Identity management requires multiple identifier

Date: 2006-11-20 15:00
By Leonard Anderson

Leonard Anderson, Soctim Consultant

Story tools

Socitm Consultant, Leonard Anderson proposes a radical approach to identity management that does away with the need for unique identifiers and replaces it with a solution based on google approach to search

People are unique, but their identifiers across computer systems are not.  Historically, government agencies have created their own unique identifiers (UIDs) – meaning that multiple identifiers are inescapable. Joined up government requires accurate matching of many system identifiers against one, and only one, unique person. 

Traditional ICT solutions specify a UID, a data cleansing process, explicit data matching and a duplicate-free central repository.  Business processes that rely on such perfectly accurate data collection are doomed to fail, or have high cost of administration.  Huge amounts of effort are spent on correcting the impact of inaccurate data.  All systems contain inaccurate data; errors that can only be resolved with human intervention; errors that are propagated into dependent systems.  If this causes problems in a single agency, just imagine the problems of integrating systems across multi-agency environments in local government.

There is an event based paradigm for public sector information sharing.  Federated identity management is the critical success factor.  It has these unlikely properties:

An architecture developed from this may appear to reverse best practice from generations of computer systems developers.  But a rationale is to compare it with Google.  Google is the most successful Web application. Google is undeniably useful, but look at its attributes. They are not dissimilar to the list above. Google:

It is impractical to give every person a single UID that can be used across all computer systems for all time, including historical records.  It would have to include foreign nationals.  People are unique, not the identifiers allocated by agencies to assist their business processes.  The current UID culture creates projects that fail to deliver benefits to citizens, and wastes resources. 

Wouldn’t it be better if someone took up the challenge to prototype a federated Persistent Identity Engine.  The call is for a serendipitous approach for managing identity with the following features:

Yes, it would be big.  But it can start small and grow.  It should be open source.  A candidate architecture has been completed.  Building it should start as an innovative research project.  Some things would work well, some would fail, but more knowledge would be spread in the public sector.  It could help people specify requirements for identity management in future Multi-Agency integrations.  An example is the information sharing required by the Common Assessment Framework for Children, which will present 150 local authorities with interesting problems in 2008.

Dr L.P. Anderson
Leonard.anderson@socitm.gov.uk