ISO 20078-3:2021
Road vehicles — Extended vehicle (ExVe) web services — Part 3: Security
Road vehicles — Extended vehicle (ExVe) web services — Part 3: Security
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 24
- Дата публикации:
- 30 ноября 2021 г.
- Издание:
- ISO IS 20078 edition 2 version 1
- ICS:
- 43.040.15
This document defines how to authenticate users and accessing parties on a web-services interface. It also defines how a resource owner can delegate access to its resources to an accessing party. Within this context, this document also defines the necessary roles and required separation of duties between these in order to fulfil requirements stated on security, data privacy and data protection. All conditions and dependencies of the roles are defined towards a reference implementation using OAuth 2.0 compatible framework and OpenID Connect 1.0 compatible framework.
Abstract
Overview
ISO 20078-3:2021 - "Road vehicles - Extended vehicle (ExVe) web services - Part 3: Security" specifies how to secure ExVe web-service interfaces. It defines authentication of resource owners, how accessing parties obtain delegated access to vehicle-related resources, and the required roles and separation of duties to meet security, data privacy and data protection requirements. The standard frames these roles against a reference implementation based on OAuth 2.0 and OpenID Connect 1.0 compatible frameworks.
Key topics and technical requirements
- Authentication and identity management
- Identity provider authenticates resource owners and manages profiles (REQ_05_01_01 - REQ_05_01_04).
- Resource owner credentials are known only to the identity provider.
- Identity provider issues identity tokens (ID tokens) as digitally signed JWTs.
- Authorization and delegation
- Authorization provider manages access policies and issues scoped authorizations to accessing parties (REQ_05_01_05 - REQ_05_01_11).
- Only a resource owner can grant or revoke access; access may be direct or via containers (REQ_05_01_10 - REQ_05_01_14).
- Authorization provider must trust identity confirmation from the identity provider (REQ_05_01_07).
- Resource access control
- Resource provider enforces access control according to the authorization policy (REQ_05_01_19).
- Support for both request/reply and push communication methods; push introduces dual authorization domains.
- Separation of duties
- Clear role boundaries: identity provider, authorization provider, resource provider (REQ_05_01_20 - REQ_05_01_25).
- Identity provider must not influence authorization policy or access resources; authorization provider must not access resource owner profiles or resources.
- Operational processes & conditions
- Offering party responsibilities: register resource owners, register accessing parties, verify vehicle eligibility and resource ownership (REQ_04_01_x).
- Revocation and restrictions: offering or accessing parties may restrict or revoke access to satisfy security or legal requirements (REQ_04_02_x).
Applications and who uses it
ISO 20078-3 is relevant for:
- Automotive OEMs and telematics providers implementing ExVe web services
- API architects and backend engineers building vehicle data platforms
- Identity and access management (IAM) teams designing OAuth/OpenID Connect integrations
- Cybersecurity, privacy and compliance teams ensuring data protection and role separation
- Third-party service providers and app developers seeking delegated access to vehicle resources
Practical use cases include secure telematics data sharing, third‑party diagnostic apps, and controlled push of vehicle events to authorized services.
Related standards
- ISO 20078-1 (Content and definitions) - normative reference for terms and content structure.
- OAuth 2.0 and OpenID Connect 1.0 - referenced for the reference implementation and token flows.
Keywords: ISO 20078-3, Extended vehicle, ExVe, web services security, OAuth 2.0, OpenID Connect, authentication, authorization, resource owner, identity provider, authorization provider, separation of duties, vehicle data privacy.
Технические детали
- Технический комитет
- ISO/TC 22/SC 31 - Data communication
- SKU
- ISO 20078-3:2021
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO 20078-3:2021
ДействующийRoad vehicles. Extended vehicle (ExVe) web services. Security.
ISO 20078-1:2019
ОтменёнRoad vehicles — Extended vehicle (ExVe) web services — Part 1: Content
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…