Cloud Security Authors: Liz McMillan, Elizabeth White, Yeshim Deniz, Lori MacVittie, Pat Romanski

News Feed Item

Novell Enables Rapid Adoption of Identity Management by Open Sourcing Key Technologies

Working within the larger identity and open source communities, the Bandit project will address common identity management requi

WALTHAM, Mass., June 12 /PRNewswire-FirstCall/ -- Novell today announced the creation of Bandit(TM), a groundbreaking open source project with a charter to unify disparate identity systems and provide a consistent approach to securing and managing identity. The identity services in development by the Bandit community are open source and will work with existing industry standards such as WS- * and Liberty Federation, and open source projects including Eclipse Higgins. Novell has already contributed significant engineering resources and code to jump start this effort. Ultimately, the goal of the Bandit project is to provide organizations with a consistent approach to enterprise identity management challenges such as secure, role- based access and regulatory compliance reporting.

"The Bandit project is looking to address one of the toughest challenges in identity management today -- provide a consistent approach to securing and managing identity," said Mike Neuenschwander, vice president and research director for the Burton Group. "The creation of identity services that abstract the complexity of identity systems and that are interoperable and freely available is a worthwhile goal and represents an important inflection point in the ongoing development of the identity management market."

While many organizations deploy identity management technologies today, disparate vendor solutions can create complexity and potentially slow adoption. By developing an open source enablement layer, Novell and the Bandit community will make it possible to standardize identity management across differing systems and resources. Bandit's freely available code can then be overlayed on an existing identity management system.

The Bandit project is focused on delivering a single, consistent experience of digital identity and includes several common identity services such as authentication, roles, policy and compliance:

-- The Common Authentication Services Adapter (CASA) provides interoperable authentication that enables application and enterprise single sign-on with a secure vault for user and system credentials. -- The Common Identity service is an implementation of the Higgins framework for representing digital identity. -- The Role Engine service can be integrated into any application to consistently calculate role information and unify authorization across systems. -- The Audit Record Framework service provides an open auditing and compliance API and receives audit records from Bandit's open identity services and other applications to provide common identity and event information to verify security and compliance.

Novell already incorporates some of Bandit's open identity services within its SUSE(R) Linux distribution and plans to include Bandit's identity services in future releases of other products. Novell will continue to support the Bandit project with substantial engineering resources and will maintain the project while the Bandit community grows.

"The Bandit project was created in response to our customers' need to reduce the complexity of identity management in the enterprise," said Jeff Jaffe, executive vice president and chief technology officer for Novell. "The industry needs to come together and deliver common identity services that provide a consistent experience, regardless of the underlying infrastructure. Novell's initial sponsorship of the Bandit project is a natural extension of our leadership in both identity and open source, and we are gratified to see the groundswell of community support."

A Community-driven Approach to Enterprise Identity Management

The Bandit project builds upon the participation of the broader identity and open source communities and many industry leaders are expressing their support and commitment to the goals of the Bandit project.


Dominic Fedronic, chief technology officer for ActivIdentity Inc., said, "The deployment of digital identity assurance and strong authentication solutions for both government and enterprise would greatly benefit from seamless interoperability and tight integration with identity management systems. ActivIdentity supports Novell's leadership with the Bandit project and Higgins as we believe the resulting open industry standards will expand the market and deliver greater value to customers."

Paul Trevithick, technology lead for the Higgins project at the Eclipse Foundation, said, "We are very pleased that Novell is promoting the adoption of open source identity technologies and that the Bandit project is contributing to and leveraging Higgins. Bandit is providing an important service by making an open identity infrastructure available on enterprise platforms including SUSE Linux."

Anthony Nadalin, Distinguished Engineer and Chief Security Architect for IBM, said, "IBM is pleased that Novell is using Higgins as the Identity Management foundation for the Bandit project. As a leading proponent of open source, IBM is committed to working with the Eclipse Higgins community to solve the identity-related challenges our customers face everyday."

George Goodman, president of the Liberty Alliance management board and director, Platform Capabilities Lab at Intel, said, "Liberty Alliance welcomes open initiatives that bring the industry closer to achieving a ubiquitous interoperable privacy-respecting identity layer for the Internet. We salute the Bandit team for contributing open source that will help advance the deployment of Liberty-enabled federations and Web services on the widest possible scale."

Kim Cameron, architect of Identity and Access for Microsoft, said: "The Identity Metasystem provides a model for identity interoperability across the industry. We're happy to see Novell playing an active role in helping realize the Identity Metasystem and look forward to working with them to ensure interoperability between our respective products."

