<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : EnCoRe</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx</link><description>Tags: EnCoRe</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Update about TSB UK EnCoRe Project – Ensuring Consent and Revocation</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118173.aspx</link><pubDate>Mon, 02 Nov 2009 17:54:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:118173</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/11/03/118173.aspx#comments</comments><description>&lt;p&gt;The 5&lt;sup&gt;th&lt;/sup&gt; Quarter Summary of EnCoRe (&lt;a href="http://www.encore-project.info/"&gt;http://www.encore-project.info&lt;/a&gt;) R&amp;amp;D activities in the space of Consent and Revocation management is now available online at: &lt;a href="http://www.encore-project.info/press_archive/Q5%20summary.pdf"&gt;http://www.encore-project.info/press_archive/Q5%20summary.pdf&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;In addition, a new &amp;quot;service&amp;quot; has been launched, about &amp;quot;Latest EnCoRe Tidbits&amp;quot; aiming at providing links to snippets of news related to consent and revocation: &lt;a href="http://www.encore-project.info/news.html#story1"&gt;http://www.encore-project.info/news.html#story1&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;More to come. Enjoy.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=118173" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category></item><item><title>Good progress in the TSB EnCoRe Project – Ensuring Consent and Revocation</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104917.aspx</link><pubDate>Tue, 25 Aug 2009 12:01:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:104917</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104917.aspx#comments</comments><description>&lt;p&gt;The &lt;a href="http://www.encore-project.info/"&gt;TSB EnCoRe project&lt;/a&gt; (Ensuring Consent and Revocation) is making good progress towards his various objectives, involving the provision and management of consent and revocation.&lt;/p&gt;
&lt;p&gt;This topic has been tackled from various perspectives including: legal and social aspects, user requirements, architectural and technological aspects, risk assessment and compliance.&lt;/p&gt;
&lt;p&gt;More information is available on the EnCoRe web site, including a brief &lt;a href="http://www.encore-project.info/press_archive/Q4%20summary.pdf"&gt;summary of the project&amp;#39;s fourth quarter activities&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=104917" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category></item><item><title>Do Enterprises know where they store personal data? </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/18/do-enterprises-know-where-they-store-personal-data.aspx</link><pubDate>Wed, 18 Mar 2009 10:03:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88435</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/18/do-enterprises-know-where-they-store-personal-data.aspx#comments</comments><description>&lt;p&gt;Apparently most of enterprises don&amp;#39;t, at least based on this survey, called &amp;quot;&lt;a href="http://www.pwc.com/extweb/insights.nsf/docid/0E50FD887E3DC70F852574DB005DE509/$File/Safeguarding_the_new_currency.pdf"&gt;Safeguarding the Currency of Business&lt;/a&gt;&amp;quot;, where they found that &amp;quot;71 percent of organizations queried said they did not have an accurate inventory of where personal data for employees and customers is stored&amp;quot;.&lt;/p&gt;
&lt;p&gt;This has strong implications (among other things ...) from a privacy perspective, in particular from a consent and revocation management angle - as also currently highlighted in a recent HP Labs report of ours (&amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-49.html"&gt;On the Management of Consent and Revocation in Enterprises: Setting the Context&lt;/a&gt;&amp;quot;). &lt;/p&gt;
&lt;p&gt;Hopefully we will explore how to tackle some of the related issues in the &lt;a href="http://www.encore-project.info/"&gt;UK TSB EnCoRe project&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88435" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Storage/default.aspx">Storage</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Personal+data/default.aspx">Personal data</category></item><item><title>Twitter and its Privacy and Identity Management Implications</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx</link><pubDate>Thu, 12 Mar 2009 09:33:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88332</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx#comments</comments><description>&lt;p&gt;I recently started using Twitter (my link: &lt;a href="http://twitter.com/MCasassaMont"&gt;http://twitter.com/MCasassaMont&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Twitter it getting more and more popular within (and across) organisations in particular for geographically distributed teams, to share their activities and whereabouts.&lt;/p&gt;
&lt;p&gt;I am interested to better understand this tool, in particular in terms of its identity and privacy implications and long term repercussions for individuals and organisations. &lt;/p&gt;
&lt;p&gt;I see some interesting research to be potentially carried out in the context of the &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics R&amp;amp;D project&lt;/a&gt; at HP Labs and &lt;a href="http://www.encore-project.info/"&gt;UK TSB EnCoRe project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88332" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Twitter/default.aspx">Twitter</category></item><item><title>Built-in Data Loss Prevention and Analogy with Privacy Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/05/built-in-data-loss-prevention-and-analogy-with-privacy-management.aspx</link><pubDate>Fri, 05 Dec 2008 13:51:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86908</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/05/built-in-data-loss-prevention-and-analogy-with-privacy-management.aspx#comments</comments><description>&lt;p&gt;I have just read this interesting article, called &amp;quot;&lt;a href="http://www.channelinsider.com/c/a/Security/Microsoft-RSA-Partner-to-Develop-NextGen-Data-Loss-Prevention/"&gt;Microsoft, RSA Partner to Develop Next-Gen data Loss Prevention&lt;/a&gt;&amp;quot;, by Lawrence Walsh:&lt;/p&gt;
