<?xml version="1.0" encoding="iso-8859-1"?><feed version="0.3"
  xmlns="http://purl.org/atom/ns#"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xml:lang="en">
	<title>.Nat Zone</title>
	<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/index.php" />
	<tagline>Thinking around Digital Identity loud. </tagline>
	<modified>2009-07-23T18:25:00+09:00</modified>
	<copyright>Copyright 2010</copyright>
	<generator url="http://www.kowa.org/" version="0.5.0RC-Final">WordPress</generator>
	
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>OASIS Open: Submission of requests for Reviews etc.</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/oasis-open-submission-of-requests-for-reviews-etc/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=106</id>
		<modified>2010-02-17T11:39:19+09:00</modified>
		<issued>2010-02-17T11:39:19+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>		<summary type="text/html">	Just a personal memo on OASIS process as one of the TC chair, but OIDF should develop this kind of chart as well, I think. 
	Due to an ever-increasing workload I must ask that each request be sent in a separate e-mail message unless related to a single, multi-part specification. ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/oasis-open-submission-of-requests-for-reviews-etc/"><![CDATA[	&lt;p&gt;Just a personal memo on OASIS process as one of the TC chair, but OIDF should develop &lt;a href=&quot;http://docs.oasis-open.org/templates/MindMaps/TCAdminRequestNotices/index.html &quot;&gt;this kind of chart&lt;/a&gt; as well, I think. &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;Due to an ever-increasing workload I must ask that each request be sent in a separate e-mail message unless related to a single, multi-part specification. As a reminder, a chart showing exactly what needs to be included with each request can be seen here:&lt;br /&gt;
http://docs.oasis-open.org/templates/MindMaps/TCAdminRequestNotices/index.html&lt;/p&gt;
	&lt;p&gt;To ensure the quickest possible handling of your request, make sure to&lt;br /&gt;
1. review the checklist: http://docs.oasis-open.org/templates/QAChecklistV3.html&lt;br /&gt;
2. Include the requisite information in the request:&lt;br /&gt;
http://docs.oasis-open.org/templates/MindMaps/TCAdminRequestNotices/index.html&lt;br /&gt;
3. do not include more than 1 document in any single request.&lt;/p&gt;
	&lt;p&gt;Thank you for understanding.&lt;/p&gt;
	&lt;p&gt;Regards,&lt;/p&gt;
	&lt;p&gt;Mary&lt;/p&gt;&lt;/blockquote&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>OAuth Wrap Mobile Web App Profile?</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/oauth-wrap-mobile-web-app-profile/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=105</id>
		<modified>2010-02-09T12:08:18+09:00</modified>
		<issued>2010-02-09T12:08:18+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OAuth</dc:subject>		<summary type="text/html">	The wrap_scope, especially when it is determined dynamically using standard vocabulary such as something similar to OpenID AX, can become quite big. Under such circumstances, we may hit the browser/server constraint on URL and HTTP header. This is more acute in the mobile scenario. 
	Lucky thing is that it is ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/oauth-wrap-mobile-web-app-profile/"><![CDATA[	&lt;p&gt;The wrap_scope, especially when it is determined dynamically using standard vocabulary such as something similar to OpenID AX, can become quite big. Under such circumstances, we may hit the browser/server constraint on URL and HTTP header. This is more acute in the mobile scenario. &lt;/p&gt;
	&lt;p&gt;Lucky thing is that it is trivial to create an Mobile friendly profile / binding of OAuth Wrap, since it is almost done. It suffices just to introduce a request artifact. &lt;/p&gt;
	&lt;p&gt;Here is the flow: &lt;/p&gt;
	&lt;p&gt;&lt;img width=&quot;100%&quot; src=&quot;http://www.websequencediagrams.com/cgi-bin/cdraw?lz=VUEtPldlYkFwcENsaWVudDogU2VydmljZSBSZXF1ZXN0CgASDC0-QXV0aHpTZXJ2ZXI6IFZlcmlmaWNhdGlvbiBDb2QAKwpub3RlIG92ZXIgAFEMLCAANAsKICAgIFBPU1QABAV3cmFwX2MAfgVfaWQACAthbGxiYWNrACkFKAAaDHN0YXRlKQANC3Njb3AACQhBZGRpdGlvbmFsIFBhcmFtZXRlcnMpCmVuZCBub3RlCgCBPAsAgXAQAIFxByBBcnRpZmFjdCBSZWRpcmVjAIF7Dy0-VUEAGxIKVUEAghUPABERAG8MAD8GUG9QIFBhZ2UAKxJQb1AgKFVzZXIAgjQFZW50AIJmBykAMxMAgnkUc3BvbnNlIChha2EABAoAgVEIKQCDGwtVQSwAg3oMAIMXBTMwMgCBcgoAgxsJdgCDaQtfY29kZQCCfB5hZGRpdACDAwVwYXJhbQCCeAwAhGkSAIRDDQCBNggAhGUcUE9TVCBBY2Nlc3MgVG9rZW4AhGEgAIRwEACEaQ4sAIR6EXNlY3JlAIFdIQCFHQ0APwYAhFQuAIZJDUNoZWNrAIY8BnJpZ2h0IG9mAIYrDTEuIACHJgYgUwCBGQUgbXVzAIMsBm1hdGNoIHRoYQAvBQCGRAoyLgADCgApBQAhCQCDOAYAEwpvYnRhaW5lZACHNgZyAIVyCDMuIACDbAwgY29kZSBNVVNUAG0GAIdGBQBxBnZlciBhdXRoegAzCjQuIACHPggAcgsKNQA7GU5PAIgOBmhhdmUgZXhwaXJlZACHJRYAiSwQAIN8DwCEOgcAg2UnMjAwIE9LAIkECnJlZnJlc2hfdG9rZW4AiRsKYQCEagUACwsAiRAGAAsMXwCBLwZzX2luAIh-EgCGAwUAiQAQAIpXDlJlc291cmNlAIkDCgAKCACKQRgAFwkgICAAimAFb3JpegCLEwU6IFdSQVAgAIEqDD0iAIEgDXN0ciIAihAK&amp;#038;s=omegapple&quot;&gt; &lt;/p&gt;
	&lt;p&gt;(fig.1) &lt;a href=&quot;http://www.websequencediagrams.com/?lz=VUEtPldlYkFwcENsaWVudDogU2VydmljZSBSZXF1ZXN0CgASDC0-QXV0aHpTZXJ2ZXI6IFZlcmlmaWNhdGlvbiBDb2QAKwpub3RlIG92ZXIgAFEMLCAANAsKICAgIFBPU1QABAV3cmFwX2MAfgVfaWQACAthbGxiYWNrACkFKAAaDHN0YXRlKQANC3Njb3AACQhBZGRpdGlvbmFsIFBhcmFtZXRlcnMpCmVuZCBub3RlCgCBPAsAgXAQAIFxByBBcnRpZmFjdCBSZWRpcmVjAIF7Dy0-VUEAGxIKVUEAghUPABERAG8MAD8GUG9QIFBhZ2UAKxJQb1AgKFVzZXIAgjQFZW50AIJmBykAMxMAgnkUc3BvbnNlIChha2EABAoAgVEIKQCDGwtVQSwAg3oMAIMXBTMwMgCBcgoAgxsJdgCDaQtfY29kZQCCfB5hZGRpdACDAwVwYXJhbQCCeAwAhGkSAIRDDQCBNggAhGUcUE9TVCBBY2Nlc3MgVG9rZW4AhGEgAIRwEACEaQ4sAIR6EXNlY3JlAIFdIQCFHQ0APwYAhFQuAIZJDUNoZWNrAIY8BnJpZ2h0IG9mAIYrDTEuIACHJgYgUwCBGQUgbXVzAIMsBm1hdGNoIHRoYQAvBQCGRAoyLgADCgApBQAhCQCDOAYAEwpvYnRhaW5lZACHNgZyAIVyCDMuIACDbAwgY29kZSBNVVNUAG0GAIdGBQBxBnZlciBhdXRoegAzCjQuIACHPggAcgsKNQA7GU5PAIgOBmhhdmUgZXhwaXJlZACHJRYAiSwQAIN8DwCEOgcAg2UnMjAwIE9LAIkECnJlZnJlc2hfdG9rZW4AiRsKYQCEagUACwsAiRAGAAsMXwCBLwZzX2luAIh-EgCGAwUAiQAQAIpXDlJlc291cmNlAIkDCgAKCACKQRgAFwkgICAAimAFb3JpegCLEwU6IFdSQVAgAIEqDD0iAIEgDXN0ciIAihAK&amp;#038;s=omegapple&quot;&gt;Wrap Mobile Web Profile&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Of course, details need to be nailed down, but the basic flow should be it.&lt;/p&gt;
	&lt;p&gt;People may criticize that it introduce state in the AuthzServer. It may, but it is not necessarily so. Since the AuthzServer knows what it can serve, it has constrained set of scope and may well be able to encode it into an Artifact, so that it does not need to keep the state.&lt;/p&gt;
	&lt;p&gt;&amp;#8211;&lt;br /&gt;
(Feb 12) Fixed typo in the figure.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>CX on OAuth WRAP</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/cx-on-oauth-wrap/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=104</id>
		<modified>2010-02-02T17:53:26+09:00</modified>
		<issued>2010-02-02T17:53:26+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>OAuth</dc:subject>		<summary type="text/html">	Like there can be OpenID GET/POST and Artifact Binding for CX, there can be WRAP binding as well. It is fairly trivial, arguably more trivial than to define OpenID bindings. 
