British Business Federation Authority

  • Introduction - British Business Federation Authority

    The BBFA (British Business Federation Authority) is a not-for-profit, self-regulating organisation to enable the implementation of federated trust across regulated UK companies and industries, based on strong authentication and authorisation policies, procedures and mechanisms, using industry investment. Its Steering Group comprises major companies from several regulated industry sectors.

    Under the Steering Group’s direction, the BBFA’s working groups and Policy Management Authorities (PMAs) are starting to leverage existing international best practice to produce policies, procedures and enable the implementation of services for federated trust. The PMAs include Government representation.

    Read more...
  • Riding the Identity Tsunami

    lipofwave thumb

    First the transistor then the computer then the Internet. Each of these has been a tsunami, having huge effect upon society and business, which no one really foresaw. The next tsunami is already upon us - federated identity management.

    Read more...

News Archive 2011


  • 22 Dec.  Cabinet Office IdAP Standards Workstream progress the Good Practice Guide 45 (Identity Verification) that is set to become a UK standard.
  • 21 Dec.  UK Payments Council attend BBFA Steering Group #17.
  • 15 Dec.  PANCRAS Printer Manufacturers WG meeting.
  • 14 Dec.  European Commission advise that details of the BBFA PANCRAS counter-fraud project to defeat fake documents have been sent to all member states.  This follows on from the US Dept of Homeland Security briefing the White House. 
  • 9 Dec.  BBFA run an RFI briefing session for potential Credential Service Providers for the UK PKI Bridge.  Nine companies attend.
  • 7 Dec.  BBFA and its EUSTIC partners attend FP7 briefing run by the Technology Strategy Board.
  • 2 Dec.  BBFA meet with UK and Austrian partners to plan the international development of a Trust Framework Meta Model, using international funding.  BBFA also met with the Austrian MOD (re MNE7) and Austrian Government CIO.
  • 28/29 Nov.  BBFA supported MOD in Multinational Experiment 7 Workshop in London to develop thinking on international Cyber Space Situational Awareness. 
  • 16 Nov.  BBFA Federation PMA meeting, including NHS and Metropolitan Police
  • 15 Nov.  BBFA Steering Group #16. UK PKI Bridge on target for Jul 12.
  • 14 Nov.  BBFA expands Governance Structure to form the Assurance Oversight Committee (AOC) to lead on assurance and certification, linked to tScheme and Kantara Initiative.
  • 9 Nov.  Initial meeting with Dept of Business Innovation & Skills re Cyber Security
  • 8 Nov - Panel member on the European Commission GINI-SA Hearing. (GINI is EU initiative similar to US NSTIC).
  • 4 Nov - Strategy meeting with Legal Counsel for OpenID, OIX and Connect.me.
  • 31 Oct - BBFA invited to Cabinet Office Minister's Briefing on e-Identity and Government Digital Services. 
  • 28 Oct - MOD debriefs BBFA on MNE7 workshops in Helsinki and Rome.  MOD asks for further BBFA support.  
  • 27 Oct - BBFA attends the BCS/EEMA event on E-Identity and questions why the level of understanding and awareness in UK is failing to keep pace with national and international developments.
  • 26 Oct - BBFA is a panel speaker at the Information Age Cloud Security Conference, London.  
  • 25 Oct - BBFA Steering Group. Work programme continues to expand.  NHS and Police present letters of support to BBFA and request assistance.
  • 20 - 21 Oct - BBFA attends the Kantara Initiative Summit (in San Francisco).  KI asks BBFA to partner and play a leading role in European expansion.
  • 20 Oct.  US Federal CIO publishes OMB memo requiring all Federal agencies to develop plans within 90 days for accepting certified, externally issued credentials at LoA 1 within 3 years and LoA 2, 3 and 4 in due course.
  • 18-19 Oct - BBFA attends Internet Identity Workshop (in San Francisco), including the NSTIC Workshop with US Gov. Excellent coordination on enabling technologies and major Internet Identity Providers, including Google, OpenID and OIX. This reinforces the importance and opportunities of BBFA's role in high assurance federation. 
  • 10-14 Oct - BBFA attends ISO/IEC SC27 WG5 in Nairobi as UK Project Leader on key Authentication & Authorisation standards.  Also the UK lead on new work for Data Protection in the Cloud (including Privacy).   Korea and Japan engage with BBFA.
  • 3 Oct - BBFA attends European Commission launch of eIAS Project, which is to recommend way ahead for Europe on e-Identity, Authentication and Signatures (eIAS) from end 2012.  eIAS ask for BBFA input.
  • 28 Sep - BBFA presents to the IET Policy Board; key points for EDF Energy(Smart Metering) and BIS (Cyber Security Strategy).  
  • 28 Sep - BBFA presents to Jericho Forum.
  • 26 Sep - Welsh Assembly Government requests BBFA assistance and joins BBFA Federation PMA.  
  • 20 Sep - NSA Trusted Computing Conference, Orlando, FL.  BBFA is invited to present as one of four highliight innovations of the year.  BBFA describes PANCRAS.  NSA confirms new policy to require the use of Trusted Platform Module (TPM) in some Federal agencies. Microsoft outlines extensive use of TPM in Windows 8 (due 2013). Intel outlines TPM enhancements. Harris describes TIA4 cloud data centre using SCAP for controlled software.
