Federation - Secure Exchange of Cryptographic Keys During IdP-RP Registration, v1.0

During federation registration events for IdPs and RPs, all key exchanges must be done using a secure method. If any symmetric keys are used, they must be unique for each IdP/RP pair.

Assessment Steps (2)

1
Registration Key Exchange (RegistrationKeyExchange)
Are all federation cryptographic keys exchanged during registration exchanged using a secure method?
Artifact
A1
Provide evidence (e.g. policies, compliance/assessment reports) that all keys exchanged securely.
2
Symmetric Key Uniqueness (SymmetricKeyUniqueness)
Are all symmetric keys used unique to specific pairs of federation participants? If no symmetric keys are used, (other than ephemeral ones generated transactionally) that would satisfy this assessment step.
Artifact
A1
Provide evidence (e.g. policies, compliance/assessment reports) that any symmetric keys are exclusive to single pairwise relationships.

Conformance Criteria (2)

C1
Protocols requiring the transfer of keying information SHALL use a secure method during the registration process to exchange keying information needed to operate the federated relationship, including any shared secrets or public keys.
Citation
NIST SP 800-63C
Section 5.1.1, Paragraph 4
C2
Any symmetric keys used in this relationship SHALL be unique to a pair of federation participants.
Citation
NIST SP 800-63C
Section 5.1.1, Paragraph 4