	Send CX proposal as an additional parameter on the Verification Code Request. Use wrap_client_id as the proposer&amp;#8217;s identifier.
On the PoP ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/cx-on-oauth-wrap/"><![CDATA[	&lt;p&gt;Like there can be OpenID GET/POST and Artifact Binding for CX, there can be WRAP binding as well. It is fairly trivial, arguably more trivial than to define OpenID bindings. &lt;/p&gt;
	&lt;ol&gt;
	&lt;li&gt;Send CX proposal as an additional parameter on the Verification Code Request. Use wrap_client_id as the proposer&amp;#8217;s identifier. &lt;/li&gt;
	&lt;li&gt;On the PoP verification page, display the terms and conditions included in the proposal.&lt;/li&gt;
	&lt;li&gt;Create the Verification code from the signature of the proposal and some nonce and random.&lt;/li&gt;
	&lt;li&gt;Web App Client sends the proposal again as an additional parameter on Access Token Request.&lt;/li&gt;
	&lt;li&gt;Sign the proposal to create the contract, serialize it with Base64 without line end, and return it as the access token on Access Token Response.&lt;/li&gt;
	&lt;/ol&gt;
	&lt;p&gt;That&amp;#8217;s all.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Why is the Artifact 400 bytes?</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/why-is-the-artifact-400-bytes/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=103</id>
		<modified>2010-02-01T13:25:02+09:00</modified>
		<issued>2010-02-01T13:25:02+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	In the current Artifact Binding manuscript, the artifact is being defined as a string shorter than 400 bytes. Some people asked why 400 and not 512, which is the limit of some mobile browsers? 
	The answer is that we use 80 bytes in the fixed string: 
	?openid.ns=http://specs.openid.net/auth/2.0&amp;#038;openid.mode=art_res&amp;#038;openid.artifact=
	Suppose we use 400 ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/why-is-the-artifact-400-bytes/"><![CDATA[	&lt;p&gt;In the current Artifact Binding manuscript, the artifact is being defined as a string shorter than 400 bytes. Some people asked why 400 and not 512, which is the limit of some mobile browsers? &lt;/p&gt;
	&lt;p&gt;The answer is that we use 80 bytes in the fixed string: &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;?openid.ns=http://specs.openid.net/auth/2.0&amp;#038;openid.mode=art_res&amp;#038;openid.artifact=&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;Suppose we use 400 bytes in Artifact. Then, the total is 480 bytes.&lt;br /&gt;
That leaves 32 bytes to the non-query portion of the URL.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Attribute Type URI and Script Type</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/attribute-type-uri-and-script-type/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=102</id>
		<modified>2010-01-19T19:12:52+09:00</modified>
		<issued>2010-01-19T19:12:52+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>XRI</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>OAuth</dc:subject>		<summary type="text/html">	There has been some talk around Attribute Type URI couple of months ago in OpenID mailing lists. Unless we define a set of widely agreed Type URIs, we will not be able to transfer attributes insuperably. Chris Messina&amp;#8217;s summary document on various type URI is very helpful to compare these. ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/attribute-type-uri-and-script-type/"><![CDATA[	&lt;p&gt;There has been some talk around Attribute Type URI couple of months ago in OpenID mailing lists. Unless we define a set of widely agreed Type URIs, we will not be able to transfer attributes insuperably. &lt;a href=&quot;http://spreadsheets.google.com/pub?key=pSGbbhtwI4kN_nJ1GXeQ7Qg&amp;#038;output=html&quot;&gt;Chris Messina&amp;#8217;s summary document on various type URI&lt;/a&gt; is very helpful to compare these. &lt;/p&gt;
	&lt;p&gt;There however is one thing that these specs are missing. The Script types and the language. &lt;/p&gt;
	&lt;p&gt;Unlike most Western language, some language like Japanese have many scripts within itself. For example, we use &amp;#8220;Kanji&amp;#8221;, &amp;#8220;Katakana&amp;#8221;, &amp;#8220;Hiragana&amp;#8221;, &amp;#8220;Romaji (alphabet)&amp;#8221; as four distinctive scripts. Often, we are required to supply name and address both in Kanji and Katakana or Hiragana, because without Katakana or Hiragana, you really do not know how to pronounce the Kanji in many cases. &lt;/p&gt;
	&lt;p&gt;Thus, while it would probably suffice to express fullname just as &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;http://axschema.org/namePerson&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;in English, we need these in each scripts. &lt;/p&gt;
	&lt;p&gt;The problem is how to express these as Type URIs. &lt;/p&gt;
	&lt;p&gt;One obvious way of approaching it would be something like&lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;http://axschema.org/namePerson#script_name/language_code&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;where script_name and language_code are optional. &lt;/p&gt;
	&lt;p&gt;For example, &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;
http://axschema.org/namePerson#kanji&lt;br /&gt;
http://axschema.org/namePerson#katakana
&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;would be the Kanji and Katakana version of the fullname. &lt;/p&gt;
	&lt;p&gt;If the default language for those were not specified, we could further qualify them as&lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;http://axschema.org/namePerson#kanji/ja_JP
&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;If there is only one script for the language, or if it does not matter, we could abbreviate like: &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;http://axschema.org/namePerson#/en_US
&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;which is the same as &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;http://axschema.org/namePerson
&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;if the default language was specified as en_US. &lt;/p&gt;
	&lt;p&gt;What would you think?
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Essence of Contract Exchange</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/essence-of-contract-exchange/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=101</id>
		<modified>2010-01-18T18:07:09+09:00</modified>
		<issued>2010-01-18T18:07:09+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>OAuth</dc:subject>
	<dc:subject>CX</dc:subject>		<summary type="text/html">	Abstract
This article describes the concept of (abstract) Contract Exchange, and then discusses the OpenID Binding and Use of the Contracts as Access Tokens. At the end, it also provides a mapping table to User Managed Access (UMA) Terminologies. 
