-
Notifications
You must be signed in to change notification settings - Fork 35
Open
Labels
TBDwe can not solve this right now, but maybe in the futurewe can not solve this right now, but maybe in the future
Description
For some use cases it is important to know the security strength of the wallet/agent when applied to present credentials.
Common assessment criteria are available: (EU) 2015/1502 lists requirements for identification means characteristics and design for eIDAS LoA Low/Substantial/High, where LoA High will be required for the EUDI Wallet. Peer review feedback and related Guidance documents provide common interpretations. NIST SP 800-63B specifies Authenticator Assurance Levels (AALs) in more concrete detail.
For example, the EUDI Wallet will require eIDAS LoA High, while webshop coupon issuers may find AAL1 sufficient.
I suggest to add one field for eIDAS:
- ID:
eidasMeansLoa
(eIDAS identification means level of assurance) - Type:
low | substantial | high
as per 2015/1502
And one field for NIST:
- ID:
nistAal
(authenticator assurance level) - Type:
1 | 2 | 3
as per SP 800-63B
Metadata
Metadata
Assignees
Labels
TBDwe can not solve this right now, but maybe in the futurewe can not solve this right now, but maybe in the future