Featured Interview with the Province of British Columbia


Last December ICF Executive Director Drummond Reed spent a day in Victoria, B.C. with the identity management team in the Office of the CIO for the Province of British Columbia, including Ian Bailey, the Executive Director of Architecture and Standards, Charmaine Lowe, Director of Information Standards, and Patricia Wiebe, Senior Identity Architect. The following interview is based on many of the topics they discussed.

Q: Let’s start with the big picture: when did your office first begin to focus on identity management?

A: Back in 1996 we determined that identity management was going to be key to developing a shared services approach for the delivery of IM/IT services for government and started a program to develop a corporate identity management Technology was a real barrier for us at that point, but with the release of Windows Active Directory in 2000 we were able to consolidate most of our directories into a single centralized domain for government workers.  Also at that time we were building our first version of an authentication service to support government’s interactions with businesses and citizens, and in 2002 we started our BCeID identity provider service.  We learned a lot from those first efforts, particularly that directory centric solutions were not going to work in the long term.

Q: So you’ve been at this a long time. Overall, what are the goals of your IdM program, i.e., what’s your vision for what IdM can do for the BC government and the people of the province?

A:   Our goals for our IdM program are to enable the delivery of high value electronic services to our citizens and businesses and to enable information sharing among the thousands of public and private sector organizations that help to deliver public services, such as Health care, Justice, Education, Social services, and the natural resources sector.  We believe that a federated, user-centric, claims approach will help us reach these goals.

Q: When did you first start to focus on Information Cards as part of the solution?

A: We had learned from our work with our enterprise directory and our BCeID service that this directory centric approach was not going to scale and wouldn’t meet our or our citizens’ expectations of privacy protection.  We couldn’t expect everything to be connected to our directories using LDAP or proprietary SSO technology.  In 2006 we engaged our major software suppliers and the lead architects from our larger public sector organizations in the development of an architecture that met our non-functional requirements around security, scalability, privacy and user experience and our functional requirements relative to the goals our IDM program (services to citizens and information sharing).  In this forum we developed a set of requirements, an architecture that met these requirements, and an analysis of what technologies or emerging technologies might be used in implementing the architecture.  Information cards and the associated protocols were the best fit to  the requirements and architecture.

Q: What was it about Information Cards and IMI (Identity Metasystem Interoperability, the technical protocol) that attracted you?

A: Besides the fit to requirements and architecture noted above, the real world analogy of cards and the card selector to our wallets, the scalability promise with loose coupling, phishing prevention, and its inherent home realm discovery service.

Q: What’s been your experience with Information Cards and IMI so far?

A:  So far we have only used Information Cards and IMI in a few pilots and only internally or with a select few partners – but not citizens yet, so our experience is limited.  Overall I think it’s quite frustrating that we and the industry haven’t moved faster on this....the 10 years we thought it would take is coming up pretty quickly.. 2016.

Q: What products do you use in your deployments?

A: So far we have being using Microsoft’s “Geneva” Server (now called Active Directory Federation Server (ADFS) 2.0), “Geneva” Framework (now called Windows Identity Foundation) and CardSpace through the Microsoft “Geneva” TAP program.  We have enterprise-wide usage of the CA SiteMinder web SSO product, and plan to integrate Information Cards with that.

Q: If the OASIS IMI Technical Committee could grant you just three wishes for IMI, what would they be?

A: We’d like a mechanism to deal with structured claims like address, which has many parts.  Also, the ability to use SAML 2 tokens in IMI, which we hear is in the works right now.  Finally we’d like to encourage work on a web services authentication profile, so we have an Identity Metasystem that can support multi-tiered environments – we think that may require IMI to have support for WS-Trust request security token collection.

Q: You have published some outstanding educational materials online. What are some of the ones you would particularly recommend to ICF members and others reading this article?

A: The best one is the Education Module found here: http://www.cio.gov.bc.ca/cio/idim/index.page.  It is a Flash-style interactive presentation that explains where we’re going and describes our user-centric claims-based architecture.  The IDM forum documents referred to earlier are found here: http://www.cio.gov.bc.ca/cio/idim/idm_forum.page.

Q: What advice do you have for other governments and government agencies who are looking at adopting federated identity management solutions?

A:  Definitely adopt the open standards approach, do some technology proof of concepts and pilots to develop an implementation strategy, and start working on an identity assurance framework and associated standards.

