I will give an invited talk at SCIS 2013. Setting aside the fundamental question of whether someone like me is suitable…. The title is:

Abstract: As social networking services such as Twitter, Facebook, and Google+ become widespread, identity federation is becoming closely connected to our lives. Turning to enterprise use, the same phenomenon can be seen as cloud adoption advances. At the same time, security and privacy considerations are indispensable when implementing these systems. Through an introduction to social trends and an organization of security and privacy problems and issues, this talk surveys the kinds of research needed to have an impact on the real world.

I think a perspective on how to bring technology into widespread use will probably be expected. I initially envisioned the following structure, but I expect to reorganize it considerably. Perhaps they would appreciate a thorough account of experiences at the OpenID Foundation and similar matters….

1. Introduction to social trends
  ・Password problems and the challenges of advanced authentication
  ・Expanding information federation and trust frameworks (U.S. NSTIC, U.K. IDAP)
  ・Mobile and cloud

2. Organization of problems and issues
  ・Security challenges
   ・Users as the weakest link
    ・Routine authentication that does not burden users, and recognition of abnormal situations
   ・Advances in cloud and mobile, and the limits of perimeter defense
    ・From Perimeter Control to Identity Based Control
  ・Quality challenges
   ・Quality of identity proofing and authentication
   ・Quality of attributes
  ・Scalability challenges
   ・Distributed, dynamic authorization—attribute-based access control
  ・Privacy challenges
   ・“Meaningless consent” and “unbalanced contracts”
   ・How to keep data use within the scope of consent
   ・Implementation of the right to be forgotten
   ・The problem of an attribute server learning the destination to which attributes are provided
   ・The problem of an IdP/Proxy learning too much information

3. What is required as research
  ・“Meaningful consent”—explicit and implicit consent, and standard labels for information sharing
  ・Making users aware of non-routine situations
  ・Registration and authorization of distributed attribute servers with distributed authorization servers
  ・Other research topics addressing the issues above

Related posts