태그 : oasis
2009/03/01 Identity Metasystem 상호호환성 문서 v1.0 공개 리뷰 등
2008/07/08 SAML2.0의 Level of Assurance 프로파일 드래프트
2008/04/27 XACML 상호운용성 시험(RSA 2008)
2007/12/24 OASIS SAML의 5개 표준 드래프트 공개리뷰
# by | 2009/07/04 05:53 | CardSpace | 트랙백
# by | 2009/03/01 19:27 | 기타 ID 동향 | 트랙백
# by | 2008/07/08 21:38 | 기타 ID 동향 | 트랙백
XACML is a language focused solely on Access Control. All it does is Access Control and nothing else [2]
BEA, IBM, Sun, Axiomatics, Cisco, and the US Department of Veteran Affairs, [correction: and Redhat/JBoss too!].[2]
HL7은 다양한 의료정보시스템간 정보의 교환을 위하여 미국국립표준연구소(ANSI)가 인증한 의료정보 교환 표준규약으로서 13개 회원국(호주,캐나다,핀란드,독일,인도,네덜란드,뉴질랜드,남아프리카 10개국 연합,영국,일본,중국,대만,한국)에 지부를 두고있다.
HL7을 이용하면, 병원간에 입원(Admissions), 퇴원(Discharges) 및 전원(Transfer) 등의 ADT 메시지를 손쉽게 교환할 수 있다. 그러나, 의사처방(Order Entry)이나 간호기록(Nursing Records), 검사결과(Results) 등과 같이 다양한 의학용어의 정의나 각 명세 항목에 대한 표준화가 80% 수준에 머물고 있으며, 이를 한글화한 정확한 표현이 없는 것이 큰 문제점으로 지적할 수 있겠다. [4]
Actually, demo app doesn't begin to do it justice - the application showed how a patient could set policy to control access to medical records, down through controls on individual physicians seeing your records to physician + resource (e.g. Dr Bob isn't allowed to see my radiography results) and more. There was even an emergency 'break glass' override included to allow a physician (duly authenticated, of course) to get access to any of your notes via a specific affirmation that an emergency is in progress.[5]
For me, the really cool thing was when Rich showed me how a patient could block access to a specific doctor, or conversely, a doctor in an emergency room situation could be granted access to patient records. This particular scenario has been one of the primary examples put forward by many government organizations I have spoken with. It was also talked widely by participants of the business requirements review of IGF at Project Liberty
Now, with web policy demonstrating these requirements in an application context at an open interop, it makes the Rich's initial recommendation of basing Attribute Authority Policy Markup Language (AAPML) as a profile of XACML to be right on target! [6]
# by | 2008/04/27 18:26 | 기타 ID 동향 | 트랙백
This specification defines a SAML HTTP protocol binding, specifically using the HTTP POST method, and not using XML Digital Signature for SAML message data origination authentication. Rather, a “sign the BLOB” technique is employed wherein a conveyed SAML message is treated as a simple octet string if it is signed. Conveyed SAML assertions may be individually signed using XMLdsig. Security is optional in this binding.
Defines a generic browser-based protocol by which a centralized discovery service implemented independently of a given service provider can provide a requesting service provider with the unique identifier of an identity provider that can authenticate a principal.
This deployment profile specifies the use of SAML V2.0 attribute queries and assertions to support distributed authorization in support of X.509-based authentication.
This related set of SAML V2.0 deployment profiles specifies how a principal who has been issued an X.509 identity certificate is represented as a SAML Subject, how an assertion regarding such a principal is produced and consumed, and finally how two entities exchange attributes about such a principal.
This profile is a replacement for the X.500/LDAP Attribute Profile found in the original SAML 2.0 Profiles specification [SAML2Prof]. The original profile results in well-formed but schema-invalid XML and cannot be corrected without a normative change.
# by | 2007/12/24 10:16 | 기타 ID 동향 | 트랙백
◀ 이전 페이지다음 페이지 ▶