FB pixel

OpenID approves 3 standards for sharing real-time digital identity security signals

OpenID approves 3 standards for sharing real-time digital identity security signals
 

Three standards for real-time digital identity security event sharing are now Final Specifications, after their approval by the OpenID Foundation.

OpenID’s Shared Signals Framework 1.0, Continuous Access Evaluation Profile (CAEP) 1.0 and Risk Information Sharing and Coordination (RISC) 1.0 have been fixed against further revision and given intellectual property protections with the designation.

The Shared Signals Framework enables connected systems to deliver real-time information on security events. CAEP “defines how systems communicate session changes to maintain continuous security. RISC sets the standards for services to share account security changes.

Together, the organization says they address a critical security gap left during open sessions and between logins. A lack of security updates in federated identity systems previously forced organizations to choose between increasing friction with reauthentication requests or accepting the security vulnerabilities of outdated login information. Now, enterprise device management systems can notify connected services when a user’s device is no longer compliant, or has been compromised. Cybersecurity platforms can share threat detection intelligence as they collect it, and data on anomalous user information can be shared between partners.

“This coordinated approach makes Zero Trust security architectures practically achievable at global scale, where security decisions are continuously evaluated based on current, real-time information rather than outdated login credentials,” says Sgnl CTO Atul Tulshibagwale, who is co-chair of the OpenID Foundation’s Shared Signals Working Group.

“For financial services institutions, healthcare organizations, government agencies, and other security critical sectors, these specifications provide the standardized foundation needed to implement comprehensive Zero Trust security architectures and continuous access evaluation policies across their entire digital infrastructure.”

Sgnl was one of nine participants at the Gartner Identity and Access Management (IAM) Summit in London earlier this year to showcase implementations of the Shared Signals Framework and CAEP. The others included Google, IBM, Okta, Omnissa, Relock, SailPoint, Thales and Beyond Identity.

OpenID Foundation ED Gail Hodges calls the finalization of the three specs “a material milestone in the adoption of the specification. This status unlocks the ability of many governments to adopt the specifications, and encourages many CTOs and CISOs that the specifications are completely stable and ready for adoption.”

An interoperability test of the OpenID for Verifiable Credential Issuance specification was successfully completed in July, showing credentials from different issuers interoperating with digital wallets from several providers.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Growing role of biometrics in everyday life demands urgent deepfake response

Biometrics are becoming more entrenched a couple of market segments, though not as fast as some would like. The top…

 

PNG expands mandatory digital ID to businesses taking gov’t contracts

The government of Papua New Guinea is making its national digital ID a mandatory form of authentication for all business…

 

Imply reaches face biometrics milestone at tech-forward Arena da Baixada

Imply Tecnologia’s facial recognition model has enabled more than 1 million accesses at Arena da Baixada, the home of Club…

 

Following IPO, ROC is investing in homegrown security for US market

In February, Colorado-based biometrics and vision AI provider ROC closed the first big biometrics IPO of 2026, raising just over…

 

Jumio expanding biometric reusable digital identity across LatAm

Following a launch in Brazil last year, U.S.-based Jumio is expanding its face biometrics-based reusable digital identity product, selfie.DONE, across…

 

Denmark imposes age checks to restrict social media to kids under 15

Welcome two more Europeans nations to the global age assurance legislation party. The Danish government is moving ahead with an…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events