サイバー空間上の信頼フレームワークとパーソナルデータ経済

92
© 2011 by Nat Sakimura. サイバー空間上の信頼フレームワークと パーソナルデータ経済 インターネット・アイデンティティとプライバシー保護の観点から 崎村 夏彦 (Nat Sakimura) The OpenID ® Foundation 理事長 野村総合研究所 上席研究員 2011/12/7 東京大学 融合情報学特別講義Ⅱ(基盤情報学特別講義Ⅱ) #第8大陸 #第八大陸 http://www.sakimura.org/ @_nat

description

2011/12/7東京大学 融合情報学特別講義Ⅱ(基盤情報学特別講義Ⅱ)#第8大陸 #第八大陸

Transcript of サイバー空間上の信頼フレームワークとパーソナルデータ経済

  • 1. (Nat Sakimura)@_natThe OpenID Foundation 2011/12/7 #8 # http://www.sakimura.org/ 2011 by Nat Sakimura.

2. ISO/IEC SC27 WG5 @_natJapan NB HoD www.sakimura.org Saints Mark ObamaNdesandjo WG Foundation =nat 2011 by Nat Sakimura. 3. 3 2011 by Nat Sakimura. 4. 4 2011 by Nat Sakimura. 5. (5 2011 by Nat Sakimura. 6. 6 2011 by Nat Sakimura. 7. ?7 2011 by Nat Sakimura. 8. 8 2011 by Nat Sakimura. 9. 9 2011 by Nat Sakimura. 10. 10 2011 by Nat Sakimura. 11. San Francisco Ferry Building on 2011-09-11 by Nat Sakimura 11 2011 by Nat Sakimura. 12. 12 2011 by Nat Sakimura. 13. cm 13 2011 by Nat Sakimura. 14. 14 2011 by Nat Sakimura. 15. 15 2011 by Nat Sakimura. 16. 16 2011 by Nat Sakimura. 17. 17 2011 by Nat Sakimura. 18. 2011 by Nat Sakimura. 19. IDnGoogleYahooFacebookTwitterMixiIDTwitterTogetterTwitterTogetterTogetter Twitter APIID ID! !! ? 19 2011 by Nat Sakimura. 20. GDP 520 510 500 -1.7% 490 480GDP 470 460 4502006200720082009 2010 21 GDPNRI20 2011 by Nat Sakimura. 21. BtoC-EC15%) 21 2011 by Nat Sakimura. 22. Wikipedia 22 2011 by Nat Sakimura. 23. EUROPOL Public Information EUROPOL Public InformationIDEUMcAfee(2009)$1 THREAT ASSESSMENT100(ABRIDGED) INTERNET FACILITATED ORGANISED CRIME700 iOCTAEU+O2 Analysis & Knowledge The Hague, 07/01/11FILE NO.: 2530-264 EUROPOL Public Information Page 1 of 11Europol Threat Assessment Internet Facilitated Organised Crime(2011) File No. 2530-264 23 2011 by Nat Sakimura. 24. Wild Wild West 2011 by Nat Sakimura. Wikipedia 24 25. 1917 http://bit.ly/uvK6IP25 2011 by Nat Sakimura. 26. 2011 by Nat Sakimura. 26() http://en.wikipedia.org/wiki/File:LombardStreet.jpg 27. Q 2011 by Nat Sakimura. 28. NSTICNational Strategy for Trusted Identities In Cyberspace28 2011 by Nat Sakimura. 29. International Strategy for Cyberspace (ISCS)n n7 l n 29 2011 by Nat Sakimura. 30. National Strategy for Trusted Identities in Cyberspase (NSTIC)n n l ID l Identity Ecosystem l 30 2011 by Nat Sakimura. 31. NSTIC31 2011 by Nat Sakimura. 32. nnn as Holy Grail l l l http://en.wikipedia.org/wiki/File:Sangreal.jpg 32 2011 by Nat Sakimura. 33. l l l l SECFDA etc. 2011 by Nat Sakimura. 33 34. n n n lOIX lKantara Inititative Peter Steiner, New Yorker, July 5, 1993. lInCommonsFair use rationale: to facilitate academic discussion. 34 2011 by Nat Sakimura. 35. 35 2011 by Nat Sakimura. 36. nnnSSNn36 2011 by Nat Sakimura. 37. (trust framework)nnnn37 2011 by Nat Sakimura. 