數(shù)字身份認(rèn)證入門(影印版)
出版時間:2023年03月
頁數(shù):446
“本書有助于我理解可驗證憑證的細(xì)微差別,以及我們?nèi)绾卧讵q他州使用數(shù)字身份認(rèn)證來改善市民的生活。”
——Alan Fuller
猶他州首席信息官
為什么公司難以獲得正確的數(shù)字身份認(rèn)證?如果你還在為網(wǎng)站身份驗證等簡單的認(rèn)證問題苦苦掙扎,這本書就是你需要的答案。作者Phil Windley提供了相關(guān)的概念框架,幫助你理解協(xié)議、標(biāo)準(zhǔn)以及可用的解決方案,同時給出了應(yīng)用時機(jī)和場合的建議。
通過將現(xiàn)今的社交登錄解決方案與新興的自我主權(quán)身份認(rèn)證問題聯(lián)系起來,本書解釋了數(shù)字身份認(rèn)證的工作原理,幫助你牢固地把控事態(tài)發(fā)展,同時還展示了如何使用數(shù)字身份認(rèn)證來解決最緊迫的認(rèn)證問題。開發(fā)人員、產(chǎn)品經(jīng)理、主管和副總裁都能從中學(xué)習(xí)到如何在應(yīng)用程序內(nèi)部和整個企業(yè)中有效利用身份認(rèn)證。
本書將幫助你:
● 理解數(shù)字身份認(rèn)證的用途以及為什么數(shù)字身份認(rèn)證是你的業(yè)務(wù)策略的根基
● 了解為什么“自建”數(shù)字身份認(rèn)證基礎(chǔ)設(shè)施不是個好主意
● 區(qū)分身份驗證和授權(quán)等核心概念
● 比較集中式、聯(lián)合式和分散式身份認(rèn)證系統(tǒng)的屬性
● 判斷適合于應(yīng)用的正確授權(quán)方法
● 理解信任、風(fēng)險、安全和隱私等核心概念
- Foreword
- Preface
- 1. The Nature of Identity
- A Bundle of Sticks?
- Identity Is Bigger Than You Think
- No Universal Identity Systems
- The Road Ahead
- 2. Defining Digital Identity
- The Language of Digital Identity
- Identity Scenarios in the Physical World
- Identity, Security, and Privacy
- Digital Identity Perspectives
- Reimagining Decentralized and Distributed
- A Common Language
- 3. The Problems of Digital Identity
- Tacit Knowledge and the Physical World
- The Proximity Problem
- The Autonomy Problem
- The Flexibility Problem
- The Consent Problem
- The Privacy Problem
- The (Lack of) Anonymity Problem
- The Interoperability Problem
- The Scale Problem
- Solving the Problems
- 4. The Laws of Digital Identity
- An Identity Metasystem
- The Laws of Identity
- Fixing the Problems of Identity
- 5. Relationships and Identity
- Identity Niches
- Relationship Integrity
- Relationship Life Span
- Relationship Utility
- Transactional and Interactional Relationships
- Promoting Rich Relationships
- 6. The Digital Relationship Lifecycle
- Discovering
- Co-Creating
- Propagating
- Using
- Updating or Changing
- Terminating
- Lifecycle Planning
- 7. Trust, Confidence, and Risk
- Risk and Vulnerability
- Fidelity and Provenance
- Trust Frameworks
- The Nature of Trust
- Coherence and Social Systems
- Trust, Confidence, and Coherence
- 8. Privacy
- What Is Privacy?
