Windows Cardspace: An early attempt at identity management
![]()
One of the most renown attempts to create an identity management system was Windows Cardspace. An excerpt from its whitepaper “the identity metasystem is an interoperable architecture for digital identity that assumes people will have several digital identities based on multiple underlying technologies, implementations, and providers. It lets users select from among a portfolio of their digital identities and use them at Internet services of their choice”. The goal of Cardspace was it to be the go-to solution for people to manage their digital identities. Through an agnostic protocol, that allowed for a secure communication through other technologies (such as LDAP, X.509, SAML and Kerberos), the identity owner could easily access the service provider with a predefined identity and thus be in control of what information gets shared.
The project was lead by some brilliant people, including Kim Cameron who has done some amazing work in the digital identity space and I encourage you all to check out his Laws of Identity. But it ultimately failed and is supposedly currently being replaced by UProve, a technology built by Stevan Brands who had influence in the development of DigiCash and Zero Knowledge Systems. The reason why Cardspace failed (apart from the neglect it received from Microsoft itself) ultimately comes down to mistrust and the different interests. Cardspace was adopted by a fair number of people that used it actively in the realm of Microsoft’s ecosystem (MSN, Hotmail etc.), but in the WWW outside of Microsoft it was rarely used. This is due to low adoption from service providers who didn’t see the clear benefits offered to them and perhaps even mistrusted the protocol and Microsoft itself. Additionally, Microsoft perceived Cardspace as a project to strengthen its product sales through a unique identification system that is part of its huge ecosystem. This made it apparent that Microsoft did not care so much for bettering the online experience of every user, but only for those who paid Microsoft for software and other products.
Lets describe some of the interesting details of it, since any future attempt at creating an identity metasystem can learn a lot from Windows Cardspace.
The Components
The metasystem is made up of five key components which we will describe briefly here:
Claims-based identities
Similarly to how JSON Web Tokens (JWT) are setup, the digital identities consist of various “claims” about your identity. You for example claim to be 2 meter tall, with no one to certify for that, it is hard to trust that claim. Which is why certified claims play an important role, where a third party asserts that a specific claim is valid.
Negotation
One of the most interesting parts of Windows Cardspace is its ability to negotiate between participants in the ecosystem and determine the right protocol to choose from in order to enable the participants to connect with each other. This is a huge step forward to creating an interoperable and agnostic identity layer that can be easily adopted by all service providers. As described in the white paper “if one party understands SAML and X.509 claims, and another understands Kerberos and X.509 claims, the parties negotiate and decide to use X.509 claims with one another.”
Encapsulating Protocol
Since the goal of Windows Cardspace is it to be completely technology-neutral (agnostic) and create an environment where service providers and identity holders can easily communicate with each other, the protocol needs to be able to exchange information and claims about identities between the parties without any interferences. This goes back to the negotiation process between technologies.
Claims Transformers
A very important part of the protocol is its ability to create new contextual meaning from identity claims. For example, your claim to be born on 01.01.1990 can be transformed into a credential OVER_18. This plays a huge role in protecting privacy since the service provider will no longer be supplied the identity claims, but a specific credential which was generated through your identity claims. This way a service provider will be supplied with the information that is relevant to it (that you are over 18 for example) and they do not have to worry about more personal details anymore (that you are born on 01.01.1990).
Consistent User Experience
By no longer leaving the identity provision to the service provider, but to the user himself, the protocol is able to offer a consistent user experience across all service providers. This means you no longer have to enter the same information on different service providers, but can use a predefined identity across all service providers, making identity much more convenient. Additionally, through such a system phishing attempts, privacy intrusion and general identity theft can be combatted.
InfoCards: Control for the user
Probably the most useful feature of CardSpace was InfoCards. An InfoCard is bascially an identity, therefore a collection of claims about that identity. These InfoCard’s could be easily chosen or switched during online communication with a service provider. Therefore, during an authentication request (e.g. signup to Microsoft.com), you were able to choose which InfoCard you wanted to use and represent yourself with on Microsoft.com.
This was a huge step forward in bringing control over ones identity back to the user. The user could decide which identity to authorize a service provider with. Below is a visualization of the signup process:
Conclusion
We’ve seen some of the innovation coming from Microsoft in regards to identity and how Cardspace could have been a truly amazing solution for identity. Sadly, the project failed but a successor will most certainly reign where Cardspace left off.
Windows CardSpace
![]()
Windows CardSpace — ныне отмененное клиентское ПО с патентованной технологией единого входа от Microsoft. WCS — это способ идентификации пользователей при перемещении между ресурсами Интернета без необходимости повторного ввода имен и паролей.
В отличие от ранее используемых технологий унифицированной идентификации (например, Microsoft Passport) WCS управляет непосредственно пользователями и приложениями, с которыми устанавливается контакт (а не из централизованного ресурса). Можно применять разные схемы и уровни сложности для идентификации при доступе на Web-форумы и для банковских операций.
15 февраля 2011 корпорация Майкрософт объявила об отмене Windows CardSpace 2.0 и о работе над замещающим ПО U-Prove.
Содержание
Критика
- Реализация Windows CardSpace гораздо сложнее альтернативных вариантов (например, OpenID).
- Требуется установка дополнительного ПО (или встроенная поддержка в ОС).
