On this page we've collected a number of resources on the quality (or level) of assurance of digital identities exchanged in federations like WAYF – i.e. the degree of trust service providers can have in the logins mediated by the federation from the user organisations, and how to describe that. A number of frameworks for assurance exist; but arguably the two most important dimensions in this concept are: how user organisations make sure the login means of a digital identity are delivered to the intended physical person (identity assurance level, “IAL”) – and with what means the user has identified herself in any specific session (authentication assurance level, “AAL”), typically with what and how many “factors”. A third dimension is how securely the evidence of a specific session (the login “token”) is mediated from user organisation to service provider, the so-called federation assurance level (“FAL”). But assurance can also be about e.g. how fresh the user data supplied are – all depending on the service provider's needs. In a login token, information on level of assurance normally is found within elements such as eduPersonAssurance, AuthnContext, acr, and amr. In WAYF, all assurance levels are, in principle, permitted – but any user organisation MUST specify, in the login token, a digit indicating the identity's level of assurance (see this page's description of eduPersonAssurance), and in addition SHOULD implement both the REFEDS MFA Profile and the REFEDS Assurance Framework, the international standard for assurance within research and higher education. It is always the responsibility of the service provider to check in the login token if the identity's assurance level is sufficient for the service sought access to.
- The leading American standard NIST 800-63-3 and its older version NIST 800-63-2.
- Article on level of assurance generally and within WAYF.
- Article on HPC-facility LUMI's requirements for identity assurance.
- REFEDS Assurance Framework:
- Website of REFEDS Assurance Framework.
- Article at WAYF on REFEDS Assurance Framework.
- American federation InCommon's guide to implementing the REFEDS Assurance Framework. Features a chart comparing various assurance frameworks.
- GÉANT project AARC's extension of the REFEDS Assurance Framework.
- Resources and frameworks for level of assurance at the Kantara Initiative.
- Interoperable Global Trust Federation's (IGTF's) framework for level of assurance.
- Danish Agency for Digital Government's National Standard for Identities' Assurance Levels (“NSIS”) for use within Denmark's public sector.
- EU Commission on levels of assurance as defined in the eIDAS regulation – for use across member states, and spiritual basis of NSIS.
- Italian federation IDEM on levels of assurance.
- On levels of assurance within German research collaboration NFDI.
- Articles on technical assistance with AAL within WAYF:
- WAYF can request AAL on behalf of service providers.
- WAYF can place AAL signal correctly on behalf of user organisations.
- REFEDS standards for AAL:
- Multi-Factor Authentication profile.
- Single-Factor Authentication profile.