ISO 20078‑3 is the third part of the multi-series standard that defines how to authenticate users and Accessing Parties on a web services interface. It also defines how a Resource Owner can delegate Access to its Resources to an Accessing Party.
ISO 20078‑3 also defines the necessary roles and required separation of duties between these in order to fulfil requirements stated on security, data privacy and data protection.
ISO 20078‑3 on security of extended vehicle(ExVe) web services is applicable to:
The increase in the use of web services in vehicles has also increased the threat of hacking and other attacks. It is important to have tight security for the Extended vehicle (ExVe) web sevices. ISO 20078‑3 defines how to authenticate users and Accessing Parties on a web services interface. It provides tools for authorization, authentication and resource access which can be used the resource owners to improve security.
ISO 20078‑3 standardizes the security model of the web service, including different roles and entities involved in an Authorization Policy. Three roles are defined: Identity Provider, Authorization Provider and Resource Provider at the Offering Party.
ISO 20078-3