Skip to content

Science1 publisher2 min readPublished

NIST and CISA finalise token-protection guidance citing a single stolen signing key

NIST and CISA have finalised implementation guidance for the identity tokens behind single sign-on, written for federal agencies and their cloud providers. The case the announcement rests on is one cited attack.

The Scientist · Science desk

Illustration accompanying NIST and CISA finalise token-protection guidance citing a single stolen signing key

What happened

  • NIST and CISA have finalised Protecting Tokens and Assertions from Forgery, Theft, and Misuse, published as NIST IR 8587, with implementation guidelines for keeping identity and access tokens secure.
  • The publication builds on recent updates to SP 800-53, NIST's catalog of security and privacy tools, and answers a tasking NIST was given in Executive Order 14306.
  • The report cites an attack in which foreign actors forged tokens from a single stolen commercial signing key, reached agency email systems and took more than 60,000 emails from one agency.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

  • exposure The compromised credential in the cited incident was a commercial signing key, which puts the most consequential control in the provider's custody and outside anything the agency could configure.
  • constraint With one incident and no incidence figures, a security team cannot use this document to rank token forgery against the other risks it funds.
  • decision Commercial buyers under no federal obligation now have a named reference they can cite in vendor questionnaires when they ask how a provider protects its signing keys.
  • precedent Guidance that answers an executive order tasking and sits on top of an SP 800-53 update tends to reappear as acquisition and audit language for agency cloud vendors.

The key stolen in the attack the report cites is described as commercial, and the mailboxes emptied were an agency's [6]. IR 8587 splits its principles along that same boundary, setting out what provider organisations should do and what consumer organisations should do [5].

The division decides who can act. NIST's release gives the agency the job of configuring its provider's services correctly, and the provider the job of delivering a secure product [5]. The tokens in the cited incident were forged from the key that signs them [6].

The report refers to agency email systems in the plural while attributing the loss of more than 60,000 emails to a single agency [6], so the total across every system those forged tokens opened is at least 60,000 [16].

The announcement's evidence is that one attack [17], so there is no base rate for how often tokens are forged or stolen across federal systems, and no estimate of how far the recommended practices move that rate. The 60,000 is a count of emails taken in one breach.

NIST calls IR 8587 implementation guidelines [1]. "This publication provides implementation considerations for protecting tokens appropriately," said Ryan Galluzzo, NIST's Digital Identity Program Lead and one of the publication's authors [9][11]. The catalogue underneath it is SP 800-53, which NIST recently updated, and the work answers a tasking in Executive Order 14306 [3][2].

Galluzzo said the document is written primarily for federal agencies and the cloud service providers they work with, and that it is usable beyond them: "Anyone who is using tokens as part of their access management infrastructure can look to this for insights, whether they are in government or commercial industry" [4][10].

Tokens carry cryptographically protected information about a user and are what lets single sign-on work without constant reauthentication [7]. They are also a key part of access management at most major cloud providers and of zero trust architectures [8].

The authors revised the initial draft in response to reader feedback, according to Galluzzo [12]; NIST's notice introduces the most notable changes without listing them [13]. He credited industry partners including the Joint Cyber Defense Collaborative with critical feedback [14], and said the document "consolidates insights from across the cybersecurity community to help improve our ability to protect government data, resources and systems from the evolving threats they face today" [15].

What to watch

  • Whether the provider-side principles in IR 8587 turn up in federal cloud contract and audit language.
  • Whether NIST publishes the list of changes between the draft and the final IR 8587.
  • Whether any measured incidence data on token forgery across agencies appears to test the practices.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories