NIST SP 800-63 Digital Identity Guidelines
Federation - FAL1/2/3

NIST SP 800-63 Digital Identity Guidelines 7: Federation - FAL1, FAL2, FAL3 Assertions, RP Validation, Trust Agreements

Implement federation per NIST SP 800-63C across FAL1 + FAL2 + FAL3 levels. FAL1 per Section 4 requires (a) Bearer Assertion (signed by IdP + not encrypted to RP), (b) Trust Agreement between IdP and RP per Section 4.3.1, (c) Assertion Content Requirements per Section 4.4 (issuer + subject + audience + assertion identifier + expiry + nonce + signature), (d) Relying Party Validation Obligations per Section 4.5 (signature verification + audience + replay protection + expiry). FAL2 adds (a) Encrypted Assertion to the RP per Section 5, (b) Cryptographic key management per Section 5.2. FAL3 adds (a) Holder-of-Key assertion binding the assertion to a key held by the subscriber per Section 6 (preventing assertion replay by an intermediary), (b) Strong cryptographic binding of the holder-of-key authenticator to the assertion. Across all FAL: (c) Federation Audit Logging per Section 8.2, (d) Federation Proxies handling per Section 7, (e) Pseudonymous Identifiers per Section 9.6 supporting privacy, (f) Attribute Minimisation per Section 9.4 (release only attributes needed by the RP), (g) Runtime Subscriber Decision per Section 9.5 supporting subscriber choice over attribute release.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.