SlideShare a Scribd company logo
1 of 21
Download to read offline
Add identity proofing to your accounts, after they’ve been established
Simplify  Protect  Secure
WHY “ADD” IDENTITY PROOFING?
Proofing value (IAL) must be added to Multi-Factor Authentication to achieve higher LOA
Higher LOA is required to provide Services to Users that involve higher RISK to the SP.
Higher Value Services require you to better proof your customer accounts! Stronger than KYC
NIST 800-63 Defines “Levels” for Identity over Time
• Enrollment Time
• Identity Assurance Level
• Credential Issuance Event
Proofing
• Over Time
• Credential Integrity
• Revocation & Validity
• Usage Tracking/ Evaluation
• Reputation Scoring
• Location Detection
Assurance • Transaction Time
• Authentication Assurance
Level
• User Verification
Authentication
800-63A 800-63B
IAL1 + AAL1 LOA2 Low
IAL2 + AAL2 LOA3 Substantial
IAL3 + AAL3 LOA4 High
Balancing Authentication & Proofing gets you LOA
4
©2016MorphoTrustUSA,LLC.Allrightsreserved.Noreproductionor
republishingwithoutwrittenpermission
IDENTITY PROOFING
What happens in-person… Identity Proofing Event
How can it translate to an online or mobile action?
Proofing
800-63A
Qualified Record
Valid Authentic
Documented
Real
Unique
Evidence
• Single Identity
• Valid Attributes
• Scanned Images
• Authenticatable
Resolved
Identity Proofing Event
⓴⓱@davidkelts
Identity
(Digital Subject)
Authenticate
Resolution
• Determine Evidence is for a
Single Legal Identity
Evidence Qualification
• Data Validation
• Document Authentication
Verification
• Multi-Factor
Authentication to Evidence
Proofing
800-63A
Resolved
Identity
Full Legal
Name
Date of
Birth
Place of
Birth
Sex
Minimum Attributes for
Legal Identity Resolution
⓴⓮@davidkelts
Legal
Identity
Citizenship
Address
Over18
Over21
US Legal
Presence
Mobile
Number
Additional Attributes
that activate Use Cases
for a Legal Identity ⓴⓯@davidkelts
Identity Resolution
What attributes resolve to a Single Legal Identity?
Attribute Valid
Provenance
Freshness
Accuracy
⓴⓱@davidkelts
https://pages.nist.gov/NISTIR-8112/
Data Validation
What measurements determine attribute validity?
Post Issuance Authentication
Authenticity of credentials at points of service
Secure Credential Design
Creates a feeling of authority that we all detect
UV & IR Exposed Features
Hardware and physical doc present
Visual Inspection
Document Authentication
Determine that the Identity Evidence is Official and Untampered
White Light Scan
• Document Authentication
• Data Extraction
Advanced Pattern Recognition
• Biometric Techniques Applied to Documents
• Machine Learning of Unique Patterns
• Detectable Security Features
New white-light
techniques enable
Doc Auth APIs
COMPARING IDENTITY PROOFING EVENTS
What are the requirements for the common identity proofs that Citizens go through?
What IAL would these proofs achieve?
Proofing
800-63A
Know Your Customer
• Not-Specified • Visual Data Validation to
Presented Document
• Unexpired Passport
• PAN Card
• Voter Identity Card
• Unexpired Driving License
• Others for Proof of Address
• Authentication Not-Specified
• Operator Visual
 Proof of Legal Name
 Commonly used Names
 Proof of Perm Address
o Collect Date of Birth
o Collect a Unique
Identifier from a Doc
Requirements Resolution Qualification Verification
⓴⓱@davidkelts
DMV Standard
•Processing to Ensure 1
Person = 1 Record
•Operator Option to Pause,
Stop, or Flag the Record
•Validate Data
•SSOLV (Name)
•PDPS & CDLIS
•EVVE (Birth)
•Scan Multiple Documents
•Anti-Forgery Efforts
•Fraud Doc Training
•Authentication Equipment
•Operator Visual
•Visual to Docs of Guardian
if < Age of Consent
•1 : Record Biometric
•1 : Many Biometric
•Background Checks
