After saying for ages that I would do it but never getting around to it, I am finally holding a session to explain ISO/IEC 29115 | ITU-T X.1254 (2012)1. On July 3 (Monday), it will begin at 22. It may be a somewhat leisurely read-through, but I intend to keep it to a little over 1 hour. Accordingly, I will not scrutinize every line of the original text. The idea is to “tear it down” so that you understand its structure and how to read it, allowing you to study and appreciate it carefully afterward.

ISO/IEC 29115 | ITU-T X.1254 (2012) is referenced by OpenID Connect and likewise by eIDAS 1, making it a surprisingly influential document. The recently published OECD Recommendation on the Governance of Digital Identity, which I discussed on June 19, also mentions LoA2 and mapping (correspondence). ISO/IEC 29115 also serves as a “yardstick” for mapping the levels defined by each country’s trust framework to the LoAs in ISO/IEC 29115 and establishing correspondences, so I believe this is the kind of mapping that the Recommendation envisages. In Japan, NIST SP 800-63 is consulted relatively often, but internationally this document may be the standard reference.

This time, I will give a broad overview of the document’s structure and the reasons behind it, comparing it with NIST SP 800-63 along the way. I would also like to consider what we would change if we were revising it now.

The document can be downloaded from https://bit.ly/X1254.

So, if this topic is relevant to your work, please do join us.

Watch this video on YouTube.
Playing the video connects to YouTube.
  1. https://www.itu.int/ITU-T/recommendations/rec.aspx?rec=11608&lang=en The texts are almost identical, but there are 4 differences
  2. Levels of Assurance. These indicate the levels of entity authentication.

Related posts