NIST SP800-63-4 Revision 2 Public Draft (2pd) was released 1 weeks ago. Today (Japan time, the 29th, 1 a.m. to 3 a.m.), the first in a planned series of workshops was held, outlining some of the most significant changes since the initial public draft.

Introduction and Housekeeping

  • The workshop on NIST Special Publication 800-63 Revision 4Revision 2 Public Draft began with housekeeping matters, including recording the session, slide availability, and use of the Q&A feature for questions. [00:00]
  • Today’s agenda was as follows:

NIST Special Publication 800-63-4 Overview

  • This workshop focused on Revision 2 Public Draft of the Digital Identity Guidelines, covering major changes, the public comment period, and how to submit comments. [02:00]
  • The guidelines establish baseline requirements for digital identity management across the federal government and consist of 4 volumes: the Base Volume and Volumes A, B, and C. [05:00]

Key Drivers of the Changes

  • Key drivers include improving equitable access to government services, responding to emerging threats and technologies, and incorporating real-world lessons from prior implementations. [07:00]

Revision 1 Public Draft: Major Changes

  • The changes included a revamped risk-management approach, updated biometric requirements, new identity-proofing processes, and considerations for privacy, usability, and equity. [09:00]

Timeline and Public Comment Period

  • The revision timeline was reviewed, highlighting publication of the Revision December 2022 Revision 1 Public Draft in August 2023 Revision 2 Public Draft in 2 draft has a public comment period of 45 days. [12:00]

Major Changes to the Base Volume

  • Connie LaSalle described the introduction of the user-controlled wallet model (Chapter 2 ), the addition of a service “definition” step to the identity risk-management process (Chapter 3 ), metrics for continuous evaluation and improvement, and redress mechanisms for exceptions. [16:00]
  • Notably, the user-controlled wallet was introduced as a variant of an IdP (identity provider), with the “issuer” treated as a CSP (credential service provider).
  • The updated digital identity risk-management process includes defining the online service, conducting an initial impact assessment, and tailoring controls based on continuous risk assessment. [20:00]
  • Continuous evaluation and improvement are emphasized, with recommended performance metrics and redress measures for addressing problems equitably. [25:00]

Major Changes to Volume A (Identity Proofing and Enrollment)

  • David Temoshok highlighted updated identity-proofing roles and types, rebalancing IAL 1(Identity Assurance Level 1), new identity-verification pathways, fraud-management requirements, and updated evidence-validation requirements. [30:00]
  • Identity-proofing roles now include proofing agents, trusted referees, process assistants, and applicant references. [32:00]
  • IAL 1 rebalancing focuses on reducing friction and increasing options for applicants and credential service providers. [35:00]
  • IAL 2 include options that do not use biometrics and validation of digital evidence. [38:00]
  • The new fraud-management section includes requirements for credential service providers and relying parties, mandatory fraud checks, and communication channels for suspected fraud cases. For example, checking the date of death is now mandatory. [42:00]
  • Updated evidence-validation requirements include performance metrics for document-authentication systems and training for identity-proofing agents. [45:00]

Volume B: Major Changes (Authenticators and Authentication)

  • Andy Regenscheid described incremental improvements, new requirements for syncable authenticators, and clarification of guidance for user-controlled digital accounts. [50:00]
  • The revised account-recovery section provides clearer paths and greater flexibility for implementing account-recovery processes. [55:00]
  • Syncable authenticators such as passkeys are now addressed, with additional requirements for the sync fabric. [52:00]
  • Use of digital wallets as authenticators has been clarified, and new account-recovery methods have been introduced, including saved recovery codes and trusted recovery contacts. [57:00]

Major Changes to Volume C (Federation and Assertions)

  • Ryan Galluzzo described the updated structure of Volume 863 C, revisions to Federation Assurance Level 3 (Federation Assurance Level 3), and the introduction of protocol-based examples. [01:00:00]
  • The new structure includes core common federation requirements and separate sections for general-purpose IdP federation and user-controlled wallet federation. [01:02:00]
  • In the wallet model, wallets can be handled by modeling them as IdPs, so that is what the draft does. (I am pleased that the comment was accepted.)
  • Traditional IDPs and wallets are distinguished by whether they are multi-user or single-user. (I am not entirely convinced by this; perhaps the concept of time should also be considered.)
  • 3 change is the introduction of Bound Authenticators. Federation Assurance Level 3 now includes Holder of Key assertions and bound authenticators. [01:05:00]
  • Protocol-based examples were also added, providing high-level explanations for implementing federation protocols such as OpenID Connect and SAML. (A Q&A comment noted that FAL 2 can be achieved without using a back channel. Indeed, it should be possible with response type = id_token. Perhaps the iGov WG should create an FAL 2 profile.) [01:08:00]

Public Comment Period and Next Steps

  • The public comment period closes on October 7. Comments may be submitted by email or using an Excel spreadsheet. The time required to finalize the document will depend on the volume of comments received. [01:15:00]
  • The team emphasized the importance of public feedback and encouraged participation in the review process. [01:20:00]
  • Feedback is particularly requested in the following areas:
  • This will be the final public consultation, with publication planned for the new year.
  • You can engage through the following channels:

Q&A Session

  • A variety of questions were addressed, including document false-acceptance rates, biometric performance, and use of passkeys. [01:25:00]
  • The team clarified specific requirements and encouraged further comments and feedback from participants. [01:30:00]

Closing Remarks

  • The workshop concluded with a call to submit comments and participate in future workshops. The team thanked participants for their time and feedback. [01:35:00]