Implement federation per NIST SP 800-63-4 Volume C (Federation and Assertions). Trust agreements per Section 4.3 between Credential Service Provider (CSP) + Identity Provider (IdP) + Relying Party (RP) defining responsibilities + assurance levels + assertion format + cryptographic parameters + audit obligations. Assertion protection per Section 5: bearer (FAL1) + encrypted (FAL2) + holder-of-key (FAL3) per Section 5.5 with required cryptographic algorithms + key management + nonce + expiry + audience binding. RP validation per Section 6.2: validate signature + audience + issuer + replay nonce + expiry + revocation status. Pseudonymous identifiers per Section 7.3 supporting privacy by letting RP-specific identifiers prevent cross-RP correlation by IdP. Attribute minimisation per Section 7.4. Runtime subscriber decision per Section 7.5: subscriber choice on attribute release at runtime. Federation proxies per Section 8 handling chained federation + assurance level propagation + proxy logging.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.