In the early 2000s, a hybrid between AES and public key algorithms (the two prevalent schemes) became the most accepted way for e-commerce operations to proceed. Additionally, the creation of a new protocol known as the Secure Socket Layer, or SSL, led the way for online transactions to take place (securing client and server in the transaction).
Transactions ranging from purchasing goods to online bill pay and banking used SSL. in 2001, the USA Patriot Act required financial establishments to know your customer (KYC) and the bank's approach to Anti-Money laundering programs required stricter standards for Identity and authentication.
Furthermore, as wireless Internet connections became more common among households, the need for multi-point encryption and the proliferation of directory services to hold user identity. Radius servers were built to handle wireless, LDAP servers handled legacy back-office functions and E-Mail associated directory services (Novell, IBM, Microsoft) held user information (typically independently). These identities for everyday transactions and activity required multiple passwords to access applications and simply logon to systems.[25]From an administrative standpoint this inefficiency and risk of password compromise persisted, largely unresolved during the era of server consolidation. Companies developed namespace (a collection of names and attribute pairs that define the security repositories) holding centralized identity. the UUID or universal userID became important so that repositories could inter-communicate.
The LDAPv3 protocol (RFC2252) evolved to handled distributed computing and directory schemas that define the namspace of people devices, organizations. Personal devices accessing privileged information grew geometrically in the last two decades (tracking with Moore's Law) increasing the security, event and risk surfaces in personal computing. Government was also expanding centralized repositories. 
In 2004 the first US statewide automated palm print database went online, and by 2009 Canada introduced the Cyber Identity verification system. By the mid-2000's some consolidation of authentication/identity was achieved but could not keep pace with the expansion of identity security repositories, directories that by design were built by vendors to be proprietary and not conforming to a single standard.

•Beginning around 1990, the use of the Internet for commercial purposes and the introduction of commercial transactions over the Internet called for a widespread standard for encryption which resulted in AES's widespread adoption. The primary concern, was the appearance of Eve in the Bob and Alice archetype. This 3rd party eavesdropper, could see or modify the transmission arbitrarily and with this information assume either Bob or Alice's online identity. With Bruce Schneier's publication of Applied Cryptography in 1994 and 1996, many more personae Identities were created to clarify the math of Identity encryption and possible security breach and audit scenarios.
