[WG-UMA] Regarding Legal Considerations in UMA

2 views
Skip to first unread message

louis.m...@identitytrustcic.org

unread,
Apr 23, 2010, 4:09:16 PM4/23/10
to wg-...@kantarainitiative.org
Hi all,
After looking over the document contained in the Legal Considerations
in UMA Authorization posted by Eve in its most recent iteration I
would be interested in studying and dissecting a use-case from a legal
perspective in hopes of helping to gain a better understanding of
liability, contractual obligations, terms and such. This may also shed
some light to how those terms are negotiated through the UMA protocol.
Would there be anybody interested in this activity? It would be nice
to enlist another legal perspective and a person with technical
know-how to help lead this. If there is enough interest can we have a
short term sub-group?

Best regards,
Louis M


_______________________________________________
WG-UMA mailing list
WG-...@kantarainitiative.org
http://kantarainitiative.org/mailman/listinfo/wg-uma

--
You received this message because you are subscribed to the Google Groups "Kantara Initiative User Managed Access WG" group.
To post to this group, send email to kantara-init...@googlegroups.com.
To unsubscribe from this group, send email to kantara-initiative...@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/kantara-initiative-uma-wg?hl=en.

Smedinghoff, Tom

unread,
Apr 25, 2010, 8:09:36 PM4/25/10
to louis.m...@identitytrustcic.org, wg-...@kantarainitiative.org
Louis,

I'm very interested in these legal issues, and I suspect that they fit in quite well with the work we are doing at the ABA. Happy to participate in a sub-group.

Best,

Tom

Thomas J. Smedinghoff
Wildman Harrold
225 W. Wacker Drive
Chicago, Illinois 60606
Phone: +1 312-201-2021
Fax: +1 312-416-4773
smedi...@wildman.com
www.wildman.com/smedinghoff



-----Original Message-----
From: wg-uma-...@kantarainitiative.org [mailto:wg-uma-...@kantarainitiative.org] On Behalf Of louis.m...@identitytrustcic.org
Sent: Friday, April 23, 2010 3:09 PM
To: wg-...@kantarainitiative.org
Subject: [WG-UMA] Regarding Legal Considerations in UMA

Hi all,
After looking over the document contained in the Legal Considerations
in UMA Authorization posted by Eve in its most recent iteration I
would be interested in studying and dissecting a use-case from a legal
perspective in hopes of helping to gain a better understanding of
liability, contractual obligations, terms and such. This may also shed
some light to how those terms are negotiated through the UMA protocol.
Would there be anybody interested in this activity? It would be nice
to enlist another legal perspective and a person with technical
know-how to help lead this. If there is enough interest can we have a
short term sub-group?

Best regards,
Louis M


_______________________________________________
WG-UMA mailing list
WG-...@kantarainitiative.org
http://kantarainitiative.org/mailman/listinfo/wg-uma
DISCLAIMER:
This communication, along with any documents, files or attachments, is intended only for the use of the addressee and may contain legally privileged and confidential information. If you are not the intended recipient, you are hereby notified that any dissemination, distribution or copying of any information contained in or attached to this communication is strictly prohibited. If you have received this message in error, please notify the sender immediately and destroy the original communication and its attachments without reading, printing or saving in any manner. This communication does not form any contractual obligation on behalf of the sender or Wildman, Harrold, Allen & Dixon LLP. Unless expressly stated otherwise, any tax advice in this message is not intended or written to be used, and cannot be used by a taxpayer, for the purpose of avoiding penalties that may be imposed on the taxpayer. Please consult your tax attorney regarding the form of tax advice that may be r
elied upon to avoid penalties under the Internal Revenue Code.

Eve Maler

unread,
Apr 25, 2010, 9:17:09 PM4/25/10
to Smedinghoff, Tom, wg-...@kantarainitiative.org
Wonderful! Please count me in too (so I can help capture any results in the doc if that's the right place for them), and let me know if I can help with setup of offline chats or anything else.

Eve
Eve Maler
e...@xmlgrrl.com
http://www.xmlgrrl.com/blog

Nat Sakimura

unread,
Apr 25, 2010, 9:26:05 PM4/25/10
to wg-...@kantarainitiative.org
I too am interested. In fact, we have been discussing some of those at
OpenID Foundation's Contract Exchange WG as well. A while ago, I was
suggesting to Eve that perhaps I should move protocol independent
portion to Kantara to discuss those legal aspects etc. I believe this
discussion is useful not only for UMA but for others, so creating a new
WG or DG may be a better way to do it.

=nat
> This communication, along with any documents, files or attachments, is intended only for the use of the addressee and may contain legally privileged and confidential information. If you are not the intended recipient, you are hereby notified that any dissemination, distribution or copying of any information contained in or attached to this communication is strictly prohibited. If you have received this message in error, please notify the sender immediately and destroy the original communication and its attachments without reading, printing or saving in any manner. This communication does not form any contractual obligation on behalf of the sender or Wildman, Harrold, Allen& Dixon LLP. Unless expressly stated otherwise, any tax advice in this message is not intended or written to be used, and cannot be used by a taxpayer, for the purpose of avoiding penalties that may be imposed on the taxpayer. Please consult your tax attorney regarding the form of tax advice that may be r
> elied upon to avoid penalties under the Internal Revenue Code.
>
> _______________________________________________
> WG-UMA mailing list
> WG-...@kantarainitiative.org
> http://kantarainitiative.org/mailman/listinfo/wg-uma
>


--
Nat Sakimura (n-sak...@nri.co.jp)
Nomura Research Institute, Ltd.
Tel:+81-3-6274-1412 Fax:+81-3-6274-1547

本メールに含まれる情報は機密情報であり、宛先に記載されている方のみに送信することを意図しております。意図された受取人以外の方によるこれらの情報の開示、複製、再配布や転送など一切の利用が禁止されています。誤って本メールを受信された場合は、申し訳ございませんが、送信者までお知らせいただき、受信されたメールを削除していただきますようお願い致します。
PLEASE READ:
The information contained in this e-mail is confidential and intended for the named recipient(s) only.
If you are not an intended recipient of this e-mail, you are hereby notified that any review, dissemination, distribution or duplication of this message is strictly prohibited. If you have received this message in error, please notify the sender immediately and delete your copy from your system.

