NIST.IR 7817

Overview#

NIST.IR 7817 is a NIST INTERNAL/INTERAGENCY REPORTS (NISTIR) covering A Credential Reliability and Revocation Model for Federated Identities

NIST.IR 7817 points out: Evidence of malicious activity at the service provider is not generally shared with the identity provider. This situation is unfortunate, as the service provider is at the forefront of attacks. It has all audit trails and knowledge of suspicious or malicious account activities ... Service provider feedback is especially useful and indicative in the federation since the feedback is likely reported by several service provider in the federation, thus providing strong evidence of credential compromise.

Uniform Reliability and Revocation Service (URRS)#

NIST.IR 7817 suggest a Uniform Reliability and Revocation Service (URRS) further stating: The URRS is the central information collection and distribution point of credential status information and its reliability. The role of the URRS is to: The URRS automatically updates the reliability score with each feedback from the service provider.

These updates are communicated to the identity provider and the user. The URRS automatically suspends the credential if a feedback causes the score to fall below the reliability score threshold. The threshold value is established and agreed upon by the identity providers and service providers when the URRS is set up.

However, there has been no further activity on the Uniform Reliability and Revocation Service since proposed in 2012

More Information#

There might be more information for this subject on one of the following: