Skip to content

History / cross organizational auth

Revisions

  • Fixed terminology table in Section 4.2.

    Dixie Baker committed Jan 4, 2018
  • Per Argonaut Security SME request, made "actor" sequence graphic more generic EHR-to-EHR. Also, in step 7 of the enumerated steps below the detailed sequence diagram, clarified that the EHR-A authorization server may transfer the token to an EHR application.

    bakerdb committed Dec 18, 2015
  • Corrected typo in 4.5.4 ("authorization JWT must be digitally signed..." to "authentication JWT must be digitally signed..."

    bakerdb committed Dec 10, 2015
  • Changed paragraph ref. for RFC6750 from 5.1 to 5.2.

    bakerdb committed Dec 7, 2015
  • In 4.5.2, clarified that "EHR-B servers" refers to both AS and RS.

    bakerdb committed Dec 5, 2015
  • Corrected inconsistency regarding the priority of the "iat" parameter (OPTIONAL to REQUIRED) and its use as a replay countermeasure, in sections 4.5.3 and 4.5.4.

    bakerdb committed Dec 4, 2015
  • Added parameters for passing access token from EHR-B to EHR-A (section 4.5.5).

    bakerdb committed Oct 30, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 28, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 16, 2015
  • Added content re countermeasures to threats to bearer tokens. Added example conformance statement.

    bakerdb committed Oct 15, 2015
  • Digital signing optional.

    bakerdb committed Oct 15, 2015
  • Removed details regarding format of access token.

    bakerdb committed Oct 15, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 13, 2015
  • Added "bearer token" definition.

    bakerdb committed Oct 13, 2015
  • Updated per discussions with Josh.

    bakerdb committed Oct 13, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 13, 2015
  • Added specific language from RFC6750 re retrieval methods.

    bakerdb committed Oct 13, 2015
  • Simplified detailed sequence diagram and added labeling for steps corresponding to enumerated list below the diagram.

    bakerdb committed Oct 5, 2015
  • Simplified actors and transactions diagram.

    bakerdb committed Oct 5, 2015
  • Incorporated Josh's comments

    bakerdb committed Oct 5, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 2, 2015
  • Added replay protection.

    bakerdb committed Oct 2, 2015
  • Added resource retrieval section. Minor edits to sequence diagram.

    bakerdb committed Oct 2, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 2, 2015
  • Added Access Token section.

    bakerdb committed Oct 2, 2015
  • Edited authorization JWT and authentication JWT sections.

    bakerdb committed Oct 1, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 1, 2015
  • Revised Authorization JWT section, using in puts from applicable standards and MITRE documentation.

    bakerdb committed Oct 1, 2015
  • Updated cross organizational auth (markdown)

    bakerdb committed Oct 1, 2015
  • Added TLS.

    bakerdb committed Oct 1, 2015