  • 19 Aug - BBFA assists MOD to plan UK industry support to NATO's Multinational Experiment 7 (MNE7) - Ensuring access to the Global Commons.  UK is the lead nation for the Cyber-Security Situational Awareness component.
  • 4 Aug - BBFA weekly support to Cabinet Office IdAP continues.  Cabinet Office confirms policies are to conform with international standards, notably ISO 29115, based on the four Levels of Assurance 1-4 outlined in US M-04-04.  CESG produces an initial draft HMG Standard for Identity Proofing & Verification of persons.
  • 2 Aug - MOJ advises BBFA on its next steps in response to European Commission requirements affecting the legal profession and electronic exchange of legal data.
  • 25 Jul - BBFA begins work with European partners to develop the Employer Register Service.
  • 20 Jul - BBFA Steering Group #13 & Half Year Review attended by guest companies, NHS and Police.
  • 19 Jul - BBFA Kick Off meeting of the UK Secure Printer Service using Pancras.  Attended by secure printer manufacturers and printing operators.
  • 1- 15 Jul - BBFA engages with secure printer companies who are Genesius members.
  • 14 Jul - BBFA supports the weekly Cabinet Office Identity Assurance (IdAP) Workstream on Assurance and Standards (in addition to the Proposition Workstream)
  • 13 Jul - BBFA increases support to the TFMM (Trust Framework Meta Model) work in Kantara being led by Austria
  • 13 Jul - Notaries Society joins BBFA dialogue with Ministry of Justice on European e-Justice
  • 8 Jul - BBFA continues support to MOD for the planning of NATO MNE7 Cyber-Security Situational Awareness
  • 8 Jul - Federation PMA plans the completion of the policy document set to enable the UK PKI Bridge Team to plan implementation
  • 30 Jun - Further discussions with Companies House on the potential relationship with a UK Employer Register
  • 29 Jun - US/European SEUAC meeting of global pharmaceutical companies involved federation for drug registration and trials, and e-health patient records
  • 22 Jun - Initial BBFA meeting with the Ministry of Justice on European Justice initiatives affecting UK
  • 22 Jun - BBFA briefs Project Genesius, the Metropolitan Police Service's counter-fraud group of secure printer companies.  BBFA proposes a new approach to defeat fake documents codenamed Pancras.
  • 21 Jun - BBFA Steering Group.  One guest company.
  • 20 Jun - BBFA, Home Office ID Crime Team and UKBA attend the European Commission A2 ID Fraud & ID Management Expert Group.  BBFA briefs national members on ID management to counter fraud.
  • 16 Jun - BBFA weekly support to Cabinet Office ID Assurance Programme Proposition Workstream begins
  • 27 May - UK PKI Bridge team planning session
  • 25 May - NL and Europol discussions on federation and counter-fraud
  • 24 May - BBFA Steering Group #11. 4 guest companies.
  • 20 May - Federation PMA, incl NZ Gov representative. Policy document development
  • 16-18 May - Kantara Initiative Workshop, Berlin to progress workstreams and documents
  • 3 May - BBFA Steering Group #10, Commercial WG #2.  Two guest companies
  • 20 Apr - G-Digital ID Assurance Kick Off Briefing
  • 14 Apr - Potential support for Project Genesius, Metropolitan Police Service
  • 11-15 Apr: ISO SC27 WG5 ID management & privacy standards development
  • 8 Apr - Initial discussions on DH supply chain requirements and sid4health/gov
  • 31 Mar - Joint BBFA/Austrian ID Management Tutorial to European Commission DG HOME, TREN and INFSO.
  • 24 Mar -  First meeting of the BBFA Commercial WG.
  • 9 Mar.  Four companies form the UK PKI Bridge Team to build the UK PKI Bridge.
  • 9 Mar.  BBFA and HMG begin to explore leveraging sid4health, the single supplier database for the NHS.
  • 8 Mar.  Six credential service provider companies join the BBFA Service Providers Group to cross-certify with the UK PKI Bridge and offer services.
  • 2 Feb - BBFA meeting with OGC to review commercial arrangements for collaborative federation capabilities funded by industry for the common good, where Government is one of many customers.
  • 18 Jan - BBFA Steering Group #8 notes increasing HMG, departmental, local authority and company engagement.  It directs the development of a revised membership model to lower the barrier to entry.
  • 18 Jan - The Russian Government announces the UEC, which will be adopted by around 1000 national and regional services along with about 10,000 commercial enterprisesand support transportation in Moscow.  This is similar to the national e-ID being deployed in India.
  • 17 Jan - BBFA participates in CSOC Horizon Scan Review Workshop where identity management and the lack of governance are major topics.
  • 13 Jan - BBFA participates in the maturing privacy technical architecture under ISO 29101.
  • 10 Jan - President Obama announces that the US National Strategy for Trusted Identity in Cyberspace (NSTIC) Implementation Plan will be published in a couple of months.  This tasks the Dept of Commerce to oversee the creation by industry of an Internet ID for Americans.  There are significant implications for UK citizens, consumers and industry, for which BBFA is seeking a focus in Government.
  • 7 Jan 11 - BBFA Federation PMA #3.  Police and NHS report the result of their practice mapping of Certificate Policies.
  • 5 Jan 11 - BBFA joins the ANSI/NASPO group developing the US ANSI standard for Identity Proofing & Verification, which is backed by US government departments.

