https://kantarainitiative.org/confluence/display/uma/UMA+telecon+2021-02-11
Minutes
Roll call
Quorum was NOT reached.
Approve minutes
Approve minutes of UMA telecon 2021-02-04 <https://kantarainitiative.org/confluence/display/uma/UMA+telecon+2021-02-04>
Connect.ID 2021 Call for Speakers (Oct 5-6)
https://www.terrapinn.com/exhibition/connect-id <https://www.terrapinn.com/exhibition/connect-id/?utm_source=pardot&utm_medi…>
Please make sure to submit your application before 26th February: https://www.terrapinn.com/exhibition/connect-id/apply-to-speak.stm <https://www.terrapinn.com/exhibition/connect-id/apply-to-speak.stm>
Other upcoming identity/security conference (checkout https://kantarainitiative.org/events/ <https://kantarainitiative.org/events/>):
Identity Week Asia
Identity Week UK
PDP Update
PD Program has sent across some proposed license changes. Currently in-review by Kantara
AEMS Update
There has been some work towards an POC here: https://github.com/uma-email/poc <https://github.com/uma-email/poc>
Check it out and get involved!
UMA WG Presentation to All-Members
1200-1230 EST Next Wednesday Feb
Topic: Industry UMA profiles bring new work to our group
Alec will share the slides with the list ahead of this session sat/sun/monday
UMA and FAPI discussion con't
There has been some reach out to FAPI around our interest in exploring this in the WG. If anyone is interested in leading this item please reach out to Alec or the mailing list.
Other profiles next steps
What's inside the Wallet? Wallet as an RS? AS?
With information (identity + other credentials) stored at the Wallet, does it become an RS for me?
With the Wallet, the 'subject' is in the data-flow, more OIDC like. An RS supports more 'delegation' or other requesting parties. Wallet may 'push' to endpoint more than allowing a RP to 'pull' data, specifically a mobile device is hard to be setup as an 'endpoint'.
How would push work? RP needs new information, calls an authorization endpoint. The AS routes to the smartphone (how? must be through some web service). The wallet receives a token to hit the RP API with the requested information.
One angle is that if the Wallet is an RS, to a client there is no difference. The RP receives a token and can redeem it for the requested information.
In the PD profile the dashboard is a normal UMA client. Maybe the 'Wallet' profile can be positioned similarly, where the API being requested is the 'policy api' hosted by the AS. The policy api would expose the registered resources and the associated policies. In the current profile, the RO would need to return to the AS to modify policy (eg invite a new advisor), or see pending requests to their pensions from an advisor. Another interesting overlap between the wallet profile + PD profile is the need to discover RS's that may not have UX or a user credential.
Topic for next week, re-introduce wallet/resource manager profiles with the additional pensions dashboard use-case as context.
Attendees
As of October 26, 2020, quorum <http://kantarainitiative.org/confluence/display/uma/Participant+Roster> is 5 of 9. (Michael, Karim, Domenico, Peter, Sal, Thomas, Andi, Alec, Eve)
Voting:
Peter
Alec
Michael
Non-voting participants:
Ian
Colin
Regrets:
Sal
Andi
Eve
Fascinating that there’s a whole list of issues.
More on this subject: It looks like AI and a wallet-like client-side approach are being put into play, potentially fixing some of Hey’s downsides, with a forthcoming solution called Big Mail:
https://getbigmail.com/https://9to5mac.com/2021/01/22/big-mail-email-radical-new-ui/
Eve Maler (sent from my iPad) | cell +1 425 345 6756
> On Sep 29, 2020, at 10:31 AM, Igor Zboran <izboran(a)gmail.com> wrote:
>
>
> Hi all,
>
> I’ve found that the topic of healthcare is quite popular among UMAnitarians. Although AEMS has been designed as a general or enterprise-oriented system, I think that it also meets the specific needs of the healthcare sector. To demonstrate the feasibility of the UMA/Email idea, I decided to build proof of concept. The full source code will be available in the public GitHub repository https://github.com/uma-email/poc. Any help welcomed.
>
> -Igor
> _______________________________________________
> WG-UMA mailing list
> WG-UMA(a)kantarainitiative.org
> https://kantarainitiative.org/mailman/listinfo/wg-uma
https://kantarainitiative.org/confluence/display/uma/UMA+telecon+2021-02-04
Minutes
Roll call
Quorum was reached.