Jim Gerken, practice manager for identity management with Novacoast, said, "We have spent years connecting disparate authentication repositories which confirms the need for consistent and standard identity services. With Novell's leadership in identity and open source, Bandit is a natural community for Novell to create that leverages its position in both markets."

Bob Lord, Red Hat senior director engineering, said, "Red Hat supports open source initiatives to build stronger identity frameworks and controls based on open standards. The Bandit project provides several initiatives that will help simplify identity management in heterogeneous environments and drive further innovation for the enterprise. We look forward to working with the open source community to extend a flexible identity framework from desktop to server, network to application."

Sara Gates, vice president of Identity Management at Sun Microsystems, said, "As a co-founder of the Liberty Alliance and a leading champion of open source, we have seen firsthand how customers are embracing open source technologies as a way to accelerate business solutions and reduce their costs. We strongly support the move of identity management services into the open source community."

Dick Hardt, Sxip Identity founder and CEO, said, "The identity management industry needs a common approach to secure, role-based access and compliance reporting for the enterprise and open source projects like Bandit from Novell and Higgins are a great step in that direction. We see this as a natural complement to the user-centric Identity 2.0 efforts being made with SXIP and DIX and are excited to work with them on adding support of Bandit, Higgins and eDirectory(TM)."

Rob Clyde, Symantec vice president of technology, office of the CTO, said, "Symantec is a strong supporter of open source initiatives that enable developer communities and vendors to work together to create flexible solutions capable of meeting the diverse needs of our customers. Companies today face a tremendous challenge as they try to integrate disparate application systems and security infrastructures each with its own authentication technologies into a cohesive, manageable solution. A standards-based approach backed by an open source implementation is a beneficial step towards addressing the vexing problem of identity management."

Jonathan Alexander, Trusted Network Technologies vice president of engineering, said, "Bandit is addressing key customer challenges, such as integrating distributed identity and roles, that we see as we help customers deploy our identity security and audit solutions. We see the Bandit and Higgins projects as filling a critical need to tie disparate identity systems together into a more pervasive, integrated and powerful solution."

About Novell

Novell, Inc. delivers Software for the Open Enterprise(TM). With more than 50,000 customers in 43 countries, Novell helps customers manage, simplify, secure and integrate their technology environments by leveraging best-of-breed, open standards-based software. With over 20 years of experience, 5,000 employees, 5,000 partners and support centers around the world, Novell helps customers gain control over their IT operating environment while reducing cost. More information about Novell can be found at http://www.novell.com/.

Novell and SUSE are registered trademarks and Bandit and eDirectory are trademarks of Novell, Inc. in the United States and other countries. * Linux is a registered trademark of Linus Torvalds. All other third party trademarks are the property of their respective owners.

Novell, Inc.

CONTACT: Kerry Adorno of Novell, +1-781-464-8042 or [email protected];
or Sarah Murray of Horn Group, +1-781-356-7135 or [email protected], for