	About Contract Exchange
	Contract Exchange (CX) is a protocol to exchange the signed ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/essence-of-contract-exchange/"><![CDATA[	&lt;h4&gt;Abstract&lt;/h4&gt;
	&lt;p&gt;&lt;em&gt;This article describes the concept of (abstract) Contract Exchange, and then discusses the OpenID Binding and Use of the Contracts as Access Tokens. At the end, it also provides a mapping table to User Managed Access (UMA) Terminologies. &lt;/em&gt;&lt;/p&gt;
	&lt;h3&gt;About Contract Exchange&lt;/h3&gt;
	&lt;p&gt;Contract Exchange (CX) is a protocol to exchange the signed contract dynamically among the entities in the network. It uses Public Key based signature, so it achieves certain degree of the non-repudiation and ability to prove. Thus, e-commerce etc. should benefit from it. In addition, since it can capture the purpose of the use, condition of the use, provisioning method etc. for the data/attributes, it can be used to achieve the server to server exchange of the data. &lt;/p&gt;
	&lt;p&gt;Draft OpenID CX is a binding of this Contract Exchange onto OpenID. It takes a form of OpenID Extension. Thus, it can be used over the existing OpenID Authentication 2.0, which is a GET/POST binding, as well as over the artifact binding which has been discussed since last fall. For the exchange of the proposal and contract etc., it is also using Attribute Exchange 1.1 Draft. &lt;/p&gt;
	&lt;h3&gt;Basic Flow of the CX. &lt;/h3&gt;
	&lt;p&gt;The basic flow of the CX has the following flow. Note that this is before binding it to a specific underlying protocol.&lt;br /&gt;
In the below, AM stands for Authorization Manager, SP for Service Provider.  &lt;/p&gt;
	&lt;p&gt;1. (SP finds Proposal Template from XRD/S of the AM)&lt;br /&gt;
2. SP obtains the proposal Template from the AM.&lt;br /&gt;
3. SP specifies the variables in the Proposal Template to create a Proposal.&lt;br /&gt;
4. SP signs the Proposal to create a Signed Proposal.&lt;br /&gt;
5. SP sends the Signed Proposal to the AM.&lt;br /&gt;
6. AM shows the conditions to the user and obtains the authorization.&lt;br /&gt;
7. If OK, the AM counter-signs the proposal to create a Contract.&lt;br /&gt;
8. AM saves the Contract and sends a copy to the SP.&lt;br /&gt;
9. SP uses the Contract to obtain data etc. and provides service to the user. &lt;/p&gt;
	&lt;p&gt;The service does not necessarily require data transfer. It may even not a service over the network.&lt;br /&gt;
However, it is expected that in majority of the cases, it will be a network based service that requires some data transfer.&lt;br /&gt;
Under such circumstances, some data transfer protocol needs to be defined in the contract. e.g., OpenID AX, OAuth, Wrap &amp;#8220;API Calls&amp;#8221;.)  &lt;/p&gt;
	&lt;h3&gt;Characteristics of the CX Template&lt;/h3&gt;
	&lt;p&gt;CX Templates has several unique features. &lt;/p&gt;
	&lt;ul&gt;
	&lt;li&gt;XML is the default format.&lt;/li&gt;
	&lt;li&gt;The template has to have a URL of the form http://uri_of_contract_template#digest_algorithm:digest, so if the template is changed, the url will also change. &lt;/li&gt;
	&lt;li&gt;Anyone can create a template, but since AM is the party that knows what data is available as well as the party which creates the permission page, AM seems to be the natural place.&lt;/li&gt;
	&lt;li&gt;As the result of the Hashed URL, template cannot be edited. Thus, we have to use variables to express the portion which is given from the outside. &lt;/li&gt;
	&lt;li&gt;Template variables are expressed in the form of {{variable_name}}. As the variable name, xs:id of the XML element is used, and the value will be the inner text of the Element. &lt;/li&gt;
	&lt;/ul&gt;
	&lt;h3&gt;Characteristics of the CX Contract&lt;/h3&gt;
	&lt;ul&gt;
	&lt;li&gt;There can be as many parties as one wants. That is, we can express n-party contract. Each Party has Obligations. &lt;/li&gt;
	&lt;li&gt;A Contract includes the public key of the each Parties. These can be used for the signature verification and data encryption. &lt;/li&gt;
	&lt;li&gt;A Contract includes a TemplteURL and a Template. Ops and RPs can use this TemplateURL to figure out what kind of template it is. &lt;/li&gt;
	&lt;li&gt;Obligation can be written in the Contract. This includes the price and damage limit. &lt;/li&gt;
	&lt;li&gt;As a default data request method, AX Request is supported. Other format can be defined. &lt;/li&gt;
	&lt;li&gt;Signature is done by XML Signature. Canonicalization is Exclusive Canonicalization. Since it is using the Digital Signature, the ability to proof is high even outside the system. &lt;/li&gt;
	&lt;/ul&gt;
	&lt;h3&gt;OpenID GET/POST Binding&lt;/h3&gt;
	&lt;p&gt;CX can be bound to OpenID through GET/POST Binding and Artifact Binding. For the purpose of this article, which binding to use is a non-issue, so I am using simpler GET/POST binding flow. &lt;/p&gt;
	&lt;p&gt;In the next diagram I am using OP (OpenID Provider) instead of AM and RP (Replying Party) instead of SP to match the OpenID terminology. In addition, UA stands for User-Agent (e.g., Web Browser). &lt;/p&gt;
	&lt;p&gt;&lt;img style=&quot;width:90%;align:center;&quot; src=&quot;http://www.websequencediagrams.com/cgi-bin/cdraw?lz=VUEtPlJQOlNlcnZpY2UgUmVxdWVzdApvcHQKICAgIG5vdGUgcmlnaHQgb2YgT1AKUHJvcG9zYWwKVGVtcGxhdGUAIgVlbmQAJgUALwVSUC0-T1A6IGZldGNoIHQAIAhlbmQKUlAAaQUgQ3JlYXRlIABFCCBmcm9tIHRoZQAkCgAiCFNpZ24AHwkKUlAtLT5VQTogU2VuZAANClVBAGwGAAgOTwAlCFBlcm1pc3Npb24gUGFnZQAmCQAOCgpPAIEtB0NvdW50ZXItAGoNIChDb250cmFjdCkAIAlTdG9yZSAAEAgKAIIYEDoAEQoAfgkAgS8FACkJAIJyBwAHDwCBbgkAQxwAgj0FAHII&amp;#038;s=omegapple&quot; /&gt;&lt;/p&gt;
	&lt;div style=&quot;text-align:center;&quot;&gt;Fig 1: OpenID GET/POST Binding Sequence&lt;/div&gt;
	&lt;h3&gt;Data Transfer using CX&lt;/h3&gt;
	&lt;p&gt;In the use case that transfers data, CX Contract can be used as either the holder-of-key or bearer access token by the RP. Alternatively, if the Data Provider has the copy of the contract, then ContractID can be used as a bearer token. (In general, AM and DP are different, so the later cannot be assumed in every case.) Using such Tokens, server to server data transfer can be achieved. Data Provider (DP) checks the authenticity of the contract and then creates a dataset and encrypts it with the public key in the Contract and provides it to the requestor. Since it is encrypted by the public key of the intended recipient, it cannot be read by somebody else. &lt;/p&gt;
	&lt;p&gt;&lt;img src=&quot;http://www.websequencediagrams.com/cgi-bin/cdraw?lz=UlAtPkRQOlByZXNlbnQgQ29udHJhY3QKRAASBkNoZWNrAAURRGF0YSBFbmNyeXB0aW9uCm5vdGUgcmlnaHQgb2YgRFAKICBDcmVhdGUgZGF0YXNldCBkZWZpbmVkIAogIGluIHRoZQBhCSBhbgASBWUASQYgaXQgd2l0aAAfBQogIHB1YmxpYyBrZXkAKRAKZW5kIG5vdGUKRFAtLT5SUDpTZW5kAIEPCGVkIERhdGEKUlAAFgVEZQBYBgBSCXByaXZhdGUga2V5LiAK&amp;#038;s=omegapple&quot;&gt;&lt;/p&gt;
	&lt;div style=&quot;text-align:center;&quot;&gt;Fig 2: Data Transfer sequence when Contract was used as a Bearer Token&lt;/div&gt;
	&lt;p&gt;&lt;hr /&gt;&lt;/p&gt;
	&lt;h4&gt;Appendix 1: Mapping to UMA terminology&lt;/h4&gt;
	&lt;table style=&quot;border:1px solid grey&quot;&gt;
	&lt;tr style=&quot;border:1px solid grey&quot;&gt;
&lt;td&gt;This Article&lt;/td&gt;
	&lt;td&gt;UMA (User Managed Access)&lt;/td&gt;
&lt;/tr&gt;
	&lt;tr style=&quot;border:1px solid grey&quot;&gt;
&lt;td&gt;AM&lt;/td&gt;
	&lt;td&gt;AM&lt;/td&gt;
&lt;/tr&gt;
	&lt;tr style=&quot;border:1px solid grey&quot;&gt;
&lt;td&gt;SP&lt;/td&gt;
	&lt;td&gt;Host&lt;/td&gt;
&lt;/tr&gt;
	&lt;tr style=&quot;border:1px solid grey&quot;&gt;
&lt;td&gt;DP&lt;/td&gt;
	&lt;td&gt;Protected Resource&lt;/td&gt;
&lt;/tr&gt;
	&lt;tr style=&quot;border:1px solid grey&quot;&gt;
&lt;td&gt;UA&lt;/td&gt;
	&lt;td&gt;Requestor&lt;/td&gt;
&lt;/tr&gt;
	&lt;tr style=&quot;border:1px solid grey&quot;&gt;
&lt;td&gt;User&lt;/td&gt;
	&lt;td&gt;Authorizing User&lt;/td&gt;
&lt;/tr&gt;
	&lt;/table&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>OAuth Wrap Web App Profile Summary</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/oauth-wrap-web-app-profile-summary/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=100</id>
		<modified>2010-01-11T14:06:45+09:00</modified>
		<issued>2010-01-11T14:06:45+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OAuth</dc:subject>		<summary type="text/html">	Here is the Sequence Diagram of OAuth Wrap Web App Profile (Section 5.4). 
	Hope the spec to include such instead of legacy ascii diagram&amp;#8230;
websequencediagrams.com source would do. 
	Notes: 
	wrap_client_id and wrap_client_secret are provisioned from the  AuthzServer to the WebAppClient in advance.
