
The NIST SP 800-63 guidelines are indispensable to modern identity management, emphasizing extensive ID proofing, strong phishing-resistant authentication and secure federated identities. Over time these guidelines have evolved to support cryptographic authenticators such as FIDO security keys or passwordless authentication methods.
TrustSwiftly makes it simple and cost-effective for businesses to obtain IAL2 and IAL3 verification, using chat, video, facial recognition with liveness detection and document authentication.
NIST 800-63A IAL3 Verification
NIST 800-63A IAL3 provides a sophisticated and nuanced definition of digital identity that goes beyond simply using username and password combinations to represent yourself online. The Digital Identity Guidelines from NIST utilize a tiered approach known as Identity Assurance Levels (IALs), which indicate how certain a claimed identity matches up with its real-life counterpart – this scale ranges from self-asserted (IAL1) to in-person verification (IAL3).
SP 800-63B Authentication and Lifecycle Management puts considerable weight on “verifier impersonation resistance,” acknowledging the pervasive threat posed by phishing attacks that use impostor identities to defraud users. Furthermore, this document deprecates email OTP and severely downgrades SMS-based authentication methods due to their ineffectiveness against modern phishing attempts.
SP 800-63C Federation and Assertions provides requirements for using federated identities and asserting results of authentication at various Federation Assurance Levels (FALs), from FAL1 through FAL3. It enforces stringent standards at FAL3 to protect both individuals and relying parties from impersonation, fraud or any other potentially detrimental harm that might result.
Easy to Implement
The fourth version of NIST 800-63A IAL3 maintains its three-part framework of Identity Proofing, Authentication and Federated Assuranace Level, while updating requirements to keep pace with modern security needs. For instance, at its highest level of assurance (IAL3) now demands phishing-resistant methods like FIDO Passkeys as part of identity proofing services like remote IAL3 identity proofing services.
Trust Swiftly’s turnkey kiosks can help your IAL3 processes meet these stringent requirements by acting as proofing agents during proofing processes. In person or remotely supervised authentication can be conducted, depending on individual needs. This helps limit highly scalable attacks using social engineering techniques to falsify evidence or steal credentials or refute an identity.
We offer preconfigured kiosks tailored specifically for this level of assurance which also offer document verification, dynamic knowledge-based authentication and biometric authentication solutions – ideal solutions that help safeguard against highly scalable attacks using social engineering techniques aimed at falsifying evidence, falsifying evidence, falsifying credentials or changing identity!
Trust Swiftly provides turnkey kiosks preconfigured specifically to IAL3 standards so IAL processes can run efficiently while offering document verification, dynamic knowledge based authentication or biometric authentication solutions from our turnkey kiosks – making our kiosks ideal platforms which offer reliable proofing solutions as well as being preconfigured to IAL3 requirements while acting as platforms for proofing solutions such as document verification or dynamic knowledge based authentication solutions from Trust Swiftly’s biometric authentication platform!
Easy to Scale
For years, the only way to meet FedRAMP High compliance with an identity assurance level of IAL3 required by FedRAMP High compliance was via supervised in-person sessions. Unfortunately, these expensive and time-consuming procedures drain employee time, create logistical nightmares between distributed teams, and ultimately diminish productivity. Furthermore, failing your third-party assessment organization (3PAO) puts your FedRAMP High certification project at risk and could possibly halt your effort altogether.
NIST 800-63-4 has modernized identity assurance levels (IAL, AAL and FAL) to make them more adaptable and officially support remote ID proofing. Furthermore, new guidelines promote phishing-resistant authentication methods like FIDO Passkeys and user wallets while mandating cryptographic binding in federated transactions and officially including FALs into one unified assurance model.
TrustSwiftly is the only hardware-based remote IAL3 solution that meets these stringent requirements. Our software-based solutions leverage chat, video, facial recognition with liveness detection and document authentication while offering step-up reproofing based on risk ensuring continuous identity assurance beyond one point in time.
Easy to Manage
The IAL3 level offers the greatest assurance in matching digital identity claims to real world NIST IAL3 verification, accomplished through an on-site, attended identity proofing session attended by a trained CSP representative as well as additional steps for verifying and collecting biometric information. Furthermore, this level adds requirements such as antiphishing-resistant multifactor authentication (MFA), support of Passkeys, hardware-backed authenticators and an effective federation engine for an even higher level of assurance in matching claimed digital identities to real world identifications.
An innovative IAL3 compliant solution offers a fully supervised remote identity proofing process, which integrates automated and human elements, for cost-effective protection while still meeting security expectations. Document authentication utilizes advanced techniques such as multispectral UV light analysis, facial recognition with liveness detection and fingerprint scanning – not to mention voice and dynamic knowledge-based authentication systems.
Trust Swiftly’s supervised process also facilitates the use of locked-down devices that can only be accessed by trained CSP representatives. Trust Swiftly has proven itself robust through an open bounty challenge where security researchers and ethical hackers were invited to attempt bypassing its defenses.