OpenID Connect for Identity
Assurance
https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html
Torsten Lodderstedt, yes.com
Objectives
● Allow OpenID Connect OPs explicit attestation of verification status of
Claims (what, how, when, according to what rules, using what evidence)
● For use cases requiring strong identity assurance, such as Anti-money
Laundering, eGovernment & eSigning
● Focus on natural person data, such as name or birth date
Design objectives
● Use existing End-User Claims and build something around to convey
attestation, define additional End-User Claims where needed
● Verified claims can be added to any JSON-based response or JWT - mixed
with unverified claims and other extensions
● Privacy by design
Representation
● Self contained and robust representation
● verified_claims Container
● verification element contains verification
metadata (multiple evidence possible)
● claims element contains respective
End-User Claims
User Info & ID Token
International Standard
● Trust frameworks, verification methods and evidence types
● So far review feedback & contributions from US, CA, UK, DE, EU & JP
Additional End-User Claims
● place_of_birth
● nationalities
● birth_family_name, birth_given_name, birth_middle_name
● salutation
● title
RPs request verified claims using “claims” parameter
● Fine grained control
● Data minimization
Constraints
● Leverages OpenID Connect Core syntax
Remark on URL length
● Request URLs can become quite long with “claims” parameter
● Recommendation: take a look into request_uri and Pushed Authorization
Requests (https://tools.ietf.org/html/draft-lodderstedt-oauth-par)
Status
● Public Review has started
https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html
● Couple of implementations are under way
Need your feedback!

More Related Content

PDF
OpenID Foundation RISC WG Update - 2018-04-02
PDF
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
PDF
OIDF Workshop 4/29/2019 -- OpenID Certification Update
PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
PDF
OpenID Foundation/Open Banking Workshop - OpenID Foundation Overview
PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
PDF
OpenID Foundation Connect Working Group Update - October 22, 2018
OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
OIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OpenID Foundation/Open Banking Workshop - OpenID Foundation Overview
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
OpenID Foundation Connect Working Group Update - October 22, 2018

What's hot (20)

PDF
OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...
PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
PDF
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
PDF
OpenID Certification Program Update - 2018-04-02
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
PDF
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
PDF
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
PPTX
OpenID Foundation MODRNA WG Update
PDF
OpenID Foundation RISC WG Update - 2017-10-16
PPTX
OpenID Foundation FastFed Working Group Update - 2017-10-16
PDF
OpenID Certification Program Update - 2017-10-16
PPTX
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
PDF
OpenID Connect "101" Introduction -- October 23, 2018
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
PDF
OIDC4VP for AB/C WG
PDF
OpenID Connect 4 SSI
PPTX
OpenID Connect: An Overview
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...
PPTX
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
PPTX
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop
OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OpenID Certification Program Update - 2018-04-02
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation MODRNA WG Update
OpenID Foundation RISC WG Update - 2017-10-16
OpenID Foundation FastFed Working Group Update - 2017-10-16
OpenID Certification Program Update - 2017-10-16
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
OpenID Connect "101" Introduction -- October 23, 2018
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OIDC4VP for AB/C WG
OpenID Connect 4 SSI
OpenID Connect: An Overview
OIDF Workshop at Verizon Media -- 9/30/2019 -- Research & Education Working G...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop
Ad

Similar to OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity Assurance Overview (20)

PDF
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
PDF
OpenID Connect 4 Identity Assurance at IIW #32
PDF
OpenID Connect 4 SSI (at EIC 2021)
PDF
OpenID Connect Explained
PPTX
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
PDF
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
PDF
Enabling Large-Scale Multi-Party Federations with OpenID Connect - OpenID Sum...
PDF
OpenID Connect 4 SSI (DIFCon F2F)
PPTX
OpenAthens Conference 2018 - Don Thibeau - OpenID Connect
PDF
OpenID for SSI
PPTX
The Client is not always right! How to secure OAuth authentication from your...
PDF
Identity Proofing with OpenID Connect
PDF
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
PDF
OpenID for Verifiable Credentials (IIW 35)
PPTX
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
PDF
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
PDF
Introducing OpenID 1.0 Protocol: Security and Performance
PDF
SAML VS OAuth 2.0 VS OpenID Connect
PPTX
OpenID Connect for W3C Verifiable Credential Objects
PDF
OpenID Connect - An Emperor or Just New Cloths?
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- FAPI Certi...
OpenID Connect 4 Identity Assurance at IIW #32
OpenID Connect 4 SSI (at EIC 2021)
OpenID Connect Explained
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
Enabling Large-Scale Multi-Party Federations with OpenID Connect - OpenID Sum...
OpenID Connect 4 SSI (DIFCon F2F)
OpenAthens Conference 2018 - Don Thibeau - OpenID Connect
OpenID for SSI
The Client is not always right! How to secure OAuth authentication from your...
Identity Proofing with OpenID Connect
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
OpenID for Verifiable Credentials (IIW 35)
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
Introducing OpenID 1.0 Protocol: Security and Performance
SAML VS OAuth 2.0 VS OpenID Connect
OpenID Connect for W3C Verifiable Credential Objects
OpenID Connect - An Emperor or Just New Cloths?
Ad

