Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

12/3/2018
12:40 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Microsoft, Mastercard Aim to Change Identity Management

A new partnership wants to improve how people use and manage the virtual identities that govern their lives online.

Microsoft and Mastercard have formed a partnership to change the way people use and manage their digital identities, the duo announced this morning.

Identity management is an old issue in need of new solutions as people rely on the internet to manage every part of their lives. Online identity verification still requires physical or digital proof from a central party: proof of address, driver's license or passport number, for example. The more accounts someone has, the more usernames and passwords they have to remember.

And the burden to users doesn't stop at passwords. The identity verification process is growing in complexity as companies find new ways to ensure the person logging into an account is who they claim to be. Microsoft and Mastercard want to provide a more secure and efficient way of doing that.

Their idea is to create a service designed to let people enter, control, and share their digital identity data with others, on the devices they use every day. A universally recognized digital identity could make it easier and more seamless for people to work with businesses.

This project, which brings together Microsoft's identity technology and Mastercard's digital transaction capabilities, will serve as the foundation for new Mastercard services run on Microsoft Azure, officials explain in a blog post on the news. The two are teaming up with banks, mobile network operators, and government organizations to make the idea reality.

Microsoft has been building on this idea of identity ownership, arguing that everyone should have their own digital identity within which they can privately store personal information. For businesses, this means creating ways to interact with customers, partners, and suppliers while minimizing security risks. Earlier this summer, the company created a new bug bounty program to reward researchers who found vulnerabilities in its identity services.

The potential for this "universal identity" concept crosses industries. In financial services, a single identity could accelerate the process of creating a new account or securing a loan. Shoppers browsing e-commerce sites could benefit from more personalized experiences and faster transactions across payment types, devices, and service providers.

Aside from financial opportunities, a single identity could simplify tax filing, passport applications, support payments like Social Security, and other government processes. Email, social media, entertainment services, and other lifestyle platforms could also be simplified.

Microsoft and Mastercard think their service could solve several challenges in the identity space. For starters, there are more than one billion people who aren't officially recognized, the majority of whom are women, children, and refugees. A digital identity could prove invaluable in helping people obtain health, financial, and social services they may not otherwise access.

"Today's digital identity landscape is patchy, inconsistent and what works in one country often won't work in another," says Ajay Bhalla, president of cyber and intelligence solutions at Mastercard, in a statement. "We have an opportunity to establish a system that puts people first, giving them control of their identity data and where it is used."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
tDi443
50%
50%
tDi443,
User Rank: Strategist
12/10/2018 | 3:18:41 PM
Re: BLOCKCHAIN
https://www.ccn.com/mastercard-applies-for-new-patent-for-anonymous-blockchain-transactions-a-regulated-bitcoin-tumbler/
Jessica Rochelle
50%
50%
Jessica Rochelle,
User Rank: Apprentice
12/10/2018 | 12:16:08 AM
Re: PCI and security
I am very much pleased with the contents you have mentioned. I wanted to thank you for this great article. 
hungthaixa
50%
50%
hungthaixa,
User Rank: Apprentice
12/7/2018 | 11:18:02 PM
Good article
I like this article. Thanks to that I understand a lot
tDi443
100%
0%
tDi443,
User Rank: Strategist
12/7/2018 | 12:55:57 PM
Re: BLOCKCHAIN
It looks like they are going with AI based sevices for this program. I would be extremely leary of the possiblity for massive privacy abuses by these stakeholders. That's even if they can manage to keep it secure from the hands of criminals and state sponserd hackers. My biggest fear is that this technology would ever fall into the hands of any government.  This identity managerment sceme seeks to create a Universal Online Identiy for everone that uses thier products and services. So basically these corporations will OWN our Cyber-DNA. Very Dangerous concept. I would feel much more  comfortable with a blockchain type solution that could at least protect some sort of anonimity and privacy. It would most likely be a much more secure soolution to the problem of identity managment. 
tDi443
100%
0%
tDi443,
User Rank: Strategist
12/7/2018 | 12:20:49 PM
Re: BLOCKCHAIN
I'm just wondering if these companies will be utulizing blockchain technology in this project. Seems to me like it would be a no-brainer. Ah, but what do I know?
Agent Aix les Bains
50%
50%
Agent Aix les Bains,
User Rank: Apprentice
12/7/2018 | 9:45:37 AM
Re: BLOCKCHAIN
What do you mean ?
tDi443
50%
50%
tDi443,
User Rank: Strategist
12/5/2018 | 1:45:03 AM
BLOCKCHAIN
?
ebyjeeby
100%
0%
ebyjeeby,
User Rank: Strategist
12/4/2018 | 2:05:09 PM
Re: PCI and security
Agreed. Wait for Amazon and VISA to unviel a competing product.
jenshadus
100%
0%
jenshadus,
User Rank: Strategist
12/4/2018 | 9:39:46 AM
PCI and security
I wonder how this will affect PCI and how other CC companies will adapt the new technology.  Guess it all depends on royalties and such.  Then there is iPhone versus the google phones to content with.  This looks like it might be an uphill battle.  Unless they get everyone to play the game it doesn't do the end user much good,
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This is not what I meant by "I would like to share some desk space"
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-1303
PUBLISHED: 2021-01-20
A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerability is due to improper enforcement of actions for assigned user roles. An attacker could exploit this vulnerability by...
CVE-2021-1304
PUBLISHED: 2021-01-20
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not autho...
CVE-2021-1305
PUBLISHED: 2021-01-20
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not autho...
CVE-2021-1312
PUBLISHED: 2021-01-20
A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device. The vulnerability is due to inadequate provisioning of kernel parameters f...
CVE-2021-1349
PUBLISHED: 2021-01-20
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. The vulnerability is due to insufficient input validation by the web-based management interf...