Government ID, Smart Cards, Identification and Authentication

Danish Government says 'yes' to SAML 2.0 and encourages Microsoft to support those specifications

Thursday, April 27, 2006

The Danish Government this week agreed to stick with its endorsement of SAML 2.0 (Security Assertion Markup Language) as the “recommended standard for federation,” and urged Microsoft to support “customer choice by implementing support for SAML 2.0 in their operating system…” Using privately-controlled specifications could “stifle innovation…” the report adds. SAML is an XML standard for exchanging authentication and authorization data between security domains.


The Danish IT Architecture Committee has decided to stand firm on SAML 2.0 as the recommended standard for federation. The OASIS ratified SAML 2.0 standard has, since April 2005, been the officially recommended standard for the federation in the Danish public sector.

Microsoft’s recent decision to ship a federation service, as part of its Windows 2003 server operating system without supporting the SAML 2.0 standard challenges this recommendation because the WS-Federation specification implemented by Microsoft cannot interoperate with SAML 2.0.

Denmark thinks Microsoft should support customer choice by implementing support for SAML 2.0 in their operating system on equal footing with the WS-Federation specification.

Basing e-government on privately controlled specifications that may stifle innovation is not desirable from the Danish point of view. As a consequence the Danish IT Architecture committee has decided to stand firm on the SAML 2.0 recommendation. At the same time the committee has decided to try and work towards convergence in the area of federation standards through dialogue with EU, other governments, suppliers and standardizations bodies. For further information, see: europa.eu.int/idabc/en/document/5538/194[end] 

Identive Group announced tomPAY, an NFC-enabled sticker tag that can be affixed to existing mobile phones to enable contactless payments.

Based on Identive’s tom (tag on metal) smart inlay technology, tomPAY is manufactured using the same processes as an ISO PVC card. When placed on a phone, tomPAY enables contactless mobile payments in compliance with MasterCard PayPass specifications, as well as loyalty, transport ticketing and other m-commerce services.

read more »

Microsoft has filed a U.S. patent for a logo that marks a device as NFC-enabled, according to NFC World.

The “Tap and Do” logo (pictured, courtesy of NFC World) will be included on computers and other hardware that feature NFC connectivity, as well as on NFC-enabled computer software.

read more »

SecureAuth has released the SecureAuth IEP 6.2 version of its identity enforcement platform. With it, customers can quickly configure a portal for simplified and secure access to cloud and web applications, as well as VPN resources.

read more »

GlobalPlatform launched its latest specifications for the Trusted Execution Environment (TEE).

The organization has released two new specifications primarily for use by software developers working within the TEE space. The “TEE Systems Architecture v1.0” explains the hardware and software architectures behind the TEE, while the “TEE Internal API Specification v1.0” specifies how to develop trusted applications.

read more »

Yubico and SSO Easy have partnered to create a simplified two-factor authentication for single sign-on (SSO).

Designed for users who must implement strong two-factor authentication for access to SAML-based SSO servers, critical applications and sensitive information, this solution utilizes Yubico’s YubiKey driverless USB-token to log in with a one-time password.

read more »

Thursby Software Systems Inc. has released ADmitMac PKI v4, the fourth generation of its two-factor security software for the Mac OS. This version supports OS X Lion and Snow Leopard.

read more »