|
RELYING PARTIES
A Relying Party is an entity that processes identity credential to support the conduct a business transaction. An Accredited
Issuing Authority (AIA) issues a credential to a Subscriber. The Subscriber will then present the credential to a Relying
Party to perform some business transaction with that Relying Party. The Relying Party then performs a series of validation
steps to ensure reasonable reliance prior to accepting the credential from the Subscriber. If successful, the credential
can be trusted by the Relying Party.
The SISAC Relying Party model is analogous to the credit card model. Credit card merchants have card processing functions
that they are required to perform prior to accepting that card in support of a payment transaction. For example, a merchant
declares which cards they accept (e.g., Visa, MasterCard, American Express), verifies that the credit card can support the
payment transaction (e.g., sufficient funds, card is not expired), and verifies that card presenter is the card owner (e.g.,
require a photo ID, validate signature on back of card). Relying Parties perform similar steps to ensure the validity of
a credential issued by an AIA. Reliance on SISAC credentials is established by performing a set of credential validation functions
that are based on a common set of business rules agreed to by SISAC participants. Therefore, businesses can rely on the common
rule set to mitigate identity risk in their applications and transactions, and in general, automated identity management processing
functions.
Further, Relying Parties are required to establish contractual relationships with each AIA to ensure that a common set of
identity credential validation functions is defined and performed. SISAC has a standard Relying Party form agreement that
can be used, or Relying Parties can negotiate their own agreements. Regardless of which agreement is used, Relying Parties
always have the ability to take advantage of competitive offerings by AIAs, and negotiate additional services, beyond the
standard validation services defined by SISAC, with any particular AIA.
SISAC has developed a Relying Party Guidance & Best Practices white paper. The document is intended to educate Relying Parties on the SISAC identity management model and obligations
required to be by a Relying Party.
|