- Нет простой и быстрой возможности перенести или взять с собой личные ключи на другой компьютер, например, в Интернет-кафе.
- Технологии CardSpace запатентованы Microsoft, [1] так что в реальности нет возможности создать сторонние приложения, использующие её.
См. также
Ссылки
Литература
- Кристиан Нейгел, Билл Ивьен, Джей Глинн, Карли Уотсон, Морган Скиннер C# 2005 и платформа .NET 3.0 для профессионалов = Professional C# 2005 with .NET 3.0. — М .: «Диалектика», 2007. — ISBN 978-5-8459-1317-3
Примечания
- ↑Open Source-проект Higgins ждет помощи Microsoft — Новости (nixp.ru)
| Программные интерфейсы и фреймворки Microsoft Windows | |
|---|---|
| Графика | Проводник Windows • DirectX • Direct3D • GDI • Windows Presentation Foundation • Windows Color System • Windows Image Acquisition • Windows Imaging Component |
| Звук | DirectSound • DirectMusic • XACT • Speech API • MME |
| Мультимедиа | DirectShow • Windows Media • Media Foundation |
| Веб | MSHTML • MSXML • Платформа RSS для Windows • JScript • ActiveX • XMLHttpRequest • Гаджеты |
| Доступ к данным | Компоненты Microsoft Data Access • Extensible Storage Engine • ADO.NET • Sync Framework • Jet-механизм |
| Сети | Winsock (LSP) • Filtering Platform • NDIS • Windows Rally • Сервис фоновой интеллектуальой передачи данных • P2P API |
| Коммуникации | TAPI |
| Администрирование | Консоль Win32 • Windows Script Host • Инструментарий управления Windows • PowerShell • Планировщик задач • Offline Files • Теневое копирование • Windows Installer • Диспетчер ошибок Windows • Журнал событий Windows |
| Модель компонентов | COM • COM+ • DCOM • .NET Framework |
| Библиотеки | Microsoft Foundation Classes (MFC) • Active Template Library (ATL) • Windows Template Library (WTL) • Base Class Library (BCL) |
| Разработка драйверов | Windows Driver Model • Windows Driver Foundation (KMDF • UMDF) |
| Безопасность | CryptoAPI (CAPICOM) • Windows CardSpace • Data protection API • Security Support Provider Interface |
| .NET | .NET Framework • ASP.NET • ADO.NET • .NET Remoting • Windows Presentation Foundation • Windows Workflow Foundation • Windows Communication Foundation • Windows CardSpace • XNA Framework • Silverlight • Библиотека параллельного программирования |
| Межпроцессное взаимодействие |
Dynamic Data Exchange (DDE) • MSRPC • Именованные каналы |
| Текст и поддержка языков |
Framework Текстовых сервисов • Объектная модель текстов • Редактор метода ввода • Языковые пакеты • Многоязычный интерфейс |
| Игры | XNA Framework • DirectX |
| .NET Framework | |
|---|---|
| Архитектура | Base Class Library • Common Language Infrastructure • .NET assembly • метаданные • COM Interop |
| Инфраструктура | Common Language Runtime • Common Type System • Common Intermediate Language • Virtual Execution System • Dynamic Language Runtime |
| Языки Microsoft | C# • Cω • Visual Basic .NET • C++/CLI (Managed) • Visual J# • JScript .NET • Windows PowerShell • IronPython • IronRuby • F# • Spec# • Sing# |
| Другие языки | A# • Boo • IronLisp • L# • Nemerle • P# • PascalABC.NET • PHP • Scala • Delphi Prism |
| Windows Foundations | Presentation • Communication • Workflow |
| Компоненты | ADO.NET (Entity Framework · Data Services) · ASP.NET (AJAX · MVC · Dynamic Data) · .NET Remoting · Language Integrated Query · Windows CardSpace · Windows Forms · XAML · ClickOnce · Dynamic Language Runtime · Parallel FX Library (PLINQ · TPL) |
| Реализации | DotGNU • Mono • .NET Compact Framework (Xbox 360) • .NET Micro Framework • Portable.NET • XNA Framework • Silverlight • Shared Source Common Language Infrastructure |
| Сравнения | C# и Java • C# и Visual Basic .NET |
| Будущие технологии | Acropolis • Jasper |
| API и фреймворки Microsoft | |
|---|---|
| Графика | Desktop Window Manager · Direct2D · Direct3D (extensions) · GDI / GDI+ · WPF · Windows Color System · Windows Image Acquisition · Windows Imaging Component |
| Аудио | DirectMusic · DirectSound · DirectX plugin · XACT · Speech API · XAudio2 |
| Мультимедиа | DirectX (Media Objects · Video Acceleration) · DirectInput · DirectShow · Image Mastering API · Managed DirectX · Media Foundation · XNA · Windows Media · Video for Windows |
| Web | MSHTML · RSS Platform · JScript · VBScript · BHO · XDR · SideBar Gadgets |
| Доступ к данным | Data Access Components · Extensible Storage Engine · ADO.NET · ADO.NET Entity Framework · Sync Framework · Jet Engine · MSXML · OLE DB · OPC |
| Сеть | Winsock (LSP) · Winsock Kernel · Filtering Platform · Network Driver Interface Specification · Windows Rally · BITS · P2P API · MSMQ · MS MPI · DirectPlay |
| Коммуникации | Messaging API · Telephony API · WCF |