NIST · NIST AI
The publication, whose full title is Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587)
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
While the document is primarily written for federal agencies and the cloud service providers (CSPs) they work with, it can help any organization that handles identity tokens and related forms of identity assertions, said NIST Digital Identity Program Lead Ryan Galluzzo.
Key facts
- The publication, whose full title is Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), provides implementation guidelines to help maintain the security of tokens
- Galluzzo highlighted the critical support NIST and CISA received from industry partners such as the Joint Cyber Defense Collaborative, which provided critical feedback
- While the document is primarily written for federal agencies and the cloud service providers (CSPs) they work with, it can help any organization that handles identity tokens and related forms
- This publication provides implementation considerations for protecting tokens appropriately,” said Galluzzo, one of the publication’s authors
Summary
When you sign in to an online service like webmail, behind the scenes is often a token, a snippet of information identifying you and what online resources you are permitted to use, such as your inbox, contacts or other potentially sensitive information. The publication, whose full title is Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), provides implementation guidelines to help maintain the security of tokens, which are widely used in digital systems. “This publication provides implementation considerations for protecting tokens appropriately,” said Galluzzo, one of the publication’s authors.