As security tokenization becomes a common practice, standardization is bound to take place. In this piece by Jesus Rodriguez, the four typical ways to create standards are laid out:
- By committee, wherein several vendors establish protocols early, laying a jointly agreed upon foundation.
- By a platform which specifies how a security token can operate on its system, an approach not dissimilar to Microsoft Windows' old developer rules.
- By competition, wherein multiple vendors compete for the best standard. JavaScripts wide adoption on the web followed this path, which Rodriguez argues is the most likely route for security tokens.
- By an industry body, who selects vendor applications based on given authority like the W3C.
Security tokenization will be a fluid process and multiple models will probably exist, not just one or two. Concerns over fragmentization or interoperability are weak in light of cloud computing developments, which has proven the markets' ability to force industry standardization over time.