An Access Token is an opaque string whose format ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/oauth-wrap-web-app-profile-summary/"><![CDATA[	&lt;p&gt;Here is the Sequence Diagram of &lt;a href=&quot;http://oauth-wrap-wg.googlegroups.com/web/WRAP-v0.9.7.2.pdf?gda=uAv-pEQAAABFB7PFAFiVedPtjcqT8uuIw3UUaV7yzsI3PxYlAJlmzRidFvlYqd_ZjmG9h9kh5-pV6u9SiETdg0Q2ffAyHU-dzc4BZkLnSFWX59nr5BxGqA&quot;&gt;OAuth Wrap&lt;/a&gt; Web App Profile (Section 5.4). &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;Hope the spec to include such instead of legacy ascii diagram&amp;#8230;&lt;br /&gt;
websequencediagrams.com source would do. &lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;Notes: &lt;/p&gt;
	&lt;ol&gt;
	&lt;li&gt;wrap_client_id and wrap_client_secret are provisioned from the  AuthzServer to the WebAppClient in advance.&lt;/li&gt;
	&lt;li&gt;An Access Token is an opaque string whose format is agreed upon between the Resource and AuthzServer. It acts as a Bearer Token. &lt;/li&gt;
	&lt;li&gt;All the communication is done over HTTPS so signatures are said to be unnecessary. (I am skeptical on it though. [*1]) &lt;/li&gt;
	&lt;/ol&gt;
	&lt;p&gt;&lt;img style=&quot;width:95%;&quot; src=&quot;http://www.websequencediagrams.com/cgi-bin/cdraw?lz=VUEtPldlYkFwcENsaWVudDogU2VydmljZSBSZXF1ZXN0CgASDC0tPlVBOiBWZXJpZmljYXRpb24gQ29kACMKbm90ZSBvdmVyIFVBLCAATQwKICAgIDMwMiBSZWRpcmVjAAsGd3JhcF9jAHUFX2lkAAgLYWxsYmFjawAxBSgAGgxzdGF0ZSkADQtzY29wAAkIQWRkaXRpb25hbCBQYXJhbWV0ZXJzKQplbmQgbm90ZQpVQS0-QXV0aHpTZXJ2ZXIAgS4cABwLAIFvB1BvUCBQYWcAMxNQb1AgKFVzZXIgQXV0aGVudACCFQcpADMTAIIoFHNwb25zZQCCLw4AghUndgCDAAtfY29kZQCCFB5hZGRpdACCGwVwYXJhbQCCDBAAg3wOAINaDQCBHQkAhAMNAIF5D09TVCBBY2Nlc3MgVG9rZW4AhAUTAIRhDCwAgwELAIN8EywAhBIRc2VjcmUAgV0hAIQ1DQA_BgCDeSEAg2MMAIQVDkNoZWNrAIVTBnJpZ2h0IG9mAINiBQCBMAgxLiAAhjUGIFMAgRkFIG11c3QgAIVqBW1hdGNoIHRoYQAwBQCFXQoyLgADCgApBgAiCGUAMwYAFApvYnRhaW5lZACGTwZyAIY0CDMuIACDbgwgY29kZSBNVVNUAG0HAIZpBQBzBnZlciBhdXRoegA0CjQuIACGWQgAdAsKNQA8GU5PVACBTAZoYXZlIGV4cGlyZWQAgicWAIg_EACEAA8AhVoRAINzHTIwMCBPSwCCRwYAiCYFcmVmcmVzaF90b2tlbgCIOAphAIRvBQALCwCILQYACwxfAIEwBnNfaW4AiBsSAIYIBQCIHRAAhVsOUmVzb3VyY2U6AIoRCCAACggAhUUYABcJICAgAIgUBW9yaXoAii8FOiBXUkFQIACBKgw9IgCBIA1zdHIiAIkuCQ&amp;#038;s=omegapple&quot; alt=&quot;UA-&gt;WebAppClient: Service Request&lt;br /&gt;
WebAppClient&amp;#8211;&gt;UA: Verification Code Request&lt;br /&gt;
note over UA, WebAppClient&lt;br /&gt;
    302 Redirect&lt;br /&gt;
    wrap_client_id&lt;br /&gt;
    wrap_callback&lt;br /&gt;
    (wrap_client_state)&lt;br /&gt;
    (wrap_scope)&lt;br /&gt;
    (Additional Parameters)&lt;br /&gt;
end note&lt;br /&gt;
UA-&gt;AuthzServer: Verification Code Request&lt;br /&gt;
AuthzServer&amp;#8211;&gt;UA: PoP Page&lt;br /&gt;
UA-&gt;AuthzServer: PoP (User Authentication)&lt;br /&gt;
AuthzServer&amp;#8211;&gt;UA: Verification Code Response&lt;br /&gt;
note over UA,WebAppClient&lt;br /&gt;
    302 Redirect&lt;br /&gt;
    wrap_verification_code&lt;br /&gt;
    (wrap_client_state)&lt;br /&gt;
    (additonal params)&lt;br /&gt;
end note&lt;br /&gt;
UA-&gt;WebAppClient: Verification Response&lt;br /&gt;
WebAppClient-&gt;AuthzServer: POST Access Token Request&lt;br /&gt;
note over WebAppClient,AuthzServer&lt;br /&gt;
    wrap_client_id,&lt;br /&gt;
    wrap_client_secret&lt;br /&gt;
    wrap_verification_code&lt;br /&gt;
    wrap_callback,&lt;br /&gt;
    (Additional Parameters)&lt;br /&gt;
end note&lt;br /&gt;
AuthzServer-&gt;AuthzServer: Check&lt;br /&gt;
note right of AuthzServer&lt;br /&gt;
1. Client Secret must&lt;br /&gt;
    match that of client_id&lt;br /&gt;
2. client_id must match the&lt;br /&gt;
    client_id obtained over redirect&lt;br /&gt;
3. verification code MUST match&lt;br /&gt;
    that over authz redirect&lt;br /&gt;
4. callback must match&lt;br /&gt;
5. verification code MUST NOT&lt;br /&gt;
    have expired&lt;br /&gt;
end note&lt;br /&gt;
AuthzServer&amp;#8211;&gt;WebAppClient: Access Token Response&lt;br /&gt;
note over WebAppClient,AuthzServer&lt;br /&gt;
    200 OK&lt;br /&gt;
    wrap_refresh_token&lt;br /&gt;
    wrap_access_token&lt;br /&gt;
    (wrap_access_token_expires_in)&lt;br /&gt;
    (Additional parameters)&lt;br /&gt;
end note&lt;br /&gt;
WebAppClient-&gt;Resource: Request Resource&lt;br /&gt;
note over WebAppClient,Resource&lt;br /&gt;
    Authorization: WRAP access_token=access_token_str&lt;br /&gt;
end note&quot;&gt;&lt;/p&gt;
	&lt;p&gt;[*1] Security Questions&lt;/p&gt;
	&lt;p&gt;It might be because I have not spent too much time on this protocol, and I was writing this (original Japanese version) at 2:00AM, I have some questions on the security characteristics. &lt;/p&gt;
	&lt;ol&gt;
	&lt;li&gt;UA may act as the man-in-the-middle to tamper the request. (e.g., when the UA is infested by a malware.) To me, it seems that it can only be coped by either the request to be signed or something like an Artifact is used instead of the request itself. Since the target of WRAP is to remove the signature, the Artifact seems to be the way to go. &lt;/li&gt;
	&lt;li&gt;To identify the client, it is using client_id and client_secret. It is essentially a username/password authentication. Thus, from the NIST SP800-63 like perspective, it is only LoA1. &lt;/li&gt;
	&lt;li&gt;Access Token is another long-term secret. Moreover, it is revealed to somebody else than the client and the verifier (AuthzServer). It has some implication from the SP800-63 perspective.&lt;/li&gt;
	&lt;li&gt;MITM is possible even for HTTPS. How to recognized that the counter party is the right one needs to be specified in more details. Certificate Chain verification is only a necessary condition. If it is not done correctly, it will be possible to mount token capture and replay attack. &lt;/li&gt;
	&lt;li&gt;Access Token is specified only as an Opaque String. This actually needs to be specified a little more in detail. For example, randomness requirements, signature requirements etc. are needed to thwart the guessing attack and the access token forgery. &lt;/li&gt;
	&lt;li&gt;Browser Swap / CSRF attack has to be thwarted. &lt;/li&gt;
	&lt;/ol&gt;
	&lt;p&gt;Much of these needs to be dealt with Section  7. Security Considerations. &lt;/p&gt;
	&lt;p&gt;In addition, I have not understood  &lt;/p&gt;
	&lt;ol&gt;
	&lt;li&gt;Why are we provisioning wrap_client_id and  wrap_client_secret out of band? The y can just be Subject and Pubkey of XRD. If we do so, the long-term client_secret problem disappears, though signature resurfaces. &lt;/li&gt;
	&lt;li&gt;Why do not we standardize on Scope format? For AuthzServers, having no standard is ok, but for WebAppClients, it is much easier to code on the standard than code a proprietary request per AuthzServer.&lt;/li&gt;
	&lt;/ol&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>OpenID Provider Selection Protocol?</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/openid-provider-selection-protocol/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=99</id>
		<modified>2009-10-20T09:26:40+09:00</modified>
		<issued>2009-10-20T09:26:40+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	In case when the site want to use OP Identifier, the site typically shows list of icons of the OPs. This list grows quickly and results in User Interface Nightmare a.k.a. &amp;#8220;Nascar Problem&amp;#8221;. 
