NIST SP 800-63-3
From MgmtWiki
Revision as of 10:00, 4 June 2019 by Tom (talk | contribs) (→Enrollment and Identity Proofing (800-63-3A))
Contents
Full Title
Digital Identity Guidelines
- Date released: 2017-06-22
Context
- Specifically applies to federal agencies implementing digital identity services but is widely used internationally.
- This third version makes substantial changes to the second version, specifically the single list of the levels of authentication has been separated into three distinct lists, one for each of the documents as described below.
Summary Document of Digital Identity Guidelines
Enrollment and Identity Proofing (800-63-3A)
- Contains IAL levels = Identity Assurance Level (Level 2 is required by Healthcare)
- There is no requirement to link the applicant to a specific real-life identity. Any attributes provided in conjunction with the subject’s activities are self-asserted or should be treated as self-asserted (including attributes a CSP asserts to an RP). Self-asserted attributes are neither validated nor verified.
- Evidence supports the real-world existence of the claimed identity and verifies that the applicant is appropriately associated with this real-world identity. IAL2 introduces the need for either remote or physically-present identity proofing. Attributes could be asserted by CSPs to RPs in support of pseudonymous identity with verified attributes. A CSP that supports IAL2 can support IAL1 transactions if the user consents.
- Physical presence is required for identity proofing. Identifying attributes must be verified by an authorized and trained CSP representative. As with IAL2, attributes could be asserted by CSPs to RPs in support of pseudonymous identity with verified attributes. A CSP that supports IAL3 can support IAL1 and IAL2 identity attributes if the user consents.
Authentication and Lifecycle Management (800-63-3B)
- Contains AAL levels = Authentication Assurance Level
Federation and Assertions (800-63-3D)
- Contains FAL levels = Federation Assurance Level