Enabling Government Collaboration

A growing number of local and central government organisations have plans for federated identity & access management.  Led by the NHS and the police, many of these are working with BBFA on collaborative pilots and operational implementation for the secure sharing of sensitive information with industry and government partners both on and off PSN.  BBFA facilitates federation with other governments for international federation.

Enabling Industry Collaboration

The international aerospace and defence, and pharmaceutical supply chains have deployed PKI federation extensively to authenticate people, organisations and systems, and for secure email, ID-linked encryption, strong digital signature and physical access control. Their purpose is secure collaboration and the sharing of sensitive information. The benefits, in terms of re-use, reduced risks and costs, transpire into significant competitive advantage.  Other industries are beginning to follow suit.  These behaviours are beginning to flow into the consumer space, opening up new markets for trust such as Big Data.

Enabling Counter-Fraud

Europol report that ID Fraud is the top enabler for all aspects of crime across Europe.  UK's NFA indicate £73 bn of fraud this year, up 20%.  Pan-European fraud is estimated at €500 bn - the biggest contributor to the € crisis. The business cases for counter-fraud are considerable.   In initiatives such as PANCRAS, BBFA is working with others to reduce fraud dramatically, through the implementation of standards-based Identity Proofing & Verification for persons, organisations, devices and software.

Enabling Cyber Security

BBFA is working internationally with cyber security organisations to establish a baseline of preventative Security Controls, including federation, for any organisation sharing sensitive information and seeking to insure their risks - and also to enable the sharing of cyber Situational Awareness information across cyber security organisations for better, shared decision making.  A multinational Information Sharing Framework has been developed in 2012 and will be enhanced in 2013 to enable implementation - enabling businesses and governments to insure for risks more affordably and to demonstrate their trustworthiness.

Latest News:

News 2013.

  • 28/29 May.  EU host Transition & Implementation meeting for Multinational Alliance for Collaborative Cyber Situational Awareness (MACCSA)
  • 15 May. BBFA presents "Embedding Cyber Security across the Value Chain" to the TMForum Summit in Nice
  • 8 May. IBM host industry ad hoc on a potential British Standard for Identity Proofing & Verification. Decision to act is deferred 3 months.
  • 7 May. BBFA participates in closed Chatham Ho on space & Cyberspace.
  • 2 May. BBFA on panel at SANS Summit. 
  • 25 Apr. US DHS and BBFA discuss STIX and TAXII for CCSA
  • 24-6 Apr.  US and UK(BBFA) present ISO 29003 WD1 to ISO SC27 WG5 national bodies.
  • 18 Apr. BBFA-NZ Gov discussions on CCSA
  • 20 Mar.  BBFA-Intellect mutual update
  • 19 Mar. MNE7 Transition Meeting announced 28/29 May @Brussels 
  • 12 Mar.  Multinational CCSA Proof of Concept planning (Collaborative Cyber Situational Awareness)
  • 8 Mar. Cabinet Office host UK IPV WG Start Up meeting
  • 25 Apr.  ISO SC27 WG5 and ETSI meeting in France, including ISO 29003 and 29115 
  • 15 Apr. Informal BBFA discussions with NZ Gov
  • 8 Mar. Cabinet Office & industry meeting on UK IPV standard development
  • 5 Mar. MNE7-EU discussions @Brussels
  • 19-21 Feb.  MNE7 Cyber Transition Workshop to create a new multinational organisation to implement Collaborative Cyber Situational Awareness (CCSA)
  • 12 Feb.  BBFA Policy Management Authority progresses federation policies for the UK PKI Bridge
  • 12 Feb.  UK NAO announce NAO Report: UK Cyber Security Strategy Landscape Review
  • 7 Feb. EU announce the EU Cyber Security Strategy, a Directive and supporting documents.
  • 5 Feb. BBFA presents at ISSA Europe, focusing on cybersecurity, alongside ENISA, DG CONNECT, EUROPOL and others.

News Archive 2012.

News Archive 2010.

User Login