Mark Lizar

unread,
Apr 25, 2010, 9:30:10 PM4/25/10
to Eve Maler, Smedinghoff, Tom, wg-...@kantarainitiative.org
Count me in too!  

Not sure if I missed the link to this earlier or not but I have just found this very well written doc that may be useful background for this effort (co-authored by Eve) 

Eve did you say that Jeff had a list of things he was surprised we didnt get too in the legal call?  Also was there a terms negotiation piece for UMA that you were going to add on to that Legal Considerations  doc? 

May be a good idea to aggregate as much pertinent info and considerations as feasible before digging in. 

Mark

Eve Maler

unread,
Apr 25, 2010, 9:57:44 PM4/25/10
to Mark Lizar, Smedinghoff, Tom, wg-...@kantarainitiative.org
Wow, this is exciting.  Glad there is so much interest. I'll forward Jeff S.'s email comments to the list. I have to prioritize the Claims 2.0 spec draft higher than working on the Legal Implications document, unfortunately, or I'd just start editing that stuff into the doc directly. (And I have to prioritize getting ready for several talks and the EIC workshop in the next couple of weeks even higher!...)

Nat, indeed we may uncover some topics that are worth breaking out into a separate work group/item; perhaps we can let that idea emerge from the discussions. I do hope we can give some "legal coverage" to the UMA protocol/UX mechanisms as a first priority, just to prove out the thesis of our current design before we go too much farther down this path.

Eve

Iain Henderson

unread,
Apr 26, 2010, 1:27:12 AM4/26/10
to Smedinghoff, Tom, wg-...@kantarainitiative.org
Yes, count me in please; there should be synergy with the work being
done in the Information Sharing group on 'standard agreements'.

Cheers

Iain
Iain Henderson
iain.he...@mydex.org

This email and any attachment contains information which is private
and confidential and is intended for the addressee only. If you are
not an addressee, you are not authorised to read, copy or use the e-
mail or any attachment. If you have received this e-mail in error,
please notify the sender by return e-mail and then destroy it.

j stollman

unread,
Apr 26, 2010, 8:40:55 AM4/26/10
to Mark Lizar, Smedinghoff, Tom, wg-...@kantarainitiative.org
I agree that the document Mark cites -- The Open Identity Trust Framework (OITF) Model -- can serve as a good starting point for a discussion of the legal issues around UMA.  At a high level it discusses a set of bi-lateral agreements between six parties: 
  1. policymakers
  2. framework providers
  3. assessors
  4. identity service providers
  5. relying parties
  6. users.

There are three key extensions of the OITF-model discussion that also will need to be addressed which comprise the stickiest issues:
  1. additional parties beyond the six specified in the document unique user-imposed terms and conditions (which is a large part of the reason to have UMA).  These include Authorization Managers, Hosts (which may not be identity service providers), etc.
  2. unique, user-specific terms and conditions not covered by existing contractual agreements
  3. liability and penalties for failure to adhere to the contracts
The incorporation of additional parties is merely a brute-force effort to design reasonable standard terms and conditions that cover the needs of both parties for protection. 

The ability to uniquely specify new terms and conditions that are (potentially) transaction specific can add massive complexity.  Likely, it will require defining numerous "standard" conditions that can be appended to a transaction to allow automated agents to make a decision whether to accept or reject the new limitations.  Additionally, there will eventually be the need to support a process to have non-standard conditions evaluated by a human.  And this will likely impose the requirement to be able to specify which humans are authorized to approve such exceptions.

No doubt, the stickiest issue is addressing the liability and penalties for failing to adhere both the standard and unique conditions of a transaction.  This problem is exacerbated by the international nature of the internet and the likelihood that disputes will cross national boundaries and, therefore, cross legal jurisdictions.   While this is a legal issue of vital importance to the launching of an UMA solution, it need not be part of the UMA technology.  But UMA will probably need to be able to specify the nationality and legal jurisdiction under which both standard contracts and transaction-specific conditions fall, in order for all parties to recognize the enforceability and penalties to which they become subject in conducting the transaction.

Jeff
--
Jeff Stollman
stoll...@gmail.com
1 202.683.8699

Smedinghoff, Tom

unread,
Apr 26, 2010, 11:20:56 AM4/26/10
to j stollman, Mark Lizar, wg-...@kantarainitiative.org
Jeff raises three very important additional categories of issues that will need to be addressed.  I would also add a fourth -- which is the fact that not all legal concerns can be addressed by contract.  That is, there are some legal issues (such as the requirements of some privacy and consumer protection laws/regulations, etc.) that cannot be varied by contract.  Thus, Trust Frameworks, system design, and/or participant obligations will have to anticipate and comply with these requirements.  And as Jeff notes, the fact that such rules vary by jurisdiction will further complicate this analysis.  -- Tom
 
 

From: j stollman [mailto:stoll...@gmail.com]
Sent: Monday, April 26, 2010 7:41 AM
To: Mark Lizar
Cc: Eve Maler; Smedinghoff, Tom; wg-...@kantarainitiative.org
Subject: Re: [WG-UMA] Regarding Legal Considerations in UMA

DISCLAIMER:
This communication, along with any documents, files or attachments, is intended only for the use of the addressee and may contain legally privileged and confidential information. If you are not the intended recipient, you are hereby notified that any dissemination, distribution or copying of any information contained in or attached to this communication is strictly prohibited. If you have received this message in error, please notify the sender immediately and destroy the original communication and its attachments without reading, printing or saving in any manner. This communication does not form any contractual obligation on behalf of the sender or Wildman, Harrold, Allen & Dixon LLP.  Unless expressly stated otherwise, any tax advice in this message is not intended or written to be used, and cannot be used by a taxpayer, for the purpose of avoiding penalties that may be imposed on the taxpayer.  Please consult your tax attorney regarding the form of tax advice that may be relied upon to avoid penalties under the Internal Revenue Code. 