Q: Tell me about your experience with identity assurance what role do you see it playing in BC’s identity management infrastructure?

A: Identity Assurance is foundational for identity federation, as it establishes trust between the organizations, but it is a real challenge given the variability in each organization’s processes, technologies, and policies.   We have made progress in developing our framework and standards, but it remains to be seen how this will play out as we federate amongst our organizations.   We also think that by implementing the identity assurance standards we will start to do a much better job of information classification and risk management as we design and develop new services.

Q: What’s your view of the approach that the U.S. government, and in particular the ICAM Subcommittee of the U.S. Federal CIO Council, is taking with their Open Identity Solutions for Open Government initiative?

A: We really like their approach, but we do have some differences in our thinking.  We think our holistic approach for both citizen services and information sharing amongst public bodies sets us apart from most other approaches. 

Q: Do you think open identity solutions like Information Cards are something that BC citizens will embrace?

A: I think it depends on what services are available for them to use – if there are some compelling high value services for them AND the user experience is familiar then yes I think so.  But, there are some real barriers to this given the high assurance requirements for these high value services, such as identity proofing and strong authentication technology.  If we all had a smart card in our wallets that we could use as easily as we use our drivers license in the real world then we could deploy these services now.

Q: I understand you will be participating in the OASIS IMI Interop at RSA 2010 in San Francisco (March 2-4)? What are your goals there?

A: Yes, we are planning to contribute an identity provider to the interop event.  This helps us inform our thinking to develop our standards and solutions now.  Also we are excited to help others to see how this technology can be applied to help deliver high value e-government services to their citizens and businesses.  We can’t do this “Identity Metasystem model” alone.  We need to figure out how to interoperate across diverse organizations and influence how this needs to be part of the Internet.

Q: Any other final thoughts that you’d like to share with ICF members and the open identity community?

A: We encourage others to consider the holistic approach that we have taken to apply this architecture to both internal and external users and services.

Comments

Really a must read

Its really a must read of every one. It was great to know his views and how he will manage all the things. premium magento templates

In 2009, British Columbia had

In 2009, British Columbia had an estimated population of 4,419,974 (about two million of whom were in Metro Vancouver).

WoW Accounts

bookmarked

Very informative and trustworthy blog. Please keep updating with great posts like this one. I have bookmarked your site and am about to email it to a few friends of mine that I know would enjoy reading live nude webcams

Great article you wrote,

Great article you wrote, really inspired me! I wish I can be like you :)

 

team building phoenix

Very good.

I have to agree

Great Artcleand i have to agree Edinburgh Airport Parking Edinbugh Airport Parking

Identity is important so

Identity is important so anyone can identify others immediately. Faked IDs are the real issue where in the age of information like this, identification can be taken from anywhere. she's out of my league download

It leads to something bigger.

It leads to something bigger. We'll never know until we get the right time to evaluate. Countertop Racks

Well, you can go find other

Well, you can go find other job mate. There must be something you enjoy doing better. best acne treatment

I always want to be a news

I always want to be a news reporter, lol.. That's a dream only. I am not really born for that. T shirts

How is the interview going

How is the interview going on? Must be great to do the job.. Life Insurance KB - A Knowledgebase of Information

They will finally see the

They will finally see the advantages of following the rules. Good luck for theparticipating people. Seattle Divorce Attorneys

Thank you. I like the report.

Thank you. I like the report. I actually need it to complete my current workout. Swinger Dictionary

I wonder if this can be a way

I wonder if this can be a way out for the obsolete policies. We have been waiting too long. Magic Tricks

I think I could agree with

I think I could agree with him. The issue is not an easy thing to be taken down, but we have to believe. These days strangers are superstars. Personal Information Management

I approve of this as

I approve of this as identification is one of the most rated issues in history. People know each other well only by their names, but not with their background. Hard Drive Data Recovery

I must say, this is a well

I must say, this is a well done interview. Looks like the the researcher did a lot of efforts to pull the questions. Good job. airbrush tanning solution

This is a good interview. I

This is a good interview. I do hope that this project goes live soon, this will really help with the identification issues. Led Bildschirm

ff

Normal 0 7.8 磅 0 2 false false false EN-US ZH-CN X-NONE  

iPad Video Converter is then designed for iPad fans to convert videos to iPad. This special ipad video converter can convert all video formats to iPad compatible formats.

ipad converter

 

