No. 1 Story

ACCC clears Optus to scrap HFC network and use NBN instead

The ACCC has cleared, provisionally, the proposed deal between Optus and NBN Co under which Optus is to be paid around $800m to shut down its HFC network and transfer customers onto the NBN. read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
Need a new One with 4G speeds at an XL size, while still being...
Fancy a 4G Windows Phone? Your wait may be over next Tuesday when Telstra...

The Concepts of Identity and Trust in Modern Society

Your IT - Home IT

Identity is such a difficult concept to grasp, particularly for our political leaders. They seek the magic device that will unambiguously distinguish "terrorist" from "tourist" or "refugee" from "freeloader."  Unfortunately, what they're seeking is some measure of trust - "knowing their identity, can I trust the motives of this person?"

More importantly, in the business world for example, we generally don’t have the ability to drag an individual up to a security officer and insist they prove who they are – we need to have some suitable means to by-pass this 'physicality of identity.'

This means that the definition of the term 'identity' needs to be relaxed – I'll explain more about why this is in a moment, but first it needs to be made very clear that my ATM card is an identity, so is my login-name at work.

The general process of granting a person permission to perform some restricted task (let's say I wish to edit a document on the corporate LAN) involves three distinct (but loosely related) concepts: Identity, Authentication and Authorisation.

These three concepts are each linked to their own specific question:

Identity: Who are you?

Authentication: Can you prove it?

Authorisation: OK, what are you permitted to do?

To edit the corporate document, my identity is my login-name; my authentication is my password and my authorisation is either 'yes' I can edit or 'no' I cannot (amongst a range of other permissions, of course).

This process of Identity / Authentication relies on the user of the identity confirming their ability or permission to assert that identity. Nothing more, nothing less, and thus the 'strength' and 'value' of the transaction will therefore impose limits on how well-defined the identity should be.

Two important points arise here: Firstly, is my login-name me?  Of course not (but it is definitely an identity under my control).

Secondly, am I limited to a single identity (even within this office context)?  Definitely not.  In fact, if you think about it, many of us are encouraged to have more than one - for instance the LAN administrator will have identities for 'administrative' work and for 'normal' work.  This also suggests that identities may be shared or transferrable.