assertion
Term · Cybersecurity · MLC-T-CYB-000225
1. A verifiable statement from an IdP to an RP that contains information about an end user. Assertions may also contain information about the end user’s authentication event at the IdP.
2. A statement from an IdP to an RP that contains information about an authentication event for a subscriber. Assertions can also contain identity attributes for the subscriber in the form of attribute values, derived attribute values, and attribute bundles.
3. A statement from an IdP to an RP that contains information about an authentication event for a subscriber. In federation, the assertion is the evidence that the IdP sends to the RP that the user has logged in. It can also contain user identifiers such as a username or email address and information about how the user logged in, such as whether MFA was used.
4. A statement from a verifier to an RP that contains information about a subscriber. Assertions may also contain verified attributes.
5. A statement from a Verifier to a Relying Party (RP) that contains identity information about a Subscriber. Assertions may also contain verified attributes.
| Identifier | MLC-T-CYB-000225 |
|---|---|
| Field | Cybersecurity |
| References | FIPS 201-3; NIST SP 800-63-4; NIST SP 800-63A-4; NIST IR 8523 from NIST SP 800-63-4 (adapted); NIST SP 800-63-3 [Superseded]; NIST SP 800-63-2 [Superseded]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000225",
"term": "assertion",
"field": "Cybersecurity",
"definition": "1. A verifiable statement from an IdP to an RP that contains information about an end user. Assertions may also contain information about the end user’s authentication event at the IdP.\n\n2. A statement from an IdP to an RP that contains information about an authentication event for a subscriber. Assertions can also contain identity attributes for the subscriber in the form of attribute values, derived attribute values, and attribute bundles.\n\n3. A statement from an IdP to an RP that contains information about an authentication event for a subscriber. In federation, the assertion is the evidence that the IdP sends to the RP that the user has logged in. It can also contain user identifiers such as a username or email address and information about how the user logged in, such as whether MFA was used.\n\n4. A statement from a verifier to an RP that contains information about a subscriber. Assertions may also contain verified attributes.\n\n5. A statement from a Verifier to a Relying Party (RP) that contains identity information about a Subscriber. Assertions may also contain verified attributes.",
"references": [
"FIPS 201-3",
"NIST SP 800-63-4; NIST SP 800-63A-4",
"NIST IR 8523 from NIST SP 800-63-4 (adapted)",
"NIST SP 800-63-3 [Superseded]",
"NIST SP 800-63-2 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/assertion/"
}
Record 225 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.