It's time for authorization standards: AuthZEN WG at OpenID Foundation
aserto.comGreat initiative, hopefully this will result in some oAuth like message exchange pattern, so we do not have to bake a proprietary pattern between applications and authorization service(s). Hopefully it can also help shield us from vendor lock-in :)
That is one of the charters of the working group, https://openid.net/wg/authzen/
The key objective is to build upon the existing cornerstones.
Note that this is not necessarily an effort to define yet another authorization architecture or runtime policy language. Instead, the WG will develop OpenID Foundation Final Specifications which leverage existing architectures and protocols as much as possible. Where appropriate, the WG intends to collaborate with international standards development organizations, such as ISO/IEC JTC 1, ITU-T, and IETF, for recognition of these OpenID Foundation specifications.