Eve Maler

unread,
Apr 26, 2010, 11:56:34 AM4/26/10
to Smedinghoff, Tom, wg-...@kantarainitiative.org
I guess there's an interesting pile of analysis work ahead...

Note that when we wrote the OITF paper, I consciously tried to keep room for entities that aren't simple IdPs and RPs even though these are the terms used. In a system like Liberty ID-WSF, for what it's worth, Host=Attribute Authority/Web Service Provider, Requester=Web Service Consumer/Relying Party, and AM=(hmm, something like IdP/Discovery Service?).

And the unfinished Legal Implications paper does try to get into the fact that pairwise terms of service will exist between many of the entities; if we find that we can point to OITF or a similar meta-framework as a constraint on the terms that can be agreed to, that may flow nicely into the forthcoming additional analysis.

Eve

louis.m...@identitytrustcic.org

unread,
Apr 28, 2010, 9:51:41 AM4/28/10
to Eve Maler, Smedinghoff, Tom, wg-...@kantarainitiative.org
Hi All,
Great response to dissecting a use case idea. What should the next steps
be?

It would be great to generate a little momentum and to identify the issues
early enough to then re-group at IIW for those of us attending. May I
suggest we schedule a call to start with on dissecting a UMA case?

Suggested Next Steps:

1. Submit suggestions to this thread for which UMA use case(s) to dissect

2. Organise a first call to discuss those suggestions and identify
important areas implicating legal discourse and create a list of topics
(this should narrow our focus)

3. Discuss where to go from there.

Does this kind of agenda approach works? Any suggestions and alternative
approaches are welcome.

A doodle poll has been set up to determine availability for calls over the
next few weeks.


Here is the link

Participation link: http://www.doodle.com/sxuyg846fqm88a59
Send this link to anyone you wish to invite.

Administration link: http://www.doodle.com/sxuyg846fqm88a597zeibu2i/admin
Access this link to change, close or delete this poll.

Louis M

Eve Maler

unread,
Apr 28, 2010, 3:18:13 PM4/28/10
to <louis.monvoisin@identitytrustcic.org>, Smedinghoff, Tom, wg-...@kantarainitiative.org
Go Louis go! I've responded to the poll, but please consider me optional as my availability is severely limited due to the Munich trip etc. You may find that you have to add a few days of availability onto the end of the poll.

It would be great if you folks could validate whether the (admittedly highly artificial) starter scenarios presented in the doc are workable for the sub-team's purpose. BTW, I'm planning to use those scenarios to bootstrap people's understanding of UMA at next Tuesday's workshop -- this is the one that uses Alice, and Bob, and TravelIt.com, and Schedewl, and Airplanr, and FrodoReview (though I may not get to Frodo...).

Eve

Mark Lizar

unread,
May 3, 2010, 11:27:23 AM5/3/10
to <louis.monvoisin@identitytrustcic.org>, Smedinghoff, Tom, wg-...@kantarainitiative.org

UMA LEGAL CALL INVITATION

For all of you interested in legal considerations of UMA you are invited to join a call on this topic.  I have added additional call times in the Doodle to help schedule this call.

As, Eve has so nicely painted a picture with the scenarios from the UMA 'Regarding Legal Considerations in UMA Authorisation

I suggest we move right on.  I have scanned this email thread for legal consideration to start with and am using this list to create a draft agenda.  Please suggest items or edits at will. 


Draft Agenda

1. addressing the liability and penalties - Jeff
2. The ability to uniquely specify new terms and conditions - Jeff
3. additional parties beyond the six specified in the OITF document - Jeff
4. I would also add a fourth -- which is the fact that not all legal concerns can be addressed by contract.- Tom


Suggestion: - we find that we can point to OITF or a similar meta-framework as a constraint on the terms that can be agreed to, that may flow nicely into the forthcoming additional analysis. - EVE


Best Regards, 

- Mark


Starter Scenarios

Let's imagine a web user, Alice Adams, who doesn't mind sharing her personal travel information with the right sources as long as the process of sharing is convenient (e.g., no requirements to alert authorized recipients every time a new trip gets booked); her expectations for the uses of that information are met (e.g., she's not worried about recipients divulging to the whole world that her house is going to be empty); and she feels "in control" of what's allowed and not allowed (e.g., she can get an at-a-glance view of who's seeing what).

She uses a website called TravelIt.com (think TripIt) to store all of her travel itineraries. Since it's the nature of travel information to change frequently, she wants to be sure that her good friend Bob Baker always has the latest version so he can pick her up from the airport on time and make sure her cat is fed while she's away; he likes to use Schedewl.com (think Google Calendar) for subscribing to TravelIt. She would also like her social travel site Airplanr.com (think Dopplr) to pick up her itineraries automatically and make them available to friends who are on that system.

Because Alice is a frequent and seasoned traveler, she's interested in entertaining discount offers from travelogue company FrodoReviews.com (think Frommer's) for making her itineraries available to them for survey purposes.

To this picture, UMA adds the possibility of a new kind of web-based application: a kind of "traffic cop" for overseeing all these instances of travel itinerary sharing, which will help Alice manage her digital footprint. We'll call this site CopMonkey.com

Mark Lizar

unread,
May 4, 2010, 9:06:22 AM5/4/10
to Mark Lizar, Tom Smedinghoff, wg-...@kantarainitiative.org

OK.  The Call date and time is selected 

Next Monday 10th of May 2 pm Eastern Standard Time,  7 pm Greenwich Mean time.   

Eve can you add announcement to the Agenda for this week ?  Also can you arrange Skype abilities this call so I can send out the call details? 

- Best Regards,

Mark

Thomas Hardjono

unread,
May 4, 2010, 10:21:48 AM5/4/10
to Mark Lizar, wg-...@kantarainitiative.org

Do we use the same dialin-number

as the Thursday calls?