Recently uploaded (20)

PPTX
AI_Cyberattack_Solutions AI AI AI AI .pptx
PDF
Course Overview and Agenda cloud security
PDF
KEY COB2 UNIT 1: The Business of businessĐH KInh tế TP.HCM
PDF
Top 8 Trusted Sources to Buy Verified Cash App Accounts.pdf
PPTX
Layers_of_the_Earth_Grade7.pptx class by
PPTX
在线订购名古屋艺术大学毕业证, buy NUA diploma学历认证失败怎么办
PDF
The_Decisive_Battle_of_Yarmuk,battle of yarmuk
PPTX
10.2981-wlb.2004.021Figurewlb3bf00068fig0001.pptx
PPTX
Viva Digitally Software-Defined Wide Area Network.pptx
PPTX
Partner to Customer - Sales Presentation_V23.01.pptx
PDF
Uptota Investor Deck - Where Africa Meets Blockchain
PDF
Alethe Consulting Corporate Profile and Solution Aproach
PDF
Virtual Guard Technology Provider_ Remote Security Service Solutions.pdf
PDF
Alethe Consulting Corporate Profile and Solution Aproach
PDF
Understand the Gitlab_presentation_task.pdf
PDF
Paper The World Game (s) Great Redesign.pdf
PPTX
KSS ON CYBERSECURITY INCIDENT RESPONSE AND PLANNING MANAGEMENT.pptx
PPTX
COPD_Management_Exacerbation_Detailed_Placeholders.pptx
PPTX
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
PDF
Containerization lab dddddddddddddddmanual.pdf
AI_Cyberattack_Solutions AI AI AI AI .pptx
Course Overview and Agenda cloud security
KEY COB2 UNIT 1: The Business of businessĐH KInh tế TP.HCM
Top 8 Trusted Sources to Buy Verified Cash App Accounts.pdf
Layers_of_the_Earth_Grade7.pptx class by
在线订购名古屋艺术大学毕业证, buy NUA diploma学历认证失败怎么办
The_Decisive_Battle_of_Yarmuk,battle of yarmuk
10.2981-wlb.2004.021Figurewlb3bf00068fig0001.pptx
Viva Digitally Software-Defined Wide Area Network.pptx
Partner to Customer - Sales Presentation_V23.01.pptx
Uptota Investor Deck - Where Africa Meets Blockchain
Alethe Consulting Corporate Profile and Solution Aproach
Virtual Guard Technology Provider_ Remote Security Service Solutions.pdf
Alethe Consulting Corporate Profile and Solution Aproach
Understand the Gitlab_presentation_task.pdf
Paper The World Game (s) Great Redesign.pdf
KSS ON CYBERSECURITY INCIDENT RESPONSE AND PLANNING MANAGEMENT.pptx
COPD_Management_Exacerbation_Detailed_Placeholders.pptx
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
Containerization lab dddddddddddddddmanual.pdf

OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity Assurance Overview

  • 1. OpenID Connect for Identity Assurance https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html Torsten Lodderstedt, yes.com
  • 2. Objectives ● Allow OpenID Connect OPs explicit attestation of verification status of Claims (what, how, when, according to what rules, using what evidence) ● For use cases requiring strong identity assurance, such as Anti-money Laundering, eGovernment & eSigning ● Focus on natural person data, such as name or birth date
  • 3. Design objectives ● Use existing End-User Claims and build something around to convey attestation, define additional End-User Claims where needed ● Verified claims can be added to any JSON-based response or JWT - mixed with unverified claims and other extensions ● Privacy by design
  • 4. Representation ● Self contained and robust representation ● verified_claims Container ● verification element contains verification metadata (multiple evidence possible) ● claims element contains respective End-User Claims
  • 5. User Info & ID Token
  • 6. International Standard ● Trust frameworks, verification methods and evidence types ● So far review feedback & contributions from US, CA, UK, DE, EU & JP
  • 7. Additional End-User Claims ● place_of_birth ● nationalities ● birth_family_name, birth_given_name, birth_middle_name ● salutation ● title
  • 8. RPs request verified claims using “claims” parameter ● Fine grained control ● Data minimization
  • 9. Constraints ● Leverages OpenID Connect Core syntax
  • 10. Remark on URL length ● Request URLs can become quite long with “claims” parameter ● Recommendation: take a look into request_uri and Pushed Authorization Requests (https://tools.ietf.org/html/draft-lodderstedt-oauth-par)
  • 11. Status ● Public Review has started https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html ● Couple of implementations are under way Need your feedback!