Reading Time: 2 minutes

Following two years of investigation into the future of federated trust and a community consultation, the Profiling OpenID Federation for Research and Education (PORE) Working Group has released its Recommendation for Continued InCommon Investment in OpenID Federation.

This recommendation addresses an important strategic need for InCommon’s engagement now, while standards and profiles are being shaped internationally. To ensure its ongoing interoperability with global academic federations, InCommon has a key role to play in enabling the research and education (R&E) community to take advantage of this technology. 

OpenID Federation represents the most viable path forward for delivering a crypto-agile, extensible trust infrastructure that supports both immediate needs (e.g., federated single sign-on) and emerging use cases (e.g., verifiable credentials and digital wallets).

A vector illustration of a team collaborating to stack blue blocks along an ascending red arrow, symbolizing growth and teamwork.

Marking a Milestone

One of the working group’s critical accomplishments was the development of a deployment profile for OpenID Federation tailored to R&E needs. To do so, the group documented completed sections on federation operator requirements, trust establishment procedures, and trustmark issuance. 

However, this work reached a natural stopping point. Many critical decisions cannot be made without understanding how implementations behave in production-like environments. 

The PORE Working Group, chartered by Internet2’s Community Architecture Committee for Trust and Identity (CACTI), laid essential groundwork through technical investigation and initial profile development. 

As we continue solving technology challenges together, the next phase of this work requires dedicated resources, operational infrastructure, and sustained community engagement.

Phasing in Progress

For this reason, the PORE working group has recommended a phased approach to further investment in OpenID federation. 

Phase 1: Participate and Learn

Engage with the eduGAIN OpenID Federation pilot as an observer and potential participant, including formal coordination with European federation operators leading the pilot and the contribution of requirements and use cases specific to U.S. higher education and research.

Phase 2: Resource and Develop

Allocate dedicated resources to advance both profile development and supporting infrastructure, as well as engaging community experts and working with InCommon Trusted Access Platform component architects. 

Phase 3: Pilot and Assess

Establish a pre-production/beta environment for community testing, conducting market research to identify initial community segments most likely to benefit from and adopt this technology, and deploying pilot infrastructure supporting a limited set of use cases with willing early adopters.

This phased approach will allow for InCommon’s effective participation in the global conversation about OpenID Federation, representing the needs of R&E.

Nurturing Next-Generation Trust Infrastructure

OpenID Federation represents a strategic opportunity for InCommon to establish next-generation trust infrastructure that addresses immediate operational needs while enabling future service expansion. 

The technology is mature enough to begin deployment planning but early enough in its adoption that InCommon can meaningfully influence its evolution.

InCommon’s investment in shaping OpenID Federation for R&E will yield dividends not only in improved single sign-on infrastructure but in enabling the verifiable credential ecosystems, agentic identity ecosystems, cross-institutional research collaboration platforms, and crypto-agile trust services that the community will need in the coming decade. Investing in OpenID federation will build on our efforts to strengthen trust, security, and identity across R&E.

Download and read the full Recommendation for Continued InCommon Investment in OpenID Federation.


ICYMI