 

Thanks.

 

/thomas/

Joni Brennan

unread,
May 4, 2010, 12:59:51 PM5/4/10
to Thomas Hardjono, wg-uma
Hello,

Line C which is your normal line is open at that time so you can feel free to use it:

Teleconference Info:
- Skype: +9900827042954214
- North American Dial-In: +1-201-793-9022 
- Room Code: 2954214

I put the call with dial-in in the UMA calendar.  If anything changes the calendar should be updated to reflect. 

thx
Joni Brennan
IEEE-ISTO
Kantara Initiative
Managing Director
voice:+1 732-226-4223
email: joni @ ieee-isto.org
gtalk: jonibrennan
skype: upon request

Join the conversation on the community@ list - http://kantarainitiative.org/mailman/listinfo/community



Eve Maler

unread,
May 5, 2010, 4:47:01 AM5/5/10
to Joni Brennan, wg-uma
Thanks to Mark and Joni and everyone for jumping on this opportunity! I can make this call time, and can initiate the call with the moderator code unless someone else was planning to.

BTW, the UMA workshop yesterday at EIC went great, and I even essayed explaining the "parties vs. tools" situation using the diagrams that are in the Legal Cons doc. AND Christian Scholz whipped up a fledgling Python implementation of the UMA protocol, practically while I watched. Wow! See:


More info on the week's events is forthcoming as soon as I have a bit more time and energy...

Eve

On 4 May 2010, at 9:59 AM, Joni Brennan wrote:

Hello,

Line C which is your normal line is open at that time so you can feel free to use it:

Teleconference Info:
- Skype: +9900827042954214
- North American Dial-In: +1-201-793-9022 
- Room Code: 2954214

I put the call with dial-in in the UMA calendar.  If anything changes the calendar should be updated to reflect. 

thx

Iain Henderson

unread,
May 5, 2010, 6:33:06 AM5/5/10
to Eve Maler, wg-uma
Nice one Christian, so you were not kidding when you said you'd
implement yesterday afternoon!!!!
> _______________________________________________
> WG-UMA mailing list
> WG-...@kantarainitiative.org
> http://kantarainitiative.org/mailman/listinfo/wg-uma

Iain Henderson
iain.he...@mydex.org

This email and any attachment contains information which is private
and confidential and is intended for the addressee only. If you are
not an addressee, you are not authorised to read, copy or use the e-
mail or any attachment. If you have received this e-mail in error,
please notify the sender by return e-mail and then destroy it.




_______________________________________________
WG-UMA mailing list
WG-...@kantarainitiative.org
http://kantarainitiative.org/mailman/listinfo/wg-uma

--

Eve Maler

unread,
May 10, 2010, 2:48:57 PM5/10/10
to wg-uma UMA
Attending: Mark Lizar, Tom Smedinghoff, Jeff Stollman, Eve Maler, Louis Monvoison

On 3 May 2010, at 8:27 AM, Mark Lizar wrote:


UMA LEGAL CALL INVITATION

For all of you interested in legal considerations of UMA you are invited to join a call on this topic.  I have added additional call times in the Doodle to help schedule this call.

As, Eve has so nicely painted a picture with the scenarios from the UMA 'Regarding Legal Considerations in UMA Authorisation

I suggest we move right on.  I have scanned this email thread for legal consideration to start with and am using this list to create a draft agenda.  Please suggest items or edits at will. 

Agenda-bashing:

Draft Agenda

1. addressing the liability and penalties - Jeff

Let's add enforcement as a related issue to #1.

2. The ability to uniquely specify new terms and conditions - Jeff
3. additional parties beyond the six specified in the OITF document - Jeff
4. I would also add a fourth -- which is the fact that not all legal concerns can be addressed by contract.- Tom


Suggestion: - we find that we can point to OITF or a similar meta-framework as a constraint on the terms that can be agreed to, that may flow nicely into the forthcoming additional analysis. - EVE


Best Regards, 

- Mark

Let's imagine a web user, Alice Adams, who doesn't mind sharing her personal travel information with the right sources as long as the process of sharing is convenient (e.g., no requirements to alert authorized recipients every time a new trip gets booked); her expectations for the uses of that information are met (e.g., she's not worried about recipients divulging to the whole world that her house is going to be empty); and she feels "in control" of what's allowed and not allowed (e.g., she can get an at-a-glance view of who's seeing what).

She uses a website called TravelIt.com (think TripIt) to store all of her travel itineraries. Since it's the nature of travel information to change frequently, she wants to be sure that her good friend Bob Baker always has the latest version so he can pick her up from the airport on time and make sure her cat is fed while she's away; he likes to use Schedewl.com (think Google Calendar) for subscribing to TravelIt. She would also like her social travel site Airplanr.com (think Dopplr) to pick up her itineraries automatically and make them available to friends who are on that system.

Because Alice is a frequent and seasoned traveler, she's interested in entertaining discount offers from travelogue company FrodoReviews.com (think Frommer's) for making her itineraries available to them for survey purposes.

To this picture, UMA adds the possibility of a new kind of web-based application: a kind of "traffic cop" for overseeing all these instances of travel itinerary sharing, which will help Alice manage her digital footprint. We'll call this site CopMonkey.com

Liability: Tom observes that, according to some work taking place in the ABA currently, there's a lot of concern about "What happens if something goes wrong or something bad happens?" But under what legal theory does liability get assigned? -- liability "for what"? E.g., the party being sued may have the ability to limit liability or not. Liability in the abstract isn't a very helpful concept.  There are contract, tort, negligence, etc. theories.