Approve minutes
Approve minutes of UMA telecon 2021-01-21 <https://kantarainitiative.org/confluence/display/uma/UMA+telecon+2021-01-21>, UMA telecon 2021-01-28 <https://kantarainitiative.org/confluence/display/uma/UMA+telecon+2021-01-28>
Andi Moves to Approve, APPROVED
Announcing, ANCR WG
As shared on the UMA mailing list, a new WG has recently started: Advanced Notice & Consent Receipt - ANCR-WG <https://kantarainitiative.org/confluence/pages/viewpage.action?pageId=14080…>
Goal, update consent receipt 1.1, update the fields captured around a specific consent receipt "the anchor receipt"
Meets Wednesday 1030ET
UMA and FAPI discussion con't
FAPI as a profile can notionally be supported by an UMA AS. How can we demonstrate that UMA/FAPI work nicely together? WIth a goal of getting some mutual recognition from FAPI(?)
In UK there is a push for strong consent+authorization+privacy, can UMA fill that need left by base security profiles? The federation and delegation cases seem to be realized as an afterthought in these solutions.
HEART started profiling UMA for the Healthcare use case, maybe this is a starting point for a UMA/FAPI security profile.
Another angle is that FAPI is a security profile for open banking use-case. Can UMA show it's value better in the use-case vs simply accepting security profiles. OpenBanking is defining the "implementation profile"/ wider ecosystem roles and interactions (eg specific client types like payment initiation service providers(sp?))
How can we take this further to include the Consent Receipt? The consent receipt today was designed to be the minimal international information needed for a real meaningful consent.
Can a consent receipt be a 'grant'? Person gives their 'grant'(s) at the AS, captured as a consent receipt, before the AS issues the technical grant(uma ticket) to a client. Tickets and token could refer to the specific receipt (ie as a uri). Human gives consent grant, which through law corresponds to outcomes/preferences as interpreted by an AS.
https://kantarainitiative.org/confluence/download/attachments/129565039/pri… <https://kantarainitiative.org/confluence/download/attachments/129565039/pri…>
Pensions Dashboard update (if needed)
No major update. Let's setup a topic around the group IPR separate from the Pensions Dashboard topic
Other profiles next steps
Attendees
As of October 26, 2020, quorum <http://kantarainitiative.org/confluence/display/uma/Participant+Roster> is 5 of 9. (Michael, Karim, Domenico, Peter, Sal, Thomas, Andi, Alec, Eve)
Voting:
Michael
Andi
Domenico
Alec
Sal
Non-voting participants:
Ian
George
Mark
Colin
Nancy
Hello Kantara,
We had a great ANCR Launch session on Privacy Day, and to follow up we are hosting a Data Privacy Hack/Workshop Jan 30.
A key hack we are working on is Enforceable Privacy and the use of Notice Receipts for each legal justifications to provide enforceable privacy rights in context.
The base schema is the 'explicit consent notice receipt’ which we are working on in the ANCR WG. In our last hackathons we have been working on for privacy agreements that better interact with terms of use.
* Contract Notice Receipt
* Legitimate Interest Notice Receipt
* Legal Obligation Notice Receipt
* Vital Interest Notice Receipt
* Public Interest Notice Receipt
(a receipt is its a notice of record - and all receipts are inherently data receipts)
In addition to Consent Notice Receipts, which cover the spectrum of legal/social consent and include: Explicit, Implied, Directed & Altruistic Consent, for the transfer of liability through transparency of privacy risk. All are welcome, so please pass this on to your groups.
Best Regards,
Mark
The calendar invites below is for the Legal Hacking Workshop - (more info on ANCR WG homepage)<https://kantarainitiative.org/confluence/pages/viewpage.action?pageId=14080…>
These are the goto meeting call details, and some guiding policy:
- you do not have to login to GotoMeeting to access the call,
- we will be recording the event - and we intend to share this on the Public ANCR WG page
- And, as a result, we do not require to put your video on, and you do not have to share information in the call,
- This is not an official ANCR work group meeting, details for work group sign up are provided after the launch.
You can join the ANCR WG Launch from your computer, tablet or smartphone. And stay in the Video Call for the Demo’ Sessions -
https://global.gotomeeting.com/join/562338533
You can also dial in using your phone.
United States: +1 (646) 749-3112
Access Code: 562-338-533
New to GoToMeeting? Get the app now and be ready for your the ANCR Launch meeting
starts: https://global.gotomeeting.com/install/562338533
Open Consent Group: Data Privacy Legal Hackathon - Launch
DPLH- Hack’s 4 Demo’s
Scheduled: Jan 28, 2021 at 8:45 AM to 10:00 AM
Location: https://global.gotomeeting.com/join/562338533
10am to 2 pm Edt
https://kantarainitiative.org/confluence/display/uma/UMA+telecon+2021-01-28
Minutes
Roll call
Quorum was reached.
Approve minutes
Approve minutes of UMA telecon 2021-01-21 <https://kantarainitiative.org/confluence/display/uma/UMA+telecon+2021-01-21>
Deferred
UMA and FAPI discussion
What is FAPI: https://openid.net/wg/fapi/ <https://openid.net/wg/fapi/>
Oauth/OIDC security profiles started for Open Banking purposes. UK open banking <https://standards.openbanking.org.uk/> has accepted FAPI as their security profile. Many UK industries are moving towards FAPI as the baseline security profile.
