Toward End-User Consent at Internet Scale

Scalable Consent is an initiative to develop a framework, and working code, in support of effective and informed end-user consent at Internet scale. The work supports fine-grained, revocable, informed, and well managed consent services that will allow both user and organization to control the release of their attributes to relying parties throughout an identity ecosystem. The development was catalyzed by an NSTIC grant from NIST, and is being enhanced and maintained by the TIER activity within Internet2. 

The deliverables include:

The work is intended to help foster an open and interoperable identity ecosystem. Goals include consent that is usable and privacy preserving, improved support for accessibility, and fostering identity portability. All the specifications and code are be open-source.


 

Attribute Release and Consent Attribute Release and Consent.pdf

An Overview for Leadership  Consent- A Leadership View.pdf

Scalable Consent FAQ Scalable Consent FAQ.docx

Scalable Consent Requirements

Current Status scalable consent - basics.pdf

Release Schedule and Capabilities release schedule and capabilities.pdf

Demonstration site - Yourtown Community Web Site and Wiki Yourtown Community Web Site and Wiki

Information on the EU General Data Protection Regulation (GDPR) - The GDPR has significant impacts on the appropriate use of consent. See the following General Data Protection Regulation (GDPR) and Safer Harbor

Information on Privacy and Consent from the UK ICO - UK Information Resources

Consent and Privacy from the Canadian Privacy Commissioner - consent_201605_e.pdf

Draft on EU Privacy Code of Conduct - http://www.bbc.com/news/science-environment-35524440 and DraftmHealthCodeofConduct.pdf

Scalable Consent Demo - The PrivacyLens demo site at https://work.iamtestbed.internet2.edu/drupal/ shows the capabilities of PrivacyLens. In addition it illustrates how PL and fine-grain attribute release is a key step towards scalable access control with privacy and security.  In addition to the real-time demo site, there are a set of annotated slides at https://work.iamtestbed.internet2.edu/confluence/display/YCW/Demonstration+Slides.

 

Basic Architecture Overview CARMA architecture.pdf

Working in a consistent fashion across multiple protocols. Working with multiple protocols

Next-gen UI -

"Informed Content" management - Information and metadata management in support of informed consent - Informed Consent Support and Metadata




 

Work described is supported in part by the National Strategy for Trusted Identities in Cyberspace (NSTIC) National Program Office and the National Institute of Standards and Technology (NIST). The views in this presentation do not necessarily reflect the official policies of the NIST or NSTIC, nor does mention by trade names, commercial practices, or organizations imply endorsement by the U.S. Government.

 

NOTE: All Internet2 Activities are governed by the Internet2 Intellectual Property Framework.