In use case 1b, a service is provided by the Service Provider to the Machine Service Consumer. The Service Consumer has been delegated by the Entitled Party.
|Delegation info PIP
|Use case variation
Note that interaction sequences are not described in the table above. In derived use case 1b, three interaction sequences are possible depending on who requests delegation info from the PIP:
- The Service Provider can request delegation info after a service request from the Service Consumer;
- The Machine Service Consumer can request delegation info and include it in its service request to the Service Provider;
- The Entitled Party can push delegation info to the Machine Service Consumer, so it can include it in its service request to the Service Provider.
Interaction sequence 3 is detailed below.
Note that no prior legal relation exists between the Service Consumer and the Service Provider. Which services can be consumed by the Service Consumer, as delegated by the Entitled Party, is set out in the mandatory relation between this Entitled Party and the Service Provider.
Use case interaction
It is prerequisite of this use case that:
- The Service Provider has and manages its own entitlement information indicating what Entitled Parties are entitled to what (parts of) services*;
- The Service Consumer is able to authenticate the Service Provider;
- The Service Provider is able to authenticate the Service Consumer;
- The delegation/authorization responsible at the Entitled Party delegates (part of) the Entitled Party's rights (as registered at the Service Provider) to the Service Consumer. He provides the Machine Service Consumer of the Service Consumer with evidence of this delegation.
*The Service Provider can outsource this function to a third party
The use case consists of the following steps:
- The Machine Service Consumer requests a service from the Service Provider. With this requests it includes the evidence obtained from the Entitled Party;
- The Service Provider authenticates the Machine Service Consumer and validates the iSHARE adherence of the Service Consumer;
- The Service Provider validates the received delegation evidence through the following steps:
- The Service Provider authenticates the Entitled Party and validates its iSHARE adherence based on the delegation evidence;
- The Service Provider authorizes the Entitled Party based on the entitlement information registered with the Service Provider.
- The Service Provider authorizes the Machine Service Consumer of the Service Consumer based on the validity of the delegation evidence;
- The Service Provider executes the requested service;
- The Service Provider provides the service result to the Machine Service Consumer.