50 likes | 147 Views
XUA Attribute Options. presented to the IT Infrastructure Technical Committee John Moehrke Feb 1, 2010. The Goal. Ensure that XUA profile can be used in conjunction with PEP/PDP systems (cfr. Access Control Whitepaper)
E N D
XUA Attribute Options presented to the IT Infrastructure Technical Committee John Moehrke Feb 1, 2010
The Goal • Ensure that XUA profile can be used in conjunction with PEP/PDP systems (cfr. Access Control Whitepaper) • Leverage the Oasis/XSPA efforts for standardizing authorization attributes in healthcare • Concrete : • Extend the SAML token (XUA profile) with authorization attributes (based on XSPA ) • A review of modifications needed (if any) for international use of the XSPA standard. XSPA has been initially driven by US needs. • Describe the integration of XUA with existing PEP/PDP systems (cookbook)
Use Case • Role-Based-Access Control: Need to specify a fuller vocabulary of attributes needed for access control decisions. • Consent/Authorization: Need to carry an indicator of BPPC document that is relevant to the transaction • Level Of Assurance for (a) the authentication event, and/or (b) the provisioning of the account • Audit Logging: Support descriptive identifiers to support environments where post-processing doesn’t have access to directory for id translation into description. • Purpose-of-Use: Carry in the assertion purpose-of-use, including support for Break-Glass / Emergency-Mode-Access • Relationship-to-Patient: Carry the indicator of the patient, relationship to patient, location of patient
Proposed Standards & Systems • SAML • XSPA (SAML, XACML, WS-Trust) • epSOS paper from Massimiliano • NHIN Messaging and Authorization Frameworks • WS-trust
Discussion • What level of effort do you foresee in developing this profile? • Medium • Co-editor: John Moehrke – GE Medical, Joerg Caumanns – Fraunhofer.