English   Deutsch

Felix Gaehtgens: ArisID is born – a next generation Identity Framework for Developers

ArisID is born – a next generation Identity Framework for Developers
by Felix Gaehtgens
fg@kuppingercole.com

At the same time, governance of identity data is simplified by creating an open and interoperable framework that can be harnessed for controlling and auditing identity information flow. Traditionally, this was virtually impossible, as applications tended to be more or less opaque with regards to their use of identity data and information about users.

The goal of the Aristotle Project is to create an open source programming interface that provides a standardised access to identity service libraries also known as "ArisID providers". It can be understood as a comprehensive framework for applications to declare their identity requirements and have them fulfilled without having to worry about looking up individual identity attributes from specific sources.

Every application has the same problem: it needs particular information about individuals (identity attributes), and there are many ways to get them. One of the most common protocols to look up identity information is LDAP, and many attributes about users are stored in LDAP directories. But not always. Identity information can just as well be stored in relational databases. In a collaborative or distributed environment, information can come from many other sources, SAML assertions, web services lookups. Nowadays it is becoming increasingly commonplace that business processes cross traditional boundaries and involve many different companies and partners. Cloud computing and SAAS (software as a service) are yet another example of how the old assumption is obsolete - that all identity information can be fetched through a LDAP lookup.

The Aristotle Project and ArisID grew out of the Identity Governance Framework (IGF). About a year ago, Oracle has spearheaded the IGF in the auspices of the Liberty Alliance. ArisID now puts two key aspects of the IGF in practice: a declarative way for applications to make their requirements known and have them catered for, plus CARML - the Client Attribute Requirements Markup Language that defines how this declaration is done.

The purpose of the IGF is to provide an open architecture that addresses governance of identity related information. That is a proud statement, but does not exactly to help to understand the value that is actually contained within the framework.

For one, Identity Governance is definitely a problem, but not one that is seen to be very urgent - there are typically many other open problems that have the focus and attention of IT professionals. This may be short-sighted however, because regulation is certain to become tighter and relate more directly how identity information is being treated and handled. The advantage of embracing ArisID is that its benefits in terms of Identity Governance come "for free" with the additional advantages that the framework brings.

Created: 15.12.08, modified: 09.01.09

top
KuppingerCole Select
Register now for KuppingerCole Select and get your free 30-day access to a great selection of KuppingerCole research materials and to live trainings.
Register now
Research
KuppingerCole CIO GPS
The KuppingerCole CIO GPS shows the nine areas CIOs should focus on for IT Spend Optimization, Business IT/Alignment, and Strategic Procurement, when looking at GRC (Governance, Risk Management, Compliance) and Information Security. GPS stands for Governance, Privacy and Data Protection, and Security.
KuppingerCole BII: The Business Impact Indicator
The KuppingerCole BII is a Business Impact Indicator for Information Technology. It shows the business value a particular technology or initiative can deliver, in a single and clearly laid out graphic. It complements other KuppingerCole research methodology that shows which technologies are best for achieving the targets in IT Spend Optimization, Business/IT Alignment, and Strategic Procurement.
Services
KuppingerCole Analyst Services
In the networked economy of the 21st century, digital identities play a key role in establishing trust, achieving security, lowering costs and making business processes more efficient. Things like Identity and Access Management (IAM) or...
KuppingerCole Vendor Services
The market for Identity and Access Management (IAM), governance, risk management, and compliance (GRC) and cloud computing is expanding by leaps and bounds. In fact, no other segment of the IT market can boast such dynamic growth rates. At the...
KuppingerCole Briefings
KuppingerCole welcomes the opportunity to hear from IT companies when they launch a new product or service or have other interesting progress to announce. Please fill in the request form , and we will contact you shortly. 
Links
 KuppingerCole News

 KuppingerCole on Facebook

 KuppingerCole on Twitter

 KuppingerCole on Google+

 KuppingerCole at LinkedIn

 Our group at LinkedIn

 Our group at Xing

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2013 KuppingerCole