Jump to content

Identity assurance

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by Fvillavicencio (talk | contribs) at 17:59, 30 January 2010 (Created page with 'Identity assurance, in the context of identity management, is the ability for a party to determine, with some level of certainty, that an electronic credential ...'). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

Identity assurance, in the context of identity management, is the ability for a party to determine, with some level of certainty, that an electronic credential representing an entity - whether a human or a machine, with which it interacts to effect a transaction, can be trusted to actually belong to the entity.

In the case the entity is a person, identity assurance is the level at which the credential being presented can be trusted to be a proxy for the individual to whom it was issued and not someone else.

The level of certainty one can have about the credential is what is referred to as the "Assurance Level". Assurance Levels (ALs) are the levels of trust associated with a credential as measured by the associated technology, processes, and policy and practice statements. An assurance level describes the degree to which a relying party in an electronic exchange can, after performing certain tests to authenticate (validate) the origin of the exchange, be confident that the identity information being presented by a credential service provider (also referred to as Identity Provider or IdP) actually represents the entity referred to in it and that it is the represented entity which is actually engaging in the exchange.


References

[1] [2]