Generalized Policy Management

Introduction

Over the past two decades, several open authentication and authorization frameworks for the Web have been conceived, and matured into widely-used standards, including XACML (3.0), OAuth (2.0) and OpenID Connect (2.0). However, after years of patchwork, an overload of extensions, and multiple attempted evolutions – OAuth 2.1, the Grant Negotiation and Authorization Protocol, OpenID’s specifications around Digital Credential, multiple Data Spaces approaches – their age has begun to show:

  • While some of these alternatives are somewhat compatible from afar, most are far from interoperable.
  • Many of them fail to adhere to basic principles of Web standards, such as the orthogonality between authentication and authorization.
  • Few of them establish a link with personal digital rights in contemporary legislation.
  • With the exception of certain approaches to Data Spaces, none of them takes into account the current emphasis on usage, rather than mere access control.

Rather than providing yet another alternative to these historical behemoths and their more recent competitors, this specification builds on top of them, by

  • extracting the shared core of information from the different messages passed within each of these frameworks;
  • aggregating the less common aspects that are unique to one or more of them;
  • constructing a generalized model that encompasses both kinds of data;
  • providing mappings between the proposed model and each of the existing frameworks; and
  • binding similar steps in the protocols to their counterpart in an generic, abstract flow.

0.1 Terminology

…

0.2 Policy Request Model

…

0.2.1 Roles

…

0.2.1.1 Parties

A Party is a person capable of fulfilling a legal role – bearing its responsibilities – with respect to a policy or related operations.

@id
RECOMMENDED IRI. An identifier of the Party.

none (implicit in mapping of legal roles)

rdf:type
RECOMMENDED IRI. The type of the Party.

none (implicit in mapping of legal roles)

credential
RECOMMENDED Assertion. An identifier or (formatted) assertion about the Party.
  • GNAP: ...("user.sub_ids[*]") (pairs of format and id; opt.)
  • GNAP: ...("user.assertions[*]") (pairs of format and value; opt.)
  • RFC….: ...("assertion") (…??; opt.)
format
RECOMMENDED UNIQUE IRI. The format of the identifier or assertion.
  • GNAP:
    • ...("user.sub_ids[*].format") (req. unique)
    • ...("user.assertions[*].format") (req. unique)
value
REQUIRED UNIQUE … (Any). The value of the identifier or assertion.
  • GNAP:
    • ...("user.sub_ide[*].id") (req. unique)
    • ...("user.assertions[*].value") (req. unique)

0.2.1.2 Agents

An Agent is an application capable of fulfilling a technical role, with respect to a policy or related operations, on behalf of and under the responsibility of a Party.

0.2.2 Operations

An Operation is the event to which a rule applies. It comprises the following information.

@id
RECOMMENDED] IRI[]. An identifier of the operation.
  • Data Spaces: iri("offer.@id") (absent if derived from dataset; opt. unique)
  • ODRL (Policy): iri("uid") (req. unique)
rdf:type
RECOMMENDED IRI[]. The type of the operation.
  • GNAP: iri("access_token.access[].type") (req.)
  • OAuth, RAR: iri("authorization_details[*].type") (req.)
target
RECOMMENDED Asset[] . The asset(s) targeted by the operation.
  • RI: Assets("resource") (req. unique)
  • UMA: Assets("resource_id") (req. unique; in ticket)
  • RAR: Assets("authorization_details[*].identifier") (opt. unique)
  • GNAP: Assets("access_token.access[*].identifier") (opt. unique)
  • Data Spaces (absent if derived from dataset):
    • Assets("offer.target") (shared; opt. unique)
  • ODRL (Policy):
    • Assets("target") (shared short; opt. unique)
    • Assets("target.uid") (shared; opt. unique)
    • Assets("<rule>[*].target") (short; opt. unique)
    • Assets("<rule>[*].target.uid") (req. unique)
  • OIDC:
    • Assets("claims.id_token") (opt.)
    • Assets("claims.userinfo") (opt.)
  • OpenID4VCI:
    • Assets("credential_configuration_id") (req. unique)
    • Assets("authorization_details[*].claims[*]") (opt.)
  • OpenID4VP:
    • Assets("dcql_query.credentials[*]") (opt.)
    • Assets("dcql_query.credentials[*].claims[*]") (opt.)
action
RECOMMENDED Action[]. The action(s) that the operation would perform.
  • OAuth: Actions("scope") (opt. unique)
  • UMA: Actions("resource_scopes") (req. unique; in ticket)
  • RAR:
    • Actions("authorization_details[*].actions") (opt. unique)
    • Actions("authorization_details[*].privileges") (opt. unique)
    • Actions("authorization_details[*].datatypes") (opt. unique)
  • GNAP:
    • Actions("access_token.access[*].actions") (opt. unique)
    • Actions("access_token.access[*].privileges") (opt. unique)
    • Actions("access_token.access[*].datatypes") (opt. unique)
  • Data Spaces (absent if derived from dataset):
    • Actions("offer.<rule>[*].action") (opt. unique)
  • ODRL (Policy):
    • Actions("action") (shared short; opt. unique)
    • Actions("action.uid") (shared; opt. unique)
    • Actions("<rule>.action") (short; opt. unique)
    • Actions("<rule>.action.uid") (req. unique)
  • OIDC, OpenID4VCI, OpenID4VP: static({ @id: "openid:read" })
actor
RECOMMENDED Party[]. The parties to whom authorized operations are assigned.
  • TE: Parties("actor_token") (req. unique)
  • ODRL: Parties("<rule>.assignee") (opt. unique)
agent
RECOMMENDED Agent[]. The software instances that will execute an operation of this rule on behalf of an Actor.
  • CM: Agents("client_uri") (req. unique)
  • OAuth: Agents("client_id") (req. unique)
  • UMA: Agents("client_id") (req. unique)
  • GNAP: Agents("client") (req. unique)

1 Policies

…

The following roles are defined as properties of policies.

subject
RECOMMENDED UNIQUE Party. The party on whose behalf the authorization is requested. They bear the ultimate responsibility for adherence to an eventual agreement. If the request contains operations without explicit actor, the subject is held to be the actor.
  • TE: Party("subject_token") (opt. unique)
  • GNAP: Party("user") (opt. unique)
  • ODRL: Party("assignee") (opt. unique)
  • DataSpaces: Party("consumerPid") (request; req. unique)
owner
RECOMMENDED UNIQUE Party. The party on whose behalf the authorization is ultimately assigned. If the request contains no explicit owner, the controller is held to be the owner.

none (existing specifications only support direct control)

controller
RECOMMENDED UNIQUE Party. The party who assigns the authorized operation(s).
  • ODRL: Party("assigner") (req. unique)
  • DataSpaces: Party("providerPid") (req. unique)

Table 1: Syntax for specifying the target and scope of an authorization request.
Spec.
       Target
        Scope
OAuth 2.x / scope
~ RI resource /
~ UMA resource_id (ticket) resource_scopes (ticket)
~ RAR authorization_details[]
 .identifier
 .location
authorization_details[]
 .actions  .privileges
 .datatypes
GNAP access_token.access[]
 .identifier
 .location
access_token.access[]
 .actions
 .privileges
 .datatypes
ODRL permission[].target permission[].action
Data Spaces offer.permission[].target offer.permission[].action
OIDC claims.id_token.[key]
claims.userinfo.[key]
 .essential
 .values[]
 .value
/
OpenID4VCI authorization_details[]
 .cred..._conf..._id
 .claims[]
    .path[]
    .mandatory
/
OpenID4VP dcql_query
 .credentials[]
    .claims[]
        .path[]
        .values[]
/