Passports v1.2 Technical Update
Montreal Connect April 2022
Martin Kuba <makub@ics.muni.cz>
Outline
GA4GH AAI and Passport Specifications
JSON Web Tokens and Claims
OAuth 2.0 and OpenID Connect
OIDC / OAuth 2 Authorization Code Grant Flow
GA4GH AAI OpenID Connect Profile
defines involved parties:
GA4GH Passport Specification
defines claim ga4gh_passport_v1 that contains a list of strings representing visas
Example of a UserInfo Response with Passport
passport claim
visas
Example of a Decoded Passport Visa
signing key id
user id
visa type
issuer
URL of claim source organization
visa value
JSON Web Keys URL
signing algorithm
assertion time in seconds since 1970-01-01
issued at time
GA4GH Passport Three-tiered Data-access Model
GA4GH AAI and Passport Implementations
NIH’s Proposed Passport version 1.1
Upcoming AAI/Passport version 1.2
Planned AAI/Passport version 2.0
GA4GH Cloud Work Stream standardized APIs
Working Subgroup
If you are interested in the development of AAI/Passport specs, join the Passports/AAI Technical Working subgroup, a collaboration between the Data Security and DURI Work Streams, meeting weekly on Thursdays at 12:00 UTC
Thank you for your attention