I will give an invited talk at SCIS 2013. Setting aside the fundamental question of whether someone like me is suitable…. The title is:
Abstract: As social networking services such as Twitter, Facebook, and Google+ become widespread, identity federation is becoming closely connected to our lives. Turning to enterprise use, the same phenomenon can be seen as cloud adoption advances. At the same time, security and privacy considerations are indispensable when implementing these systems. Through an introduction to social trends and an organization of security and privacy problems and issues, this talk surveys the kinds of research needed to have an impact on the real world.
I think a perspective on how to bring technology into widespread use will probably be expected. I initially envisioned the following structure, but I expect to reorganize it considerably. Perhaps they would appreciate a thorough account of experiences at the OpenID Foundation and similar matters….
1. Introduction to social trends ・Password problems and the challenges of advanced authentication ・Expanding information federation and trust frameworks (U.S. NSTIC, U.K. IDAP) ・Mobile and cloud 2. Organization of problems and issues ・Security challenges ・Users as the weakest link ・Routine authentication that does not burden users, and recognition of abnormal situations ・Advances in cloud and mobile, and the limits of perimeter defense ・From Perimeter Control to Identity Based Control ・Quality challenges ・Quality of identity proofing and authentication ・Quality of attributes ・Scalability challenges ・Distributed, dynamic authorization—attribute-based access control ・Privacy challenges ・“Meaningless consent” and “unbalanced contracts” ・How to keep data use within the scope of consent ・Implementation of the right to be forgotten ・The problem of an attribute server learning the destination to which attributes are provided ・The problem of an IdP/Proxy learning too much information 3. What is required as research ・“Meaningful consent”—explicit and implicit consent, and standard labels for information sharing ・Making users aware of non-routine situations ・Registration and authorization of distributed attribute servers with distributed authorization servers ・Other research topics addressing the issues above
Related posts

I Will Appear on the Okinawa Open Days Panel “Current and Future OSS Initiatives in Economic Security”
It is already the day of the event—in fact, I am writing this now (12/4 9:45) at my desk while preparing for the panel—but I will…

The “DS-511 Guidelines for Handling Digital Identity in Identity Verification for Administrative Procedures, etc.” Have Been Published
After 3 years of development, the Digital Identity Guidelines, to which I had the privilege of contributing as an expert (Expert Meeting on the Revision of…

Age Verification: The UK Online Safety Act Is Being Toyed With in All Kinds of Ways—Bypassing It With VPNs and Evading Biometrics With Death Stranding
What Is the UK's Online Safety Act? The UK's Online Safety Act formally became law after receiving Royal Assent on October 26, 2023, and came into…