Web site: http://www.novell.com/

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
Major trends and emerging technologies – from virtual reality and IoT, to Big Data and algorithms – are helping organizations innovate in the digital era. However, to create real business value, IT must think beyond the ‘what’ of digital transformation to the ‘how’ to harness emerging trends, innovation and disruption. Architecture is the key that underpins and ties all these efforts together. In the digital age, it’s important to invest in architecture, extend the enterprise footprint to the cl...
SYS-CON Events announced today that MathFreeOn will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. MathFreeOn is Software as a Service (SaaS) used in Engineering and Math education. Write scripts and solve math problems online. MathFreeOn provides online courses for beginners or amateurs who have difficulties in writing scripts. In accordance with various mathematical topics, there are more tha...
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
@ThingsExpo has been named the Top 5 Most Influential Internet of Things Brand by Onalytica in the ‘The Internet of Things Landscape 2015: Top 100 Individuals and Brands.' Onalytica analyzed Twitter conversations around the #IoT debate to uncover the most influential brands and individuals driving the conversation. Onalytica captured data from 56,224 users. The PageRank based methodology they use to extract influencers on a particular topic (tweets mentioning #InternetofThings or #IoT in this ...
@ThingsExpo has been named the Top 5 Most Influential M2M Brand by Onalytica in the ‘Machine to Machine: Top 100 Influencers and Brands.' Onalytica analyzed the online debate on M2M by looking at over 85,000 tweets to provide the most influential individuals and brands that drive the discussion. According to Onalytica the "analysis showed a very engaged community with a lot of interactive tweets. The M2M discussion seems to be more fragmented and driven by some of the major brands present in the...
In the next forty months – just over three years – businesses will undergo extraordinary changes. The exponential growth of digitization and machine learning will see a step function change in how businesses create value, satisfy customers, and outperform their competition. In the next forty months companies will take the actions that will see them get to the next level of the game called Capitalism. Or they won’t – game over. The winners of today and tomorrow think differently, follow different...
In an era of historic innovation fueled by unprecedented access to data and technology, the low cost and risk of entering new markets has leveled the playing field for business. Today, any ambitious innovator can easily introduce a new application or product that can reinvent business models and transform the client experience. In their Day 2 Keynote at 19th Cloud Expo, Mercer Rowe, IBM Vice President of Strategic Alliances, and Raejeanne Skillern, Intel Vice President of Data Center Group and ...
The Internet of Things (IoT), in all its myriad manifestations, has great potential. Much of that potential comes from the evolving data management and analytic (DMA) technologies and processes that allow us to gain insight from all of the IoT data that can be generated and gathered. This potential may never be met as those data sets are tied to specific industry verticals and single markets, with no clear way to use IoT data and sensor analytics to fulfill the hype being given the IoT today.
More and more brands have jumped on the IoT bandwagon. We have an excess of wearables – activity trackers, smartwatches, smart glasses and sneakers, and more that track seemingly endless datapoints. However, most consumers have no idea what “IoT” means. Creating more wearables that track data shouldn't be the aim of brands; delivering meaningful, tangible relevance to their users should be. We're in a period in which the IoT pendulum is still swinging. Initially, it swung toward "smart for smar...
Virgil consists of an open-source encryption library, which implements Cryptographic Message Syntax (CMS) and Elliptic Curve Integrated Encryption Scheme (ECIES) (including RSA schema), a Key Management API, and a cloud-based Key Management Service (Virgil Keys). The Virgil Keys Service consists of a public key service and a private key escrow service. 

Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, will discuss the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
What happens when the different parts of a vehicle become smarter than the vehicle itself? As we move toward the era of smart everything, hundreds of entities in a vehicle that communicate with each other, the vehicle and external systems create a need for identity orchestration so that all entities work as a conglomerate. Much like an orchestra without a conductor, without the ability to secure, control, and connect the link between a vehicle’s head unit, devices, and systems and to manage the ...
Machine Learning helps make complex systems more efficient. By applying advanced Machine Learning techniques such as Cognitive Fingerprinting, wind project operators can utilize these tools to learn from collected data, detect regular patterns, and optimize their own operations. In his session at 18th Cloud Expo, Stuart Gillen, Director of Business Development at SparkCognition, discussed how research has demonstrated the value of Machine Learning in delivering next generation analytics to impr...
For basic one-to-one voice or video calling solutions, WebRTC has proven to be a very powerful technology. Although WebRTC’s core functionality is to provide secure, real-time p2p media streaming, leveraging native platform features and server-side components brings up new communication capabilities for web and native mobile applications, allowing for advanced multi-user use cases such as video broadcasting, conferencing, and media recording.
Amazon has gradually rolled out parts of its IoT offerings, but these are just the tip of the iceberg. In addition to optimizing their backend AWS offerings, Amazon is laying the ground work to be a major force in IoT - especially in the connected home and office. In his session at @ThingsExpo, Chris Kocher, founder and managing director of Grey Heron, explained how Amazon is extending its reach to become a major force in IoT by building on its dominant cloud IoT platform, its Dash Button strat...
SYS-CON Events announced today that SoftNet Solutions will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. SoftNet Solutions specializes in Enterprise Solutions for Hadoop and Big Data. It offers customers the most open, robust, and value-conscious portfolio of solutions, services, and tools for the shortest route to success with Big Data. The unique differentiator is the ability to architect and ...
A critical component of any IoT project is what to do with all the data being generated. This data needs to be captured, processed, structured, and stored in a way to facilitate different kinds of queries. Traditional data warehouse and analytical systems are mature technologies that can be used to handle certain kinds of queries, but they are not always well suited to many problems, particularly when there is a need for real-time insights.
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
One of biggest questions about Big Data is “How do we harness all that information for business use quickly and effectively?” Geographic Information Systems (GIS) or spatial technology is about more than making maps, but adding critical context and meaning to data of all types, coming from all different channels – even sensors. In his session at @ThingsExpo, William (Bill) Meehan, director of utility solutions for Esri, will take a closer look at the current state of spatial technology and ar...
Everyone knows that truly innovative companies learn as they go along, pushing boundaries in response to market changes and demands. What's more of a mystery is how to balance innovation on a fresh platform built from scratch with the legacy tech stack, product suite and customers that continue to serve as the business' foundation. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, will discuss why and how ReadyTalk diverted from healthy revenue an...