This isn't probably the first thing to settle; rather, we could discuss "What could go wrong?" and go from there. Eve suggests validating a scenario, describing its "success conditions" (as if it were a software user story/use case), and then describing its "error conditions". She walked through the three proposed sharing scenarios in the Legal Cons doc. The three are:

- Alice->Bob through TravelIt/CopMonkey/Schedewl
- Alice->Airplanr (on her own behalf) through TravelIt/CopMonkey
- Alice->FrodoReviews (on its own behalf) through TravelIt/CopMonkey

Here are some possible error conditions:

- Alice's calendar being shared to the world (or at least a wider circle), not just Bob
- Alice's calendar being misrepresented as being someone else's calendar
- Alice's calendar being unavailable on the promised schedule, despite FrodoReviews having already given her some consideration for it

In fact, each of the seven entities involved in this set of scenarios could be exposed to liability by making something go wrong.

Most Terms of Service disclaim liability for pretty much anything, though there are a few legal limits on how much they can do this (the amount of harm is one factor that gets considered). If all these services have TOS's that disclaim all liability, how can the Alices and Bobs in the world deal with this? And what liability should they "ideally" have, even if they want to disclaim it?

Louis suggests that we should focus on ways in which UMA wants to provide unique value, and see if we can identify key ways we can extend confidence to the user that this value can be provided. Eve identifies the main value-add as allowing the authorizing user to extract promises from the requesting party (this is under NDA, this is under embargo until X date, you have to adhere to DataPortability.org best practices, you have to be over 18 to see this photo...). A consequence of the UMA architecture in its most Internet-scale form, though not truly a unique value-add in the sense that it's why we're building UMA, is that the host must come to trust the user's chosen AM.

Eve's hope is that UMA can help users to hold out an incentive (fresh data access) to requesting parties to "ratchet up" their terms of service, so that in addition to prevailing law and their own existing generic TOS's, they might agree to pairwise terms that meet the user's requirements.

When you add the international dimension, enforcement could get *really* complicated. Can we work on a simple U.S.-only case for starters, to see what we flesh out?  International treaties or conventions would have to recognize agreements and consider enforcement mechanisms.

So let's take the very simple case of demanding that a requesting party (let's say this is for the Alice->Airplanr scenario through TravelIt/CopMonkey) support data portability, such that any data they end up storing about you they must offer to export on your request.  We assume, to begin with, that the desired policies are boilerplated and well known, and their semantics can be conveyed in an entirely machine-readable manner. Examples of such policies are Creative Commons (webby, lightweight) and IncoTerms (used in international trade).

Things that could go wrong:

- Alice could forget to configure the policies that constrain Airplanr
- CopMonkey could incorrectly issue an access token without correctly requesting/requiring the promise from Airplanr
- CopMonkey could fail to secure its audit logs that show the promise and that Airplanr made it for this particular kind of access
- TravelIt could incorrectly give access even though Airplanr didn't present a properly formed token
- TravelIt could give the wrong kind of access that doesn't match the access granted (e.g., as listed above)
- Even if everything else was done correctly, Airplanr could be total losers and not make Alice's data on their site available or wipe her account as required by DP.org practice

[Eve had to drop at this point; hopefully other folks will capture other juicy discussions...]

Eve Maler

unread,
May 10, 2010, 5:23:39 PM5/10/10
to Eve Maler, wg-uma UMA
By the way, I forgot to mention it on today's legal subteam call, but last week when I was at the EIC conference in Munich, Gerry Gebel (formerly of Burton Group) reminded me of a concept the BG folks had come up with called the "Limited Liability Persona". If we think the idea is a good matchup for what we're trying to achieve here, we might consider folding in some of the concepts and maybe reach out to these folks afresh...


Eve

Iain Henderson

unread,
May 10, 2010, 5:50:54 PM5/10/10
to Eve Maler, wg-uma UMA
Yes, I always thought that concept had legs and was worth nudging forward.

Iain
Iain Henderson
iain.he...@mydex.org

This email and any attachment contains information which is private and confidential and is intended for the addressee only. If you are not an addressee, you are not authorised to read, copy or use the e-mail or any attachment. If you have received this e-mail in error, please notify the sender by return e-mail and then destroy it.




_______________________________________________
WG-UMA mailing list
WG-...@kantarainitiative.org
http://kantarainitiative.org/mailman/listinfo/wg-uma

--

Mark Lizar

unread,
May 10, 2010, 6:06:21 PM5/10/10
to Iain Henderson, wg-uma UMA

I will add this to the agenda on the next call.

j stollman

unread,
May 11, 2010, 1:25:56 PM5/11/10
to Eve Maler, wg-uma UMA
Eve,

While I find the title "Limited Liability Persona" catchy, my brief review of the first blog article does not make a compelling argument.  The Burton proposal is to have the state (or a state court) serve as an Identity Provider and, in addition to creating a new identity that is not linked to me as a natural person, it offers the possibility of a government vetted age attribute.  But that is all that is being accomplished. 

Excepting the issue of the age attribute, the independent persona can be obtained by merely creating a Limited Liability Corporation and performing all transactions through the corporation.  While many B-C web sites are not set up to handle B-B transactions, neither are they set up to deal with Limited Liability Personas.  It might be easier and make more sense to just set up a B-B capability -- as long as a new capability is needed.

The idea of using a secured credit card without overdraft protection to gain liability protection does not require a Limited Liability Persona.  This could be obtained by a natural person or an LLC.

Maybe I am missing some better examples in the subsequent blog entries, but I am out of time.

Jeff

Eve Maler

unread,
May 11, 2010, 3:38:32 PM5/11/10
to j stollman, wg-uma UMA
I have to admit that my brief review of the first blog entry also resulted in an underwhelmed impression...  But I didn't want to prejudice the discussion right out of the box. :-) It's possible that some of our existing scenarios in UMA might result in the kind of controlled and limited sharing they're talking about. In any case, I'm happy for there to be no additional actions on our part, unless someone else is interested and wants to run with it.

Eve

Mark Lizar

unread,
May 13, 2010, 7:49:30 AM5/13/10
to wg-uma UMA, Smedinghoff, Tom

FYI: I have appended more notes below, recapped some issues and also listed the time and date of next Legal Subteam Call 


Attending: Mark Lizar, Tom Smedinghoff, Jeff Stollman, Eve Maler, Louis Monvoison

On 3 May 2010, at 8:27 AM, Mark Lizar wrote:


UMA LEGAL CALL INVITATION

For all of you interested in legal considerations of UMA you are invited to join a call on this topic.  I have added additional call times in the Doodle to help schedule this call.

