UMA telecon 2023-05-04
UMA telecon 2023-05-04
Date and Time
Every other Thursday @ 1:00ET/10:00am PT
Screenshare and dial-in: https://zoom.us/j/99487814311?pwd=dTAvZi9uN0ZmeXJReWRrc1Zycm5KZz09
United States: +1 346 248 7799, Access Code: 994 8781 4311
See UMA calendar for additional details: https://kantara.atlassian.net/wiki/spaces/uma/pages/4857518/Calendar
Agenda
Approve minutes since UMA telecon 2023-01-12
Check-in, Pensions Dashboard Use-case report
IIW Recap?
AOB
Attendees
NOTE: As of Sept 15, 2022, quorum is 4 of 6. (Peter, Sal, Alec, Eve, Steve, Sophia)
Voting:
Alec
Steve
Non-voting participants:
Nancy
Mark
Regrets:
Quorum: No
Meeting Minutes
Approve previous meeting minutes
Approve minutes of UMA telecon 2023-01-12 UMA telecon 2023-01-19 , UMA telecon 2023-02-02 , UMA telecon 2023-02-09 , UMA telecon 2023-02-17 , UMA telecon 2023-03-02 , UMA telecon 2023-03-09 , UMA telecon 2023-03-16 , UMA telecon 2023-03-23 , UMA telecon 2023-03-30 , UMA telecon 2023-04-06 , UMA telecon 2023-04-20
Deferred - no quorum
Topics
Pensions Dashboard / Open Banking Use-case report
Draft will be worked on here: Pension Dashboard Use-Case Report
AOB
UDAP, it’s a different need - user not present use-case. While UMA focused entirely on user-present (at at least managed) data flows.
could we create a HL7 group with a liaison to progress “UMA in health” use cases with appropriate visibility? Nancy and Alec will chat more on this topic
could we show broad access cases (UMA protects a FHIR API) in addition to granular use-cases (e.g. sensitive information, or FHIR resource(s))
Potential Future Work Items / Meeting Topics
Tentative 2023 roadmap:
120 A financial use-case report (following the Julie healthcare template)
openbanking is to FHIR(data model) as FAPI is to SMARTonFHIR(authZ protocol profile)
123 Pensions Dasboard Report → use-case is well understood and live/going live soon. tight use-case
Let’s reach out to some of the involved people eg at Origo or Forgerock. Were there any gaps in UMA they had to work around?
127 Open Banking Report → requires more research, determine use case
Who would lead this/ needs this for UMA in open banking contexts? Should come after FAPI review?
130 IDPro knowledge base articles
140 Wikipedia article refresh: User-Managed Access
UMA simple value explainers, business and technical ‘marketing’
Full list:
20 Confluence clean up, archive old items and promote the latest & greatest
10 UMA glossary – Steve has started
100 FAPI Review (FAPI + UMA)
scope: how the FAPI work could be applied to UMA ecosystems
review may inform what profiling work is required, eg if UMA must support PAR to work with FAPI
120 A financial use-case report (following the Julie healthcare template)
openbanking is to FHIR(data model) as FAPI is to SMARTonFHIR(authZ protocol profile)
123 Pensions Dasboard Report → use-case is well understood and live/going live soon. tight use-case
Let’s reach out to some of the involved people eg at Origo or Forgerock. Were there any gaps in UMA they had to work around?
127 Open Banking Report → requires more research, determine use case
Who would lead this/ needs this for UMA in open banking contexts? Should come after FAPI review?
130 IDPro knowledge base articles
140 Wikipedia article refresh
150 Minor profiling work,
resource scopes → scopes
PAR as dynamic scopes eg fhir query params
policy manager & policy description
110 pushed claims types: templates + profiles (beyond IDTokens): 171 VCs, 113 consent, policy, mDL
use-case, consent as claims (needs_info),
if the client has gathered RqP consent, can it be presented to the AS
the policy to access a resource says "you must have agreed to this TOS/consent"
compare to interactive claims gathering where the AS would present this consent/TOS to the RqP
intersection with ANCR/consent receipt/trust registry work in other Kantara groups
170 UMA + Verifiable Credentials
how would VCs work in an UMA ecosystem? How could VCs be used as claims in UMA
There are openapi specs for VC formats
Could UMA protect a VC presentation or issuance endpoint?
There's a lot of openid4vc profiles
300 mDL + UMA
scope: how mDL could work in UMA ecosystems, how mDL could be a claim to UMA
is there a role for UMA in token fabrication and referencing it as the RS?
600 Review of the email-poc correlated authorization specification
500 UMA + GNAP https://oauth.xyz/specs/
would we have an UMA GNAP version (eg extension of GNAP or UMA? UMAonGNAP)
will GNAP meet all the UMA outcomes?
UMA 2 playground/sandbox