	Various people have been working on this, such as IDIB efforts and some Infocard integration, but to ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/openid-provider-selection-protocol/"><![CDATA[	&lt;p&gt;In case when the site want to use OP Identifier, the site typically shows list of icons of the OPs. This list grows quickly and results in User Interface Nightmare a.k.a. &amp;#8220;Nascar Problem&amp;#8221;. &lt;/p&gt;
	&lt;p&gt;Various people have been working on this, such as IDIB efforts and some Infocard integration, but to me, there seems to be even simpler solution. &lt;/p&gt;
	&lt;p&gt;I have been wondering why nobody proposes this.&lt;br /&gt;
It is extremely simple. &lt;/p&gt;
	&lt;p&gt;Simply add your OP Identifier to the end of User Agent string, separated by semi-colon. For example, if you are using Safari, and if your OP is mixi.jp, then it would be like: &lt;/p&gt;
	&lt;p&gt;Mozilla/5.0 (Windows; U; Windows NT 5.1; ja-JP) AppleWebKit/531.9 (KHTML, like Gecko) Version/4.0.3 Safari/531.9.1;op=mixi.jp&lt;/p&gt;
	&lt;p&gt;Creating custom header in IE is a bit of problem, but the UA string is an exception and can be changed just by changing a registry entry as far as I know. Most other major browsers provide ways to set the user agents. &lt;/p&gt;
	&lt;p&gt;The RP, upon receipt of the above string, extracts mixi.jp and redirects user to mixi.jp automagically. If he has a session there, which is likely, he may be returned to the site immediately. &lt;/p&gt;
	&lt;p&gt;True that it reveals your OP to every site. Some people may consider it a privacy problem, and some would complain about the security implication, but how real would be an attack using that information? Not much, I think. Anti-Phishing? It should be dealt with other mechanisms.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Sequence Diagram for Artifact Binding</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/sequence-diagram-for-artifact-binding/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=98</id>
		<modified>2009-10-08T20:29:09+09:00</modified>
		<issued>2009-10-08T20:29:09+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	Based on https://openid.pbworks.com/OpenIDwithArtifactBinding
 </summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/sequence-diagram-for-artifact-binding/"><![CDATA[	&lt;p&gt;Based on &lt;a href=&quot;https://openid.pbworks.com/OpenIDwithArtifactBinding&quot;&gt;https://openid.pbworks.com/OpenIDwithArtifactBinding&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;&lt;a href=&quot;http://www.websequencediagrams.com/?lz=VXNlci0-VUE6IENsaWNrIExvZ2luClVBLT5SUDoABwdSUC0-T1A6IEdldCBYUkRTAAwFUlA6IEZpbmQgU2VydmljZQpvcHQgSWYgbm8gQXNzb2MKICAgIAAyCAANBWlhdGlvbiBSZXEAFwVPUC0AXwYADw5zCmVuZABqCURpcmVjdCBBdXRoTgA1BU8AgQUHQ3JlYXRlIEFydGlmYWN0AA8JU3RvcmUgUmVxdWVzABEFAF0HACAIUlAtAIFpBgAyCABXBWVudGljAIEWCQA2BVVBAIE0BwAJHwCBbgl0IGltbWVkaWF0ZQCBVgoAglQFcmVkZW50aWFsIElucHV0IFNjcmVlbgCCHAUAgnUKABUGACIKABkGAH4HUE9TVCBjAA4OAIIBCWhlY2sAEQxlbmQAggAPQXNzZXJ0aW9uAIILBgCBYR5zcG9uc2UAg3oJAAghAIMbEABkCACCcxIADxMAOQtSUDogVmVyaWZ5AIElCwCDJglTZXNzaW9uCg&amp;#038;s=omegapple&quot;&gt;&lt;br /&gt;
&lt;img src=&quot;http://www.websequencediagrams.com/cgi-bin/cdraw?lz=VXNlci0-VUE6IENsaWNrIExvZ2luClVBLT5SUDoABwdSUC0-T1A6IEdldCBYUkRTAAwFUlA6IEZpbmQgU2VydmljZQpvcHQgSWYgbm8gQXNzb2MKICAgIAAyCAANBWlhdGlvbiBSZXEAFwVPUC0AXwYADw5zCmVuZABqCURpcmVjdCBBdXRoTgA1BU8AgQUHQ3JlYXRlIEFydGlmYWN0AA8JU3RvcmUgUmVxdWVzABEFAF0HACAIUlAtAIFpBgAyCABXBWVudGljAIEWCQA2BVVBAIE0BwAJHwCBbgl0IGltbWVkaWF0ZQCBVgoAglQFcmVkZW50aWFsIElucHV0IFNjcmVlbgCCHAUAgnUKABUGACIKABkGAH4HUE9TVCBjAA4OAIIBCWhlY2sAEQxlbmQAggAPQXNzZXJ0aW9uAIILBgCBYR5zcG9uc2UAg3oJAAghAIMbEABkCACCcxIADxMAOQtSUDogVmVyaWZ5AIElCwCDJglTZXNzaW9uCg&amp;#038;s=omegapple&quot; alt=&quot;OpenID Artifact Binding &quot; style=&quot;width:95%;border:0px;&quot; /&gt;&lt;/a&gt;
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>OpenID Process Change</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/openid-process-change/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=97</id>
		<modified>2009-10-08T16:07:47+09:00</modified>
		<issued>2009-10-08T16:07:47+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	Finally!
	I am glad to write that OpenID Foundation Board has approved the change in the OpenID Process document so that a working group can be started without membership vote. 
	The change itself requires membership vote, so the notice will go out soon, and it is a month or more away ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/openid-process-change/"><![CDATA[	&lt;p&gt;Finally!&lt;/p&gt;
	&lt;p&gt;I am glad to write that OpenID Foundation Board has approved the change in the OpenID Process document so that a working group can be started without membership vote. &lt;/p&gt;
	&lt;p&gt;The change itself requires membership vote, so the notice will go out soon, and it is a month or more away for the new process to get effective, but once that is done, we can spin up WGs pretty quickly. That would certainly help AX 2.0, Auth 2.1 etc.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Re: Is OpenID User Centric?</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/re-is-openid-user-centric/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=96</id>
		<modified>2009-10-08T15:59:45+09:00</modified>
		<issued>2009-10-08T15:59:45+09:00</issued>
		
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	As I was not able to login to comment on Johannes&amp;#8217;s blog&amp;#8230;
	It is about this entry &amp;#8220;Is OpenID User Centric?&amp;#8221;. 
	Johannes&amp;#8217;s comment that OpenID being &amp;#8220;http://netmesh.info/jernst/digital_identity/is-openid-still-user-centric&amp;#8221; is very apt. This is one use case that OpenID is supposed to serve. 
	The other use case that it is serving right now ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/re-is-openid-user-centric/"><![CDATA[	&lt;p&gt;As I was not able to login to comment on Johannes&amp;#8217;s blog&amp;#8230;&lt;/p&gt;
	&lt;p&gt;It is about this entry &amp;#8221;&lt;a href=&quot;http://netmesh.info/jernst/digital_identity/is-openid-still-user-centric&quot;&gt;Is OpenID User Centric?&lt;/a&gt;&amp;#8221;. &lt;/p&gt;
	&lt;p&gt;Johannes&amp;#8217;s comment that OpenID being &amp;#8220;http://netmesh.info/jernst/digital_identity/is-openid-still-user-centric&amp;#8221; is very apt. This is one use case that OpenID is supposed to serve. &lt;/p&gt;
	&lt;p&gt;The other use case that it is serving right now is the Web SSO. &lt;/p&gt;
	&lt;p&gt;As a &amp;#8220;personal/business card&amp;#8221;, you do not need privacy. You do not want privacy. You want to reveal that it was you, and you want to be tracked. &lt;/p&gt;
	&lt;p&gt;In Web SSO case, you might or might not want to be tracked. &lt;/p&gt;
	&lt;p&gt;For User Centric thing, I believe that the user should control one&amp;#8217;s XRD. Then, I can use Yahoo! or Google as authentication service that provide PPID. &lt;/p&gt;
	&lt;p&gt;If I want to preserve anonymity, I would use OP identifier to Yahoo! or Google. Alternatively, I could provide an XRD address that service PPID, but that would be a tall order for most people. &lt;/p&gt;
	&lt;p&gt;If I want to leave my track, then I will provide my (signed) XRD address. &lt;/p&gt;
	&lt;p&gt;As to the email as attribute being sent&amp;#8230; &lt;/p&gt;
	&lt;p&gt;I think we should define contact service just like XRI people do. It could be email, twitter, or authenticated something, etc. The service should be advertised in the XRD. Then we should not need to provide &amp;#8220;physical&amp;#8221; address like email to the RP.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>OpenID BizDay #4</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/openid-bizday-4/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=95</id>
		<modified>2009-09-24T15:11:51+09:00</modified>
		<issued>2009-09-24T15:11:51+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	I have not been reporting this, but apart from TechNight and BizDay, we are having several discussion groups going on and meetings are getting more like &amp;#8220;weekly&amp;#8221; than &amp;#8220;monthly&amp;#8221;. OK. That is not an excuse not writing them here. I will try to be more timely. 
