惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
Y
Y Combinator Blog
博客园 - Franky
D
Docker
B
Blog RSS Feed
M
MIT News - Artificial intelligence
雷峰网
雷峰网
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
宝玉的分享
宝玉的分享
S
SegmentFault 最新的问题
GbyAI
GbyAI
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MyScale Blog
MyScale Blog
B
Blog
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
Vercel News
Vercel News
The Cloudflare Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News

OpenID Foundation

OpenID Foundation launches refreshed conformance suite interface Post-Quantum OpenID Connect Implementer’s Draft of OpenID Connect Key Binding Approved - OpenID Foundation Implementer’s Drafts of Two OpenID Federation Extensions Approved - OpenID Foundation Verifying Guardianship Online - OpenID Foundation Notice of Vote for Proposed OpenID Connect Ephemeral Subject Identifier 1.0 Final Specification - OpenID Foundation OpenID Foundation seeks Technical Director OIDF’s key recommendations to Australia’s Digital ID Act review OIDF responds to ARNECC’s consultation on the Model Participation Rules OIDF responds to Australia’s digital trust consultation OpenID Well-Known Conference 2027 – Call for Proposals - OpenID Foundation Notice of Vote for Proposed Implementer’s Draft of OpenID Connect Key Binding - OpenID Foundation Notice of Vote to Approve Proposed Implementer’s Drafts of Two OpenID Federation Extensions - OpenID Foundation OpenID4VP and OpenID4VCI conformance tests are complete and open for self-certification - OpenID Foundation OpenID launches conformance tests for widely adopted standards Getting Cozy with COAZ: Securing APIs and AI Agents with Standardized Authorization Public Review Period for Proposed OpenID CAEP Interoperability Profile Final Specification - OpenID Foundation Public Review Period for Proposed OpenID Connect Ephemeral Subject Identifier 1.0 Final Specification - OpenID Foundation How we got here: what six decades of identity history tell us about the agent age Call for Participation: Demonstrate MCP-based AI agent security with open identity standards AuthZEN at Identiverse 2026: authorization in the agent era Public Review Period for Proposed Implementer’s Draft of OpenID Connect Key Binding - OpenID Foundation As AltID launches, Danish media seek OIDF view Errata to OpenID Identity Assurance Specifications Approved - OpenID Foundation Public Review Period for Proposed Implementer’s Drafts of Two OpenID Federation Extensions - OpenID Foundation OIDF proud to support BIS Innovation Hub’s Aperta Report Announcing the new Digital Credentials Harmonized Presentation Working Group OpenID Foundation advances authorization for the agent era with new AuthZEN Working Group Drafts Australian Digital Trust Community Group’s 2nd Innovation Day – 24th June 2026 - OpenID Foundation OIDF conformance tests deliver results in La Ciotat
OIDF welcomes CISA and NIST’s new guidance on token security
Serj Hallam · 2026-09-16 · via OpenID Foundation

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released Interagency Report 8587: Protecting Tokens and Assertions from Forgery, Theft, and Misuse, as announced by CISA and NIST respectively. 

The report sets out how federal agencies and cloud service providers should defend identity infrastructure against increasingly sophisticated attacks targeting tokens and assertions. The OpenID Foundation was pleased to be able to participate directly in developing the concrete security guidance provided in the report.

Atul Tulshibagwale, co-chair of the OpenID Foundation’s Shared Signals Working Group, said: “The problems described in the opening pages of the report are urgent and must be addressed if we want to ensure that security online is maintained. In this new era of AI supercharged attacks, providers that do not address them risk their infrastructure by exposing it to these kinds of breaches.”

Implementing IR 8587 with OpenID Foundation specifications

The report specifically recommends two OpenID Foundation specifications: the Shared Signals Framework (SSF) and the Continuous Access Evaluation Profile (CAEP) - paragraph 2 on page 31. SSF defines how identity providers and relying parties exchange security event signals in a standard way.  CAEP builds on this so providers can communicate changes in a user's session or risk posture, letting access be re-evaluated continuously rather than only at sign-in.

These are proven approaches to the token protection challenges IR 8587 outlines. Organisations implementing the report's recommendations will find these specifications provide a concrete path forward.

Organisations interested in exploring SSF and CAEP can do so using the free resources available on the Shared Signals Working Group homepage. The OpenID Foundation’s open-source test suite is also available to validate implementations at no cost.

Timeline for implementers

This autumn, the OpenID Foundation will launch the suite for self-certification aligned with this specification, giving implementers a clear compliance pathway. More details to come on this.

Gail Hodges, Executive Director of the OpenID Foundation, said: "This report gives implementers concrete guidance, and we encourage them to read it and act on it. The specifications it recommends are open, while our test suite is open-source and free to build against, with self-certification to follow.

"We would encourage implementers in both government and the private sector to go further, and build not just the specifications, but the conformance tools into their own requirements and procurement processes. That is how the full benefit of the specifications is realised."

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation's OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile - built on OAuth 2.0 - has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation's standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling "networks of networks" to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.