38. TheOpenIdentityTrustFramework(OITF)ModelPrinciples of Openness PrinciplesofOpenness Open Identity Trust Framework (OITF) AllparticipantsinanOpenIdentityTrustFrameworkmustcommittoabidebythePrinciplesofOpennessandtoincorporatethemintotheiragreementsrelatingtothetrustframework.ThesePrinciplesare:Open Identity Trust Framework Lawfulness.OITFProvidersareresponsibleforensuringthatthetechnical,operational,andlegalrequirementsoftheOITFareconsistentwiththelawsofthejurisdiction(s)wherepartiesuseittoconductexchangesinvolvingidentityinformation.Principles of OpennessOpenreportingandpublication.OITFProvidersmustproduceperiodicreportsontheoperationandgovernanceofthetrustframework.TheymustensurethatawebsitedevotedtotheOITFprovideseasyandtimelyaccessto(a)theperiodicreports,(b)allagreementsthatconstitutethelegalstructureofthetrustframework,(c)allpoliciesandproceduresbywhichtheOITFoperates(includingcriteriaandprocessesforcertification),(d)aplainlanguagen explanationofthetrustframeworkstrustcharacteristics(forexample,dataprotectionstrengthsandweaknesses),and(e)recordsofdisputeresolutionactivitiesandtheirresults.However,publicationisnotrequiredforassessmentreports.OITFProvidersmustensurethatallpartiestoagreementsundertheOITFhavevisibilityintowhoisnparticipatinginitandinwhatcapacity.Ombudsmen.OITFProvidersmustaskgovernmentswheretheydobusinesstodesignateindependentombudsmennwhoseroleistolookaftertheinterestsofindividualusersundertheirrespectivejurisdictions,andtheymustensurethattheOITFisdesignedtoallowtheseombudsmentodotheirjob.Iflawrequiresthesharingofidentityinformationn(includingbiometricdata,behavioraldata,andsocialgraphs)withouttheinformedconsentofthepersoninquestion,partiestotheOITFwhoareorderedtosharethisinformationmustinvolvetheombudsmen.Anticircumventionandopendisclosure.OITFparticipantsmustnotbepartytoanysideagreementsthatncompromisetheintegrityofcommitmentsunderthetrustframework.Ifaparticipantispartytoanyagreementsthatmightotherwiseconflictwithobligationsunderthetrustframework,thatpartymustdisclosetheexistenceandnnatureoftheseagreementstotheaffectedpartyorpartiesattheearliestopportunity.OITFProvidersandassessorsmustdisclosealltheiragreementsandthetermsofthoseagreements.Nondiscrimination.ParticipantsintheOITFmustavoiddiscrimination.Participantsmustnotengageinexclusiven dealingarrangementsrelatingtothetrustframework.Interoperability.SoftwareandhardwarespecifiedinthetechnicalrequirementsofanOITFmustconformtodefinedn standardsthatpromoteinteroperability.Openversioning.OITFProvidersmustspellouthownewversionsoftheOITFwillbedecided,whentheywillben published,howparticipantswillbetransitionedtothesenewversions,andhowtheinterestsofparticipantsintheOITFwillbeprotected.Participantinvolvement.OITFProvidersmustenableparticipantstosharecontactdetailssothattheymayconvenen virtuallytodiscussmattersrelatedtothetrustframework.Open Identity Trust DataProtection.ParticipantsinOITFswilladheretodataprotectionpracticesatleastasstrongasthoseofthenFramework OECDsPrivacyGuidelines(PartTwoinitsentirety,concerningcollectionlimitation,dataquality,purposespecification,uselimitation,securitysafeguards,openness,individualparticipation,andaccountability).OpenIDn