Assurance profile   othershow all attributes
Name eduPersonAssurance
Description Set of URIs that assert compliance with specific standards for identity assurance
Vocabulary not applicable, no controlled vocabulary
References eduPerson
OIDC n/a
OID 1.3.6.1.4.1.5923.1.1.1.11
LDAP Syntax Directory String
# of values multi
Example values
  • urn:mace:incommon:IAQ:sample
  • http://idm.example.org/LOA#sample

Definition

Set of URIs that assert compliance with specific standards for identity assurance.

Notes

  • This multivalued attribute represents identity assurance profiles (IAPs), which are the set of standards that are met by an identity assertion, based on the Identity Provider's identity management processes, the type of authentication credential used, the strength of its binding, etc. An example of such a standard is the InCommon Federation's proposed IAPs.

  • Those establishing values for this attribute should provide documentation explaining the semantics of the values.

  • As a multivalued attribute, relying parties may receive multiple values and should ignore unrecognized values.

  • The driving force behind the definition of this attribute is to enable applications to understand the various strengths of different identity management systems and authentication events and the processes and procedures governing their operation and to be able to assess whether or not a given transaction meets the requirements for access.

Example applications

  • Determining strength of asserted identity for on-line transactions, especially those involving more than minimal institutional risk resulting from errors in authentication.

  • A system supporting access to grants management in order to provide assurance for financial transactions.


All attribute definitions in a single document: Switch edu-ID Attribute Specification