO report | 34564 | final report 3 / 44 Appendices A OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data B The European and international legal context – a selection C Selection of relevant legislative and regulatory framework & organizations D E-Government in Austria - timeline E E-Government in the Netherlands – timeline Contents Abstract .......................................................................................................................... 2 1 Introduction and definitions ......................................................................................... 4 1.1 Scoping the exercise ........................................................................................................ 5 1.2 Methodology.................................................................................................................... 8 2 Case studies ....................................................................................................................9 2.1 The Netherlands............................................................................................................... 9 2.2 The United States of America........................................................................................ 15 2.3 Austria............................................................................................................................ 21 3 Analysis and federation-related privacy issues ......................................................... 26 3.1 Dilemmas....................................................................................................................... 30 3.2 Challenges......................................................................................................................31 4 Suggestions and recommendations............................................................................. 34 4.1 Addressing roadblocks by means of regulatory, co- and self-regulatory measures....... 34 4.2 Addressing roadblocks by means of technical solutions ............................................... 35 5 Instead of conclusions.................................................................................................. 36 6 Bibliography................................................................................................................. 39 7 Other resources............................................................................................................ 41 8 Signature.......................................................................................................................43 TTNO report | 34564 | final report 4 / 44 1 Introduction and definitions "A stone is a stein is a rock is a boulder is a pebble." Ernest Hemingway ("A rose is a rose is a rose is a rose." Gertrude Stein) This paper was written in the context of the TNO-ICT project FAIM. FAIM is an abbreviation of Federated Authentication and Identity Management. The project FAIM set itself the task to explore the various facets and, insofar as possible, address the questions around the concept of FAIM, in order to allow TNO ICT to formulate a vision on the subject. The main aim and objective of this paper, as part of the FAIM project, was to develop our own understanding of current developments, the impact of ICT on society, and in particular privacy-related issues pertaining to FAIM. In the title, we introduced a new term, that of the infoservice society. The infoservice society refers to a new stage in the development of the information society. Regarding the information society and for the purpose of this paper we chose to restrict the period to which we referred in this paper to the post-digital revolution era. The purpose of introducing the new term is a practical one. It is meant to describe more accurately specific recent developments. During the past decade western societies witnessed the explosive growth and broad availability of information and knowledge. (Advances in) information technologies were instrumental in making this possible. The access to information and, to a certain extent, the production or the making available of information have lost their spatial and, arguably, temporal dimensions. These developments had a profound social and economic impact. During the alpha, or preliminary stage of development the available information in terms of sheer quantity, grew exponentially. Particularly, the internet had a democratizing effect on information. Established roles, especially gate-keeping roles, were challenged, and new roles and competencies were negotiated. A certain sense of chaos became prevalent and with it the need for structure. This stage, the beta stage, could be equated with a prototype and experimental stage. From a technical perspective, information systematization became imperative (from basic search engines to information management). From a social perspective, new configurations emerged: whether as new networks or changed power positions. From an economic perspective, the commercial potential of information was recognized and began to be exploited (from information itself as a commodity to information technologies as new and effective means to deliver services). The three perspectives, however, should not be seen separately but together, constituting an entity. This stage corresponds to the infoservice society. A case in point are the various forms of electronic governments. Providers of services are no longer exclusively businesses, but also governments. The pervasiveness of internet, especially broadband internet makes possible the delivery of complex services over the internet. The issue of federated TTNO report | 34564 | final report 5 / 44 authentication and identity management is characteristic for this phase, and often at the core of e-Gov and other types of services. FAIM have the potential to increase efficiency, reduce costs, and enhance privacy. Definitions of concepts The Liberty Technical Glossary defines federation as an association comprising any number of service providers and identity providers. The same Glossary defines identity as the essence of an entity. One’s identity is often described by one’s characteristics, among which may be any number of identifiers.1 1.1 Scoping the exercise This contribution to the FAIM project focuses on the broader social, juridical, ethical and political – and to a certain extent on the historical and cultural – context in which federated identification and authentication management evolves. FAIM cannot be seen isolated from the socio-political context in which it is developed. Interestingly, one could see in FAIM an attempt to rectify the societal discourse on dealing with personal data in a direction in which more respect is paid to privacy concerns. This societal discourse has been guided in the direction of collecting and aggregating more personal data and use of these personal data for identification purposes. Previous attempts of states to introduce central administrations