{"id":194,"date":"2007-01-26T20:18:07","date_gmt":"2007-01-27T00:18:07","guid":{"rendered":"http:\/\/blogs.law.harvard.edu\/ugasser\/2007\/01\/26\/the-mobile-identity-challenge-some-ob"},"modified":"2007-01-26T20:53:19","modified_gmt":"2007-01-27T00:53:19","slug":"the-mobile-identity-challenge-some-observations-from-the-sfo-mid-wo","status":"publish","type":"post","link":"https:\/\/archive.blogs.harvard.edu\/ugasser\/2007\/01\/26\/the-mobile-identity-challenge-some-observations-from-the-sfo-mid-wo\/","title":{"rendered":"The Mobile Identity Challenge &#8211; Some Observations from the SFO mID-Workshop"},"content":{"rendered":"<p>I\u2019m currently in wonderful San Francisco, attending the Berkman Center\u2019s <a href=\"http:\/\/cyber.law.harvard.edu\/identity\/Mobile_Identity_Workshop\">Mobile Identity workshop<\/a> \u2013 a so-called <a href=\"http:\/\/en.wikipedia.org\/wiki\/Open_Space_Technology\">\u201cunconference\u201d<\/a> &#8212; led by my colleagues <a href=\"http:\/\/cyber.law.harvard.edu\/home\/doc_searls\">Doc Searls<\/a>, <a href=\"http:\/\/cyberlaw.stanford.edu\/blogs\/rundle\/archives001535.shtml\">Mary Rundle<\/a>, and <a href=\"http:\/\/cyber.law.harvard.edu\/home\/john_clippinger\">John Clippinger<\/a>. We\u2019ve had very interesting discussions so far, covering <a href=\"http:\/\/cyber.law.harvard.edu\/identity\/Topics_for_discussion\">various topics<\/a> ranging from <a href=\"http:\/\/cyber.law.harvard.edu\/projectvrm\/Main_Page\">Vendor Relationship Management<\/a> to mobile identity in developing countries.<\/p>\n<p>In the context of digital identity in general and user-centric identity management systems in particular, I\u2019m especially interested the question as to what extent the issues related to mobile ID are distinct from the <a href=\"http:\/\/blogs.law.harvard.edu\/ugasser\/tag\/eid\/\">issues we\u2019ve been exploring<\/a> in the browser-based and traditionally wired desktop-environment. Here\u2019s my initial take on it:<\/p>\n<p>Although mobile identity can be best understood as part of the generic concept of digital identity and despite the fact that identity as such has some degrees of mobility by definition, I would argue that mobile (digital) identity has certain characteristics that might (or should) have an impact on the ways we frame and address the identity challenges in this increasingly important part of the digitally networked environment. I would argue that the characteristics, by and large, may be mapped onto four layers.<\/p>\n<ul>\n<li><strong>Hardware layer<\/strong>: First and most obviously, <a href=\"http:\/\/en.wikipedia.org\/wiki\/Mobile_devices\">mobile devices<\/a> are characterized by the fact that we carry them with us \u2013 from location to location. This physical dimension of mobility has a series of implications regarding identity management, especially at the logical and content layer (see below), but also with regard to vulnerabilities such as theft and loss. In addition, the devices themselves have distinct characteristics \u2013 ranging from relatively small screens, small keyboards to limited computing power, but also SIM cards, among other things &#8212; that might shape the design of the identity management solution.<\/li>\n<li><strong>Logical layer:<\/strong> One of the consequences of location-to-location mobility and multi-mode devices is that identity issues have to be managed in a <em>heterogeneous<\/em> wireless infrastructure environment, which includes multiple providers of different-generation cellular networks, public and private WiFi, Bluetooth, etc., that are using different technologies and standards, and are operating under different incentive structures. This links  back to our last week&#8217;s discussion about <a href=\"http:\/\/cyber.law.harvard.edu\/home\/home?wid=10&amp;func=viewSubmission&amp;sid=2564\">ICT interoperability<\/a>.<\/li>\n<li><strong>Content layer:<\/strong> The characteristics of mobile devices have ramifications at the content layer. Users of mobile devices are limited in what they can do with these devices. Arguably, mobile device users tend to carry out rather specific information requests, transactions, tasks, or the like \u2013 as opposed to open, vague and time-consuming \u201cbrowsing\u201d activities. This demand has been met on the supply-side with application and service providers offering location-based and context-specific content to mobile phone users. This development, in turn, has increased the exchange of location data and contextual information among user\/mobile device and application\/service providers. Obviously, the increased relevance of such data adds another dimension to the digital ID and privacy discussion.<\/li>\n<li><strong>Behavioral layer<\/strong>: The previous remarks also make clear that different dimensions of mobility and the characteristics of mobile devices lead to different uses of mobile devices when compared to desktop-like devices. The type and amount of personal information, for example, that is disclosed in a mobile setting is likely to be distinct from other online settings. Furthermore, portable devices get more often lost (or stolen) than non-portable devices. These \u201cbehavioral\u201d characteristics might vary among cultural contexts &#8211; a fact that might add to the complexity of mobile identity management (<a href=\"http:\/\/cyber.law.harvard.edu\/home\/bio_cmaclay\">Colin Maclay<\/a>, for instance, pointed out that sharing cell phones is a common practice in low income countries.)<\/li>\n<\/ul>\n<p>Today, I got the sense that the technologists in the room have a better understanding of how to deal with the characteristics of mobile devices when it comes to digital identity management. At least it appears that technologists have identified both the opportunities and challenges associated with these features. I\u2019m not sure, however, whether we lawyers and policy people in the room have fully understood the implications of the above-mentioned characteristics, among others, with regard to identity management and privacy issues. It only seems plain that many of the questions we\u2019ve been discussing in the digital ID context get even more complicated when we move towards ubiquitous computing. (One final note in this context: I\u2019m not sure whether we focused too much on mobile phones at this workshop \u2013 ID-relevant components of the mobile space such as <a href=\"http:\/\/en.wikipedia.org\/wiki\/RFID\">RFID<\/a> tags, for instance, have remained largely unaddressed &#8211; at least in the sessions I attended.)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I\u2019m currently in wonderful San Francisco, attending the Berkman Center\u2019s Mobile Identity workshop \u2013 a so-called \u201cunconference\u201d &#8212; led by my colleagues Doc Searls, Mary Rundle, and John Clippinger. We\u2019ve had very interesting discussions so far, covering various topics ranging from Vendor Relationship Management to mobile identity in developing countries. In the context of digital [&hellip;]<\/p>\n","protected":false},"author":202,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1265,1172,1281,1282,1057],"tags":[],"class_list":["post-194","post","type-post","status-publish","format-standard","hentry","category-digital-id","category-eid","category-miw2007","category-mobile","category-web-20"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/posts\/194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/users\/202"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/comments?post=194"}],"version-history":[{"count":0,"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/posts\/194\/revisions"}],"wp:attachment":[{"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/media?parent=194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/categories?post=194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/ugasser\/wp-json\/wp\/v2\/tags?post=194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}