<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Credential</id>
	<title>Credential - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Credential"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Credential&amp;action=history"/>
	<updated>2026-05-01T12:09:38Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Credential&amp;diff=1286&amp;oldid=prev</id>
		<title>Omaerz: 33 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Credential&amp;diff=1286&amp;oldid=prev"/>
		<updated>2018-06-28T03:51:47Z</updated>

		<summary type="html">&lt;p&gt;33 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;
==Definition==&lt;br /&gt;
#A set of data presented as evidence of a claimed digital identifier or set of attributes.&lt;br /&gt;
#A set of data held by the user that allows presentation of evidence of a claimed digital identifier or set of attributes.&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
A certificate associated with a credential can establish a level of confidence in the attributes used in the identity claim as well as the security of the credential.&lt;br /&gt;
&lt;br /&gt;
The security of some credentials, as defined in 1 above, like passwords, are not generally secure. The security of credentials that are not directly passed, as defined in 2 above, can be made arbitrarily secure.&lt;br /&gt;
&lt;br /&gt;
Previous proposed definitions include:&lt;br /&gt;
#Attribute(s) presented as evidence of a claimed identity.  (Taxonomy AHG) &lt;br /&gt;
#An object or data structure that authoritatively binds an identity (and optionally, additional attributes) to a token possessed and controlled by a Subscriber. (NIST 800-63)&lt;br /&gt;
#Some form of token presented to facilitate identification and authentication. (Wallace)&lt;br /&gt;
#Verified attributes presented as evidence of a claimed identity.(Faron)&lt;br /&gt;
#Evidence of possession of an attribute by an entity, provided during identity proofing and similar processes.(Fenton)&lt;br /&gt;
#Something that is verifiable and is presented as evidence of a claimed identity and/or entitlement.(Corwin)&lt;br /&gt;
#A credential is an attestation of qualification, competence, or authority issued to an individual by a third party with a relevant or de facto authority or assumed competence to do so. (Wikipedia)  &lt;br /&gt;
#A credential needs to be an unique property of an individual that cannot be transferred. (Tom Jones)&lt;br /&gt;
&lt;br /&gt;
Open question: Is binding necessary, or preferred?&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
ITU-T X.1252&lt;br /&gt;
&lt;br /&gt;
NIST 800-63: An object or data structure that authoritatively binds an identity (and optionally, additional attributes) to a token possessed and controlled by a Subscriber. &lt;br /&gt;
While common usage often assumes that the credential is maintained by the Subscriber, this document also uses the term to refer to electronic records maintained by the CSP which establish a binding between the Subscriber’s token and identity.&lt;br /&gt;
&lt;br /&gt;
[http://www.w3.org/TR/credential-management-1/#concept-credential W3C Credential Management Level 1]&lt;br /&gt;
&lt;br /&gt;
From a developer’s perspective, a &amp;#039;&amp;#039;credential&amp;#039;&amp;#039; is an object which allows a developer to make an authentication decision for a particular action. Various types of credentials are used or presented by the [[User Agent]]. A credential is effective for a particular site if it is accepted as authentication on that site. Even if a credential is effective at a particular point in time, the [[User Agent]] can’t assume that the same credential will be effective at any future time, for a couple reasons:&lt;br /&gt;
#A password credential may stop being effective if the account holder changes their password.&lt;br /&gt;
#A credential made from a token received over SMS is likely to only be effective for a single use.&lt;br /&gt;
&lt;br /&gt;
Single-use credentials are generated by a credential source, which could be a private key, access to a federated account, the ability to receive SMS messages at a particular phone number, or something else. Credential sources are not exposed by the [[User Agent]]. To unify the model, we consider a password to be a credential source on its own, which is simply copied to create password credentials.&lt;br /&gt;
&lt;br /&gt;
== Status ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;background:green&amp;quot;&amp;gt;MC Approved&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Comment}}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Quick Links: [[Taxonomy]]  | [[Taxonomy Project Management]]  |  [[Taxonomy AHG Catalog]]  |    [[Taxonomy AHG Glossary]]  |  &lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Glossary]]&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>