Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Toward End-User Consent at Internet Scale

Section
Column
width66%

Scalable Consent is an initiative to develop a framework, and working code, in support of effective and informed end-user consent and attribute release at Internet scale. The work supports fine-grained, revocable, informed, and well managed consent services that will allow both user and organization to control the release of their attributes to relying parties throughout an identity ecosystem. The development was catalyzed by an NSTIC grant from NIST, and is being enhanced and maintained by the TIER activity within Internet2.

The deliverables include:

  • an architectural model and APIs associated with each flow and component within the model. The hub of the model is a Consent-informed Attribute Release Manager (CARMA) that interacts with the UI and integrates individual and institutional attribute release preferences.
  • working code, both as a standalone service and embedded within a Shibboleth IdP, that implements scalable consent and attribute release across a variety of protocols, including SAML, OIDC, OAuth, etc.
  • a next-gen UI that allows the user to manage their attribute releases in an informed and effective manner
  • API's and sample connectors that deliver the information for informed consent - services such as RP identification, minimal and optional attributes, information dialogues, histories of prior and similar releases, etc.
  • enterprise management services to help an organization deploy and management attribute release that integrates both end-user and institutional policies.  
  • planning documents, discussion materials, and inter-institutional communications to facilitate deployments

The work is intended to help foster an open and interoperable identity ecosystem. Goals include consent that is usable and privacy preserving, improved support for accessibility, and fostering identity portability. All the specifications and code are open-source.

Column
width34%
iFrame
allowfullscreentrue
srchttps://www.youtube.com/embed/qKIrXs1uOaw
width250
height140

 

This demo provides a look at Duke University's implementation of the CAR module that allows an individual to see the attributes being requested by a service and then make a decision about release.


iFrame
srchttps://www.youtube.com/embed/7Y-K9czSh7A
width250
height140

 

This video gets more specific into the interaction between the CAR module and institutional attribute release policies. The example looks at institutional attribute release policies and access to the LIGO collaboration.

 

Section
Column
width25%
Panel
borderColor#3C78B5
bgColor#F8F7EF
borderWidth1px
titleBGColor#EFEFFF
borderStylesolid
titleScalable Consent Basics

Attribute Release and Consent.pdf

An Overview for Leadership  Consent- A Leadership View.pdf

Scalable Consent FAQ.docx

CAR Demonstrations

CAR under the hood and its use with R&S - CAR under the hood.pdf

 

Presentation for IAM On-Line on Attribute Release and CAR Demos 6/28/17   iamonline6-28-kjk-rob.pdf

Column
width25%
Panel
borderColor#3C78B5
bgColor#F8F7EF
borderWidth1px
titleBGColor#EFEFFF
borderStylesolid
titleCommunity Resources

Information on the EU General Data Protection Regulation (GDPR) - The GDPR has significant impacts on the appropriate use of consent. See the following General Data Protection Regulation (GDPR) and Safer Harbor

CAR and GDPR    GDPR and CAR.pdf

Information on Privacy and Consent from the UK ICO - UK Information Resources

Consent and Privacy from the Canadian Privacy Commissioner - consent_201605_e.pdf

Draft on EU Privacy Code of Conduct - http://www.bbc.com/news/science-environment-35524440 and DraftmHealthCodeofConduct.pdf

 

Column
width25%
Panel
borderColor#3C78B5
bgColor#F8F7EF
borderWidth1px
titleBGColor#EFEFFF
borderStylesolid
titleTechnical Information
See CAR: Consent-informed Attribute Release system

 

...