What's Going On With NSTIC? Pilots! Steering Groups! - (1A)
NSTIC Update & Identity Intro (1A)
Convener: Jeremy Grant
Notes-taker(s): Allan Friedman
Tags for the session - technology discussed/ideas considered:
NSTIC, federal, DoC, pilots, grants,...
Discussion notes, key understandings, outstanding questions, observations, and, if appropriate to this discussion: action items, next steps:
Not NSTIC 101
Good news: lots going on
- Funding! - $16.5 M
Bad news: Lots going on slowly
- Inter-agency review
Steering group
- Privately led, with some govt funding
- Still in review
- Look for an organization to convene the group by application
- Goal: want all stakeholders involved
- Ideally open to everyone who wants to participate
- Want to impose some structure, but don't want to hand-choose
- Govt as one stakeholder at the table, albeit an active one
Staffing up - 6-7 hires
$10 NSTIC pilot program
- Focus on testing & demonstrating new ideas, not in the market place today
- Begin with motivation for govt involvement- market failure, lack of standards
- Objectives - primarily non-technical barriers
- Multi-sector
- Public-private partnerships
- Establish consumer demand
- liability clarity
- privacy-enhancing tech in business models
- interoperability across different niches
- user-centric frameworks for attribute exchange
- trust frameworks with multiple RP
- New interfaces
- Usability --> consumer uptake
- Role of public sector for improving private sector adoption
- RFP in early Feb
- Potential 2-step process to allow NSTIC to select more promising proposals for full applications
Explicitly NOT about purely technical solutions - we have those
Q: Role of Chamber of Commerce?
A: Hosted the launch, but not involved more than an interested stakeholder
Don Thibodeau - The broad perspective
- Takeaway - action-forcing events
- Different areas of activity
- Smart cards tying physical with information architecture
- UMA enabling interoperability of data ecosystems
- OASIS working on trust elevation
- How attributes are verified & exchanged for risk
- User-driven assertions vs. automatic attributes
- Defining the terms - ABA vs. other
- Attributes are actionable, definable, monetizable
- List of organizations
- NIST - NSTIC, standards
- Open Identity Exchange (OIX) - trust frameworks for the exchange of attributes
- Can customize for different communities & use cases
- InCommon
Going to see a top-down & bottom up merge
- Common standards between competitors
Q: Will trust frameworks certify?
- See Kaliya's diagrams of protocols & organization -
- Focused on Discovery
- Another on the evolution of community
- Eve - "venn of identity" and others
Alphabet soup
- Open Web Foundation -
- W3C - Fed Soc Web, Browser ID
Shift between identity and management of attributes