Accountability.OITFProvidersmuststateonapubliclyaccessiblewebsitehowtheOITFprovidesaccountabilitytoallparticipants,includingtheuserswhoseidentityinformationwillbeexchangedunderit.Auditability.OITFProvidersmustensurethatallpartiestoagreementsunderthetrustframework,includingthemselves,agreetobesubjecttoauditforconformancewiththesePrinciplesofOpenness.Redress.OITFProvidersmustensurethatallagreementsundertheOITFaffordthepartiesaneffectiverightandmechanismtoseekredress.Rundel, et al. OITF White paper 38ThePrinciplesofOpennessaregovernedbyaCreativeCommonsAttributionNoDerivative 2011 by Nat Sakimura. Works3.0UnitedStatesLicense(http://creativecommons.org/licenses/bynd/3.0/us/). 39. Peter Steiner, New Yorker, July 5, 1993. Fair use rationale: to facilitate academic discussion. 39 2011 by Nat Sakimura. 40. 40 2011 by Nat Sakimura. 41. IDID IDID 2011 by Nat Sakimura. 42. 2011 by Nat Sakimura. 43. nm 2011 by Nat Sakimura. 44. TFP n+m 2011 by Nat Sakimura. 45. 45 2011 by Nat Sakimura. 46. n etc. nhttp://www.sakimura.org/2011/06/1124/46 2011 by Nat Sakimura. 47. IdentityIdentityIdentityIdentityIdentityEgo 2011 by Nat Sakimura. 48. Identity IdentityIdentity Identity Identity Ego 2011 by Nat Sakimura. 49. 2011 by Nat Sakimura. 50. 2011 by Nat Sakimura. 51. etc. 2011 by Nat Sakimura. 52. n l l 2011 by Nat Sakimura. 53. 2011 by Nat Sakimura. 54. 9430 24601 2011 by Nat Sakimura. 55. 2011 by Nat Sakimura. 56. 2011 by Nat Sakimura. 57. 2011 by Nat Sakimura. 58. 2011 by Nat Sakimura. 59. 2011 by Nat Sakimura. 60. -- Bob Blackley, Gartner (2010/12/10) 2011 by Nat Sakimura. 61. Q 2011 by Nat Sakimura. 62. n n nn 2011 by Nat Sakimura. 63. Fair Information Practice Principles (FIPPs)(DHS version)1. Transparency2. Individual Participation3. Purpose Specification4. Data Minimization5. Use Limitation6. Data Quality and Integrity7. Security8. Accountability and Auditing 63 2011 by Nat Sakimura. 64. NSTIC Translatednnn n l l l ln 64 2011 by Nat Sakimura. 65. v.s. 2011 by Nat Sakimura. 66. 90 2220 35% NY1100 300 GPS Mike Saunders Multi National Experiment 7 66 2011 by Nat Sakimura. 67. http://bit.ly/rVjRqF 2011 by Nat Sakimura. 68. 2011 by Nat Sakimura. 69. 2011 by Nat Sakimura. 70. 1860 - 1890n n n 1895 1898 1898 1898 1899 2011 by Nat Sakimura. 71. 2011 by Nat Sakimura. 72. (1895)n n l()() l l() l() l 2011 by Nat Sakimura. 73. n, 1 n 1 101 2 (,.1977 190 2011 by Nat Sakimura. 74. nn, n18986n18989n1901 Too Late 2011 by Nat Sakimura. 75. 2011 by Nat Sakimura. 76. Q 2011 by Nat Sakimura. 77. API 2011 by Nat Sakimura. 78. Personal Data Ecosystem?n: Personal data is the new oil of the Internet and the new currency of the digital world. http://bit.ly/vLFGfT 78 2011 by Nat Sakimura. 79. Digital Identity 2011 by Nat Sakimura. 80. ? ? ? ??? ? ? ? ??? ID / ID / ID / A B C ID A B C ID / ID ID / ID / / IDID ID ??? ? / ID ID ? ID ?ID ID 80 2011 by Nat Sakimura. 81. 2011 by Nat Sakimura. 82. 2011 by Nat Sakimura. 83. 2011 by Nat Sakimura. 84. 2011 by Nat Sakimura. 85. 2011 by Nat Sakimura. 86. JAL 2011 by Nat Sakimura. 87. 2011 by Nat Sakimura. 88. 2011 by Nat Sakimura. 89. Q 2011 by Nat Sakimura. etc. 90. v.s.API 2011 by Nat Sakimura. 91. nn 2011 by Nat Sakimura. 92. Q 2011 by Nat Sakimura.