Hi, I'm Elizabeth Garber. I'm the Marketing and Strategy Director at the OpenID Foundation and I have not prepared my panel for anything. So we are going to just review a lot of the stuff that we reviewed the other day, give people a bit of an update about what is going on at the Foundation and in their working groups. So what I would first like the panel to do is go down the line, say your names, say which working groups you're on and one, only one exciting thing that's happening in your working group.
Mike Jones, I'm one of the chairs of the OpenID Connect working group which produced a spec called OpenID Connect once upon a time. It's widely used even though it's not a consumer brand and we finished OpenID Federation not very long ago, which is about trust establishment. So we'll talk about that. Alex Olivier, I'm one of the co-chairs of AuthZen with David and our spec went final in January and the exciting thing now is we actually have real world companies and implementers going and putting this into their systems so it's becoming real finally.
David Bessard, co-chair of the AuthZen working group. We might be the working group with the most co-chairs. We got five, I don't know.
Anyway, the other exciting bit of course is we're running a profile for AI integration called Cozy. Check it out, there's a draft out there so please provide some feedback. Nat Sakimura, the co-chair of the OpenID Connect working group as well as the FAPI working group. What do you think? That's a very good question because there are too many things, right?
It's hard, especially when you have many working groups you're involved in. Nat, since you are the chairman of the board, I'm going to let you pick your top three favorite things.
I mean, that's like saying what's your favorite child, right? I'm being so mean to Nat.
Okay, all right, Nat. What is coming up in the FAPI working group that might interest this audience? So FAPI working group has been kind of stable in the sense that we've finished down with FAPI 2.0 two years ago, I think now, right? Almost. And there are things like implementation guidance which could be useful for ecosystems and Dima is working on a lot of the ecosystem side. So perhaps you might want to talk a little bit about that. By the way, Dima is the vice chair of the foundation.
No, I think from FAPI perspective, the only thing I would add is it's actually, back to the previous comment, it's great to see those specs being adopted. So we do have a few more ecosystems going live with FAPI as a baseline for the open bank in Chile. I think the hotspot right now is Latin America and North America as well. So this is where we see, and we're talking about millions of people and billions of transactions that will be coming through FAPI rails. So that's an exciting bit.
And yes, we're looking at, from ecosystems perspective, we're seeing the patterns across many ecosystems and we're trying to standardize them and publish them somehow. Yes, will be. So on DCP working group side, there will be another profile that's used heavily in many jurisdictions. That's wonderful. Thank you.
Okay, so you said there's so many things going on. Let's not talk about the AI community group because we have a whole 20 minutes dedicated to AI coming up. What's a second working group that you attend regularly and what's coming up? It's connected working group. And what I'm interested in these days is the federation specs because we can sign the things, but just signing the stuff doesn't give you trust. And you have to attach metadata and the trust anchors and things like that. And one entity, an actor belongs to multiple trust frameworks. You need something like that.
And for that, of course, I still hear someone with shortcomings to it, but we're doing pretty good job on the federation. We've finished the federation 1.1 quite recently. And you've done some really cool interop events as well. Everybody here has been involved in interop events over the last few months. What has that meant for you and the maturity of your specifications? So mid year, last year, the OpenID Foundation organized a interop event for OpenID Federation implementations that was hosted at Synet in Stockholm, Sweden.
We had like 30, 35 people in the room, about 15 implementations, people coming from as far as Australia and New Zealand to Europe to do that. That was great. We learned a lot. We improved the spec as a result of what we learned, we finished. The really fun thing to me is another federation interop was organized, not by the OpenID Foundation, but by practitioners that I went to Amsterdam in February and Niels van Dyck, who I don't think is in the room from surf, but is floating around here.
And Davide Vigetti of GAR in Italy were the organizers, and it was at the time the Trust and Identity Management Europe on conference. So the fact that this came about from community interest rather than the OpenID Foundation pushing it was wonderful.
Yeah, for the AuthZen spec, so I think we won a record for how fast we went from initial start to a ratified version. A lot of that is down to previous co-chairs, not me, I can't take any credit, around the interops. So who were they? Someone who looks like this, but not you. Elmeri Atul, as well, who's still one of the co-chairs. Over the last few years, we did six different interops at different events. We had one here at ERC a couple of years ago. We did it at Identiverse, the other place that begins with G, but I won't mention the name, another analyst.