 Proof of Legal Name
 Commonly used Names
 Proof of Perm Address
 Proof of Date of Birth
 Proof of Signature
o Nationality & Legal
Presence in US/State
o Collect Front-Facing
Photo
Requirements Resolution Qualification Verification
In-Person
⓴⓱@davidkelts
Real ID
• Processing to Ensure
1 Person = 1 Record
• Participate Cross State
1 Person = 1 Record
• Operator Option to Pause,
Stop, or Flag the Record
• Validate Data
• SSOLV (Name & SSN)
• PDPS & CDLIS
• EVVE (Birth)
• SAVE (Legal Presence)
• Retain Scan Docs 5 – 7 Years
• Anti-Forgery Efforts
• Fraud Doc Training
• Authentication Equipment
• Operator Visual
• Visual of Guardian if < Age of
Consent
• 1 : Record Biometric
• 1 : Many Biometric
• Background Checks
 Proof of Legal Name
 Commonly used Names
 Proof of Perm Address
 Proof of Date of Birth
 Proof of Signature
 Proof of Nationality &
Legal Presence in US
 Proof of Social Security #
o Collect Front-Facing
Photo at Start of Proofing
o Collect Scan of Docs
o Unique Identifying Num
Requirements Resolution Qualification Verification
In-Person
⓴⓱@davidkelts
Comparing Proofing Processes
What you need to know
• KYC is a little more than an
Identity Verification
• Every DMV Proofing meets IAL3
• Real ID exceeds that
– States have all implemented
– Road blocked 4 States? Legislative
• These open opportunities for
you to attach to strong identity
IDENTITY ASSURANCE
ACCURACY OF THE IDENTITY ATTRIBUTES
Underlying concepts needed to understand how to validate identity data
Assurance
Measure of Freshness, Based on Decay Rate
Proofing Event
Decay Rate
Authentications
Refresh Cycle
Stale
Decay Rates vary by attribute
• Date Of Birth
• Place of Birth
• Sex
• Citizenship
• Full Name
• Legal Presence
• Over 21, Over 18
• Mobile Number
• Address
• Driver StatusTime
Accuracy
DecayRateTolerance
NeverAnnually
Measure of Provenance
Distance from original legal identity record (birth + authorized changes)
Primary Records
Birth Registry
Social Security
Marriage Registry
Nationality DBs
Death Master File
Proofing Authority
Document Issuer
DL Valid/Exists
Passport Valid/Exists
Aggregated Proofs
Published Records
Public Records
Algorithmic Correlations
Correlated
• Public Records
• Public Posts
• Public Data
More Authoritative
⓴⓯ @davidkelts
More Subject to Error incl. from Decay Rate
Can you validate against
Authenticated Token?
Validate
ADDING IDENTITY PROOFING
Qualified Evidence can be added if the user is Authenticated to the Identity Record at high AAL.
Reputation scoring, while valuable, is not identity proofing
Usage tracking and patterns, while valuable, are not identity proofing
Assurance
Your Accounts – the goal is to…
Strengthen Proofing Concepts Validate Assurance Concepts
Resolution
•Determine single legal identity
Evidence Qualification
•Data Validation
•Document Authentication
Verification
•Multi-Factor Authentication to
the Identity Evidence
Attribute
Valid
Provenance
Freshness
Accuracy
Identity Assurance Level (IAL) 2 IAL 3
Add Identity Assurance to Your Accounts
Scan
Authentic
Identity
Documents
Validate
Identity Data
you Hold
Verify
Identity of
Account
Holder
Bind to
another
High IAL
Account
Proof the
Individual
Even after registration, Qualified Evidence can bring your accounts upward to NIST 800-63A Identity Assurance Levels
APIs for User and ID Verification
API Connections to Authoritative
Sources for Data Validation
Key Additional Steps
• Authenticate your User at your Highest Possible AAL before
– Scan, upload, or snap a document
– Webcam or selfie their face
– Capture a biometric (see hole in TouchID)
– Scan data from one of their documents
• Presentation Attack Detection
• Risk: Evaluation of Signals
• Privacy: Beware of Outsourcing (GDPR)

