OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

coel message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] (COEL-76) RPE: Improve Security of the Consumer ID


     [ https://issues.oasis-open.org/browse/COEL-76?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

David Snelling updated COEL-76:
-------------------------------

    Assignee: Paul Bruton

> RPE: Improve Security of the Consumer ID
> ----------------------------------------
>
>                 Key: COEL-76
>                 URL: https://issues.oasis-open.org/browse/COEL-76
>             Project: OASIS Classification of Everyday Living (COEL) TC
>          Issue Type: Task
>            Reporter: Paul Bruton
>            Assignee: Paul Bruton
>
> Pseudonymous Keys used as Consumer IDs need to be handled carefully since they could be mis-used to pollute the atom collection in a data engine, or to retrieve data about a consumer if a service providers credentials are divulged. 
> We can reduce the likelihood of this happening by ensuring that the consumer ID is only used between a small number of actors: the Operator, Service Provider and Data engine. This can be achieved by using device ids elsewhere so that the consumer rarely gets their Consumer ID. (We cannot say never give the Consumer ID to the consumer, but we can enumerate the scenarios that they are likely to need it k - for example when confirming they have been forgotten - and point out that this is a weak link.)
> We should make some statements about secure us of the consumer ID between the Operator and Service provider (since much of that is out of band as far as the standard is concerned).



--
This message was sent by Atlassian JIRA
(v6.2.2#6258)


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]