Study. uk . com
  1. Home
  2. All questions
  3. Question 49

CISSP study material · question 49 of 500

Two research institutes agree to federate under the SP 800-63C-4 federation guidance. They share no common public key infrastructure and neither will join the other's, yet their architects want federation assurance level 3 (FAL3) for a jointly funded data programme. Which binding approach suits this deployment?

  1. A bearer assertion restricted to one relying party as its audience and protected against replay
  2. An assertion reference redeemed once over the back channel by the authenticated relying party
  3. A holder-of-key assertion naming a subscriber certificate the relying party validates through the issuing certificate authority
  4. A phishing-resistant bound authenticator registered in the relying party's own subscriber account for that user
Show the answer

Answer: D. A phishing-resistant bound authenticator registered in the relying party's own subscriber account for that user

Bound authenticators live in the relying party's subscriber account, which is exactly the case with no shared PKI; holder-of-key assertions assume a certificate infrastructure both sides already trust.

Source: NIST SP 800-63C Rev. 4 (NIST) — SP 800-63C-4 > 3.15 Holder-of-Key Assertions and 3.16 Bound Authenticators

Challenge yourself on this topic → Study as cards