On NIST SP800-63-4 and the Binding Level of Assurance and account hijack possibilities
nat.sakimura.org·3h
🔐HSM Integration
Preview
Report Post

Abstract

This paper analyzes the “Binding” provisions within the new digital identity standard, NIST SP800-63-4 (released July 31, 2025). While the standard does not explicitly define a “Binding Level of Assurance,” the document concentrates on the implicit levels found in SP800-63A-4 and a critical security flaw in the process for adding subsequent authenticators, as detailed in SP800-63B-4.

The core issue is that the current provision allows a new, higher-level authenticator (e.g., AAL2 or AAL3) to be bound to a subscriber’s account within a low-assurance session (e.g., AAL1). This creates a vulnerability where an attacker, having compromised a lower-level authenticator, could bind their own high-level authenticator to the victim’s account, potentially leading to an ac…

Similar Posts

Loading similar posts...