- Correlation
- Privacy, Authenticity, and Confidentiality
- Functional Privacy
- Privacy by Design
- Privacy Regulations
- The Time Value and Time Cost of Privacy
- Surveillance Capitalism and Web 2.0
- Privacy and Laws of Identity
- 9. Integrity, Nonrepudiation, and Confidentiality
- Cryptography
- Message Digests and Hashes
- Digital Signatures
- Digital Certificates
- Zero-Knowledge Proofs
- Blockchain Basics
- The Limitations of PKI
- 10. Names, Identifiers, and Discovery
- Utah.gov: A Use Case in Naming and Directories
- Naming
- Discovery
- Heterarchical Directories
- Discovery Is Key
- 11. Authentication and Relationship Integrity
- Enrollment
- Authentication Factors
- Authentication Methods
- Classifying Authentication Strength
- Account Recovery
- Authentication System Properties
- Authentication Preserves Relationship Integrity
- 12. Access Control and Relationship Utility
- Policy First
- Authorization Patterns
- Abstract Authorization Architectures
- Representing and Managing Access Control Policies
- Handling Complex Policy Sets
- Digital Certificates and Access Control
- Maintaining Proper Boundaries
- 13. Federated Identity—Leveraging Strong Relationships
- The Nature of Federated Identity
- SSO Versus Federation
- Federation in the Credit Card Industry
- Three Federation Patterns
- Addressing the Problem of Trust
- Network Effects and Digital Identity Management
- Federation Methods and Standards
- Governing Federation
- Networked Federation Wins
- 14. Cryptographic Identifiers
- The Problem with Email-Based Identifiers
- Decentralized Identifiers
- Autonomic Identifiers
- Cryptographic Identifiers and the Laws of Identity
- 15. Verifiable Credentials
- The Nature of Credentials
- Verifiable Credentials
- Exchanging VCs
- Credential Presentation Types
- Answering Trust Questions
- The Properties of Credential Exchange
- VC Ecosystems
- Alternatives to DIDs for VC Exchange
- A Marketplace for Credentials
- VCs Expand Identity Beyond Authn and Authz
- 16. Digital Identity Architectures
- The Trust Basis for Identifiers
- Identity Architectures
- Algorithmic and Autonomic Identity in Practice
- Comparing Identity Architectures
- Power and Legitimacy
- Hybrid Architectures
- 17. Authentic Digital Relationships
- Administrative Identity Systems Create Anemic Relationships
- Alternatives to Transactional Relationships
- The Self-Sovereign Alternative
- Supporting Authentic Relationships
- Taking Our Rightful Place in the Digital Sphere
- 18. Identity Wallets and Agents
- Identity Wallets
- Platform Wallets
- The Roles of Agents
- Properties of Wallets and Agents
- SSI Interaction Patterns
- What If I Lose My Phone?
- Web3, Agents, and Digital Embodiment
- 19. Smart Identity Agents
- Self-Sovereign Authority
- DID-Based Communication
- Exchanging DIDs
- DIDComm Messaging
- Protocological Power
- Smart Agents and the Future of the Internet
- Operationalizing Digital Relationships
- Digital Memories
- 20. Identity on the Internet of Things
- Access Control for Devices
- The CompuServe of Things
- Alternatives to the CompuServe of Things
- The Self-Sovereign Internet of Things
- Relationships in the SSIoT
- Unlocking the SSIoT
- 21. Identity Policies
- Policies and Standards
- The Policy Stack
- Attributes of a Good Identity Policy
- Recording Decisions
- Determining Policy Needs
- Writing Identity Policies
- Policy Outline
- The Policy Review Framework
- Assessing Identity Policies
- Enforcement
- Procedures
- Policy Completes the System
- 22. Governing Identity Ecosystems
- Governing Administrative Identity Systems
- Governing Autonomic Identity Systems
- Governing Algorithmic Identity Systems
- Governance in a Hybrid Identity Ecosystem
- Governing Individual Identity Ecosystems
- The Legitimacy of Identity Ecosystems
- 23. Generative Identity
- A Tale of Two Metasystems
- Generativity
- The Self-Sovereign Internet
- Generative Identity
- Our Digital Future
- Index
書名:數(shù)字身份認(rèn)證入門(影印版)
國內(nèi)出版社:東南大學(xué)出版社
出版時間:2023年03月
頁數(shù):446
書號:978-7-5766-0669-0
原版書書名:Learning Digital Identity
原版書出版商:O'Reilly Media
Phillip J. Windley
Phil Windley是AWS Identity的開發(fā)經(jīng)理。此前,他是楊百翰大學(xué)(Brigham Young University)信息技術(shù)辦公室的首席工程師和Sovrin基金會的創(chuàng)始主席。他也是Internet身份認(rèn)證研討會(Internet Identity Workshop)的聯(lián)合創(chuàng)始人和組織者,這是世界上最具影響力和最悠久的身份認(rèn)證會議之一,也是Digital Identity(O'Reilly出版)和The Live Web(Course Technology出版)的作者。此外,Phil是猶他州的首席信息官和iMALL公司(電子商務(wù)工具的早期先行者)的創(chuàng)始人兼首席技術(shù)官。
The animal on the cover of Learning Digital Identity is a nankeen night heron (Nycticorax caledonicus), also known as a rufous night heron. Nycticorax means “night raven” in Ancient Greek, and was used to describe birds of ill omen. In 1555, the term was applied to the night heron.
Nankeen night herons can be found all over Australia, generally in areas where there is permanent water. They like to roost in tall trees and foliage during the day near heavily vegetated wetlands, river margins, floodplains, swamps, parks, and gardens. They breed in colonies that can contain hundreds to thousands of breeding pairs. The largest of these colonies can be found in the Murray-Darling Basin. At twilight, they feed on insects, crustaceans, fish, and amphibians in shallow waters.
The name rufous (reddish-brown) night heron comes from the rich, cinnamoncolored upper parts of the birds. They have white undersides, a black beak, and a black crown on their large heads. Their relatively short legs are yellow, as are their feet and eyes. Compared to other herons, they are stocky and medium-sized.
Populations of nankeen night herons remain stable, so they are listed as a species of least concern on conservation lists.