How do the FAPI profile interact with our own profiling work, both UMA as a profile of OAuth, and downstream profiles such as the Pensions Dashboard? Are there was to converge FAPI and UMA such that they can easily be used together? They are not 'competing' profiles, FAPI is around security and UMA is around delegation + sharing.
As the pensions dashboard profile is part of the 'financial' industry, there is a likely requirements to realize the FAPI profiles, specifically for strong customer authentication (SCA).
GNAP ("OAuth 3") is a 'backwards incompatible' iteration of OAuth, incorporating many other protocol goals, including UMA. Suggest we park this and focus on OAuth 2 profiles/efforts.
FAPI is similar to the HEART initiative for Health Care. HEART was security profile of OAuth2+UMA2, including the definitions of FHIR and associated scopes. There is some prior work of using HEART with additional FAPI requirements to secure an UMA implementation. This is the Nordic health UMA profile(https://julkaisut.valtioneuvosto.fi/bitstream/handle/10024/78439/MyData-nordic-model.pdf <https://julkaisut.valtioneuvosto.fi/bitstream/handle/10024/78439/MyData-nor…>). Suggest FAPI should take up an UMA 2 security profile in addition to the OAuth2/OIDC profiles.
There is a push to open data control to end-users "Life-tech" (at least in the UK). FAPI is not enough to realize this(?). FAPI is setup with trust list/directories that in theory create open/wide ecosystems of dynamic client registration between RPs and AS/RS providers. In practice, there are a lot of operational challenges to a dynamic ecosystem. UMA has considered these wide ecosystem questions from both the protocol but also the whole "BLT".
As a heads up to implementors/vendors. In the UK, the Pension Dashboard software provided to Pension Providers(RS) will need to realize all of the pensions dashboard profile, the FAPI security profiles and the Open Banking data APIs.
If we believe that FAPI should support a UMA2 security + privacy profile, should we produce and contribute this? Yes. Alternatively, should UMA 2 adopt(recommend?) FAPI as the security profile, and keep all the good privacy work in UMA? Is there any barrier today to using FAPI and UMA? Likely not, but this would require some analysis.
Let's work towards completing this analysis. Bringing the disparate profiles together removes a lot of uncertain around how different efforts work together. Presumably the financial-grade security is useful in many industries. WG members are encouraged to review FAPI and send any comments/notes to the mailing list.
How does the FAPI work benefit other industry (health care) use-cases? Should be immediately useful as a strong security profile? Health care in the US is working towards very UMA aligned features/requirements. How can our WG better represent UMA in those forums?
Pensions Dashboard update
Still working through IPR concerns. Ideally want to reference a completely open + free specification. They support the Kantara + WG process, more questions of timing around the profiles availability.
Other profiles next steps
Deferred
- Alec
Hi,
We are very excited about the opportunities to collaborate and look forward to a reviewing and sharing.
This is very much an open invitation and happy to review and share, as I believe we have a new wiki space we can add it to.
Thank you Lisa,
Mark
PS I sent multiple emails but they didn’t get through to the ISI-WG list. But at last this last invite was from Smart Species email address
> On Jan 27, 2021, at 9:00 PM, Lisa LeVasseur <lisa.levasseur(a)me2ba.org> wrote:
>
> Hi Mark,
>
> Looks like an interesting couple of meetings. Unfortunately, I’m unable to make tomorrow’s call.
>
> I notice that[IEEE P7012](https://standards.ieee.org/project/7012.html#Standard)(Machine Readable Personal Privacy Terms) isn’t included in your landscape, and I think there may be meaningful overlap.
>
> Our most recent work in P7012 is the drafting of a baseline data schema that can describe private, legally binding, information sharing agreements, whether they are (a) notice & choice [aka “consent”], (b) two-party contract, or (c) license. This proposed structure is syntax-agnostic; Mary (Hodder) is currently creating a version of the Creative Commons No Stalking terms in the[Accord Project’s](https://accordproject.org/about/)syntax using our draft schema, for example.
>
> We haven’t fully tackled interop yet, but Bernd Blobel is advocating for aligning with ISO 23903 (Health informatics — Interoperability and Integration Reference Architecture – Model and Framework ) for interoperability; we’re still navigating that.
>
> It would be great if we could get some synergy across these efforts.
>
> Thanks!
