2023-03-22 Meeting notes

approved

https://kantara.atlassian.net/wiki/spaces/PEMCP/pages/170065921


Date

Mar 22, 2023

Attendees

See the Participant roster

Voting (5 of 9 required for quorum)

Participant

Attending

Participant

Attending

1

Aronson, Marc

Yes

2

Chaudhury, Atef / Krishnaraj, Venkat

Yes

3

Davis, Peter

 

4

D'Agostino, Salvatore

Yes

5

Hodges, Gail

 

6

Jones, Thomas

Yes

7

Thoma, Andreas

 

8

Wunderlich, John

Yes

9

Williams, Christopher

Yes

Non-Voting

Participant

Attending

Participant

Attending

1

Auld, Lorrayne

 

2

Balfanz, Dirk

 

3

Brudnicki, David

 

4

Dutta, Tim

 

5

Flanagan, Heather

Yes

6

Fleenor, Judith

 

7

Glasscock, Amy

 

8

Gropper, Adrian

 

9

Hughes, Andrew

 

10

Jordaan, Loffie

Yes

11

LeVasseur, Lisa

 

12

Lopez, Cristina Timon

 

13

Snell, Oliver

 

14

Stowell, Therese

 

15

Tamanini, Greg

 

16

Vachino, Maria

 

17

Whysel, Noreen

 

Other attendees

  • Jazzmine Dowtin

Goals

  • Check-in on work progress

  • Review draft outline and status of writing tasks

Discussion items (AKA Agenda)

Time

Item

Who

Notes

Time

Item

Who

Notes

5 min.

  • Start the meeting.

  • Call to order.

  • Approve minute

  • Approve agenda

@John Wunderlich 

Called to order: 13:04

Quorum reached: Yes

Minutes to approve: Approved, no objections

https://kantara.atlassian.net/wiki/spaces/PEMCP/pages/166002689

Introductions:

  • New member - Jazzmine Dowtin, working for Idemia as their government relation associate.

0 min.

Open Tasks Review

All

 

45 min.

Draft Report

@John Wunderlich

Draft report: Google doc

  • This is the framing document, not the final deliverable of recommendations.

  • Purpose and Scope

    • diagram must be replaced with most current version (done). Would be helpful to have a legend that explains the different types of lines, arrows, colors.

  • Reading this doc (and throughout)

    • Instead of “user” or “Hope” consider using “Holder” or “Verifier” as appropriate.

    • Need to reconsider the word “describe” in the definition of Holder. It says nothing about the binding to the device; perhaps we deal with that in the use case description. Perhaps “the natural person whose attributes are contained in a mobile credential.”

      • Is it ok that we’re touching on delegates? Where are they handled in the doc? The Holder and the Subject are distinct. The Holder has to control the device, even though that’s not part of the definition now.

  • UC2 - reminder to see the conversation from last week (https://kantara.atlassian.net/wiki/spaces/PEMCP/pages/166002689 ). There is no verification that the Holder is the holding the device. There are different definitions of unattended, and if we’re referring to the ISO use case, it might take us in a different direction. Suggest to just remove the offending sentence entirely.

    • Regarding @PeterD (Deactivated) ‘s comment in the doc, will come back to it when he’s on the call.

  • UC3 - if we’re deleting the previous in-person note, we should remove it from this as well.

  • UC4, UC5 - consider replacing “mDL” with “mobile credential”. We need to be consistent throughout, though if we want to be specific, it’s not wrong in a use case.

  • UC5 - “and use high levels of security”

    • might suggest an arrow between the Issuer and Verifier in the diagram? No, this is more like wallet providers talking to the OS.

  • UC6 - ok

  • Terms and Definitions

    • appropriate friction - a term we may want to come back to.

    • also a concerned with the use of “implied” consent.

      • To discuss on the next call. Please submit any written input for review before the call. Individuals are welcome to post to the PEMC blog, but please make sure it is clear they are writing as individuals, not on behalf of the PEMC WG.

 

5 min.

Government-issued Digital Credentials and the Privacy Landscape

@Heather Flanagan (Unlicensed)

Draft ready for a private comment period; public comment period to start the first week of April

5 min.

Other Business



NCCoE call for comment on the mDL - see . Comments due 31 March 2023. Even a mention that our work is underway would be helpful

 

Adjourn



 

Next meeting

Mar 29, 2023

Action items

@John Wunderlich to update the charter language in the overview based on the revised charter
@John Wunderlich and @Christopher Williams requested to do an early review of the Government-issued Digital Credentials and the Privacy Landscape white paper.
@John Wunderlich to draft a short comment in response to the NCCOE call for comments on mDLs that share the work the PEMC WG is doing.