More Related Content

Similar to Proofing ex post facto from Cloud Identity Summit 2017

Trust elevation-abbie-v1
Trust elevation-abbie-v1Trust elevation-abbie-v1
Trust elevation-abbie-v1Abbie Barbir
 
Authentication(pswrd,token,certificate,biometric)
Authentication(pswrd,token,certificate,biometric)Authentication(pswrd,token,certificate,biometric)
Authentication(pswrd,token,certificate,biometric)Ali Raw
 
The Importance of SSL Encryption
The Importance of SSL EncryptionThe Importance of SSL Encryption
The Importance of SSL EncryptionStephanieOrtega20
 
Identity Verification
Identity VerificationIdentity Verification
Identity VerificationIDology, Inc
 
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays
 
Pki Digital Id Itmc University Wisconsin
Pki Digital Id Itmc University WisconsinPki Digital Id Itmc University Wisconsin
Pki Digital Id Itmc University WisconsinNicholas Davis
 
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...Liam Cleary [MVP]
 
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19Andrew Hughes
 
Authentication Technologies
Authentication TechnologiesAuthentication Technologies
Authentication TechnologiesNicholas Davis
 
Authentication technologies
Authentication technologiesAuthentication technologies
Authentication technologiesNicholas Davis
 
Date security identifcation and authentication
Date security   identifcation and authenticationDate security   identifcation and authentication
Date security identifcation and authenticationLeo Mark Villar
 
Pki & personal digital certificates, securing sensitive electronic communicat...
Pki & personal digital certificates, securing sensitive electronic communicat...Pki & personal digital certificates, securing sensitive electronic communicat...
Pki & personal digital certificates, securing sensitive electronic communicat...Nicholas Davis
 
Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...
Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...
Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...Nicholas Davis
 
Authenticationtechnologies 120711134100-phpapp01
Authenticationtechnologies 120711134100-phpapp01Authenticationtechnologies 120711134100-phpapp01
Authenticationtechnologies 120711134100-phpapp01Hai Nguyen
 
Single SignOn with Federation using Claims
Single SignOn with Federation using ClaimsSingle SignOn with Federation using Claims
Single SignOn with Federation using ClaimsVolkan Uzun
 
Portabl - The state of open banking, regulations, and the intersection of SSI...
Portabl - The state of open banking, regulations, and the intersection of SSI...Portabl - The state of open banking, regulations, and the intersection of SSI...
Portabl - The state of open banking, regulations, and the intersection of SSI...SSIMeetup
 
api-security-Jan23.pptxsdfffffffffffffffffffffffffffff
api-security-Jan23.pptxsdfffffffffffffffffffffffffffffapi-security-Jan23.pptxsdfffffffffffffffffffffffffffff
api-security-Jan23.pptxsdfffffffffffffffffffffffffffffDucAnhLe56
 
Reduce Friction and Risk with Device Authentication
Reduce Friction and Risk with Device AuthenticationReduce Friction and Risk with Device Authentication
Reduce Friction and Risk with Device AuthenticationTransUnion
 
Public Key Infrastructures
Public Key InfrastructuresPublic Key Infrastructures
Public Key InfrastructuresZefren Edior
 

Similar to Proofing ex post facto from Cloud Identity Summit 2017 (20)

Trust elevation-abbie-v1
Trust elevation-abbie-v1Trust elevation-abbie-v1
Trust elevation-abbie-v1
 
Authentication(pswrd,token,certificate,biometric)
Authentication(pswrd,token,certificate,biometric)Authentication(pswrd,token,certificate,biometric)
Authentication(pswrd,token,certificate,biometric)
 
The Importance of SSL Encryption
The Importance of SSL EncryptionThe Importance of SSL Encryption
The Importance of SSL Encryption
 
Identity Verification
Identity VerificationIdentity Verification
Identity Verification
 
E collaborationscottrea
E collaborationscottreaE collaborationscottrea
E collaborationscottrea
 
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
 
Pki Digital Id Itmc University Wisconsin
Pki Digital Id Itmc University WisconsinPki Digital Id Itmc University Wisconsin
Pki Digital Id Itmc University Wisconsin
 
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
 
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
 
Authentication Technologies
Authentication TechnologiesAuthentication Technologies
Authentication Technologies
 
Authentication technologies
Authentication technologiesAuthentication technologies
Authentication technologies
 
Date security identifcation and authentication
Date security   identifcation and authenticationDate security   identifcation and authentication
Date security identifcation and authentication
 
Pki & personal digital certificates, securing sensitive electronic communicat...
Pki & personal digital certificates, securing sensitive electronic communicat...Pki & personal digital certificates, securing sensitive electronic communicat...
Pki & personal digital certificates, securing sensitive electronic communicat...
 
Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...
Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...
Pki &amp; Personal Digital Certificates, Securing Sensitive Electronic Commun...
 
Authenticationtechnologies 120711134100-phpapp01
Authenticationtechnologies 120711134100-phpapp01Authenticationtechnologies 120711134100-phpapp01
Authenticationtechnologies 120711134100-phpapp01
 
Single SignOn with Federation using Claims
Single SignOn with Federation using ClaimsSingle SignOn with Federation using Claims
Single SignOn with Federation using Claims
 
Portabl - The state of open banking, regulations, and the intersection of SSI...
Portabl - The state of open banking, regulations, and the intersection of SSI...Portabl - The state of open banking, regulations, and the intersection of SSI...
Portabl - The state of open banking, regulations, and the intersection of SSI...
 
