As of 2010/4/29, the Japanese edition of Wikipedia describes OpenID as follows:

“OpenID is a standard for an authentication system that can be used regardless of the website, as well as the identifier used in that system.
With one OpenID, users can access multiple websites that support OpenID systems.” (Source: Japanese Wikipedia/OpenID)

Personally, I think that is not quite right.

The ID in OpenID stands for Identity.

Therefore, to understand it, you must first understand what Identity, or Digital Identity, is.

This apparently turns out to be surprisingly difficult for ordinary people. The problem is probably the way we use the terminology.

We specialists explain Digital Identity something like this:

An Entity/Subject means a person, company, piece of software, machine, resource being accessed, transaction, or the like.
An Identity is the collection of various attributes, preferences, and traits associated with an Entity/Subject.
An attribute is acquired information that describes the subject. Examples include medical history, purchase history, bank balance, name, student ID number, and driver’s license number. Because some of these arise through a relationship with another subject, they are also often separated out and called a “relationship.”
Attributes often change.
A preference is something like a favorite food or a preference for a window seat.
A trait means a characteristic innate to the individual, such as sex or date of birth. In most cases, it either does not change throughout the individual’s existence or changes only very slowly.
These may also be referred to collectively as “attributes.”*1
A Digital Identity is this “Identity” transferred into the digital realm.
An Internet Identity is a Digital Identity that exists on the Internet.
OpenID is an open standard for a framework that implements such a Digital Identity.

Yes, I imagine many people’s heads are spinning by now.

To discuss “ID” properly, you really need to understand at least this much. Still, I would like an intuitive, one-sentence explanation that many people can understand.

So I tried saying the following to several people who seemed to have nothing to do with this kind of technology:

Do you know Nintendo’s Wii?
When you play games on it, you create a Mii, right? It is your avatar.
You make its face resemble yours, give it a name, and the Mii holds all your game records and so forth.
The Mii is also the one that goes off to play the games. That is a Digital Identity.
However, a Mii can live only inside the Wii.
To enable it to live on the wider Internet, it must be “standardized” and its specifications made open so that many machines can understand how it is constructed. OpenID is one standard for such Digital Identities.
In other words, to receive a service from a website, you send your avatar, the OpenID (the equivalent of a Mii on the Wii), to that service—for example, to subscribe to a magazine.

For a magazine subscription, the magazine website will probably provide something like a pass. The OpenID can hold that pass. In that case, when the OpenID visits the site, it presents the pass to the site.*2

Alternatively, the site may keep the pass for you at its service counter.
In that case, when the OpenID shows its identification at the site’s counter, the counter hands over the pass, allowing it to enter and use the site. When it leaves, it returns the pass to the counter.*3

Because an OpenID is your avatar, you can entrust it with various things. These might include your service agreements with websites. They might also include your purchase history.

Those people told me, “Yes, I understand,” but…
Did that make it a little easier to understand?

I welcome suggestions for ways to make it even clearer.

*1 Adapted and supplemented based on Phil Windley’s “Digital Identity”
*2 Example of a Bearer Token
*3 Example of a Session Cookie

Related posts