Skip to content

Add identification means / authenticator assurance level #34

@sander

Description

@sander

For some use cases it is important to know the security strength of the wallet/agent when applied to present credentials.

Common assessment criteria are available: (EU) 2015/1502 lists requirements for identification means characteristics and design for eIDAS LoA Low/Substantial/High, where LoA High will be required for the EUDI Wallet. Peer review feedback and related Guidance documents provide common interpretations. NIST SP 800-63B specifies Authenticator Assurance Levels (AALs) in more concrete detail.

For example, the EUDI Wallet will require eIDAS LoA High, while webshop coupon issuers may find AAL1 sufficient.

I suggest to add one field for eIDAS:

  • ID: eidasMeansLoa (eIDAS identification means level of assurance)
  • Type: low | substantial | high as per 2015/1502

And one field for NIST:

  • ID: nistAal (authenticator assurance level)
  • Type: 1 | 2 | 3 as per SP 800-63B

Metadata

Metadata

Assignees

No one assigned

    Labels

    TBDwe can not solve this right now, but maybe in the future

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions