IBM Shields Online Personal Data

'Identity Mixer' will allow customers to purchase items without revealing info.

Researchers at IBM have created a new shield for personal information to help prevent identity theft online.

Code-named Identity Mixer—or Idemix for short—the software was crafted by IBM researchers at the companys laboratory in Zurich, Switzerland, and will let customers buy goods and services online without revealing their personal information.

To Jan Camenisch, the projects lead researcher, it makes sense that minimizing the number of parties with personal information will reduce the threat of the data being compromised.

"I think thats the first step in safeguarding your data," he said. "If they have it encrypted, they cant lose it."

Idemix works by allowing the consumer using the software to get an anonymous digital credential, or voucher, from a trusted third party, such as a bank. Government agencies can also serve as third parties, Camenisch said.

The bank would provide a credential containing a credit card number and expiration date that would be digitally sealed by the Idemix software when an online purchase is made. As a result, the real credit card numbers are never revealed to the merchant. A new encrypted credential would be used every time a new purchase is made.

"When people dont have to disclose their personal information on the Web, the risk of identity theft is dramatically reduced," said John Clippinger, senior fellow at the Berkman Center for Internet and Society at Harvard Law School, in Cambridge, Mass. "The ability to anonymize transactions using Idemix has the potential to bolster consumer confidence, opening digital floodgates to new forms of Internet commerce."

IBM, of Armonk, N.Y., will contribute its Idemix software to the Higgins project, an open-source effort led by the Eclipse Foundation aimed at developing user-centric software to manage and protect user identities.

A user-centric approach means individuals can actively and securely control who has access to their online personal information, such as bank accounts, credit card numbers and medical records, rather than having institutions manage the data, IBM officials said.

Currently, the softwares code is going through the Eclipse Foundations intellectual property review process, IBM officials said. Once thats completed, the code will be available on Eclipse through the Higgins project.

The Idemix software will provide the required added layer of privacy to the Project Higgins framework for true user centric identity management, IBM officials said. IBM plans to incorporate the Idemix technology into its Tivoli software portfolio of federated identity management software, Camenisch said, adding that the software offers more protection than Microsofts CardSpace.

Analyst Jon Oltsik said he is optimistic that the fact the software is open source would have a positive impact on the speed of its widespread adoption.

"In the identity space, weve seen a lot of progress with open standards for federated identity," said Oltsik, of Enterprise Strategy Group. "There is no reason why open source wouldnt follow suit. Also, this is being managed by the Eclipse Foundation, which is getting a lot of enterprise and industry attention."

He added that the software has the potential to be effective in reducing the risk of personal data being compromised by businesses.

"Idemix lets a user control who has access to what data," Oltsik said. "In addition, it can work as a trusted response. Rather than asking my bank for an exact bank balance, a mortgage company could ask a yes-no question, like, Does this person have a balance in excess of $25? and get a trusted yes-no response. In this way, we can pass the information necessary for transactions while protecting other private data."

Ron OBrien, an analyst with Sophos, said many people have become cautious online and are skeptical of e-commerce because of security concerns. This software, he said, can go a long way in giving online shoppers peace of mind.

"I think this is a huge first step in terms of keeping people using the Internet as it was intended," he said. ´