Digital Identity Guidelines¶
Grassi, P. A., Fenton, J. L., Newton, E. M., Perlner, R. A., Regenscheid, A. R., Burr, W. E., Richer, J. P., et al. (2017). Digital Identity Guidelines: Authentication and Lifecycle Management.
Cited by¶
4 citations across 4 artifacts.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Independent Signal Verification Lane
- The pattern is the security practice of out-of-band verification: confirm a request through a separate channel precisely because the requesting channel may be compromised.
This sourceDefines out-of-band verification through a separate communication channel so compromise of the requesting path alone is insufficient.
- The pattern is the security practice of out-of-band verification: confirm a request through a separate channel precisely because the requesting channel may be compromised.
- Multi-Factor Authentication
- The contrast that makes the design legible is a weak second factor: a one-time code sent by SMS can be intercepted through a SIM-swap, so it raises the bar far less than an origin-bound key.
This sourceNIST Special Publication 800-63B. National Institute of Standards and Technology (2017). Warns that SMS authentication is vulnerable to SIM-change attacks and distinguishes it from phishing-resistant, verifier-bound cryptographic authentication.
- The contrast that makes the design legible is a weak second factor: a one-time code sent by SMS can be intercepted through a SIM-swap, so it raises the bar far less than an origin-bound key.
- Out-of-Band Escalation Path
- Its defining idea is out-of-band
This sourceDefines out-of-band as deliberately keeping the fallback off the primary path.
- Its defining idea is out-of-band
- Permission or Access Revocation
- Revocation is only as fast as the slowest place the old permission is still honoured: cached credentials, long-lived tokens, and replicated grant stores can keep the door open after you think you've shut it.
This sourceNIST requires prompt authenticator revocation and notes that offline certified attributes can remain usable until certification expires unless the authenticator is surrendered or destroyed.
- Revocation is only as fast as the slowest place the old permission is still honoured: cached credentials, long-lived tokens, and replicated grant stores can keep the door open after you think you've shut it.
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Not recorded. Neither this nor any other of the 4 citations of this work carries a recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:5260c2b6642d · see in the full table