Federated Authorization over Access to Personal Data for Decentralized Identity Management
Thomas Hardjono · IEEE Communications Standards Magazine · 2019
The digital identity problem is a complex one in large part because it involves personal data, the algorithms which compute insights on the data, and the management of the identifiers that are linked to personal data. The reality of today is that personal data of an individual is distributed throughout the Internet, in both private and public institutions, and increasingly also on the user's devices. In order to empower individuals to have a say in who has access to their personal data and to enable individuals to make use of their data for their own purposes, a coherent and scalable federated authorization architecture is required as a fundamental component of the decentralized identity solution. This federation must allow an individual to easily manage access policies, and to grant and retract consent for access to data distributed across multiple repositories. This article describes the User Managed Access architecture and protocols that provide the foundation for scalable federated authorization.