api-security-Jan23.pptxsdfffffffffffffffffffffffffffff
api-security-Jan23.pptxsdfffffffffffffffffffffffffffffapi-security-Jan23.pptxsdfffffffffffffffffffffffffffff
api-security-Jan23.pptxsdfffffffffffffffffffffffffffff
 
Reduce Friction and Risk with Device Authentication
Reduce Friction and Risk with Device AuthenticationReduce Friction and Risk with Device Authentication
Reduce Friction and Risk with Device Authentication
 
Public Key Infrastructures
Public Key InfrastructuresPublic Key Infrastructures
Public Key Infrastructures
 

Recently uploaded

Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Sonam Pathan
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Dana Luther
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书zdzoqco
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Paul Calvano
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts servicevipmodelshub1
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一z xss
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMartaLoveguard
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Excelmac1
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationLinaWolf1
 
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Lucknow
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一Fs
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一Fs
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Complet Documnetation for Smart Assistant Application for Disabled Person
Complet Documnetation   for Smart Assistant Application for Disabled PersonComplet Documnetation   for Smart Assistant Application for Disabled Person
Complet Documnetation for Smart Assistant Application for Disabled Personfurqan222004
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhimiss dipika
 
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)Christopher H Felton
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012rehmti665
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Sonam Pathan
 
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一3sw2qly1
 

Recently uploaded (20)

Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptx
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 Documentation
 
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
 
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Complet Documnetation for Smart Assistant Application for Disabled Person
Complet Documnetation   for Smart Assistant Application for Disabled PersonComplet Documnetation   for Smart Assistant Application for Disabled Person
Complet Documnetation for Smart Assistant Application for Disabled Person
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhi
 
