View scope

keyword
CH-XUA
Description
Scope for the EPD Swiss CH:XUA profile

145 Assertions in Scope

net.ihe.gazelle.assets.SearchCriteria

Id scheme
Assertion id
Predicate
CH-XUACH-XUA-002[SAML Assertion] There MUST be one <Attribute> element with the name attribute "urn:oasis:names:tc:xspa:1.0:subject:subject-id". The <AttributeValue> child element MUST convey the subjects real world name as plain text as defined by IHE XUA in all extensions (see Section 1.6.4.3.4.2 Message Semantics)
CH-XUACH-XUA-003[SAML Assertion] There MUST be one or more <Attribute> elements with the name attribute "urn:oasis:names:tc:xspa:1.0:subject:organization-id". The <AttributeValue> child element MUST convey the ID of the subjects organization or group registered in the HPD or empty, if not known (see Section 1.6.4.3.4.2 Message Semantics)
CH-XUACH-XUA-004[SAML Assertion] There MUST be one or more <Attribute> elements with the name attribute: "urn:oasis:names:tc:xspa:1.0:subject:organization". The <AttributeValue> child element MUST convey a plain text the subjects organization name as registered in the HPD or empty, if not known (see Section 1.6.4.3.4.2 Message Semantics)
CH-XUACH-XUA-005[SAML Assertion] There MUST be one <Attribute> element with the name attribute "urn:oasis:names:tc:xacml:2.0:subject:role". The <AttributeValue> child element MUST convey a coded value of the subjects role (see Section 1.6.4.3.4.2 Message Semantics)
CH-XUACH-XUA-006[SAML Assertion] There MUST be one <Attribute> element with the name attribute:"urn:oasis:names:tc:xacml:2.0:resource:resource-id". The <AttributeValue> MUST convey the EPR-SPID identifier of the patients record and the patient assigning authority formatted in CXsyntax as specified in the XUA profile (see Section 1.6.4.3.4.2 Message Semantics)
CH-XUACH-XUA-007[SAML Assertion] There MUST be one <Attribute> element with the name attribute: "urn:oasis:names:tc:xspa:1.0:subject:purposeofuse". The <AttributeValue> child element MUST convey a coded value of the current transactions purpose of use (see Section 1.6.4.3.4.2 Message Semantics)
CH-XUACH-XUA-008The Get X-User Assertion response message extends the <wst:RequestSecurityTokenResponse> message defined in WS-Trust 1.3 (see Section 1.6.4.2.4.2 Message Semantics)
CH-XUACH-XUA-012See ITI TF-2b, chapter 3.40 Provide X-User Assertion [ITI-40]. The SAML User Assertion MUST be taken from the Get X-User Assertion transaction (see Section 1.6.4.2.1 Scope)
CH-XUACH-XUA-013The User Authentication Provider authenticates the user and returns a SAML 2 Authentication Assertion (see Section 1.6.4.1.1 Scope)
CH-XUACH-XUA-018X-Assertion Provider verifies authorization information, creates a SAML Authorization Assertion and sends it to the X-Service User (see Section 1.6.4.2.2 Use Case Roles)
CH-XUACH-XUA-020X-Service User actor MUST implement the SAML User Authentication Request of the «Authenticate User» transaction (see Section 1.6.4.1.1 Scope)
CH-XUACH-XUA-021X-Service User actor MUST implement the SAML User Assertion Request (see Section 1.6.4.2.2 Use Case Roles)
CH-XUACH-XUA-024The X-Assertion Provider actor MUST authenticate the technical user by validating the signature of the Assertion with the certificate registered with the technical user (see Section 1.6.4.2.4.4.3 Technical User Extension)
CH-XUACH-XUA-026X-Service User actor MUST be able to send SAML attribute queries to the Identity Provider to query specific attributes according to the Identity Provider (see Section 1.6.4.2.2 Use Case Roles)
CH-XUACH-XUA-029X-Service Provider actor MUST be grouped with the actor «Authorization Decision Provider» as defined in the CH:ADR integration profile (see Table 4: Required groupings of actors defined in this national extension)
CH-XUACH-XUA-030X-Service Provider actors MUST implement the Provide X-User Assertion [ITI-40] specified by the IHE XUA integration profile (see Section 1.6.2 Actors / Transactions)
CH-XUACH-XUA-032[SAML Assertion - HCP - ASS - TCU] The organization attribute ("urn:oasis:names:tc:xspa:1.0:subject:organization") of the <AttributeStatement> MUST convey the name of the organizations or groups the subject is a member of (see Section 1.6.4.3.4.2.1 Heathcare Professional Extension)
CH-XUACH-XUA-033[SAML Assertion - HCP - ASS - TCU] The organization ID attribute ("urn:oasis:names:tc:xspa:1.0:subject:organization-id") MUST convey the identifiers of the organizations or groups the subject is assigned to. The identifiers MUST be OID in the format of URN as registered in the healthcare provider directory (see Section 1.6.4.3.4.2.1 Heathcare Professional Extension)
CH-XUACH-XUA-034The <SubjectConfirmation> element MUST contain a <NameID> child element. The <NameID> element must convey the GLN of the subject with name qualifier name qualifier attribute set to urn:gs1:gln (Assistant Extension) or the unique ID the technical user is registered within the community and NameQualifier "urn:e-health-suisse:technical-user-id" (see Section 1.6.4.3.4.2.3 Technical User Extension)
CH-XUACH-XUA-035[SAML Assertion - ASS] The <Conditions> element MUST contain a <AudienceRestriction> element coveying a single <Audience> child element with the value set to "urn:e-health-suisse:token-audience:all-communities" (see Section 1.6.4.3.4.2.3 Technical User Extension)