Identity Metasystem Interoperability (Pairwise Pseudonym Identifier, Private Personal Identifier)
7.5.14 Private Personal Identifier
URI: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier
Type: xs:base64binary
Definition: A private personal identifier (PPID) that identifies the Subject to a Relying Party. The word “private” is used in the sense that the Subject identifier is specific to a given Relying Party and hence private to that Relying Party. A Subject’s PPID at one Relying Party cannot be correlated with the Subject’s PPID at another Relying Party. Typically, the PPID SHOULD be generated by an Identity Provider as a pair-wise pseudonym for a Subject for a given Relying Party. For a self-issued Information Card, the Self-issued Identity Provider in an Identity Selector system SHOULD generate a PPID for each Relying Party as a function of the card identifier and the Relying Party’s identity. The processing rules and encoding of the PPID claim value is specified in Section 7.6.
Compatibility Note: Some existing Identity Selectors omit listing the PPID claim as an ic:SupportedClaimType from the ic:SupportedClaimTypeList when saving a self-issued Information Card in the Information Cards Transfer Format defined in Section 6.1, even though the PPID claim is supported by the card. This behavior is deprecated, as all supported claims SHOULD be listed. Nonetheless, Identity Selectors MAY choose to recognize this case and support the PPID claim for self-issued cards not explicitly listing this claim.
PPIDはRPに対するSubjectの識別子。「プライベート」はSubject識別子があるRPに専用のもので、つまりRPに対してプライベートということ。あるRPでのSubjectのPPIDは他のRPでのSubjectのPPIDと関連性を持ってはいけない。たいていはPPIDは与えられたRPに対するサブジェクトの”pair-wise pseumonym"としてのIdentity Providerによって生成されるべき。自己発行情報のCardではIdentity Selectorシステムの自己発行Identity ProviderがそれぞれのRPのPPIDをカード識別子とRPのアイデンティティの関数として生成すべき。PPIDのクレーム値の処理ルールとエンコーディングは7.6章。
(そのうち訳を見直すよ)
Comments [0]