	Today, I want to ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/openid-bizday-4/"><![CDATA[	&lt;p&gt;I have not been reporting this, but apart from TechNight and BizDay, we are having several discussion groups going on and meetings are getting more like &amp;#8220;weekly&amp;#8221; than &amp;#8220;monthly&amp;#8221;. OK. That is not an excuse not writing them here. I will try to be more timely. &lt;/p&gt;
	&lt;p&gt;Today, I want to report the following: &lt;/p&gt;
	&lt;p&gt;OpenID BizDay #4&lt;/p&gt;
	&lt;p&gt;Date: Sept. 25, 2009 (Fri) 14:30 - 16:30&lt;br /&gt;
Venue: Vila Fontaine Shiodome Meeting room 2,3&lt;br /&gt;
    1-9-2 Shinbashi, Minato-ku, Tokyo 105-0021&lt;br /&gt;
    JAPAN&lt;br /&gt;
    http://www.sumitomo-rd.co.jp/vf/shiodome/conference/map.html&lt;/p&gt;
	&lt;p&gt;Program:&lt;br /&gt;
&amp;#8220;Application of OpenID at NTTCom&amp;#8221;&lt;br /&gt;
Kazuhiro Kitamura, General Manager, Net Business Div.&lt;br /&gt;
NTT Communications Corp. &lt;/p&gt;
	&lt;p&gt;&amp;#8220;gooID that grows with customers&amp;#8221;&lt;br /&gt;
Yasushi Tsuruki, Manager, Service Dept., Media Div.&lt;br /&gt;
NTT Resonant Inc.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>To Push or Not to Push: that is the question</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/to-push-or-not-to-push-that-is-the-question/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=94</id>
		<modified>2009-09-17T23:27:49+09:00</modified>
		<issued>2009-09-17T23:27:49+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>OAuth</dc:subject>		<summary type="text/html">	So I was designing OpenID Authn Artifact Binding based on OAuth.
OAuth pushes request token (RT) to the Service Provider (saml:responder, openid:op). 
	Then, I looked back at the saml artifact binding. 
	It is the opposite. It sends the artifact first and the SP/responder pulls the data from Consumer/requester. Why? 
	It has ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/to-push-or-not-to-push-that-is-the-question/"><![CDATA[	&lt;p&gt;So I was designing OpenID Authn Artifact Binding based on OAuth.&lt;br /&gt;
OAuth pushes request token (RT) to the Service Provider (saml:responder, openid:op). &lt;/p&gt;
	&lt;p&gt;Then, I looked back at the saml artifact binding. &lt;/p&gt;
	&lt;p&gt;It is the opposite. It sends the artifact first and the SP/responder pulls the data from Consumer/requester. Why? &lt;/p&gt;
	&lt;p&gt;It has got to do with the scale. &lt;/p&gt;
	&lt;p&gt;When the SP/Responder is big, chances are that the servers are distributed and there will be a big sync up problem among them. Thus, when the RT/message is sent there and the user arrives through browser redirect, the RT/message itself may not be accessible from the server that the user landed. &lt;/p&gt;
	&lt;p&gt;In case of SAML flow, the requester creates the artifact, and in the artifact, there is a node index included. Then, user arrives to the responder with artifact, and the responder pulls the data using this artifact. When requester receives the artifact, it knows where the RT/message is stored, so it can reliably fetch it. &lt;/p&gt;
	&lt;p&gt;So, SAML actually is kinder to a large scale providers. &lt;/p&gt;
	&lt;p&gt;On the other hand, OAuth has its own edge. In case of OAuth, the Requester always makes the action. It does not matter if it is behind the firewall or something. Typically, if it is an application living on a PC or Phone or something like that, the chances are that SP/Responder/OP cannot reach the client because it has got a private address. Since OAuth had such use case from the beginning, I suppose, the current choice was made. &lt;/p&gt;
	&lt;p&gt;So, coming back to OpenID Artifact Binding: Which design should we chose? &lt;/p&gt;
	&lt;p&gt;To Pull, or to Push: That is the question.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Difference between UMA and CX</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/difference-between-uma-and-cx/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=92</id>
		<modified>2009-09-16T15:41:07+09:00</modified>
		<issued>2009-09-16T15:41:07+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>XRD</dc:subject>
	<dc:subject>OAuth</dc:subject>
	<dc:subject>CX</dc:subject>		<summary type="text/html">	This afternoon, I attended UMA WG session at Kantara Initiative. UMA stands for User Managed Access, formally known as ProtectServe. 
	The purpose of this Work Group is to develop a set of draft specifications that enable an individual to control the authorization of data sharing and service access made between ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/difference-between-uma-and-cx/"><![CDATA[	&lt;p&gt;This afternoon, I attended UMA WG session at Kantara Initiative. UMA stands for User Managed Access, formally known as ProtectServe. &lt;/p&gt;
	&lt;p&gt;The purpose of this Work Group is to develop a set of draft specifications that enable an individual to control the authorization of data sharing and service access made between online services on the individual&amp;#8217;s behalf, and to facilitate the development of interoperable implementations of these specifications by others.&lt;/p&gt;
	&lt;p&gt;Thus, it roughly is equal to CX in it&amp;#8217;s concept. &lt;/p&gt;
	&lt;p&gt;A little bit of comparison was done in today&amp;#8217;s session.&lt;br /&gt;
Most notably: &lt;/p&gt;
	&lt;p&gt;In CX, contract proposal is sent from the data consumer to the data provider (user) while in UMA, the proposal is being sent from the data provider (user) to the data consumer. &lt;/p&gt;
	&lt;p&gt;This is subtle but important distinction, at least, philosophically. &lt;/p&gt;
	&lt;p&gt;In fact, when I started discussing CX among my friends, we first consider the user providing the policy just like UMA. It was because it is closer to the VRM like setting. Then, after a while, we made a conscious decision to do the other way round. &lt;/p&gt;
	&lt;p&gt;Why? &lt;/p&gt;
	&lt;p&gt;In most cases, the data consumer is actually web service. It is a machine. On the other hand, on the data provider side, there is the user, the human being, who makes the decision. &lt;/p&gt;
	&lt;p&gt;If we offer a contract proposal from the user side, the machine has to negotiate it automagically. It is hard.&lt;br /&gt;
It looked like it is an daunting task to do it over a wide range of possible use cases. &lt;/p&gt;
	&lt;p&gt;On the other hand, the other way round is easy. You show the user the condition and terms, and it is this human being parsing that proposal and making decision. This seemed like a reasonably easy thing to achieve technically. &lt;/p&gt;
	&lt;p&gt;To approximate user providing the acceptable policy, we can create a common repository of contract proposals and the user can publish the URL in his XRD, so that the data consumer can pick an acceptable policy. &lt;/p&gt;
	&lt;p&gt;I believe this approach saves us from the hard question of designing negotiation protocol and still achieve something roughly the same. Also, note that we do not have to agree on the syntax of the machine readable condition. It is up to the application to decide it(*1). &lt;/p&gt;
	&lt;p&gt;We are right now doing CX WG at OpenID Foundation. However, CX is not only for OpenID. I consider it as an OpenID Binding of CX. It can equally be done for OAuth or some other protocol. &lt;/p&gt;
	&lt;p&gt;UMA&amp;#8217;s approach is definitely interesting, but I still do not know how it can be achieved. It is a &amp;#8220;must track&amp;#8221; kind of thing for me right now.&lt;/p&gt;
	&lt;p&gt;(*1) There was yet another reason to do it this way: I was not comfortable floating around a contract proposal signed by me waiting for some unknown party to counter-sign floating around. From the &amp;#8220;consumer protection&amp;#8221; (note different use of the term &amp;#8220;consumer&quot;) perspective, IMHO, the user should be the last one to sign.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>What is an OpenID Extension?</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/what-is-an-openid-extension/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=91</id>
		<modified>2009-08-13T20:44:13+09:00</modified>
		<issued>2009-08-13T20:44:13+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	OpenID Extension is defined in the section 12 of the OpenID Authentication 2.0 as: 
	An Extension to OpenID Authentication is a protocol that &amp;#8220;piggybacks&amp;#8221; on the authentication request and response. Extensions are useful for providing extra information about an authentication request or response as well as providing extra information about ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/what-is-an-openid-extension/"><![CDATA[	&lt;p&gt;OpenID Extension is defined in the section 12 of the OpenID Authentication 2.0 as: &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;An Extension to OpenID Authentication is a protocol that &amp;#8220;piggybacks&amp;#8221; on the authentication request and response. Extensions are useful for providing extra information about an authentication request or response as well as providing extra information about the subject of the authentication response. &lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;OK. My question: Does it entirely have to depend on authenticaiton request and response, or can it partially depend on it? &lt;/p&gt;
	&lt;p&gt;By definition, I think it is the later, because, the subsequent paragraph goes: &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;OpenID extensions are identified by a Type URI. The Type URI MAY be used as the value of an &lt;xrd :Type&gt; element of an OpenID &lt;xrd :Service&gt; element in an XRDS document associated with a Claimed Identifier. The Type URI is also used to associate key-value pairs in messages with the extension. &lt;/xrd&gt;&lt;/xrd&gt;&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;Clearly, this is not authentication request (section 9) and response (section 10), but Discovery (seciont 7.3). Thus, if it were to be entirely on request and response, the spec contradicts itself. &lt;/p&gt;
	&lt;p&gt;Therefore, it has to mean that an extension is a protocol that has to utilize request and response. &lt;/p&gt;
	&lt;p&gt;QED
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>OpenID International Activities Updates</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/openid-international-activities-updates/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=90</id>
		<modified>2009-08-12T23:43:36+09:00</modified>
		<issued>2009-08-12T23:43:36+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>		<summary type="text/html">	I should be doing this more often: 
	Japan
	- CX discussion group has produced use cases and requirement document  on Creative Commons License. Contributors are 
	Yoichi Ohnawa, NEC BIGLOBE, Ltd.
