[gnso-rds-pdp-wg] One Way Gated Access to Data Might Work

Volker Greimann vgreimann at key-systems.net
Mon Dec 12 15:40:19 UTC 2016


Hi Scott,

thank you for your clarification. That reaction was based on my 
misconception of the proposal then. I am looking forward to seeing how 
this evolves further.

Best,

Volker



Am 12.12.2016 um 15:45 schrieb Hollenbeck, Scott:
>
> *From:*gnso-rds-pdp-wg-bounces at icann.org 
> [mailto:gnso-rds-pdp-wg-bounces at icann.org] *On Behalf Of *Volker Greimann
> *Sent:* Monday, December 12, 2016 9:13 AM
> *To:* gnso-rds-pdp-wg at icann.org
> *Subject:* [EXTERNAL] Re: [gnso-rds-pdp-wg] One Way Gated Access to 
> Data Might Work
>
> Interesting, but I am not sure this is ultimately what we should be 
> looking for for one simple reason. This proposed implementation 
> apparently does not provide for any differentiation between access 
> levels except for the three authentification levels.
>
> [SAH] No, not true. While this particular experiment includes three 
> levels of access, the approach is designed to be tailored to make 
> authorization and access control decisions based on a number of 
> different factors. What you currently see in my experiment is just one 
> possibility. It already includes support for specification of query 
> purpose (for example), and that information can be used to provide 
> additional levels of access control based on the policies implemented 
> by the server operator.
>
> So once one obtains and advanced authentification, one can access all 
> data in the database, which I would consider insufficient 
> differentiation. Access should be further scecialized on a "need to 
> know" and "right to know" basis. For example, should a certified and 
> authentificated law enforcement agency have access to all registrant 
> data or only to registrant data that applies to their jurisdiction 
> (plus maybe an identifier that details which jurisdiction applies to a 
> data set that agency cannot access).
>
> [SAH] The actual protocol proposal* I’ve developed includes support 
> for specification of a query purpose that can be used to make more 
> specific access control decisions. If other factors are needed, they, 
> too, can be included.
>
> Similarly, would a IP rights holder have access to all data or only to 
> just enough data needed to achieve their goal, which would likely be 
> to contact the registrant?
>
> In other words, the access level scheme should differentiate between 
> levels of access much more and restrict that access to those with a 
> right to access or a legitimate need to access without overstepping 
> legal or jurisdictional boundaries.
>
> This proposed implementation it too simplistic.
>
> [SAH] In no way did I infer that the existing implementation is 
> “final” or a complete solution. It is just an early proposal and an 
> early experiment to demonstrate possibilities. I fully expect to make 
> revisions based on the outputs of this WG.
>
> Scott
>
> * https://datatracker.ietf.org/doc/draft-hollenbeck-regext-rdap-openid/
>

-- 
Bei weiteren Fragen stehen wir Ihnen gerne zur Verfügung.

Mit freundlichen Grüßen,

Volker A. Greimann
- Rechtsabteilung -

Key-Systems GmbH
Im Oberen Werk 1
66386 St. Ingbert
Tel.: +49 (0) 6894 - 9396 901
Fax.: +49 (0) 6894 - 9396 851
Email: vgreimann at key-systems.net

Web: www.key-systems.net / www.RRPproxy.net
www.domaindiscount24.com / www.BrandShelter.com

Folgen Sie uns bei Twitter oder werden Sie unser Fan bei Facebook:
www.facebook.com/KeySystems
www.twitter.com/key_systems

Geschäftsführer: Alexander Siffrin
Handelsregister Nr.: HR B 18835 - Saarbruecken
Umsatzsteuer ID.: DE211006534

Member of the KEYDRIVE GROUP
www.keydrive.lu

Der Inhalt dieser Nachricht ist vertraulich und nur für den angegebenen Empfänger bestimmt. Jede Form der Kenntnisgabe, Veröffentlichung oder Weitergabe an Dritte durch den Empfänger ist unzulässig. Sollte diese Nachricht nicht für Sie bestimmt sein, so bitten wir Sie, sich mit uns per E-Mail oder telefonisch in Verbindung zu setzen.

--------------------------------------------

Should you have any further questions, please do not hesitate to contact us.

Best regards,

Volker A. Greimann
- legal department -

Key-Systems GmbH
Im Oberen Werk 1
66386 St. Ingbert
Tel.: +49 (0) 6894 - 9396 901
Fax.: +49 (0) 6894 - 9396 851
Email: vgreimann at key-systems.net

Web: www.key-systems.net / www.RRPproxy.net
www.domaindiscount24.com / www.BrandShelter.com

Follow us on Twitter or join our fan community on Facebook and stay updated:
www.facebook.com/KeySystems
www.twitter.com/key_systems

CEO: Alexander Siffrin
Registration No.: HR B 18835 - Saarbruecken
V.A.T. ID.: DE211006534

Member of the KEYDRIVE GROUP
www.keydrive.lu

This e-mail and its attachments is intended only for the person to whom it is addressed. Furthermore it is not permitted to publish any content of this email. You must not use, disclose, copy, print or rely on this e-mail. If an addressing or transmission error has misdirected this e-mail, kindly notify the author by replying to this e-mail or contacting us by telephone.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mm.icann.org/pipermail/gnso-rds-pdp-wg/attachments/20161212/3588b999/attachment.html>


More information about the gnso-rds-pdp-wg mailing list