Abstract

This paper analyzes the “Binding” provisions within the new digital identity standard, NIST SP800-63-4 (released July 31, 2025). While the standard does not explicitly define a “Binding Level of Assurance,” the document concentrates on the implicit levels found in SP800-63A-4 and a critical security flaw in the process for adding subsequent authenticators, as detailed in SP800-63B-4.

The core issue is that the current provision allows a new, higher-level authenticator (e.g., AAL2 or AAL3) to be bound to a subscriber’s account within a low-assurance session (e.g., AAL1). This creates a vulnerability where an attacker, having compromised a lower-level authenticator, could bind their own high-level authenticator to the victim’s account, potentially leading to an ac…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help