Skip to content

Fraud Prevention - SSO Account Sharing Across Deployments #19

@carrollgt91

Description

@carrollgt91

If we allow for multiple, entirely decoupled deployments of the PIS system, we open up the following possibility:

Let's say we have an application that is attempting to use the PIS system to verify a positive COVID test result within the past two weeks in order to distribute aid to that person. They have a SSO with PIS feature that supports the OpenMined-hosted PIS and the Amazon-hosted PIS. User A has tested positive with COVID a few days ago.

He signs up for the OpenMined PIS and verifies his test results there. Then, he has his friend sign up for the Amazon-hosted PIS, but he then links his test results account to his friend's Amazon PIS account, and his friend signs up for receiving aid and gets it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions