Home > SOA Tips > Guest Commentary > The Concordia Project and XML security interoperability
SOA Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

GUEST COMMENTARY

The Concordia Project and XML security interoperability


Ed Tittel
06.20.2007
Rating: -3.00- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Those already familiar with XML security standards, especially those that relate to identity presentation and management, also know that this is a fragmented landscape, populated with multiple, formerly unrelated and not always compatible, schemes. Simply put, the Concordia Project seeks to make some order from this chaos, and to define mechanisms whereby various competing or incompatible identity schemes can seek what the groups goals describe as "harmonization and interoperability of identity specifications and protocols."

This already sounds pretty good, but when you look at the group's purpose, principles, and charter, you find specific mention of the following existing or emerging standards:

  • CardSpace, Microsoft's .NET initiative for identity presentation and management.
  • Liberty Alliance Project, an open initiative that aims to establish a similarly open standard for federated network identity.
  • OpenID, an open and decentralized identity system designed "not to crumble if one company turns evil or goes out of business."
  • openLiberty.org, an organization "established to provide easy access to tools and information to jumpstart the development of more secure and privacy-respecting identity-based applications based on Liberty Federation and Liberty Web Services standards."
  • Open Source, a general movement for creating open, royalty-free, publicly accessible information processing standards and software (SourceForge currently plays host to over 1100 digital identity related projects, of which Open Single Sign-On or Open SSO is a leading example).
  • SAML, or the Security Assertion Mark-up Language, initiative underway at OASIS, seeks to define and maintain a standard, XML-based framework for creating and exchanging security information, including identity, betw

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Guest Commentary
    Getting a grip on JavaFX 1.2 for Rich Internet Applications (RIA)
    On the road to SOA – Part 1, Boubez on early insights
    On the road to SOA – Part 2, Governance is fundamental
    SpringSource approach to adding enterprise class management and deployment features to Tomcat
    SOA Pattern of the Week (#6): Canonical Schema
    Legacy: Can't Live With It, Can't Live Without It
    Review of protocols for cloud services - Part 1
    SOA and TOGAF: A Good Fit?
    Using atomicity to gain SOA granularity
    Too Many Servers: A Case for Enterprise Architecture and TOGAF 9

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


    een online partners.

  • WS-Federation (Web Services Federation Language), a member of the Web Services family of XML specifications, is spearheaded by IBM and seeks to define "mechanisms to allow different security realms to federate by allowing and brokering trust of identities, attributes [and] authentication between participating Web services."
  • This working group, organized on April 24, 2007, wants to unite these and other standards and to help foster development of one ubiquitous, interoperable, privacy-respecting layer that all developers and Web site operators can share. Their thinking is to drive the cost of development down, lower the barriers for secure identity establishment and management to help assure successful development, promote more (and more usable) commercial and service offerings, and in general cut the ever-so-tangled knot of possible solutions that surround simplified identity management nowadays.

    What can we expect from these guys? It's still to early to tell, but with XML heavyweight Eve Maler at the helm of the organization and a wealth of already published use cases there could actually be some relief in sight for those grappling with (or holding off from committing to) identity establishment and management problems and issues. Count on us to keep an eye on this effort and to report further as more tangible developments and tools emerge.

    About the author

    Ed Tittel is a full-time writer and trainer whose interests include XML and development topics, along with IT Certification and information security topics. Among his many XML projects are XML For Dummies, 4th edition, (Wylie, 2005) and the Shaum's Easy Outline of XML (McGraw-Hill, 2004). E-mail Ed at etittel@techtarget.com with comments, questions or suggested topics or tools for review.


    Rate this Tip
    To rate tips, you must be a member of SearchSOA.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    SOA Trends and Strategy - SOA Education, SOA Development, SOA Implementations
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts