ISO/TR 20078‑4 is the fourt part of the multi- series standard that describes the processes of an Offering Party’s implementation to provide (ISO 200782) Access controlled (ISO 200783) Resources (ISO 200781) to Accessing Parties. The processes are summarized as: Registration of different stakeholder as well as granting, denying and revoking of Access to Resources.
Those processes are held as examples of combining ISO 200781, ISO 200782 and ISO 200783 and can vary depending on the actual implementation of the Offering Party.
ISO/TR 20078‑4 on extended vehicle (ExVe) web services control is applicable to:
The increase in the use of web services in vehicles has also increased the threat of hacking and other attacks. It is important to have tight security for the Extended vehicle (ExVe) web services.
ISO/TR 20078‑4 standardizes the security model of the web service, including different roles and entities involved in an Authorization Policy. Three roles are defined: Identity Provider, Authorization Provider and Resource Provider at the Offering Party.
ISO/TR 20078‑4 deals with registration of different stakeholder as well as granting, denying and revoking of Access to Resources.
ISO/TR 20078-4