Search This Blog

Thursday, October 18, 2007

Call for Participation: W3C Workshop on Video on the Web

W3C issued a Call For Participation in an open "W3C Workshop on Video
on the Web", to be held December 12-13, 2007 in San Jose, California,
USA, hosted by Cisco Systems. Position papers are due November 21, 2007.
The high-level goal: Make video a first class Web citizen, including
making it easy to create, link to and from, describe, and search. Part
of making video a first class Web citizen will involve addressing issues
of accessibility, internationalization, privacy, digital rights,
performance, and device-independence. Web based video is exploding.
More and more we are seeing video on the Web used for advertising,
enterprise collaboration, entertainment, product reviews, and other
applications. As prices drop for consumer electronics, amateur and
professionals alike are creating increasingly high quality videos.
Social networks are sprouting up around Web-delivered media. "IP TV"
(Internet-based delivery of television programming) is also maturing
quickly. These rapid changes are posing challenges to the underlying
technologies and standards to support the platform-independent creation,
authoring, encoding/decoding, and description of video. W3C encourages
people interested in the topics to participate in the Workshop;
in-scope topics include strategic thinking about video on the Web,
user experience, video production, and Web architecture. W3C membership
is not required in order to participate in the Workshop; there is no
participation fee, but registration is required. Position papers are
the basis for the discussion at the Workshop. Position papers, agenda,
accepted presentations, and report will be published online.

SAP Open Sources Memory Analysis

SAP has announced its first contribution to the Eclipse developer
community, previously only available in its NetWeaver stack. Memory
Analyzer, which was developed under the Eclipse Public License, is
intended to make life easier for developers building applications that
require lots of memory. Developers use the Eclipse Framework to create
applications and toolkits for Java and other programming languages.
The framework includes the open source, Java-based Eclipse integrated
development environment (IDE) on which SAP's NetWeaver is based. Other
competitive Java IDEs are also based on the Eclipse IDE, including
those from IBM's Rational, BEA, and Oracle among others who may now
also potentially benefit from this SAP contribution. SAP was an original
member of the Eclipse consortium, which began in 2001, and it was a
founding member of the Eclipse Foundation in 2004, so it's not
surprising it chose Eclipse to contribute to. Memory Analyzer provides
a graphics-based snapshot of object-retention patterns and provides
developers with the information they need to optimize memory usage
without interrupting the business applications in use or crashing the
Java virtual machine hosting the application. Michael Bechauf, vice
president of standards for SAP's Global Ecosystems and Partner Group,
said SAP held off on sharing the code until it was confident the
Eclipse environment was developed enough to support the needs of
large enterprise customers running multiple, high-volume applications
at the same time. A Memory Analyzer plug-in has been available for
download from SAP's Web site at no cost for more than a year.

HTTP Response Signing Abstract Model

I've argued that there's a need for an HTTP-specific mechanism for
signing HTTP responses. So let's try and design one. Usually at this
point, I would start coding, but with security-related stuff, I think
it's better to have more discussion up front... Let's suppose that the
mechanism will take the form of a new Signature header. Here is my
current thinking as to the steps involved in constructing a Signature
header: [eleven steps in the abstract design]... (1) What kinds of
security token can be used? At least X.509 certificates should be
supported. But there should be the potential to support other kinds
of token. (2) How are security tokens identified? It depends on the
type. For X.509, it would make sense to have a URI that allowed the
client to fetch the certificate. It would also be desirable to have
an identifier that uniquely identifies the certificate, so that the
client can tell whether it already has the certificate without having
to go fetch it. As far as I can tell, in the X.509 case, people mostly
use the SHA-1 hash of the DER encoding of the certificate for this.
(3) How does the server know what kind of signature (if any) the
client wants? The client can provide a Want-Signature header in the
request... (4) Can there be multiple signatures? Yes. In the normal
HTTP style, the Signature header should support a comma-separated
list of signatures. The order of this list would be significant.
There should be a way for each signature in the list to specify which
of the previous signatures in the list are included in what it signs.
There's a semantic difference between two independent signatures, and
a later signature endorsing an earlier signature... (5) How about
streaming? Tricky. The fundamental problem is that HTTP 1.1 isn't
very good at enabling the interleaved delivery of data and metadata... More Information See also the followup: Click Here

