Thoughts on the Attribute Exchange proposal.

Wayne Pierce wayne at knowngood.com
Fri Mar 9 19:25:47 UTC 2007


Hello,

I am new to the list, but have been following OpenID from a short
distance for a while.  Unfortunately I just found out about the
Attribute Exchange proposal, I say unfortunately because I have been
working on something similar, albeit very very slowly, for a couple of
years.  I was going to submit a spec to OpenID when I discovered the
existing Attribute Exchange spec.

My project was "side tracked" due to a Military deployment.  The
location of my project is http://xri.net/=Pierce/code.knownGood .
Most of the work I have done at this point is in talking to people and
learning what their problems are.  From this I have been working on an
approach to solving all of their common problems.

There are two main areas that I have not seen discussed in the
archives or documents, at least not to the extent of addressing some
of the issues people have raised with me.

  1. Updating information.  When I update an attribute is there any
proposed way to notify subscribers without the subscribers having to
poll my URI?

  2. Is there any way for an entity to create a collection of
attributes for individuals to associate values with?  I saw a
reference to "Personas" in one of the documents but these seemed to be
user-derived.

The system I have been looking at is very similar, but seems to start
from a different perspective.  My starting point was about making an
organization more efficient and easing the burden of updating my
information with multiple organizations at once.

To accomplish this I was looking at ways to allow an organization to
create "Profiles" of Attributes.  In the talks I have had with people
they seemed to want profiles that match their existing HR documents or
data they would like to collect but have no documents or processes
for.

Individuals would then associate Attributes with the fields for a
Profile, when the local Attribute was updated any Profile containing
that Attribute would be updated.  This would trigger an update to the
authorized organizations.

Other things I have looked at are ways to secure the data, potentially
using GnuPG and building a client application for managing the
Attributes and Profiles.

I am still reading some of the specs and mailing list archive, but I
will help out where I can.

Wayne
-- 
Phone: 414.208.0808
Blog: http://xri.net/=Pierce/(+blog)

Learn something from everybody.  Some people will teach you what to
do, while others will teach you what not to do.



More information about the specs mailing list