1Kosmos has announced a new offering aimed at enhancing identity verification in the government sector.
The company’s new 1Kosmos “Credential Service Provider” (CSP) service is designed to offer an automated, seamless process for residents seeking government services, verifying their identity to a certified NIST Identity Assurance Level 2 (IAL2). What’s more, 1Kosmos’ CSP is meant to provide end users with a strong, phishing-resistant multi-factor authentication (MFA) credential certified up to NIST Authentication Assurance Level 2 (AAL2).
IAL2 and AAL2 are both standards set by the National Institute of Standards and Technology designed to secure digital identities at different stages of user interaction. IAL2 ensures a moderate level of confidence in the identity of users by requiring strong evidence and verification processes during identity proofing. AAL2, on the other hand, focuses on the authentication process, ensuring a moderate level of assurance that the person asserting an identity is indeed who they claim to be, typically involving two-factor authentication mechanisms.
Both levels are interconnected as they provide a comprehensive approach to security, with IAL2 verifying identity robustness and AAL2 ensuring continued security through robust authentication methods.
1Kosmos’ CSP platform allows residents to enroll using various methods and their existing IDs like driver’s licenses or passports, through a web interface, mobile app, or in-person. It employs a decentralized data storage approach using FIDO2 certified cryptography, which ensures user privacy and security by allowing data sharing only with user consent.
Its enrolment process includes several verification steps: email and device verification, document scanning for identity documents such as driver’s licenses or passports, and non-biased biometric capture, which includes a liveness check process in which the user is asked to blink or smile. Additional verification measures include phone number verification through SIM binding, which links a security token to a device trusted by both the user and the service provider, and optional verification of the user’s social security number and address.
1Kosmos says it is seeking to achieve an Authority to Operate (ATO) under the FedRAMP program to ensure compliance with federal security standards.
–
April 24, 2024 – by Cass Kennedy
Follow Us