← Back to KHAO

NIST ·

The publication, whose full title is Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587)

2 min read

Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.

★ Tier-1 Source

While the document is primarily written for federal agencies and the cloud service providers (CSPs) they work with, it can help any organization that handles identity tokens and related forms of identity assertions, said NIST Digital Identity Program Lead Ryan Galluzzo.

Key facts

Summary

When you sign in to an online service like webmail, behind the scenes is often a token, a snippet of information identifying you and what online resources you are permitted to use, such as your inbox, contacts or other potentially sensitive information. The publication, whose full title is Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), provides implementation guidelines to help maintain the security of tokens, which are widely used in digital systems. “This publication provides implementation considerations for protecting tokens appropriately,” said Galluzzo, one of the publication’s authors.

Read full article at NIST AI →

#NIST