Takaya Tanaka, KDDI Corporation
Daisuke Ikeda, JCB Co, Ltd.
Takayuki Komatsu, SoftBank BB Corp.
Toru Hada, NEC Corporation
Tatsuo Kudo, Nomura Research Institute Ltd., Editor
Nat ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/openid-international-activities-updates/"><![CDATA[	&lt;p&gt;I should be doing this more often: &lt;/p&gt;
	&lt;h2&gt;Japan&lt;/h2&gt;
	&lt;p&gt;- CX discussion group has produced &lt;a href=&quot;http://lists.openid.net/pipermail/openid-specs-cx/attachments/20090731/86e7e9eb/attachment-0002.doc&quot;&gt;use cases and requirement document &lt;/a&gt; on Creative Commons License. Contributors are &lt;/p&gt;
	&lt;p&gt;Yoichi Ohnawa, NEC BIGLOBE, Ltd.&lt;br /&gt;
Takaya Tanaka, KDDI Corporation&lt;br /&gt;
Daisuke Ikeda, JCB Co, Ltd.&lt;br /&gt;
Takayuki Komatsu, SoftBank BB Corp.&lt;br /&gt;
Toru Hada, NEC Corporation&lt;br /&gt;
Tatsuo Kudo, Nomura Research Institute Ltd., Editor&lt;br /&gt;
Nat Sakimura, Nomura Research Institute, Ltd.&lt;br /&gt;
Taizo Matsuoka, Yahoo Japan Corporation&lt;br /&gt;
Naoki Koshikawa, Rakuten, Inc. &lt;/p&gt;
	&lt;p&gt;- Payment Discussion Group is starting in a few week.&lt;br /&gt;
  As an off spring of the CX Discussion Group, Payment Discussion Group&lt;br /&gt;
  is starting in Tokyo. It will first evaluate the recent change in the&lt;br /&gt;
  payment law in Japan, then subsequently disucss the applicability&lt;br /&gt;
  of OpenID and related technologies on it. &lt;/p&gt;
	&lt;p&gt;- Ministry of Internal Affairs and Communication has published a request for public comment on the coming substantiative experiment which involves OpenID and SAML interop and uses in Telecos and other entities. (Aug. 6) &lt;/p&gt;
	&lt;p&gt;- Ministry of Economy, Trade and Industry has put a tender for substantiative experiment on Government-Private Sector Authentication and Identity interoperability, which is likely to be OpenID. (Aug. 4) &lt;/p&gt;
	&lt;p&gt;- &lt;a href=&quot;http://www.nri.co.jp/news/2009/090806.html&quot;&gt;NRI&lt;/a&gt; and &lt;a href=&quot;https://www.verisign.co.jp/press/2009/pr_20090806.html&quot;&gt;Verisign&lt;/a&gt; Japan announced their intent to start high assurance authentication service based on mobile phone identification, risk based authentication, etc. over OpenID. (Aug. 6) &lt;/p&gt;
	&lt;p&gt;- NTT has &lt;a href=&quot;http://www.ntt.co.jp/news/news09/0905tfxb/ghvz090513a_23.html&quot;&gt;announced&lt;/a&gt; that it will support OpenID as &amp;#8220;NTT Single Signon Service&amp;#8221;. When the service opens, it will be the largest OpenID provider in Japan with over 70 million users. (May 12) &lt;/p&gt;
	&lt;p&gt;- Numerous miscellaneous press coverages and seminars. We stopped counting them at OIDF-J because there are too many now. OIDF-J now has 52 member companies spanning from the telcos, banks, retailers, transportation, IT, etc. &lt;/p&gt;
	&lt;h2&gt;Europe&lt;/h2&gt;
	&lt;p&gt;- In June, Robert Ott has become the Vice President of OIDE, and is the acting head of OIDE now, as Snorri is extremely busy right now to run his family&amp;#8217;s business after his father passed away late last year.  &lt;/p&gt;
	&lt;p&gt;- Jean-Noel Colin is now the representative for Belgium&lt;/p&gt;
	&lt;p&gt;- OIDE will be representing OpenID in OpenID at &lt;a href=&quot;http://www.suisse-emex.ch/de/&quot;&gt;EMEX Suisse&lt;/a&gt;. &lt;/p&gt;
	&lt;p&gt;- In autumn, Robert Ott will present OpenID at a Security Event in the IBM innovation center here in Switzerland.&lt;/p&gt;
	&lt;p&gt;- The major Dutch social website Hyves released it&amp;#8217;s support for OpenID in April. &lt;/p&gt;
	&lt;p&gt;- &amp;#8220;OpenID, put into practice&amp;#8221; held in Amsterdam, May 12, was a great success. &lt;/p&gt;
	&lt;p&gt;- &lt;a href=&quot;http://2009.cloudviews.org/site/&quot;&gt;CloudViews 2009&lt;/a&gt; held in O Porto, where Nat Sakimura was an invited speaker on identity. &lt;/p&gt;
	&lt;p&gt;- The largest Portuguese Portal now supports OpenID. &lt;/p&gt;
	&lt;p&gt;I am pretty sure I am missing many important news. Please let me know so that I can keep the list updated.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Contract Exchange 1.0 Draft 1</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/contract-exchange-10-draft-1/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=89</id>
		<modified>2009-08-10T14:48:25+09:00</modified>
		<issued>2009-08-10T14:48:25+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>CX</dc:subject>		<summary type="text/html">	Here is my first cut to the Contract Exchange 1.0 (CX) Draft. It is unfinished, and has lots of places needs text, but essence is there, I think. 
 </summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/contract-exchange-10-draft-1/"><![CDATA[	&lt;p&gt;Here is my first cut to the Contract Exchange 1.0 (CX) Draft. It is unfinished, and has lots of places needs text, but essence is there, I think. &lt;/p&gt;
	&lt;p&gt;&lt;iframe src=&quot;http://docs.google.com/View?id=dhsz4ffx_84g7wr99g3&quot; style=&quot;width:100%; height:600px; border:none;&quot;&gt;&lt;br /&gt;
&lt;/iframe&gt;
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>What is Identity?</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/what-is-identity/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=88</id>
		<modified>2009-08-03T14:03:31+09:00</modified>
		<issued>2009-08-03T14:03:31+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>		<summary type="text/html">	From this morning, there is a thread going on on Identity Commons mailing list (identity gangs) on &amp;#8220;What is Identity?&amp;#8221;. 
	The thread started off by quoting Kim Cameron&amp;#8217;s definition of Digital Identity. 