Exploring Claims-Based Identity

This column introduces the new identity model in the Microsoft .NET
Framework 3.0... Trust and Federated Identity: WCF and other
communication frameworks use cryptography to ensure that the sender of
a security token is indeed the subject and that the claims in the token
were signed by the issuer named in the token. But all of this fancy
plumbing doesn't have any idea how much you trust the issuer. If you
don't trust him, you're not going to trust the claims he makes about
his subjects! That's why the issuer is always identified when you
receive a claim set, and it's the first thing you should look at when
processing a claim set. It's easy to write code that accepts tokens
from a single trusted issuer. Just make sure the claim set you received
was issued by the one authority you trust, and then you can use those
claims to make security decisions. You've essentially delegated
responsibility to the STS for doing the heavy lifting such as mapping
users onto roles and dealing with different types of security tokens.
Now imagine you wanted to take this one step further. Instead of only
accepting Windows credentials and X.509 certificates, what if your STS
also accepted signed SAML tokens issued by an STS at a trusted partner?
This leads to the realm of federated identity, which is very powerful.
Instead of having to worry about managing user accounts for external
users from partner companies, you can instead accept signed statements
from those partners in the form of SAML tokens... Federated identity
ultimately boils down to claims transformation, if you think about it.
The partner's STS makes the client's life easy by accepting as input
whatever credential is most natural for her, given her operating system
and platform. For example, if the client is running Windows, the STS
could use Kerberos to automatically authenticate her and issue a SAML
token. Another partner company might run a completely different OS that
uses other strong authentication protocols. But the STS at that company
would use those protocols to seamlessly authenticate the user and issue
a SAML token. Meanwhile, the user enjoys the benefits of single-sign on,
even when using applications like yours from federated partner companies.

Creating Interactive Forms with GWT and XForms

This is Part 4 in a four-part series demonstrating how to use the
Google Web Toolkit (GWT) and XForms together to create a dynamic Web
application. Part 1 looks at the JavaScript underpinnings of each
technology. Part 2 shows how to use those JavaScript underpinnings to
start mixing the two technologies together to build the rock star
application. Part 3 refactors the application to use XForms and GWT
together. In this concluding part, we continue to refactor and improve
the rock star application. The article uses GWT version 1.4 and the
Mozilla XForms plugin 0.8. The Mozilla XForms plugin works with any
Mozilla-based Web browser, such as Firefox and Seamonkey. GWT requires
knowledge of Java technology, and Web technologies such as HTML and
CSS. This article makes heavy use of JavaScript as well. XForms makes
heavy use of the Model-View-Control paradigm, so familiarity with that
is helpful. In the article you see how to add interactive forms to
your application. These forms can use GWT to create XForms controls
that can then invoke GWT Ajax services. The response from these
services can be handled through GWT, and can in turn use JSNI to alter
your XForms model data and update your XForms UI controls. This tight
integration between GWT and XForms allows XForms to take advantage
of key features of GWT. You also see that you can localize your XForms
using GWT's localization facilities. Finally, you see one of the
lesser-known, but powerful, features of GWT: Java-style sorting.
Features like this, as well features like localization and GWT's new
image bundling, make it so beneficial to use GWT not only for new
projects, but also to enhance other projects and technologies.
More Informaton

Wednesday, October 17, 2007

IBM Uses RFID to Track Conference Attendees

At its "Information on Demand" conference, IBM is deploying RFID
technology on name tags worn by attendees that automatically tracks
their session and meal attendance. This is the first time that IBM
has used RFID technology at this conference, and the company is not
making a secret of it. There are signs at the registration desk offering
attendees the option of getting a name tag without the chip. Of the
6,500 people here, approximately 2% didn't want a name tag with an
RFID chip in it. From a simple unique identifier on the chip, begins
what could be a long tail of data analysis. The chip's 24-character
identifier includes the name, title and company of the person wearing
it. There is no other personal information on the chip. As a person
walks through the door leading into a conference session, an RFID
receiver logs the chip's data. The system, by AllianceTech in Austin
is networked and the data is received in real time by its on-site
systems at the conference. The data is organized in a DB2 database.
The RFID system, coupled with what the conference knows about the
person wearing the name badge, is providing lots of raw data. Mary
Ann Alberry, IBM's conference manager, said the data will be used
to help organizers with future conference planning, such as optimizing
sessions around interests and demands of conference attendees. It
will also let organizers know the number of people who have received
meals so they can plan meals in such a way that food is available
at the right time. Because RFID keeps count of people getting meals
at the conference, it creates a means to audit and help control
conference costs. The real-time aspects of the system help with
day-to-day conference management. If a room gets filled to capacity,
a decision can be made to repeat the session. If a person needs to
be reached in an emergency, he can also be tracked down. Many
conferences already track who enters sessions by scanning bar codes
on name badges, but Art Borrego, CEO of AllianceTech, said RFID
allows people to enter a room without delay. He said conference goers
have accepted it in much the same way many use RFID to avoid having
to stop on a highway to pay a toll. More Information

Augmented BNF for Syntax Specifications: ABNF

The Internet Engineering Steering Group (IESG) announced the approval
of the "Augmented BNF for Syntax Specifications: ABNF" specification as
a Full IETF Standard. ABNF is used for formal language description in
IETF RFCs, W3C specifications, and elsewhere. The document was reviewed
by Bill Fenner, Frank Ellerman, Julian Reschke, Steven Legg, Alexey
Melnikov. An implementation report is available. Abstract: "Internet
technical specifications often need to define a formal syntax. Over
the years, a modified version of Backus-Naur Form (BNF), called Augmented
BNF (ABNF), has been popular among many Internet specifications. The
current specification documents ABNF. It balances compactness and
simplicity, with reasonable representational power. The differences
between standard BNF and ABNF involve naming rules, repetition,
alternatives, order-independence, and value ranges. This specification
also supplies additional rule definitions and encoding for a core
lexical analyzer of the type common to several Internet specifications. More Information
See also the implementation report: Click Here