Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

It seems likely that different federations will define different profiles for identity assurance. InCommon, for one, has stated that it will define "bronze" and "silver" profiles, and will certify particular IdPs to be in conformance with a named profile provided their operations and infrastructure meet the associated criteria.  It is the intention of InCommon that an institution with an identity assurance profile of bronze could reasonably be mapped to what NIST SP 800-63 defines as level one.  Silver is intended to map to NIST level two.  The ultimate arbiter is the SP that receives assertions from an IdP.  They may well want to do a risk assessment of their applications and then decide which identity assurance profiles are appropriate for each.

The identity assurance of a given interaction of user, IdP and SP is dependent on many factors.  However, in the interest of simplicity of operation, it seems desirable for an IdP to assert that a given interaction, taking everything into consideration, fits a particular identity assurance profile.