As, Eve has so nicely painted a picture with the scenarios from the UMA 'Regarding Legal Considerations in UMA Authorisation

I suggest we move right on.  I have scanned this email thread for legal consideration to start with and am using this list to create a draft agenda.  Please suggest items or edits at will. 

Agenda-bashing:

Draft Agenda

1. addressing the liability and penalties - Jeff

Let's add enforcement as a related issue to #1.

2. The ability to uniquely specify new terms and conditions - Jeff
3. additional parties beyond the six specified in the OITF document - Jeff
4. I would also add a fourth -- which is the fact that not all legal concerns can be addressed by contract.- Tom


Suggestion: - we find that we can point to OITF or a similar meta-framework as a constraint on the terms that can be agreed to, that may flow nicely into the forthcoming additional analysis. - EVE


Best Regards, 

- Mark

Let's imagine a web user, Alice Adams, who doesn't mind sharing her personal travel information with the right sources as long as the process of sharing is convenient (e.g., no requirements to alert authorized recipients every time a new trip gets booked); her expectations for the uses of that information are met (e.g., she's not worried about recipients divulging to the whole world that her house is going to be empty); and she feels "in control" of what's allowed and not allowed (e.g., she can get an at-a-glance view of who's seeing what).

She uses a website called TravelIt.com (think TripIt) to store all of her travel itineraries. Since it's the nature of travel information to change frequently, she wants to be sure that her good friend Bob Baker always has the latest version so he can pick her up from the airport on time and make sure her cat is fed while she's away; he likes to use Schedewl.com (think Google Calendar) for subscribing to TravelIt. She would also like her social travel site Airplanr.com (think Dopplr) to pick up her itineraries automatically and make them available to friends who are on that system.

Because Alice is a frequent and seasoned traveler, she's interested in entertaining discount offers from travelogue company FrodoReviews.com (think Frommer's) for making her itineraries available to them for survey purposes.

To this picture, UMA adds the possibility of a new kind of web-based application: a kind of "traffic cop" for overseeing all these instances of travel itinerary sharing, which will help Alice manage her digital footprint. We'll call this site CopMonkey.com

Liability: Tom observes that, according to some work taking place in the ABA currently, there's a lot of concern about "What happens if something goes wrong or something bad happens?" But under what legal theory does liability get assigned? -- liability "for what"? E.g., the party being sued may have the ability to limit liability or not. Liability in the abstract isn't a very helpful concept.  There are contract, tort, negligence, etc. theories.

This isn't probably the first thing to settle; rather, we could discuss "What could go wrong?" and go from there. Eve suggests validating a scenario, describing its "success conditions" (as if it were a software user story/use case), and then describing its "error conditions". She walked through the three proposed sharing scenarios in the Legal Cons doc. The three are:

- Alice->Bob through TravelIt/CopMonkey/Schedewl
- Alice->Airplanr (on her own behalf) through TravelIt/CopMonkey
- Alice->FrodoReviews (on its own behalf) through TravelIt/CopMonkey

Here are some possible error conditions:

- Alice's calendar being shared to the world (or at least a wider circle), not just Bob
- Alice's calendar being misrepresented as being someone else's calendar
- Alice's calendar being unavailable on the promised schedule, despite FrodoReviews having already given her some consideration for it

In fact, each of the seven entities involved in this set of scenarios could be exposed to liability by making something go wrong.

Most Terms of Service disclaim liability for pretty much anything, though there are a few legal limits on how much they can do this (the amount of harm is one factor that gets considered). If all these services have TOS's that disclaim all liability, how can the Alices and Bobs in the world deal with this? And what liability should they "ideally" have, even if they want to disclaim it?

Louis suggests that we should focus on ways in which UMA wants to provide unique value, and see if we can identify key ways we can extend confidence to the user that this value can be provided. Eve identifies the main value-add as allowing the authorizing user to extract promises from the requesting party (this is under NDA, this is under embargo until X date, you have to adhere to DataPortability.org best practices, you have to be over 18 to see this photo...). A consequence of the UMA architecture in its most Internet-scale form, though not truly a unique value-add in the sense that it's why we're building UMA, is that the host must come to trust the user's chosen AM.

Eve's hope is that UMA can help users to hold out an incentive (fresh data access) to requesting parties to "ratchet up" their terms of service, so that in addition to prevailing law and their own existing generic TOS's, they might agree to pairwise terms that meet the user's requirements.

When you add the international dimension, enforcement could get *really* complicated. Can we work on a simple U.S.-only case for starters, to see what we flesh out?  International treaties or conventions would have to recognize agreements and consider enforcement mechanisms.

So let's take the very simple case of demanding that a requesting party (let's say this is for the Alice->Airplanr scenario through TravelIt/CopMonkey) support data portability, such that any data they end up storing about you they must offer to export on your request.  We assume, to begin with, that the desired policies are boilerplated and well known, and their semantics can be conveyed in an entirely machine-readable manner. Examples of such policies are Creative Commons (webby, lightweight) and IncoTerms (used in international trade).

Things that could go wrong:

- Alice could forget to configure the policies that constrain Airplanr
- CopMonkey could incorrectly issue an access token without correctly requesting/requiring the promise from Airplanr
- CopMonkey could fail to secure its audit logs that show the promise and that Airplanr made it for this particular kind of access
- TravelIt could incorrectly give access even though Airplanr didn't present a properly formed token
- TravelIt could give the wrong kind of access that doesn't match the access granted (e.g., as listed above)
- Even if everything else was done correctly, Airplanr could be total losers and not make Alice's data on their site available or wipe her account as required by DP.org practice


[Eve had to drop at this point; hopefully other folks will capture other juicy discussions...]

