Publications

2024Short papersEnglish

Bridging the Gap: Managing Dual Assurance Levels in OpenID Connect

Extended annals of the XXIV Brazilian Symposium on Information and Computational Systems Security · São José dos Campos, Brazil

Abstract

This paper introduces and addresses challenges in managing electronic identity's Level of Assurance (LoA), which has two types: LoA of authentication and LoA of identity. We explore different technical specifications, protocols, and concrete identity providers' strategies for managing these two levels of assurance, highlighting the implications of protocols supporting only a single LoA instead of two. An extension to the OpenID Connect protocol is proposed to support both LoA types, instituting a new claim, the Identity Context Class Reference (ICR). This approach ensures compatibility and versatility with existing technical specifications.

Materials

Reference