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
 
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
 

Proofing ex post facto from Cloud Identity Summit 2017

  • 1. Add identity proofing to your accounts, after they’ve been established Simplify  Protect  Secure
  • 2. WHY “ADD” IDENTITY PROOFING? Proofing value (IAL) must be added to Multi-Factor Authentication to achieve higher LOA Higher LOA is required to provide Services to Users that involve higher RISK to the SP. Higher Value Services require you to better proof your customer accounts! Stronger than KYC
  • 3. NIST 800-63 Defines “Levels” for Identity over Time • Enrollment Time • Identity Assurance Level • Credential Issuance Event Proofing • Over Time • Credential Integrity • Revocation & Validity • Usage Tracking/ Evaluation • Reputation Scoring • Location Detection Assurance • Transaction Time • Authentication Assurance Level • User Verification Authentication 800-63A 800-63B IAL1 + AAL1 LOA2 Low IAL2 + AAL2 LOA3 Substantial IAL3 + AAL3 LOA4 High
  • 4. Balancing Authentication & Proofing gets you LOA 4 ©2016MorphoTrustUSA,LLC.Allrightsreserved.Noreproductionor republishingwithoutwrittenpermission
  • 5. IDENTITY PROOFING What happens in-person… Identity Proofing Event How can it translate to an online or mobile action? Proofing 800-63A
  • 6. Qualified Record Valid Authentic Documented Real Unique Evidence • Single Identity • Valid Attributes • Scanned Images • Authenticatable Resolved Identity Proofing Event ⓴⓱@davidkelts Identity (Digital Subject) Authenticate Resolution • Determine Evidence is for a Single Legal Identity Evidence Qualification • Data Validation • Document Authentication Verification • Multi-Factor Authentication to Evidence Proofing 800-63A
  • 7. Resolved Identity Full Legal Name Date of Birth Place of Birth Sex Minimum Attributes for Legal Identity Resolution ⓴⓮@davidkelts Legal Identity Citizenship Address Over18 Over21 US Legal Presence Mobile Number Additional Attributes that activate Use Cases for a Legal Identity ⓴⓯@davidkelts Identity Resolution What attributes resolve to a Single Legal Identity?
  • 9. Post Issuance Authentication Authenticity of credentials at points of service Secure Credential Design Creates a feeling of authority that we all detect UV & IR Exposed Features Hardware and physical doc present Visual Inspection Document Authentication Determine that the Identity Evidence is Official and Untampered White Light Scan • Document Authentication • Data Extraction Advanced Pattern Recognition • Biometric Techniques Applied to Documents • Machine Learning of Unique Patterns • Detectable Security Features New white-light techniques enable Doc Auth APIs
  • 10. COMPARING IDENTITY PROOFING EVENTS What are the requirements for the common identity proofs that Citizens go through? What IAL would these proofs achieve? Proofing 800-63A
  • 11. Know Your Customer • Not-Specified • Visual Data Validation to Presented Document • Unexpired Passport • PAN Card • Voter Identity Card • Unexpired Driving License • Others for Proof of Address • Authentication Not-Specified • Operator Visual  Proof of Legal Name  Commonly used Names  Proof of Perm Address o Collect Date of Birth o Collect a Unique Identifier from a Doc Requirements Resolution Qualification Verification ⓴⓱@davidkelts
  • 12. DMV Standard •Processing to Ensure 1 Person = 1 Record •Operator Option to Pause, Stop, or Flag the Record •Validate Data •SSOLV (Name) •PDPS & CDLIS •EVVE (Birth) •Scan Multiple Documents •Anti-Forgery Efforts •Fraud Doc Training •Authentication Equipment •Operator Visual •Visual to Docs of Guardian if < Age of Consent •1 : Record Biometric •1 : Many Biometric •Background Checks  Proof of Legal Name  Commonly used Names  Proof of Perm Address  Proof of Date of Birth  Proof of Signature o Nationality & Legal Presence in US/State o Collect Front-Facing Photo Requirements Resolution Qualification Verification In-Person ⓴⓱@davidkelts
  • 13. Real ID • Processing to Ensure 1 Person = 1 Record • Participate Cross State 1 Person = 1 Record • Operator Option to Pause, Stop, or Flag the Record • Validate Data • SSOLV (Name & SSN) • PDPS & CDLIS • EVVE (Birth) • SAVE (Legal Presence) • Retain Scan Docs 5 – 7 Years • Anti-Forgery Efforts • Fraud Doc Training • Authentication Equipment • Operator Visual • Visual of Guardian if < Age of Consent • 1 : Record Biometric • 1 : Many Biometric • Background Checks  Proof of Legal Name  Commonly used Names  Proof of Perm Address  Proof of Date of Birth  Proof of Signature  Proof of Nationality & Legal Presence in US  Proof of Social Security # o Collect Front-Facing Photo at Start of Proofing o Collect Scan of Docs o Unique Identifying Num Requirements Resolution Qualification Verification In-Person ⓴⓱@davidkelts
  • 14. Comparing Proofing Processes What you need to know • KYC is a little more than an Identity Verification • Every DMV Proofing meets IAL3 • Real ID exceeds that – States have all implemented – Road blocked 4 States? Legislative • These open opportunities for you to attach to strong identity
  • 15. IDENTITY ASSURANCE ACCURACY OF THE IDENTITY ATTRIBUTES Underlying concepts needed to understand how to validate identity data Assurance
  • 16. Measure of Freshness, Based on Decay Rate Proofing Event Decay Rate Authentications Refresh Cycle Stale Decay Rates vary by attribute • Date Of Birth • Place of Birth • Sex • Citizenship • Full Name • Legal Presence • Over 21, Over 18 • Mobile Number • Address • Driver StatusTime Accuracy DecayRateTolerance NeverAnnually
  • 17. Measure of Provenance Distance from original legal identity record (birth + authorized changes) Primary Records Birth Registry Social Security Marriage Registry Nationality DBs Death Master File Proofing Authority Document Issuer DL Valid/Exists Passport Valid/Exists Aggregated Proofs Published Records Public Records Algorithmic Correlations Correlated • Public Records • Public Posts • Public Data More Authoritative ⓴⓯ @davidkelts More Subject to Error incl. from Decay Rate Can you validate against Authenticated Token? Validate
  • 18. ADDING IDENTITY PROOFING Qualified Evidence can be added if the user is Authenticated to the Identity Record at high AAL. Reputation scoring, while valuable, is not identity proofing Usage tracking and patterns, while valuable, are not identity proofing Assurance
  • 19. Your Accounts – the goal is to… Strengthen Proofing Concepts Validate Assurance Concepts Resolution •Determine single legal identity Evidence Qualification •Data Validation •Document Authentication Verification •Multi-Factor Authentication to the Identity Evidence Attribute Valid Provenance Freshness Accuracy
  • 20. Identity Assurance Level (IAL) 2 IAL 3 Add Identity Assurance to Your Accounts Scan Authentic Identity Documents Validate Identity Data you Hold Verify Identity of Account Holder Bind to another High IAL Account Proof the Individual Even after registration, Qualified Evidence can bring your accounts upward to NIST 800-63A Identity Assurance Levels APIs for User and ID Verification API Connections to Authoritative Sources for Data Validation
  • 21. Key Additional Steps • Authenticate your User at your Highest Possible AAL before – Scan, upload, or snap a document – Webcam or selfie their face – Capture a biometric (see hole in TouchID) – Scan data from one of their documents • Presentation Attack Detection • Risk: Evaluation of Signals • Privacy: Beware of Outsourcing (GDPR)