Having the support from the community, both from the analyst side of things, but also implementers through that journey, we had around 40 different vendors of various sorts involved, or vendors of open source projects involved with that along the way. So both from a policy enforcement point, which is what David and I are, decision point, sorry, which David and I am, but also on the enforcement side of things. So we did one around API gateways.
We got, for example, AWS came in and did one with around AWS API gateway. And then the last one we did before the spec went final was around the IDPs.
So during, using all Zen as a mechanism to make decisions around what goes inside of a token, token issuance, enrichment, those kind of things. And it was being very, very useful, firstly, as a forcing function for us to get our ducks in a row and actually have something that someone could go and implement. And then also as a feedback, and we found some of the nasty edge cases during that, which further fed the versions of the spec until we got to final in January.
Yeah, if we look at the numbers, I think we have like 15 different policy decision points that implement all the Zen to a certain degree. We had eight or 10 API gateways, eight or 10 IDPs. So this is really good. And of course, some of those actually are in multiple categories, right? Some IDPs also have PDPs and so on. And then just a quick note, I guess, on the shared signals, I'm not a co-chair, I'm not even in the working group of shared signals, but Atul straddles both worlds, and they've been doing interops as well.
They've been very successful in moving forward, and they've had some pretty successful implementations. And it's interesting to see that there's also cross-pollination between the different working groups within OpenID. So shared signals is relevant to all the Zen, all the Zen is relevant to shared signals. And we haven't looked at federation yet, but I'm pretty sure we could find some interesting integration use cases between authorization and federation.
Yeah, I just wanted to touch on shared signal, and you did it. So that's really good. The other thing which I wanted to touch on is actually a KYC idea working group, and I'm looking for Mark. Mark's in the room. Maybe he's walked out. He's the co-chair of the EKYC idea working group. Another chair is floating around here, like now here, but that group is doing...
Yeah, he's come back. I just call upon you on some of the works that EKYC idea work group is doing, like authority specs and... No pressure.
Sorry, what was the question? 42.
Okay, so we've been doing some maintenance work on existing final specs. We've been having a long and drawn out conversation around the authority spec, which actually has been in draft for multiple years now, but it seems like it might help us with a range of different challenges we're facing across age-related parent-child relationships, delegation from people to organizations, organizations to organizations, and all of the fun things to do with AI agents as well, perhaps.
And we've been also looking at how to support the work that our good colleague Julianna Caffick has been doing, originating in the United States between the vehicle licensing authorities there and the financial services sector to enable use of MDL and similar things as part of financial service onboarding journeys. So we're moving towards a spec that actually goes deeper into defining the naming and semantics relating to identity assurance metadata. And I think that's probably the key things. Did I miss anything? Great.
Oh yeah, and conformance testing tool. If anybody's implementing the identity assurance specs that we've got as final, we really need people to test the test tools as well. I'll bounce back on that, because we're doing the same thing in all design. We're building the conformance test suites, and that's going to be really important for both PEPs and PDPs to actually validate that they implement all the ZEN correctly. And that's ongoing.
Yeah, it's already deployed in staging. So we've talked a little bit about the interrelationships between standards, and you've done sessions at both IAW and earlier this week about how the three different specs we have, shared signals off ZEN and IPSE that are particularly focused on the enterprise, how they do overlap and complement one another, but they're not necessarily dependent on each other. Were there any one line or one or two line lessons learned from those conversations you had?
What was the most interesting takeaway that you had, or the most interesting thing for our audience when you've done those panels? I mean, for me, having been relatively new to this whole standard space, I've only been involved for the last couple of years, is seeing how these things relate.
In fact, Gail, we were talking the other day around, we're getting to a point now where we have a very strong set of standards, but now it's the point of working out how they all connect together and the work that the IPSE group, for those that aren't following it, is basically creating profiles on top of all these different standards to meet certain thresholds of rigor that say inside of an enterprise.
And coming at it somewhat fresh, like getting to the point where you can almost have like a one line, a stack up and running that does OIDC, does shared signals, does AuthZen, and demonstrating to the kind of wider community around how these standards, A, are real, B, meets a bar of quality and rigor that they need to be deployed inside the enterprise, and then just show functionally how they'd all connect together, which I think the work, you know, I'm quite keen we're pushing on the side of AuthZen, is like getting things like the shared signals interop in place, making sure we also interop nicely with other standards outside of OpenID.
