Generalized Policy Management
Introduction
Over the past two decades, several open authentication and authorization frameworks for the Web have been conceived, and matured into widely-used standards, including XACML (3.0), OAuth (2.0) and OpenID Connect (2.0). However, after years of patchwork, an overload of extensions, and multiple attempted evolutions – OAuth 2.1, the Grant Negotiation and Authorization Protocol, OpenID’s specifications around Digital Credential, multiple Data Spaces approaches – their age has begun to show:
- While some of these alternatives are somewhat compatible from afar, most are far from interoperable.
- Many of them fail to adhere to basic principles of Web standards, such as the orthogonality between authentication and authorization.
- Few of them establish a link with personal digital rights in contemporary legislation.
- With the exception of certain approaches to Data Spaces, none of them takes into account the current emphasis on usage, rather than mere access control.
Rather than providing yet another alternative to these historical behemoths and their more recent competitors, this specification builds on top of them, by
- extracting the shared core of information from the different messages passed within each of these frameworks;
- aggregating the less common aspects that are unique to one or more of them;
- constructing a generalized model that encompasses both kinds of data;
- providing mappings between the proposed model and each of the existing frameworks; and
- binding similar steps in the protocols to their counterpart in an generic, abstract flow.
0.1 Terminology
…
0.2 Policy Request Model
…
0.2.1 Roles
…
0.2.1.1 Parties
A Party is a person capable of fulfilling a legal role – bearing its responsibilities – with respect to a policy or related operations.
@id-
RECOMMENDED IRI. An identifier of the Party.
NoteMappings
none (implicit in mapping of legal roles)
rdf:type-
RECOMMENDED IRI. The type of the Party.
NoteMappings
none (implicit in mapping of legal roles)
credential-
RECOMMENDED Assertion. An identifier or (formatted) assertion about the Party.
NoteMappings
- GNAP:
...("user.sub_ids[*]")(pairs offormatandid; opt.) - GNAP:
...("user.assertions[*]")(pairs offormatandvalue; opt.) - RFC….:
...("assertion")(…??; opt.)
format- RECOMMENDED UNIQUE IRI. The format of the identifier or assertion.
NoteMappings- GNAP:
...("user.sub_ids[*].format")(req. unique)...("user.assertions[*].format")(req. unique)
value- REQUIRED UNIQUE … (Any). The value of the identifier or assertion.
NoteMappings- GNAP:
...("user.sub_ide[*].id")(req. unique)...("user.assertions[*].value")(req. unique)
- GNAP:
0.2.1.2 Agents
An Agent is an application capable of fulfilling a technical role, with respect to a policy or related operations, on behalf of and under the responsibility of a Party.
0.2.2 Operations
An Operation is the event to which a rule applies. It comprises the following information.
@id-
RECOMMENDED]
IRI[]. An identifier of the operation.NoteMappings- Data Spaces:
iri("offer.@id")(absent if derived from dataset; opt. unique) - ODRL (Policy):
iri("uid")(req. unique)
- Data Spaces:
rdf:type-
RECOMMENDED
IRI[]. The type of the operation.NoteMappings- GNAP:
iri("access_token.access[].type")(req.) - OAuth, RAR:
iri("authorization_details[*].type")(req.)
- GNAP:
target-
RECOMMENDED
Asset[]. The asset(s) targeted by the operation.NoteMappings- RI:
Assets("resource")(req. unique) - UMA:
Assets("resource_id")(req. unique; in ticket) - RAR:
Assets("authorization_details[*].identifier") (opt. unique) - GNAP:
Assets("access_token.access[*].identifier")(opt. unique) - Data Spaces (absent if derived from dataset):
Assets("offer.target")(shared; opt. unique)
- ODRL (Policy):
Assets("target")(shared short; opt. unique)Assets("target.uid")(shared; opt. unique)Assets("<rule>[*].target")(short; opt. unique)Assets("<rule>[*].target.uid")(req. unique)
- OIDC:
Assets("claims.id_token")(opt.)Assets("claims.userinfo")(opt.)