> Lisa
>
> From:WG-UMA <wg-uma-bounces(a)kantarainitiative.org>On Behalf OfSmart Species
> Sent:Wednesday, January 27, 2021 4:36 PM
> To:Salvatore D'Agostino <sal(a)idmachines.com>; Vitor Jesus <Vitor.Jesus(a)bcu.ac.uk>
> Cc:wg-uma@kantarainitiative.org WG <WG-UMA(a)kantarainitiative.org>; Kantara Leadership Council <lc(a)kantarainitiative.org>; wg-isi(a)kantarainitiative.org
> Subject:[WG-UMA] ANCR WG Launch Invitation
>
> Hello Kantara Community
>
> We hope this email finds you and yours safe and well.
>
> We are ecstatic to invite you- to the ANCR WG introduction (on Jan 28th where we are discussing data governance interoperability with notice and consent receipts work and discussion that is in progress.
>
> Information for the sessions tomorrow are below.
>
> Kind Regards,
>
> - Mark
>
> Goto meeting call details, (with some guidance):
>
> - you do not have to login to GotoMeeting to access the call,
>
> - we will be recording the event - and we intend to share this on the Public ANCR WG page
>
> - And, as a result, we do not require to put your video on, and you do not have to share information in the call, but, we recommend our normal practice of showing your video when you speak.
>
> - This is not an official ANCR work group meeting, details for work group sign up are provided after the launch.
>
> You can join the ANCR WG Launch from your computer, tablet or smartphone. And stay in the Video Call for the Demo’ Sessions - https://global.gotomeeting.com/join/562338533
>
> You can also dial in using your phone.
> United States: +1 (646) 749-3112
>
> Access Code: 562-338-533
>
> New to GoToMeeting? Get the app now and be ready for your the ANCR Launch meeting
> starts: https://global.gotomeeting.com/install/562338533
>
> ANCR WG - Launch
>
> Session 1: - Data Gov Interop Landscape 2021
>
> Scheduled: Jan 28, 2021 at 8:45 AM to 10:00 AM
>
> Location: https://global.gotomeeting.com/join/562338533
>
> Introductions to topic, each other & WG
>
> Kantara ANCR WG - Sal & Vitor
>
> ISO 29184/27560 - Mark
>
> W3C -DPVC - CG - Beatrix
>
> ToiP-ISIWG - DDE Architecture (MMM)- Paul
>
> UMA Legal Editor - Tim Reinegar
>
> MyData/aNG, : Matthias, Olivier
>
> ANCR WG -Demo’s
>
> Session 2: Demo's - Receipts and Dynamic Data Economy
>
> Scheduled: Jan 28, 2021 at 10:00 AM to 11:45 AM
>
> (Up to 9 min Demo’s +2-3 min chat)
>
> - Vitor - Privacy As Expected: Consent Gateway
>
> - Paul - Data Immunity Passport
>
> - Christoph - Data Sharing Hub
>
> - Lal - iGrant
>
> - Xavier - Fair Data
Hello Kantara Community
We hope this email finds you and yours safe and well.
We are ecstatic to invite you - to the ANCR WG introduction (on Jan 28th where we are discussing data governance interoperability with notice and consent receipts work and discussion that is in progress.
Information for the sessions tomorrow are below.
Kind Regards,
- Mark
Goto meeting call details, (with some guidance):
- you do not have to login to GotoMeeting to access the call,
- we will be recording the event - and we intend to share this on the Public ANCR WG page
- And, as a result, we do not require to put your video on, and you do not have to share information in the call, but, we recommend our normal practice of showing your video when you speak.
- This is not an official ANCR work group meeting, details for work group sign up are provided after the launch.
You can join the ANCR WG Launch from your computer, tablet or smartphone. And stay in the Video Call for the Demo’ Sessions -
https://global.gotomeeting.com/join/562338533
You can also dial in using your phone.
United States: +1 (646) 749-3112
Access Code: 562-338-533
New to GoToMeeting? Get the app now and be ready for your the ANCR Launch meeting
starts: https://global.gotomeeting.com/install/562338533
ANCR WG - Launch
Session 1: - Data Gov Interop Landscape 2021
Scheduled: Jan 28, 2021 at 8:45 AM to 10:00 AM
Location: https://global.gotomeeting.com/join/562338533
Introductions to topic, each other & WG
Kantara ANCR WG - Sal & Vitor
ISO 29184/27560 - Mark
W3C -DPVC - CG - Beatrix
ToiP-ISIWG - DDE Architecture (MMM)- Paul
UMA Legal Editor - Tim Reinegar
MyData/aNG, : Matthias, Olivier
ANCR WG -Demo’s
Session 2: Demo's - Receipts and Dynamic Data Economy
Scheduled: Jan 28, 2021 at 10:00 AM to 11:45 AM
(Up to 9 min Demo’s +2-3 min chat)
- Vitor - Privacy As Expected: Consent Gateway
- Paul - Data Immunity Passport
- Christoph - Data Sharing Hub
- Lal - iGrant
- Xavier - Fair Data