diff --git a/AAI/FAQ.md b/AAI/FAQ.md index c5e0c6f..893c45e 100644 --- a/AAI/FAQ.md +++ b/AAI/FAQ.md @@ -9,6 +9,19 @@ A collection of questions (and hopefully useful answers). {% hr2 %} ## Background +### Do passports capture details of access grants, such as data use and required vetting? + +Passports convey a grant to access data. They do not currently attempt to communicate any conditions or details of the approval process. + +Authorizations for researcher identities ("the collection of researchers that may access the dataset" as described in the DURI vision statement) are approved by a data custodian or data access committee (sometimes using an approval management system like DUOS or REMS). The approvals can be contingent on factors such as: + +* intended data use (in data access request) matches permitted data use (in data set metadata) +* researcher reputation +* identity proofing (verification) +* etc. + +Some of these details could, in a future revision, be communicated in the passport for enforcement by the passport clearinghouse. + ### Why Brokers? We have found that there are widely used Identity Providers (IdP). diff --git a/AAI/assets/lifecycle.png b/AAI/assets/lifecycle.png new file mode 100644 index 0000000..e1c4757 Binary files /dev/null and b/AAI/assets/lifecycle.png differ diff --git a/AAI/assets/network-of-standards-detailed.svg b/AAI/assets/network-of-standards-detailed.svg new file mode 100644 index 0000000..0c4e320 --- /dev/null +++ b/AAI/assets/network-of-standards-detailed.svg @@ -0,0 +1,2024 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + DATABASE + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Data Security Infrastructure Policy + + + + Your DNA Your Day + + + + Ethics Review and Recognition Policy + + + + Data Access CommitteeReview Standards + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + DATA DONOR + RESEARCHER /CLINICIAN + DATA STEWARD + DATA ACCESSCOMMITTEE + RESEARCH ETHICSCOMMITTEE + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Data transformationfor database storage + + + + + + GA4GHPassport + + Apply forGA4GHPassport + + + + + Return of Results Policy + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Governing Outputs + + + + + + Data UseOntology + + + + GA4GHPassport + + Approval ofData AccessRequest + + + + + + + + GA4GHPassport + + AAI + RequestAccess toDataset + + + + + + Service Info + + + + Service Registry + + DiscoverServices + + + + + + DRS + + + + TES + + + + TRS + + + + WES + + AnalyzeDatasets + + + + + + htsget + + + + RNAget + + + + refget + + RetrieveDatasets + + + + Share Datasets + + + VRS + + + + VA + + + + Phenopackets + + + + Pedigree + + + + + + Consent Policy + + + + Consent Clauses + + + + Machine-ReadableConsent Guidance + + Consents + + + + Data UseOntology + + + + + + + Data Connect API + + + + Beacon API + + Find Datasets + + + Data UseOntology + + + + + + + + + + + + + + + + + + + + + + + + + + I + N + F + O + R + M + I + N + G + + H + U + M + A + N + + H + E + A + L + T + H + + & + + M + E + D + I + C + I + N + E + + + + + + + + + + + + + + + + + APPROVED + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Data Privacy and Security Policy + + + + Crypt4GH + + + + CRAM/BAM + + + + VCF + + Genomic Sequencing + + + + + + + + + + + + + + + + + + + + + + + + + + Record + + + + + + + + + + + + + + \ No newline at end of file diff --git a/index.md b/index.md index 621c170..1248e17 100644 --- a/index.md +++ b/index.md @@ -8,3 +8,21 @@ layout: home * [FAQ]({% link AAI/FAQ.md %}) * [Implementations]({% link AAI/implementations.md %}) * [Changes]({% link AAI/VERSIONS.md %}) + + +GA4GH AAI and Passports provide secure, standards-based data access in cases where the data access committee / data steward is not tightly coupled with the data holder. + +lifecycle + +When the data access approval system, data analysis system, and data repository system are all tightly integrated and are running in the same infrastructure, secure data access is simpler. When the data holder and access authorization systems are operated separately, then it becomes harder to meet two fundamental needs: + +* unlock data access for the researcher +* uphold the authority of the data custodian + +GA4GH AAI and Passports make it easier to solve both problems by communicating the access grants (authorizations) in a JWT token accessed via OAuth2. This mechanism is easy to implement and secure because it uses standard and secure means including the OIDC, OAuth2, and JWT standards, as well as approved cryptography algorithms. + +AAI and Passports minimize risk and cost by: + +* reusing existing and familiar libraries and tools +* leveraging existing security regimens +* simplifying compliance and system interconnection approvals