Integrity - use of values or principles to guide action in the situation at hand.

Below are links and discussion related to the values of freedom, hope, trust, privacy, responsibility, safety, and well-being, within business and government situations arising in the areas of security, privacy, technology, corporate governance, sustainability, and CSR.

Liberty Alliance Project - Trust and Security - It's all about privacy!, 16.6.05


The Liberty Specifications were built with privacy in mind.

The decisions made in developing technology were all made to enhance privacy and make it easier to implement good privacy practices.

Non Technical Privacy Features

  • Consumer consent
    • All of the relevant specifications include the reference to the need of consumer consent for relevant transactions.

  • Consumer choice of Identity Providers
    • Federated architecture allows consumer to choose an Identity Provider independent of the used network or service.
    • Selection is only constrained by laws, regulations and business models, not the Liberty specifications

  • Decentralized or federated storage of PII or other information related to your identity
    • Federated architecture allows the information related to a specific identity to be stored in relevant locations defined by the consumer, government or business relationship between the consumer and certain Service Provider
    • Storage of PII or other identity related information is only constrained by laws, regulations and business models, not the Liberty specifications
    • Simplified password management

    Technical Privacy Features

  • XML Signature - XMLDSig allow a proper verification of the transaction parties, and if messages are signed and stored, allows for later auditing
  • Pseudonymous access - Identity Federation in Liberty creates a pseudonym, constructed of a random set of characters and being unique in the context of a specific Identity Provider and Service Provider
  • Anonymous Access - Liberty specs provide means for a Service Provider to access Identity Services without a need to know who the consumer they are providing services to really is.
  • Usage Directives - Allows for indication of associated privacy policy in both a request and reply for principal attributes
  • Consent header block - SOAP header block used to explicitly assert that the Principal consented to the present interaction
  • Interaction Service - The Interaction Service specification defines schemas and profiles that enable an Identity Service to interact with the owner of the information exposed by that Identity Service

