New OpenID Connect Standard Extends Digital Identities Across the Web

A new standard for Internet security and privacy has been ratified by the OpenID Foundation. Organizations can now use OpenID Connect to develop secure, flexible and interoperable identity Internet ecosystems, allowing digital identities to be used across websites and applications via any computing or mobile device.

OpenID Connect enables applications to outsource the business of identity verification to specialist identity service operators, called identity providers, while still managing their relationships with users. The standard has been implemented worldwide by Internet and mobile companies such as Google, Microsoft, Salesforce.com, Ping Identity, Nomura Research Institute, mobile network operators and other companies and organizations. It will be built into commercial products and implemented in open source libraries for global deployment.

"Widely available secure, interoperable digital identity is the key to enabling easy-to-use, high-value cloud-based services for the devices and applications that people use," said Alex Simons, director of program management for Microsoft Active Directory, in a prepared statement. "OpenID Connect fills the need for a simple yet flexible and secure identity protocol and also lets people leverage their existing OAuth 2.0 investments."

Next week at the London headquarters of mobile operators association GSMA, OpenID Foundation members will meet with counterparts at the GSMA to begin work on interoperability across global mobile network operators. The OpenID Foundation, the Open Identity Exchange and the GSMA are collaborating on pilot and discovery projects and in 2014 will begin testing how OpenID Connect implementations can enhance online choice, efficiency, security and privacy.

Mobile Connections
Building on the OpenID Connect standard, the GSMA association for mobile operators recently launched Mobile Connect, a collaborative effort to develop a new service that will allow consumers to securely access a wide array of digital services using their mobile phone account for authentication.

"The GSMA's role is to work with the mobile operators to deliver relevant services to their customers; one such area that is growing in importance is the use of the mobile phone for authentication or identification purposes," said Marie Austenaa, head of personal data for the organization, in a press release. "In order to achieve global scale and ease of implementation both for mobile operators and for the service providers, it is important to have a consistent approach — and this is what OpenID Connect provides."

About the Author

Rhea Kelly is editor in chief for Campus Technology, THE Journal, and Spaces4Learning. She can be reached at [email protected].

Featured

  • glowing crystal ball with network connections

    Call for Opinions: 2026 Predictions for Higher Ed IT

    How will the technology landscape in higher education change in the coming year? We're inviting our readership to weigh in with their predictions, wishes, or worries for 2026.

  • digital book with circuit patterns

    Turnitin and ACUE Partner on AI Training for Educators

    Turnitin is teaming up with the Association of College and University Educators to create a series of courses on AI and academic integrity designed to help faculty navigate the responsible use of AI in learning and assessment.

  • Hand holding a stylus over a tablet with futuristic risk management icons

    Why Universities Are Ransomware's Easy Target: Lessons from the 23% Surge

    Academic environments face heightened risk because their collaboration-driven environments are inherently open, making them more susceptible to attack, while the high-value research data they hold makes them an especially attractive target. The question is not if this data will be targeted, but whether universities can defend it swiftly enough against increasingly AI-powered threats.

  • Red alert symbols and email icons floating in a dark digital space

    Google Cloud Report: Cyber Attackers Are Fully Embracing AI

    According to Google Cloud's 2026 Cybersecurity Forecast, AI will become standard for both attackers and defenders, with threats expanding to virtualization systems, blockchain networks, and nation-state operations.