2024-11-27 Meeting notes

Date

Nov 27, 2024

Attendees

See the Participant roster

Voting (3 of 6 required for quorum)

Participant

Attending

Participant

Attending

1

Chaudhury, Atef

 

2

Jones, Thomas

Yes

3

Krishnaraj, Venkat

 

4

Thoma, Andreas

 

5

Wunderlich, John

Yes

6

Williams, Christopher

Regrets

Non-Voting

Participant

Attending

Participant

Attending

1

Auld, Lorrayne

 

2

Aronson Mark

 

3

Balfanz, Dirk

 

4

Brudnicki, David

 

5

D'Agostino, Salvatore

 

6

Davis, Peter

 

7

Dowtin, Jazzmine

 

8

Dutta, Tim

 

9

Flanagan, Heather

 

10

Fleenor, Judith

 

11

Glasscock, Amy

 

12

Graaf, Irene

 

13

Gropper, Adrian

 

14

Hodges, Gail

 

15

Hughes, Andrew

Yes

16

Jordaan, Loffie

Yes

17

LeVasseur, Lisa

 

18

Lopez, Cristina Timon

 

19

McBride, Adam

 

20

Pasquale, Jim

 

21

Snell, Oliver

 

22

Stowell, Therese

 

23

Sutor, Hannah

 

24

Tamanini, Greg

 

25

Vachino, Maria

 

26

Whysel, Noreen

 

Goals

  • Review process for requirement creation and review

Discussion items (AKA Agenda)

Item

Who

Notes

Item

Who

Notes

  • Start the meeting.

  • Call to order

  • Approve minutes

  • Approve agenda

@John Wunderlich

Called to order: 14:05

Quorum reached: No

Minutes to approve:

https://kantara.atlassian.net/wiki/spaces/PEMCP/pages/754679809

Open Tasks Review

All

Link to Recommendations (Commenter Link): Recommendations for Privacy Enhancing Mobile Credentials

Requirements Analysis

@Andrew Hughes

 

@Andrew Hughes has provided an requirements analysis

Discussion

  • Consider the use of the phrase “Authorized Processing” for the purposes of including consent plus other ways in which processing of credential data may proceed

  • In the context of this document the normal and expected presentation of the credential is a tap (or possibly a QR Code).

    • The only time that credential data may be collected without a tap or without notice would be will a legal authority or by a bad actor - both of which are out of scope

  • Requirements need to be read as a whole for a given actor in a given use case (i.e. an entity can’t pick and choose the requirements that they like.

  • Normative as term should be read as a description of the future state of the system.

Comment Disposition

@John Wunderlich

 

Working throuch comments provided

Discussion

 

NOTE: Only Kantara Members can vote on approving report for publication. If you or your organisation are not Kantara members and want to vote, you will need to become Kantara members.

 

Implementors and Implementors Guidelines

All

Looking for organisations to volunteer to implement the requirements and self certify. This is a valuble first step towards ensuring that the requirements are practicable and may lead to usefull revisions

 

Adjourn

 

Next meeting

Dec 4, 2024

Action items

@John Wunderlich to coordinate comment dispostion

 

 

Related pages