
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released Interagency Report 8587: Protecting Tokens and Assertions from Forgery, Theft, and Misuse, as announced by CISA and NIST respectively.
The report sets out how federal agencies and cloud service providers should defend identity infrastructure against increasingly sophisticated attacks targeting tokens and assertions. The OpenID Foundation was pleased to be able to participate directly in developing the concrete security guidance provided in the report.
Atul Tulshibagwale, co-chair of the OpenID Foundation’s Shared Signals Working Group, said: “The problems described in the opening pages of the report are urgent and must be addressed if we want to ensure that security online is maintained. In this new era of AI supercharged attacks, providers that do not address them risk their infrastructure by exposing it to these kinds of breaches.”
Implementing IR 8587 with OpenID Foundation specifications
The report specifically recommends two OpenID Foundation specifications: the Shared Signals Framework (SSF) and the Continuous Access Evaluation Profile (CAEP) - paragraph 2 on page 31. SSF defines how identity providers and relying parties exchange security event signals in a standard way. CAEP builds on this so providers can communicate changes in a user's session or risk posture, letting access be re-evaluated continuously rather than only at sign-in.
These are proven approaches to the token protection challenges IR 8587 outlines. Organisations implementing the report's recommendations will find these specifications provide a concrete path forward.
Organisations interested in exploring SSF and CAEP can do so using the free resources available on the Shared Signals Working Group homepage. The OpenID Foundation’s open-source test suite is also available to validate implementations at no cost.
Timeline for implementers
This autumn, the OpenID Foundation will launch the suite for self-certification aligned with this specification, giving implementers a clear compliance pathway. More details to come on this.
Gail Hodges, Executive Director of the OpenID Foundation, said: "This report gives implementers concrete guidance, and we encourage them to read it and act on it. The specifications it recommends are open, while our test suite is open-source and free to build against, with self-certification to follow.
"We would encourage implementers in both government and the private sector to go further, and build not just the specifications, but the conformance tools into their own requirements and procurement processes. That is how the full benefit of the specifications is realised."
About the OpenID Foundation
The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation's OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile - built on OAuth 2.0 - has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation's standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling "networks of networks" to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.