&lt;p&gt;&amp;quot;The alliance between Microsoft and RSA will move data loss prevention technology into the fabric of the IT infrastructure and improve protection by associating data with identities and classifications. Analysts are already calling the idea a &amp;quot;game changer.&amp;quot;&amp;quot;&lt;/p&gt;
&lt;p&gt;The main message I got is that we need to move away from bolt-on solutions, towards &amp;quot;built-in DLP approaches&amp;quot;. I tend to agree with this approach, despite being much harder to achieve.&lt;/p&gt;
&lt;p&gt;This has some interesting analogies with privacy and the way privacy management is currently carried out, at least with most of current privacy-enhancing technology (PET) approaches. I believe that we need to move toward built-in approaches too, that require deep understanding of the interconnections with the relevant &amp;quot;IT infrastructure fabric&amp;quot;, related business processes (and needs), along with involved risks and their potential impact. &lt;/p&gt;
&lt;p&gt;So, I believe this is something to consider very carefully, for example, in the context of the &amp;quot;Consent and Revocation Management&amp;quot; R&amp;amp;D area, within the &lt;a href="http://www.encore-project.info/"&gt;TSB EnCoRe project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86908" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/built-in+approach/default.aspx">built-in approach</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/data+loss+prevention/default.aspx">data loss prevention</category></item><item><title>Part II: TSB EnCoRe Project – Ensuring Consent and Revocation</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/10/28/part-ii-tsb-encore-project-ensuring-consent-and-revocation.aspx</link><pubDate>Mon, 27 Oct 2008 21:59:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86346</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/10/28/part-ii-tsb-encore-project-ensuring-consent-and-revocation.aspx#comments</comments><description>&lt;p&gt;In a previous &lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/20/announcing-encore-ensuring-consent-and-revocation-a-new-uk-it-collaborative-project.aspx"&gt;post of mine&lt;/a&gt;, I announced the UK TSB EnCoRe project, focusing on research on Consent and Revocation.&lt;/p&gt;
&lt;p&gt;A new version of the &lt;a href="http://www.encore-project.info/"&gt;EnCoRe web site&lt;/a&gt; is now available online.&lt;/p&gt;
&lt;p&gt;I would be interested in getting your views and input on two aspects:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prior art and work in the space of consent and revocation. In a first analysis, very little work is available in terms of automation of revocation of consent, in a wide sense. Any known work/solution in this space?&lt;/li&gt;
&lt;li&gt;Your (user) requirements in the space of consent and revocation &lt;/li&gt;&lt;/ul&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86346" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/consent/default.aspx">consent</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/revocation/default.aspx">revocation</category></item><item><title>Announcing EnCoRe (Ensuring Consent and Revocation): a new UK IT Collaborative Project</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/20/announcing-encore-ensuring-consent-and-revocation-a-new-uk-it-collaborative-project.aspx</link><pubDate>Fri, 19 Sep 2008 16:23:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84822</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/20/announcing-encore-ensuring-consent-and-revocation-a-new-uk-it-collaborative-project.aspx#comments</comments><description>&lt;p&gt;A new UK IT collaborative project has been officially announced: &lt;a href="http://www.encore-project.info/"&gt;EnCoRe&lt;/a&gt; - Ensuring Consent and Revocation (some initial press releases: &lt;a href="http://uk.news.yahoo.com/vdunet/20080912/ttc-encore-project-aims-to-boost-user-pr-6315470.html"&gt;here&lt;/a&gt; and &lt;a href="http://www2.warwick.ac.uk/fac/sci/wmg/mediacentre/wmgnews/uk_academics_turn/"&gt;here&lt;/a&gt;):&lt;/p&gt;
&lt;p&gt;&amp;quot;As more and more personal information flows from individuals to organisations when they interact online, people are becoming more and more concerned that they can not effectively control what this information is used for, with which other organisations it is shared, and where it is stored. They may have given their consent, often in vague terms and implicitly, for its use, sharing and storage, but they have no real control over the specifics of these, nor the ability to revoke their consent and be sure that their wish is respected. In summary, they are not able to control where their personal information flows to, and this makes them uneasy about interacting online.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;The overall vision of this project is to make giving consent as reliable and easy as turning on a tap, and revoking that consent as reliable and easy as turning it off again.&amp;quot;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;This &lt;span style="FONT-SIZE:12pt;FONT-FAMILY:&amp;#39;Times New Roman&amp;#39;;mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-ansi-language:EN-GB;mso-fareast-language:EN-GB;mso-bidi-language:AR-SA;"&gt;£3.6m&lt;/span&gt; project consortium is multi-disciplinary, spanning across a number of IT and social science specialisms. The project partners are Hewlett-Packard Laboratories, HW Communications, QinetiQ, the London School of Economics, the Ethox Centre of the University of Oxford and the University of Warwick. &lt;/p&gt;
&lt;p&gt;The EnCoRe project runs from June 2008 to November 2011. It receives funding from the &lt;a href="http://www.innovateuk.org/"&gt;UK Government&amp;#39;s Technology Strategy Board&lt;/a&gt;, &lt;a href="http://www.esrc.ac.uk/ESRCInfoCentre/index.aspx"&gt;Economic &amp;amp; Social Research Council &lt;/a&gt;and &lt;a href="http://www.epsrc.ac.uk/default.htm"&gt;Engineering &amp;amp; Physical Sciences Research Council&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84822" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/consent/default.aspx">consent</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/revocation/default.aspx">revocation</category></item></channel></rss>