So as David said, we're doing the MCP profile, so how we work with the MCP working group going on sort of under the Anthropic slash spin out group, and just as a wider standards community, making sure we can demonstrate that these things are real, they do work, and they can be done securely inside your enterprise and giving you all those nice green tick marks as you build out your systems. Feel free, you don't have to add.
Yeah, I can't top it. Alex wins.
Okay, I wanted to, now I can't tell if you're about to jump in. You're welcome to jump in, but I have a question for Mike, unless you do. Did you want to jump in? There was another spec I wanted to touch on, but can save. Go right ahead.
All right, so one of the recent voting was on international government. Mm-hmm, I got it. I got spec. It went for the implementers draft voting. I actually haven't checked. I'm trying to check how it went, but I think it's passed.
Yeah, yeah. So one of the interesting aspects of it is calling for post-quantum algorithms, and probably it's going to start retiring all the algorithms, I guess. So that's another interesting development around the aspects. And you did a PQC talk, right? I will. Mike's doing a PQC talk.
Sorry, making sure that you... Yeah, a little later today, there's a sequence of a talk and a panel on post-quantum cryptography, where I will be trying to instill in all of you a sense of responsibility to act sooner than later. There was a really good piece of news out of the ITF yesterday, which is they published the RFC for using post-quantum signatures for JSON web tokens and CWTs for Jose and Koze.
Now, the code points for those had been allocated since July, which is great. So they had been usable since that, but they're now final.
I mean, I'll give you a preview of my conclusion that there's a bunch of things that are hard about post-quantum cryptography. There's developing the cryptographic algorithms.
Well, that's hard, but we have cryptographers who do that. Developing the standards that use the cryptography is hard, but we have people like people on this panel who know how to do standards. So we've done some of that. Then you have to update software to use the standards.
Well, we have developers who do that. Then it comes closer to home. Organizations and individuals need to look at all the software that they have that uses cryptography and update or replace it all. That's really hard. But what's even harder is convincing people to act now in the face of uncertainty about timelines. But I will make the case for why you care now if you come to my talk. What time? I don't know. Let me look it up.
Oh, you're going to look that up. But I wanted to throw a question to you because I know one of the things that the federation subgroups, what the Connect working group's doing with federation is security analysis, and we haven't spoken to that. That's an important phase that our more mature standards go through. Do you want to speak to that, Mike? So my talk is at 3.55, answering the previous question.
One of the things I really like about the way the OpenID Foundation works is we will do formal security analysis of key specifications somewhere near the end of their development lifetime or timeline. And we do that both so that we can be confident that the specs that we're using and producing are sound and ready to be deployed. But sometimes you also find problems because the security analysis will reveal things that human beings wouldn't necessarily find.
So we did a security analysis of OpenID Federation a bit over a year ago, and there's a team of professional developers in Stuttgart, or professional security analysts in Stuttgart who do this. And guess what? They found a problem not only with the way that OpenID Federation could be used, it applied to FAPI, it applied to CIBA, it applied to OAuth client authentication, and so we've been fixing all those things. Some of them are done being fixed. I will talk next week at the OAuth security workshop about fixing OAuth itself. I know. Thank you. Were you about to say something, Nat?
No, I was just mentioning that although it's rightly so, FAPI spec actually hasn't changed. Okay, great. So we are out of time, but what we've just done, normally our sessions, our updates about the Foundation as a whole, we did one on Tuesday, Tuesday morning, and it was an hour and a half long.
That's a good amount of time to cover nine working groups, multiple community groups, but we tried to give you a bit of a whistle-stop tour of some of the working groups, what's going on, and you've seen that there's a lot of interdependencies interplayed between the specifications, that they all go through a bit of a life cycle involving the development of a spec that interrupts and the role of implementers and people like you play in helping to mature those specs.
We then get through things like our security analysis and the building of conformance tests to help you implement them correctly, and all those things are happening all the time with amazing people like these ones here, and thank you for trying to do a bit of a whistle-stop tour, and I'm going to hand over now the moderator position to Gail, and we're going to double-click on the artificial intelligence, not just the community group, but how AI is influencing the Foundation as a whole. Thank you all.