OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

members message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Call for Consent for Secure QR Code Authentication Version 1.0 as OASIS Standard


OASIS Members:

The Electronic Secure Authentication (ESAT) TC members [1] have approved submitting the following CS01 to the OASIS Membership in a call for consent for OASIS Standard:

Secure QR Code Authentication Version 1.0
Committee Specification 01
01 July 2022

This is a call to the primary or alternate representatives of OASIS Organizational Members to consent or object to this approval. You are welcome to register your consent explicitly on the ballot; however, your consent is assumed unless you register an objection [2]. To register an objection, you must:

1. Indicate your objection on this ballot, and

2. Provide a reason for your objection and/or a proposed remedy to the project.

You may provide the reason in the comment box or by email to the TC on its comment mailing list [2]. If you provide your reason by email, please indicate in the subject line that this is in regard to the Call for Consent. Note that failing to provide a reason and/or remedy may result in an objection being deemed invalid.

Description

The specification describes the use of QR Codes and a mobile phone as a replacement for a username and password in user login authentication. An alternative to passwords that includes QR Codes is described, and typical use cases are described. This document also provides an overview and context for using QR Codes for security purposes.

In addition, the document specifies a "Secure QR Code Authentication Protocol" (SQRAP) and assesses the related security threats and risks.
Â
Details

The Call for Consent opens at 21 September 2022 00:00 UTC and closes on 04 October 2022 23:59 pm timezone. You can access the ballot at:

Internal link for voting members: https://www.oasis-open.org/apps/org/workgroup/voting/ballot.php?id=3728

Publicly visible link: Âhttps://www.oasis-open.org/committees/ballot.php?id=3728

OASIS members should ensure that their organization's voting representative responds according to the organization's wishes. If you do not know the name of your organization's voting representative is, go to the My Account page at

http://www.oasis-open.org/members/user_tools

then click the link for your Company (at the top of the page) and review the list of users for the name designated as "Primary".

More Information

The Project received 3 Statements of Use from HYPR, Trusona, and CVS [3].

URIs
The prose specification document and related files are available here:

Editable source (Authoritative):
https://docs.oasis-open.org/esat/sqrap/v1.0/cs01/sqrap-v1.0-cs01.docx

HTML:
https://docs.oasis-open.org/esat/sqrap/v1.0/cs01/sqrap-v1.0-cs01.html

PDF:
https://docs.oasis-open.org/esat/sqrap/v1.0/cs01/sqrap-v1.0-cs01.pdf

For your convenience, OASIS provides a complete package of the specification document and any related files in ZIP distribution files. You can download the ZIP file at:

http://docs.oasis-open.org/esat/sqrap/v1.0/cs01/sqrap-v1.0-cs01.zip

Additional information

[1] Electronic Secure Authentication (ESAT) TC
https://www.oasis-open.org/committees/esat/

Project IPR page
https://www.oasis-open.org/committees/esat/ipr.php

[2] Comments may be submitted to the TC via the project mailing list at esat-comment@lists.oasis-open.org. To subscribe, send an empty email to esat-comment-subscribe@lists.oasis-open.org and reply to the confirmation email.

All emails to the TC are publicly archived and can be viewed at https://lists.oasis-open.org/archives/esat-comment/

[3] Statements of use

- HYPR:
https://www.oasis-open.org/apps/org/workgroup/esat/email/archives/202207/msg00001.html

- Trusona:
https://www.oasis-open.org/apps/org/workgroup/esat/email/archives/202207/msg00000.html

- CVS:
https://www.oasis-open.org/apps/org/workgroup/esat/email/archives/202206/msg00009.html

[4] Timeline Summary:

- Committee approved submitting the CS01 to the members as a candidate for OASIS Standard on 19 July 2022: https://www.oasis-open.org/committeesapps/ballot.php?id=3718

- Committee approved the CS01 on 01 July 2022: https://www.oasis-open.org/committees/ballot.php?id=3713

- Committee Specification Draft 01 (CSD01) with 30-day public review approved 25 April 2022: https://www.oasis-open.org/committees/document.php?document_id=69904&wg_abbrev=esat.
 - 30-day public review 01 to be opened on 12 May 2022 and closed on 10 June 2022.
 - Public review announcement: https://lists.oasis-open.org/archives/members/202205/msg00003.html.

--

ChetÂEnsign

Chief Technical Community Steward

OASIS Open

ÂÂÂ
+1 201-341-1393
chet.ensign@oasis-open.org
www.oasis-open.org


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]