Is is possible to resurrect Kopal for trust networking for the national identity ecosystem?

3 views
Skip to first unread message

Jim Whitescarver

unread,
Mar 11, 2015, 11:41:12 AM3/11/15
to ko...@googlegroups.com
Can anyone support Kopal  with trust networking capabilities for pilot projects starting by january?  Funding would start Sept.

We planned to use Synario but that is not working out.  If you are interested we need to connect ASAP.  The proposal is due tuesday.  Our NSTIC pilot proposal made the short list last year so we have a better change of winning it this year.

Currently identity trust is delegated from an authority from the top down. User Managed Authorization (UMA) is beginning to change that for the individual but there is a lack of a mechanism for developing personal trust networks which may be found to be trustworthy at a higher level.

We are seeking public funding for bottom up evolution of a trustworthy identity ecosystem where the rules of  organizations and users participating are all obeyed for there to be any authorization of a transaction.

The project would start on or after Sept 1.  We are asking for developer resources to help build it and pilot groups that have application for it.  

At this stage we only need a promise to participate in a particular role if funded.  But time is short, we need commitments in less than a week.

The goal is establishing trust P2P creating trust circles which become trust networks for groups or organizations.

Trust would include:
1. I trust (or not) the ID provider (IdP) you trust most (yourself perhaps) to be the identity provider about yourself that I trust
2. I trust (or not) you will not divulge any of my personal information according to my rules (extended OpenUMA)
3. I trust who you trust except where I have made a choice to trust or not.

While not necessary for this project provision for trusts like "I trust you to deliver what you promise" should be considered for future projects.

The handling of independent trusts for different persona and roles of an individual is also being considered.  These correspond to aspects in Kopal with which trusts would be associated with rather than individuals.  Persona for organization also needs to be considered.

A network of FreeTrust ForgeRock IdPs would interoperate with distributed FreeTrust Kopal servers.  Trust and aspect updates would make ForgeRock API calls update user managed rules in a private and secure manner. There would be hooks in Kopal to access and update UMA rules for a trust relationships (rules) for aspects and individuals.

Let me know what you may be interested in offering.

Thanks,

Jim

Vikrant Chaudhary

unread,
Mar 11, 2015, 12:21:07 PM3/11/15
to ko...@googlegroups.com, Vikrant Chaudhary, Jim Whitescarver
Thanks for reaching out.
Yes, development on Kopal is currently stagnant, but the project is definitely not dead.
The current implementation requires some key changes in the underlying protocol to make it as efficient and responsive as current social-networks while still making the same guarantees on privacy and security of its users' data.
I'm always looking to come back to Kopal but financial needs have been constantly keeping me busy elsewhere. :-(
Kopal is NOT a small project and it would require months of dedicated development to reach to an usable state.
While I'd "love" to work full-time on Kopal and will definitely be doing so in (hopefully) near future, I can not see that happening in the immediate future unless I've strong financial incentives to do so.
Reply all
Reply to author
Forward
0 new messages