30 likes | 193 Views
Invitation-based Authotization Simple mechanism based on e-mail Simpler (and more local) than entitlements Applicable to any federated application It requires an opaque, unique code associated to user e-mail. schacPersonalUniqueCode in our case. schacPersonalUniqueCode (sPUC)
E N D
Invitation-based Authotization • Simple mechanism based on e-mail • Simpler (and more local) than entitlements • Applicable to any federated application • It requires an opaque, unique code associated to user e-mail. • schacPersonalUniqueCode in our case
schacPersonalUniqueCode (sPUC) • Unique and persistent • URN-based: • urn:mace:terena.org:shac:personalUniqueCode:es:rediris:sir:mbid:{md5}6fa359e1e4efc46166 • Digest of the user e-mail • Privacy preservation (no reversible) • Identity proof (associates a SIR identity to an e-mail address)