Here's my take on this thread:
Based on my own knowledge of technical standards that
currently exist - PKI, SAML, XACML, SOAP, etc. - all the
components for creating this framework exist. However,
the question is - how does all this come together to solve
the specific business problem identified here?
Interestingly, the problem I'm witnessing is no different from
the business problem I ran into 18 months ago before
StrongKey (the open-source Symmetric Key Management
System software, which is the basis for SKSML in EKMI TC)
was created. Every single component technology to solve
the (enterprise-wide symmetric key-management) problem
existed (except for the thin layer that SKSML represents),
but nobody had quite solved it completely. With the
creation of StrongKey, almost everything became crystal
clear - what part needed to become a standard? What part
should be left to vendors for innovation? How will ISVs and
corporate applications use the standard? Etc.
It appears to me that this problem needs a similar solution.
Someone has to attack the business problem using the
identified component technologies and standards and
create an open-source solution that just works! Once you
have a working solution, then just as in EKMI, everything
will start becoming clear, as someone will have leaped
over the fog that's slowing these standards from taking off.
If something is missing (as was SKSML), it becomes
patently clear what's missing and what that missing link
must look like to solve the problem.
I'm not sure from David's response, how much of the core
service requirements and designs are being coded into a
software product, but I would strongly encourage it. With a
working implementation of the end-to-end architecture, it
allows people to focus much more sharply on how to
address the problem.
Arshad Noor
StrongAuth, Inc.