Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Section
Column
width50%

The InCommon Silver Identity Assurance Profile includes stronger identity management procedures which will be required by some Service Providers (some applications from the National Institutes of Health, for example). Identity Providers will need more-stringent requirements for validating the identities of individuals to whom they grant user IDs and passwords.

Refining Silver - As the need for Silver gets closer, the InCommon Technical Advisory Committee (TAC) is refining the Silver Identity Arruance Profile to provide clarity and ensure that only necessary requirements are included. This process is expected to be completed by the Internet2 2011 Spring Member Meeting (April 18-20).

The TAC is accepting comments on the refined Silver Identity Assurance Profile (v .1.1) and the refined Silver Identity  Assurance Assessment Framework (v 1.1) through March 28, 2011. Please send any comments to refining-silver@incommon.org.

Silver Optional - Silver will be optional and available for campuses that want to meet a set of criteria that satisfies higher-risk applications' requirements.

Assurance process is designed to support the needs of service providers that must require identity providers to meet a more detailed set of requirements than is defined with our basic federation services. The National Institutes of Health and National Science Foundation are examples of such service proviers.

These new assurance levels are named bronze and silver and originally corresponded with the National Institute of Standards (NIST) security guide 800-63 for level 1 and level 2 of assurance. Silver provides a higher level of assurance, including criteria for more robust identity management and identity-proofing procedures. InCommon has undertaken a detailed review and as a result is refining the Identity Assurance Profile with the goal of simplifying the profile and ensuring it meets the current requirements of the federal government. 

This project has two main drivers:

1. The federal government requirements have changed. The standards are now being developed by the Identity, Credential and Access Management (ICAM) effort at the GSA. The Identity Assurance Profiles were originally written to comply with an older government initiative - eAuth - which is no longer active and had a number of criteria that no longer apply.

2. A group of schools has been working through the Silver adoption process and uncovering a number of questions and recommendations. These have also been incorporated into the updated profile.

The updated Identity Assurance Profile and the related Identity Assurance Assessment Framework are now available for community comment. In the box to the right, you will find links to the new documents (both version 1.1), along with the current 1.0 versions. I invite you to send your comments to ia-review@incommon.org.

We will accept comments through March 28, 2011, with the goal of completing this process by April 18, 2011.

The community wishes to thank the schools that have been working on the Silver adoption process – the Committee for Institutional Cooperation (CIC), which includes the Big Ten plus the University of Chicago, along with the University of Washington and Virginia Tech. In addition, a group of member-institutions of SURA (Southeastern University Research Association) has recently started a Silver adoption process. Both of these collaborations will document their efforts, which will help all of us as we move to adopt SilverService Providers will determine their particular profile requirements, based on an assessment of the risk associated with their federated application. The Silver profile is expected to become a valuable standard for managing organizational identities as higher-risk SPs enable federated access.

Column
width50%
Info
iconfalse
titleRelated Documents and Resources


Identity Assurance Assessment Framework

  • Candidate Release
  • Current Release (1.0.4)

Bronze and Silver Identity Assurance Profile

  • Candidate Release
  • Current Release (1.0)

Frequently Asked Questions About the Silver Refinement

Assurance Profile Assessment Checklist

InCommon Assurance Technical Procedures

Silver Report from the CIC: Phase 1 - Several schools are working together to implement Silver, including the CIC (Big Ten and the University of Chicago), the University of Washington and Virginia Tech. They have completed one of three phases and have issued this report.