	Digital Identity: the digital representation of a set of claims made by one digital subject about itself or ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/what-is-identity/"><![CDATA[	&lt;p&gt;From this morning, there is a &lt;a href=&quot;http://lists.idcommons.net/lists/arc/community/2009-08/msg00000.html&quot;&gt;thread going on on Identity Commons mailing list (identity gangs)&lt;/a&gt; on &amp;#8220;What is Identity?&amp;#8221;. &lt;/p&gt;
	&lt;p&gt;The thread started off by quoting Kim Cameron&amp;#8217;s definition of Digital Identity. &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;Digital Identity: the digital representation of a set of claims made by one digital subject about itself or another digital subject. &lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;Then, Bob Blakly paraphrases American Heritage Dictionary in the same thread as: &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;the set of characteristics by which a thing is generally recognized or known&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;These two seems to be in a general agreement, but I would like to dig a little more because I have a bit of problem with this definition. &lt;/p&gt;
	&lt;p&gt;When we talk about a term, it is always useful to get back to its root. The below is an excerpt from my lecture at Security Expo 2009 Tokyo. &lt;/p&gt;
	&lt;p&gt;&lt;hr /&gt;&lt;/p&gt;
	&lt;p&gt;The term &amp;#8220;identity&amp;#8221; first appeared in documents around 1570. It was a term that was derived from middle age french word identit&amp;eacute;, which was in tern formed from 5th century Latin Identitatem. Identitatem was a combined word of &amp;#8220;idem et idem&amp;#8221;, where &amp;#8220;idem&amp;#8221; is &amp;#8220;same&amp;#8221;. From this, it is apparent that the central notion of &amp;#8220;identity&amp;#8221; in fact is the &amp;#8220;sameness&amp;#8221;. &lt;/p&gt;
	&lt;p&gt;This is captured in the &amp;#8220;Principle of Identity of Indiscernibles&amp;#8221; by Gottfried Wilhelm Leibniz, (1646 ? 1716) . &lt;/p&gt;
	&lt;p&gt;Subject x and y are identical if any predicate possessed by x is also possessed by y and vice versa. &lt;/p&gt;
	&lt;p&gt;i.e., &lt;/p&gt;
	&lt;p&gt;(1) &lt;img src=&quot;http://upload.wikimedia.org/math/b/e/d/bed21ed35fec0991e709326f44f0c8e9.png&quot;&gt;&lt;/p&gt;
	&lt;p&gt;This is rather controversial. &lt;/p&gt;
	&lt;p&gt;Clearly, The indiscernibility of identicals: &lt;/p&gt;
	&lt;p&gt;(2) &lt;img src=&quot;http://upload.wikimedia.org/math/3/1/c/31c438f18239007ecbe9d527c768a5fe.png&quot;&gt;&lt;/p&gt;
	&lt;p&gt;holds, but not the identity of indiscernible. &lt;/p&gt;
	&lt;p&gt;To illustrate it, I have depicted the relationship between Subject and identity (partial identity) in the following figure.&lt;/p&gt;
	&lt;p&gt;&lt;a style=&quot;float: left; margin: 0 10px 0 0;&quot; href=&quot;http://www.sakimura.org/en/modules/wordpress/attach/subject-identity-rel.jpg&quot;&gt;&lt;img src=&quot;http://www.sakimura.org/en/modules/wordpress/attach/thumb-subject-identity-rel.jpg&quot; alt=&quot;Subject-Identity Relationship&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;In this figure, I have represented Subject as a molecular structure. It is there, but we cannot observe it directly because whenever we observe, it is merely a projection of it onto the cognitive surface or hyper-plane. Unfortunately, this mapping/projection is not one-to-one. Different Subject can map onto the same thing on a cognitive surface/hyper-plane, i.e., &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;Two objects having same identity may NOT be identical.
&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;This sound contradictory. &lt;/p&gt;
	&lt;p&gt;From (1) and (2), it is clear that to have the proposition&lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;Two objects having same identity is identical
&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;hold, it has to be Subject=Identity. &lt;/p&gt;
	&lt;p&gt;Of course, &lt;/p&gt;
	&lt;blockquote&gt;&lt;p&gt;Two objects having same partial identity may NOT be identical.
&lt;/p&gt;&lt;/blockquote&gt;
	&lt;p&gt;We sometimes call this &amp;#8220;Partial Identity&amp;#8221; a &amp;#8220;Persona&amp;#8221;. &lt;/p&gt;
	&lt;p&gt;The problem of American Heritage definition probably is that it is supposing there is a general cognitive plane (generally recognaized). There is no such thing in practice, unfortunately.&lt;/p&gt;
	&lt;p&gt;&lt;strong&gt;References:&lt;/strong&gt;&lt;br /&gt;
Definition of identity?, http://lists.idcommons.net/lists/arc/community/2009-08/msg00000.html&lt;br /&gt;
Identity of Indiscernibles, http://en.wikipedia.org/wiki/Identity_of_indiscernibles
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>Discussion Note on Contract Exchange</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/discussion-note-on-contract-exchange/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=87</id>
		<modified>2009-07-30T21:00:15+09:00</modified>
		<issued>2009-07-30T21:00:15+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>OpenID</dc:subject>
	<dc:subject>XRD</dc:subject>
	<dc:subject>CX</dc:subject>		<summary type="text/html">	Here is the discussion note that I wrote for Contract Exchange. 
	http://openid.net/pipermail/specs-cx/attachments/20090730/8d9862f8/attachment-0001.pdf
	Hopefully, the concept is quite clear and it acts as the level setting ground for the participants at specs-cx.

 </summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/discussion-note-on-contract-exchange/"><![CDATA[	&lt;p&gt;Here is the discussion note that I wrote for Contract Exchange. &lt;/p&gt;
	&lt;p&gt;&lt;a href=&quot;http://openid.net/pipermail/specs-cx/attachments/20090730/8d9862f8/attachment-0001.pdf&quot;&gt;http://openid.net/pipermail/specs-cx/attachments/20090730/8d9862f8/attachment-0001.pdf&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Hopefully, the concept is quite clear and it acts as the level setting ground for the participants at specs-cx.
&lt;/p&gt;
]]></content>
	</entry>
		<entry>
	  	<author>
			<name>Nat</name>
		</author>
		<title>XRD as of July 22.</title>
		<link rel="alternate" type="text/html" href="http://www.sakimura.org/en/modules/wordpress/xrd-as-of-july-22/" />
		<id>http://www.sakimura.org/en/modules/wordpress/index.php?p=86</id>
		<modified>2009-07-23T18:25:00+09:00</modified>
		<issued>2009-07-23T18:25:00+09:00</issued>
		
	<dc:subject>Digital Identity</dc:subject>
	<dc:subject>XRD</dc:subject>		<summary type="text/html">	According to the current XRI TC discussion, it is looking like this. 
	&amp;lt;xrd&amp;gt;
    &amp;lt;Subject set=&quot;beginswith&amp;#8221;&amp;gt;&amp;#8230;&amp;lt;/Subject&amp;gt;
    &amp;lt;Alias&amp;gt;&amp;#8230;&amp;lt;/Alias&amp;gt;
    &amp;lt;KeyDescriptor use=&quot;*&amp;#8221;&amp;gt;
        &amp;lt;ds:KeyInfo&amp;gt;
           &amp;#8230;
     ...</summary>
		<content type="text/html" mode="escaped" xml:base="http://www.sakimura.org/en/modules/wordpress/xrd-as-of-july-22/"><![CDATA[	&lt;p&gt;According to the current XRI TC discussion, it is looking like this. &lt;/p&gt;
	&lt;pre style=&quot;border:1px dashed grey;background-color:#eeeeee;font-size:12px;&quot;&gt;
&amp;lt;xrd&amp;gt;
    &amp;lt;Subject set=&quot;beginswith&quot;&amp;gt;...&amp;lt;/Subject&amp;gt;
    &amp;lt;Alias&amp;gt;...&amp;lt;/Alias&amp;gt;
    &amp;lt;KeyDescriptor use=&quot;*&quot;&amp;gt;
        &amp;lt;ds:KeyInfo&amp;gt;
           ...
        &amp;lt;/ds:KeyInfo&amp;gt;
    &amp;lt;/KeyDescriptor&amp;gt;
    &amp;lt;ds:Signature&amp;gt;
        &amp;lt;ds:KeyInfo&amp;gt;
           ...
        &amp;lt;/ds:KeyInfo&amp;gt;
    &amp;lt;/ds:Signature&amp;gt;
    &amp;lt;link&amp;gt;
        &amp;lt;rel&amp;gt;...&amp;lt;/rel&amp;gt;
        &amp;lt;uri&amp;gt;...&amp;lt;/uri&amp;gt;
        &amp;lt;Subject&amp;gt;...&amp;lt;/Subject&amp;gt;
        &amp;lt;ds:KeyInfo&amp;gt;
           ...
        &amp;lt;/ds:KeyInfo&amp;gt;
    &amp;lt;/link&amp;gt;
&amp;lt;/xrd&amp;gt;
&lt;/pre&gt;
	&lt;h2&gt;Description&lt;/h2&gt;
	&lt;p&gt;xrd/Subject : Type=URI. Subject Identifier or portion of Subject Identifier. CanonicalID in XRDS. &lt;/p&gt;
	&lt;p&gt;xrd/Subject/@set : (Option) Can specify &amp;#8220;beginswith&amp;#8221; to signify that the URI is only partial and beginswith the string. &lt;/p&gt;
	&lt;p&gt;xrd/Alias: Alias URI for the Subject. &lt;/p&gt;
	&lt;p&gt;xrd/KeyDescriptor: Wrapper element for ds:KeyInfo for the Subject.&lt;/p&gt;
	&lt;p&gt;xrd/KeyDescriptor/@use : Specify the usage of the KeyInfo, e.g., Signature, Encription, etc.&lt;/p&gt;
	&lt;p&gt;xrd/ds:Signature: Expresses the Signatory and the Signature over this XRD. &lt;/p&gt;
	&lt;p&gt;xrd/link: Shows the relationship that this Subject perceives against other subject. &lt;/p&gt;
	&lt;p&gt;xrd/link/Subjct: the Subject of the linked XRD.&lt;br /&gt;
xrd/link/ds:KeyInfo: has the public key of the Signatory of the Subject of the linked XRD. The linked XRD will be signed by the private key that corresponds to this public key, users can verify that the link is actually an inteded one.&lt;/p&gt;
	&lt;h2&gt;Discussion Points&lt;/h2&gt;
	&lt;ol&gt;
	&lt;li&gt;Do we really need KeyDescriptor? &lt;/li&gt;
	&lt;li&gt;Do we really need xrd/link/Subject? Would not xrd/link/uri suffice? &lt;/li&gt;
	&lt;/ol&gt;
]]></content>
	</entry>
	</feed>
