Overview

In recent years, the rapid development of the digital society has made online identity proofing and authentication increasingly important. The U.S. National Institute of Standards and Technology (NIST) has now released an updated draft of its “SP 800-63-4” digital identity guidelines (2nd Public Draft). This update aims to strengthen security and create an environment in which everyone has equitable access to digital services.

A notable feature of this update is its support for the latest digital technologies. For example, it introduces new concepts such as “syncable authenticators” (passkeys) and “user-controlled wallets.” Passkeys offer stronger security than conventional passwords, while user-controlled wallets can securely store various digital credentials.

At the same time, NIST continues to emphasize traditional identity proofing methods. Consideration is given to ensuring that people without smartphones or digital credentials can still access the services they need. For example, the guidelines set out detailed provisions for in-person identity proofing and exception handling for people without conventional identity documents. They also introduce the concept of an “applicant reference,” allowing a person’s identity to be verified without identity documents when a trusted third party can vouch for them.

The guidelines also provide important direction on biometrics. While emphasizing biometric accuracy and the importance of protecting personal information, they recommend providing alternatives, especially for public services. They also call for manual procedures to be established in case errors occur in biometric systems.

This proposed update to the guidelines reflects feedback from a wide range of stakeholders, including private companies and advocacy groups. NIST is focused on balancing fraud prevention measures with equitable access to services, and the update is expected to have a significant impact on the future development of the digital society.

Managing digital identity will likely become increasingly important. NIST’s initiative is attracting attention around the world as an advanced effort to balance security, usability, and equity. We, too, should follow these developments while thinking more deeply about how we manage our own digital identities.

Comments on this document are being accepted until October 7. Further details are available on this page.

Appendix: Highlights from the Original Release

Overview of the NIST Digital Identity Guidelines Update

  • NIST updated its draft digital identity guidance to improve security and accessibility.
  • The update reflects feedback from a variety of stakeholders, including private companies and advocacy groups.
  • The guidelines aim to balance fraud prevention with equitable access to digital services.

Key Features of the Updated Guidelines

  • The draft includes guidance on modern digital pathways, such as syncable authenticators and user-controlled wallets.
  • Syncable authenticators (passkeys) provide greater security than conventional passwords. They are described in Appendix B.
  • User-controlled wallets can store various digital credentials, including identity documents. They are described in Appendix C.

Accessibility and Traditional Identity Proofing Methods

  • The guidelines ensure that individuals without smartphones or digital credentials can still access services.
  • The expanded guidance includes in-person identity proofing and exception handling for people without conventional identity documents.
  • The concept of an “applicant reference” allows a trusted individual to vouch for someone who does not have identity documents.

Biometrics and Privacy Considerations

  • The updated guidance retains the use of biometrics for identity proofing while emphasizing accuracy and privacy.
  • Alternatives to biometric methods are recommended, particularly in public-service systems.
  • NIST aims to include manual processes for addressing potential errors in biometric systems.