Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

IBM's 'Need to Know' Software

IBM's Idemix application lets consumers do business on the Web without giving away unnecessary personal data

You've seen it before: A Website wants to verify that you're over 18, so they require you to enter a credit card number. They want to prove that you're a U.S. citizen, so they require a driver's license number or Social Security ID. And there you go again -- putting your entire electronic identity at risk just to enter an electronic contest or buy online movie tickets.

Can't Websites find a way to get the data they need without forcing you to input the very information that identity thieves crave?

Later this year, some Websites may be able to do just that. IBM today announced software that allows people to hide or make anonymous their personal information on the Web. Developed by researchers at IBM's laboratory in Zurich, Switzerland, the software (codenamed Identity Mixer, or Idemix for short) will enable consumers to purchase goods and services on the Internet while disclosing only the personal information the merchant truly needs to know.

As consumers hand over personal details in exchange for downloading music or subscribing to online newsletters, they leave a data trail that reveals pieces of information about the size, frequency, and source of their online purchases. This can be traced back to the user, IBM observes. IBM's Idemix software eliminates that trail by using artificial identity information -- called "pseudonyms" -- to make online transactions anonymous.

For example, the software allows people to purchase books or clothing without revealing their credit card number. It can confirm someone's spending limit without sharing their bank balance, or provide proof of age without disclosing date of birth.

Essentially, Idemix is a cryptographic go-between, explains Nataraj Nagaratnam, chief architect for identity management at IBM's Tivoli unit. "It lets the user establish trust without giving up their privacy."

With Idemix software, a user can get an anonymous digital credential, or voucher, from a trusted third party, like a bank or government agency, such as the Department of Motor Vehicles. A bank would provide a credential containing a credit card number and expiration date, and when an online purchase is made, the Idemix software digitally seals the information by transforming the credential so the user can send it to the online merchant.

By using sophisticated cryptographic algorithms, the Idemix software acts as the middleman confirming bank authorization for the purchase -- so the real credit card numbers are never revealed to the merchant. The next time a purchase is made, a new, encrypted credential would be used.

"When people don't have to disclose their personal information on the Web, the risk of identity theft is dramatically reduced," explains John Clippinger, senior fellow at the Berkman Center for Internet and Society at Harvard Law School. "The ability to anonymize transactions using Idemix has the potential to bolster consumer confidence."

IBM will contribute its Idemix software to the Eclipse Higgins project, an open source effort dedicated to developing software for "user-centric" identity management. As Nagaratnam explains it, the goal is to create a "digital wallet" in which the user can establish various "tokens" of trust and authentication, such as credit cards, driver's licenses, bank accounts, and so forth. Depending on the online transaction, the user could supply one or more of these tokens to provide the necessary third-party verifications -- without actually giving the token to the merchant.

IBM plans to deliver Idemix later this year, and it will probably be another year or two before the fruits of Idemix and the Higgins project will become widely available to consumers, Nagaratnam says. But technologies such as Idemix and Microsoft's CardSpace -- a function of Vista -- will eventually help end users build a secure way to store personal information while continuing to do business online, he says.

"The market is finally going to have its chance to test the theories and the hype behind the electronic information card," said Mike Neuenschwander, research director for Burton Group's Identity and Privacy Strategies service, in a report issued earlier this week. "With the appearance of Microsoft CardSpace, user-centric identity technologies are moving off the discussion boards and into products."

— Tim Wilson, Site Editor, Dark Reading

  • IBM Corp. (NYSE: IBM)
  • Microsoft Corp. (Nasdaq: MSFT)
  • IBM Tivoli Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Threaded  |  Newest First  |  Oldest First
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 9/21/2020
    Hacking Yourself: Marie Moe and Pacemaker Security
    Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
    Startup Aims to Map and Track All the IT and Security Things
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    Special Report: Computing's New Normal
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    How IT Security Organizations are Attacking the Cybersecurity Problem
    How IT Security Organizations are Attacking the Cybersecurity Problem
    The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2015-4719
    PUBLISHED: 2020-09-24
    The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
    CVE-2020-15604
    PUBLISHED: 2020-09-24
    An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CW...
    CVE-2020-24560
    PUBLISHED: 2020-09-24
    An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CW...
    CVE-2020-25596
    PUBLISHED: 2020-09-23
    An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. T...
    CVE-2020-25597
    PUBLISHED: 2020-09-23
    An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, will not become invalid over the life time of a guest. Howeve...