Identity is important so

Identity is important so anyone can identify others immediately. Faked IDs are the real issue where in the age of information like this, identification can be taken from anywhere. Arcade Games

The interview is good and

The interview is good and well put. I hope they can do something about the issue. herbal highs

France, especially Paris, is

France, especially Paris, is one of the wonders of this world. Many people love this country and their culture, many people come and stay at the country, only few just don't get it why they have to love something out the borders. UK Classified Ads

I will not write the thing,

I will not write the thing, therefore can only everywhere have a look, discovered that you wrote have been too good, I very unusual like waste bin|Actuated valve|globe valve|gate valve

I guess it's about computer

I guess it's about computer or technology. They have a lot of stuff written on the site. Quite interesting. PHP Programmer

I believe they will find the

I believe they will find the time worth it. It is just rational to expect more upcoming ideas in the future. iron gates

Thank you. It is just amazing

Thank you. It is just amazing how they handle the issues and come back with more statements and also solutions. Jolly Technologies

Thanks for posting this

Thanks for posting this interview. Its good to see that there are those who see the importance of identity authentication especially over the web. Spionage Kamera

[...]Hey I love your style I

[...]Hey I love your style I will subscribe for your feed please keep posting! logo design - logo designs [..]

This is a really good

This is a really good interview. I just hope that you'll be able to ensure the accuracy of the authentication process. Fettverbrennungsofen

Its easy to fake IDs and

Its easy to fake IDs and other authentication papers for the purpose of Identity Thefts, especially over the internet! You can see numerous ads for virtual credit cards mainly for the purpose of verifying paypal & ebay accounts and even ads for those who's had their paypal accounts frozen.Thanks

 

Christian Dating

great info

Good luck for the media

Good luck for the media interview. It is time to reveal out more exciting stories to public. Ofen Kamine

What ws this interview about?

What ws this interview about? I think they will be delivering more results in the future. Just see the trials… San Francisco Plastic Surgery

Identity thefts

Now a days for the purpose of Identity thefts, its easy to fake IDs and other authentication papers , especially over the internet! You can see numerous ads for virtual credit cards mainly for the purpose of verifying paypal & ebay accounts and even ads for those who's had their paypal accounts frozen ...! Dubai Golf Courses

Time will prove out the

Time will prove out the effectiveness. Meanwhile we should expect more progressive report from the people. Good luck! prostatitis

It works fast enough that we

It works fast enough that we do not have much to complain for. They are making it perfect this time. Mining Companies

How's the interview going on

How's the interview going on in result? It has been a year, you know.. Yet we haven't seen any remarkable achievement. make your own beats

I like the ideas too. The

I like the ideas too. The more you realize the hidden opportunities, the more you will be able to act. Bristol Airport Parking

Very nice

I am from a site <a href="http://www.stagcleaningservices.co.uk/hertfordshire/domestic-cleaning/">Cleaning hertfordshire</a>. I just liked your article very much.

thanks you very much for your information

good article for your sharing thank you........................

<a href="http://poptropicagamess.blogspot.com/">Poptropica</a>

Love it....

I love reading interviews. This was a brilliant entry in my bookmarks.

Thanks

 

<a href="http://www.redbrickpm.co.uk/">Property management</a>

This is a very interesting

This is a very interesting interview. Their idea of Information Cards is very good. Schnell Abnehmen Tipps

borsamagazin.com

Thanks and

Thanks and GREETINGS FROM GERMANY FROM Tom private Krankenversicherung

Intimately, the post is in

Intimately, the post is in reality the sweetest on this noteworthy topic. I agree with your conclusions and will thirstily look forward to your incoming updates. Saying thanks will not just be sufficient, for the phenomenal lucidity in your writing. I will immediately grab your rss feed to stay abreast of any updates. Authentic work and much success in your business efforts News | Stuffs | Reviews

Sometimes server is down

Sometimes server is down because of they are doing maintenance for it, so they stop it for a while. But I think they should not turned it off if it's possible. Pet Memorials that Contain Ashes of Your Pet

location automobile

Happy to see your blog as it is just what I’ve looking for and excited to read all the posts. I am looking forward to another great article from you. After skimming through your website

location automobile

thanks ypu for the artice

thanks ypu for the artice .... you have excellent writing skills. I wil try to follow your tips for my

Search Engine Optimization site

Very usefull , thanks for the

Very usefull , thanks for the tips , holiday villa pool

Information Card Foundation Copyright 2009 ©