Information Cards and CardSpace: A Brief Tour
Cards refer to informational claims about a subject—the user that is to be given access to a web site, web service, or application (know as the “Relying Party” or RP). Claims might include your name, address, phone number, birth date, or any other information that might prove useful to identify you. Different RP’s may demand different sets of claims to authenticate and authorize callers.
Two types of information cards exist: personal cards and managed cards. Personal cards are self-issued cards that can be created directly in the CardSpace user interface. Managed cards are obtained from a third-party provider who is willing to assert that a set of claims really do relate to you. CardSpace can store both types of cards, and creates or obtains a security token containing the claims represented by those cards. That’s the ultimate goal: to reliably create a security token that carries claims to identify the user.
The CardSpace user interface is accessible from the Digital Identities icon in the Control Panel shown in Figure B-1.

Figure B-1. You can create and manage cards from Digital Identities in the Control Panel; this option is installed with .NET Framework 3.0 on XP/SP2
When you select Digital Identities, it launches a hardened CardSpace user interface where you can safely create personal cards, import and export cards, protect cards with ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access