Informatievlaanderen / OSLOthema-consent

GitHub repository for the OSLO trajectory "consent"
0 stars 0 forks source link

Consent given to Agents with the necessary credentials #3

Closed dimi-schepers closed 2 years ago

dimi-schepers commented 2 years ago

Most authentication systems are bound to specific individuals (or organisations). Credential consents (e.g., every nurse has consent to access my blood group information) are also important, however. There are two approaches for this:

During the workshop dd. 2021-09-23, the credential-based approach was generally preferred. The Core Criterion and Core Evidence Vocabulary and W3C’s Verifiable Credentials could perhaps serve as modelling suggestions.

michaelgeamanu commented 2 years ago

Digitaal Vlaanderen proposes to use the CCCEV data model which is a European standard for organisations to set the requirements of a certain service. It helps to standardise the wide possibilities of contexts for which a consent could be needed.

CCCEV contains two basic and complementary core concepts:

  1. the Requirement, a broad notion encompassing all forms of requests for information, that is often, but not necessarily, made with the objective to use it as a basis for making a judgement or decision; and
  2. the Evidence, the data proving or disproving that a specific Requirement is met by someone or something, and thus has been fulfilled.