Next in thread → Next in month →

Re: [idtrust-sc] NIST event

From
Arshad Noor
Date
2007-06-23T00:28:00+00:00
ID
Thread
Re: [idtrust-sc] NIST event
Here are my thoughts:

1) The last time I attended PKI R&D workshop was about
4 years ago, and most of it was not relevant to my daily
work; it was too far out to have an impact on building and
operating PKIs in the near-term.
As such, I felt that the
conference was geared more towards researchers in the
academic community rather than practitioners in the real
world;

2) I don't know how much of their total budget $20K represents,
but I believe the value to OASIS should be commensurate
with the portion that $20K represents to the workshop;  we
should ask for actual expenses for the last 3 years and some
high-level breakdown to understand this equation.  The
number of positions on the organizing committees should
be proportional to the contribution we're  making.

3) If they're truly attempting to evolve past PKI to IDtrust,
then the workshop should be targeted along two tracks:

a) Authentication and Authorization
b) EKMI

The former track (AA) will cover PKI, SAML, XACML, SPML, Liberty, OATH, etc - all technologies related
to authentication and authorization.  The track can
cover current issues, as well as R&D papers.

The latter track will cover key-management issues, as well
as attempting to merge PKI and SKMS into a single unit
over the next few years.  It should also cover Quantum
Computing and the risks they pose to cryptography, in
general (in case you're interested, the ABA ST-ISC forum
has a debate going on about QC and its impact on PK
cryptography right now that's very interesting).

4) While I believe there is value in investing in an IDtrust
workshop, I think it should be focused at least 50% on
real-world problems and 50% on R&D.  If they want to stay
focused on R&D, then they should be looking to one or
more of the well-endowed universities to sponsor it.

Arshad Noor
StrongAuth, Inc.
Next in thread → Next in month →