- OpenID4VCI:
Assets("credential_configuration_id")(req. unique)Assets("authorization_details[*].claims[*]")(opt.)
- OpenID4VP:
Assets("dcql_query.credentials[*]")(opt.)Assets("dcql_query.credentials[*].claims[*]")(opt.)
- RI:
action-
RECOMMENDED
Action[]. The action(s) that the operation would perform.NoteMappings- OAuth:
Actions("scope")(opt. unique) - UMA:
Actions("resource_scopes")(req. unique; in ticket) - RAR:
Actions("authorization_details[*].actions")(opt. unique)Actions("authorization_details[*].privileges")(opt. unique)Actions("authorization_details[*].datatypes")(opt. unique)
- GNAP:
Actions("access_token.access[*].actions")(opt. unique)Actions("access_token.access[*].privileges")(opt. unique)Actions("access_token.access[*].datatypes")(opt. unique)
- Data Spaces (absent if derived from dataset):
Actions("offer.<rule>[*].action")(opt. unique)
- ODRL (Policy):
Actions("action")(shared short; opt. unique)Actions("action.uid")(shared; opt. unique)Actions("<rule>.action")(short; opt. unique)Actions("<rule>.action.uid")(req. unique)
- OIDC, OpenID4VCI, OpenID4VP:
static({ @id: "openid:read" })
- OAuth:
actor-
RECOMMENDED
Party[]. The parties to whom authorized operations are assigned.NoteMappings- TE:
Parties("actor_token")(req. unique) - ODRL:
Parties("<rule>.assignee")(opt. unique)
- TE:
agent-
RECOMMENDED
Agent[]. The software instances that will execute an operation of this rule on behalf of an Actor.NoteMappings- CM:
Agents("client_uri")(req. unique) - OAuth:
Agents("client_id")(req. unique) - UMA:
Agents("client_id")(req. unique) - GNAP:
Agents("client")(req. unique)
- CM:
1 Policies
…
The following roles are defined as properties of policies.
subject-
RECOMMENDED UNIQUE
Party. The party on whose behalf the authorization is requested. They bear the ultimate responsibility for adherence to an eventual agreement. If the request contains operations without explicit actor, the subject is held to be the actor.NoteMappings- TE:
Party("subject_token")(opt. unique) - GNAP:
Party("user")(opt. unique) - ODRL:
Party("assignee")(opt. unique) - DataSpaces:
Party("consumerPid")(request; req. unique)
- TE:
owner-
RECOMMENDED UNIQUE
Party. The party on whose behalf the authorization is ultimately assigned. If the request contains no explicit owner, the controller is held to be the owner.NoteMappingsnone (existing specifications only support direct control)
controller-
RECOMMENDED UNIQUE
Party. The party who assigns the authorized operation(s).NoteMappings- ODRL:
Party("assigner")(req. unique) - DataSpaces:
Party("providerPid")(req. unique)
- ODRL:
| Spec. | |
|
|---|---|---|
| OAuth 2.x | / | scope |
| ~ RI | resource |
/ |
| ~ UMA | resource_id (ticket) |
resource_scopes (ticket) |
| ~ RAR | authorization_details[].identifier.location |
authorization_details[].actions .privileges.datatypes |
| GNAP | access_token.access[].identifier.location |
access_token.access[].actions.privileges.datatypes |
| ODRL | permission[].target |
permission[].action |
| Data Spaces | offer.permission[].target |
offer.permission[].action |
| OIDC | claims.id_token.[key]claims.userinfo.[key].essential.values[].value |
/ |
| OpenID4VCI | authorization_details[].cred..._conf..._id.claims[].path[].mandatory |
/ |
| OpenID4VP | dcql_query.credentials[].claims[].path[].values[] |
/ |