RFC 8225: PASSporT: Personal Assertion Token
Recent RFCs 2018-02-15
Summary:
This document defines a method for creating and validating a token
that cryptographically verifies an originating identity or, more
generally, a URI or telephone number representing the originator of
personal communications. The Personal Assertion Token, PASSporT, is
cryptographically signed to protect the integrity of the identity of
the originator and to verify the assertion of the identity
information at the destination. The cryptographic signature is
defined with the intention that it can confidently verify the
originating persona even when the signature is sent to the
destination party over an insecure channel. PASSporT is particularly
useful for many personal-communications applications over IP networks
and other multi-hop interconnection scenarios where the originating
and destination parties may not have a direct trusted relationship.