Mark's notes

Eve explained what was unique about UMA is that users are enabled to be in control in offering data on a ongoing basis with strings attached.  These strings need to be reasonable.
Uniqueness Of UMA
E.g. I want to release this under an NDA. Or release information on a subscription basis.  
E.g. Use cases where Alice wants Bob to be under a NDA, 
E.g. UMA has a host vs AM distinction where trust is dynamically built 

Jeff Questions: 7 entities are they all involved in the trust relationship?  Is there a trust framework that everyone buys into when using UMA? 

EVE: Assuming in the most internet scale case there is no trust framework.  There is law, there is TOS, and there may be pairwaise conditions that we may want participants to utilise. 
UMA is intended to be able to ratchet up the quality of TOS and expectations 

Tom: mentions identifying the legal spectrum ; what the rules ought to be as to oppose to what they are now. 

ReCap: 
Liabilities around TOS, and what this may look like using UMA to understand what the enforcement and Liability Issues are/

Enforcement can be addressed through economic treaty states, where internationally there are conventions that can be used to drive enforcement mechanisms. 

Eve discussed how to distinguish use cases by how  automated it is and whether the user needs to do anything.  So how automated this is for the user. 
 Tom discusses the need and place for automation in the opposite context where an individual is imposing terms on a service Airplner.com (in this case data portability)that the reception of those terms by Airplner also needs to be automated.  E.g. a user sets preferences for creative commons licenses and so on. 

(need to look at defining lines of processes that can be automated.) 

Discussed OITF document and unique user imposed conditions.  Also that if it cant be automated it may be to difficult. 

Louis asks why would a company offer terms to just one User and not all of them?  Would this not fall under a trust framework, rather than new terms,or type of customer service? 
We discussed how user-to-user there may be need for unique terms and that service porviders may need to abide by these terms.   Maybe what we are talking about is a lack of consideration for the use of information in terms of service and that UMA is stepping ahead of legislated action. 

If UMA is acting on behalf of the User then there is liability for UMA in that activity.   There are many ways that liability can also get more complex, what mechanism does UMA have to deal with those issues. 

Mark discusses how trust-frameworks are being developed to deal with that liability like the identity assurance framework.  How does UMA work with a trustframework. 

Should we simplify this, in reality this might not have any value.   

TOM: Take this conversation forward in stages.  Start with standardised terms and treaties and frameworks.  

Look at it say that the law says this but it should maybe say this.  Policy recommendations for the use of UMA. 

Recapping of how to look at the spectrum of user-to-organisation and organsiation-to-user options and UMA's role as an access manager, the role trust-frameworks may have in this and we discussed how to approach the potential of UMA legally. 


We agreed to go for another UMA Call 30th of May at the same time 7pm UK time:


Issues raised for next Agenda
- Enforcement
- Automation levels and the need for user/ host/AM/requester action
- Terms of Service Negotiation
- Unique User Imposed Conditions (advanced UMA)
- Liability
- Policy Recommendations for the use of UMA.  (where the law may be lacking and UMA can 'bridge a gap;) 
- LLP - does it have an impact

Eve Maler

unread,
May 13, 2010, 9:37:51 AM5/13/10
to Mark Lizar, wg-uma UMA, Smedinghoff, Tom
Thanks very much for these additional notes! A lot of progress was made (the notion of "advanced UMA" is important to distinguish but scary :-).

Does someone have the action to incorporate the thinking so far into the doc?  If not, I will (try to) do that before the next call.  Speaking of which, is the next call really on Sunday, May 30?

Eve

Mark Lizar

unread,
May 13, 2010, 10:35:59 AM5/13/10
to Eve Maler, wg-uma UMA, Smedinghoff, Tom
Ah,.  No the call is infact on Monday May 31st. 

Mark Lizar

unread,
May 28, 2010, 4:47:27 PM5/28/10
to Mark Lizar, Smedinghoff, Tom, Juan Avellan, Scott David, wg-uma UMA, Louis Monvoisin, Aaron Titus
Regarding Next Monday's Call Time:


As I didn't realise next Monday is a holiday I propose that we move the next UMA Legal Subteam Cal from Monday May 31l to  June 7.  If this is not a good time please message me and I will setup a new doodle poll. With no objections received we can assume that all can make the call on June 7th at 7pm UK time. 

In addition, I am cc'ing this to other interested lawyers who may want to participate. 

Best Regards,

Mark


Mark Lizar

unread,
May 28, 2010, 8:18:46 PM5/28/10
to wg-uma UMA, Aaron Titus, Scott David, Louis Monvoisin, Juan Avellan
Regarding Next Monday's Call Time:


As I didn't realise next Monday is a holiday I propose that we move the next UMA Legal Subteam Cal from Monday May 31l to  June 7.  If this is not a good time please message me and I will setup a new doodle poll. With no objections received we can assume that all can make the call on June 7th at 7pm UK time. 

In addition, I am cc'ing this to other interested lawyers who may want to participate. 

Best Regards,

Mark

On 13 May 2010, at 15:35, Mark Lizar wrote:

Eve Maler

unread,
May 30, 2010, 10:05:46 AM5/30/10
to Mark Lizar, wg-uma UMA, Aaron Titus, Scott David, Louis Monvoisin, Juan Avellan
Sounds good.  I'll revise the minutes so that no one gets confused.  (I also added a couple of corrections to the attendance list in the minutes.)

By the way, you can see and subscribe to the UMA-specific calendar here:


Thanks to Anna for updating it to reflect this subteam meeting!

Eve

On 28 May 2010, at 5:18 PM, Mark Lizar wrote:

Regarding Next Monday's Call Time:


As I didn't realise next Monday is a holiday I propose that we move the next UMA Legal Subteam Cal from Monday May 31l to  June 7.  If this is not a good time please message me and I will setup a new doodle poll. With no objections received we can assume that all can make the call on June 7th at 7pm UK time. 

In addition, I am cc'ing this to other interested lawyers who may want to participate. 

Best Regards,

Mark

Mark Lizar

unread,
Jun 7, 2010, 2:18:52 PM6/7/10
to WG UMA, Tom Smedinghoff, Scott David, Aaron Titus
Due to a conference bridge issue the UMA legal sub-team did not meet today. 

 I was hoping to add to the agenda the concept of an UMA policy legally, its potential as a default policy.   Perhaps we can re-schedule and fix the conference bridge issue? 

On 7 Jun 2010, at 19:11, Mark Lizar wrote:

I have been on the UMA conference bridge for the last 10 minutes no one has showed. 

On 7 Jun 2010, at 19:05, Smedinghoff, Tom wrote:

Is there a call today?  Or do I have the time wrong?
 

Thomas J. Smedinghoff
Wildman Harrold
225 W. Wacker Drive
Chicago, Illinois 60606
Phone: +1 312-201-2021
Fax:  +1 312-416-4773
smedi...@wildman.com  
www.wildman.com/smedinghoff

 


From: wg-uma-...@kantarainitiative.org [mailto:wg-uma-...@kantarainitiative.org] On Behalf Of Eve Maler
Sent: Sunday, May 30, 2010 9:06 AM
To: Mark Lizar
Cc: wg-uma UMA; Aaron Titus; Scott David; Louis Monvoisin; Juan Avellan
Subject: Re: [WG-UMA] Updated: Notes from 10 May 2010 legal subteam call

Mark Lizar

unread,
Jun 15, 2010, 11:40:39 AM6/15/10
to Mark Lizar, WG UMA, Tom Smedinghoff, Aaron Titus, Scott David
Hello All, 

An update on this conference call and legal sub team effort.   There was an issue with no moderator for the conference bridge on June 7th, Joni Brennon sends here apologies to those of us who were on the call for the lack of moderator. 

I suggest that we re-book the call for Monday July 5th at 7pm to continue through the agenda.  To this end please let me know if you can attend and are interested in legal/policy surrounding UMA and its implementation. 

Best Regards, 

Mark



Smedinghoff, Tom

unread,
Jun 15, 2010, 11:47:44 AM6/15/10
to Mark Lizar, WG UMA, Aaron Titus, Scott David
Mark -- Given that Monday July 5 is the 4th of July holiday, I would suggest that we push it off until Tuesday the 6th if that works for everyone.  -- Tom
 
Thomas J. Smedinghoff
Wildman Harrold
225 W. Wacker Drive
Chicago, Illinois 60606
Phone: +1 312-201-2021
Fax:  +1 312-416-4773
smedi...@wildman.com  
www.wildman.com/smedinghoff
 


From: wg-uma-...@kantarainitiative.org [mailto:wg-uma-...@kantarainitiative.org] On Behalf Of Mark Lizar
Sent: Tuesday, June 15, 2010 10:41 AM
To: Mark Lizar
Cc: WG UMA; Smedinghoff, Tom; Aaron Titus; Scott David

Mark Lizar

unread,
Jun 15, 2010, 11:58:36 AM6/15/10
to Smedinghoff, Tom, WG UMA, Aaron Titus, Scott David
Ah Yes, Another Holiday,  Seems I have a knack for picking an off date. 

I am happy to move it the 6th. Maybe we can move the conference time ahead an hour to 6pm UTC? 

Mark Lizar

unread,
Jun 15, 2010, 12:35:30 PM6/15/10
to Mark Lizar, Smedinghoff, Tom, WG UMA, Aaron Titus, Scott David
Ok, after a couple of responses regarding the next date for our sub-group meeting I suggest that we move the call to Monday the 12th of July.  7PM UTC. 

Please let me know how this sits with your schedule. 

- Mark

j stollman

unread,
Jun 15, 2010, 2:29:48 PM6/15/10
to Smedinghoff, Tom, WG UMA, Aaron Titus, Scott David
Mark,

I concur with Tom's guidance.  Also, in specifying the time, please articulate the time zone.  I am not sure "which" 7 PM you are referring to.  I am assuming that you mean 7 PM British Summer Time, but I am not sure.

Thank you.

Jeff

Eve Maler

unread,
Jun 15, 2010, 3:08:52 PM6/15/10
to j stollman, Smedinghoff, Tom, WG UMA, Aaron Titus, Scott David
July 12 7pm UTC (GMT) appears to be:


So that's noon Pacific, 3pm Eastern, etc...  Mark, if that isn't what you meant, a timeanddate.com link is probably the best way to disambiguate!

Eve

Aaron Titus

unread,
Jun 15, 2010, 1:54:36 PM6/15/10
to Mark Lizar, Smedinghoff, Tom, WG UMA, Scott David

Looks OK to me right now.

 

-Aaron Titus

Information Privacy Director

Liberty Coalition

(202) 204-9790

http://www.nationalidwatch.org

http://wiki.privacycommons.org

http://www.libertycoalition.net

Twitter: @aarontitus

Mark Lizar

unread,
Jul 29, 2010, 11:13:19 AM7/29/10
to Eve Maler, wg-uma UMA, Smedinghoff, Tom
Hello All,

My apologies, for being unable to make this weeks and last weeks meeting.  I have been over run with guests from Canada and am still digging myself out from the pile of work. 

Even so, I would like to refresh the list with the latest agenda bashing that has been going on and to see if there are any more items that can be added  below or discussed on the list.  

- Mark


Agenda-bashing:

Issues raised for next Agenda
- Enforcement
- Automation levels and the need for user/ host/AM/requester action
- Terms of Service Negotiation
- Unique User Imposed Conditions (advanced UMA)
- Liability
- Policy Recommendations for the use of UMA.  (where the law may be lacking and UMA can 'bridge a gap;) 
  - UMA legal policy and its impact on usability.  (this refers to how a user controlled flow of control may impact on the legal relationships in information sharing and access) 
-  Privacy Icons - Better transparency and choices is a hot topic these days - Privacy Nutrition Labels  (Is there a need for a standard in Notice?) 
- ISWG Standard Agreements 


Reply all
Reply to author
Forward
0 new messages