From 000af5377cf6ea84f139469e158a7d5e230090f0 Mon Sep 17 00:00:00 2001 From: ABIS Date: Thu, 13 Oct 2016 18:19:51 -0700 Subject: [PATCH] Update IdentityVerification.yml Extending details and distinctions of IdentityVerification proposed as tiered process for either organization members (staff) or users of organization (e.g., exchange, brokerage, etc.). Includes traditional and decentralized identification methods. --- _data/definitions/IdentityVerification.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/_data/definitions/IdentityVerification.yml b/_data/definitions/IdentityVerification.yml index 2a95e63..350d524 100644 --- a/_data/definitions/IdentityVerification.yml +++ b/_data/definitions/IdentityVerification.yml @@ -4,7 +4,13 @@ file: Identity Verification term: Identity Verification description: > Identity verification is a tiered process by which an organization or system attempts to confirm the authenticity of an [actors'](#actor) claim to be a given individual. - Typical methods of identity verification include: + Typical methods of identity verification which are necessary for staff or consultants working for organizations (exchanges, brokerages, etc.) include: - one or more forms of government-issued identification (driver's license, passport, etc.) - one or more proofs of residency at the individual's home (utility bills, bank statements, etc.) - successful completion of challenge questions through a reputable identity-verification service operating in the individual's country of residence (e.g. Equifax) + Methods of identity verification which could be deemed necessary for users (of an exchange, brokerage, web wallet, etc.) might include: + - GUID (key) and password + - blockchainMe + - Blockchain ID + - IDMAS (Identity Management System based on BIP0032) + - 2FA (Where, per guidance of Draft NIST Special Publication 800-63B, the verifying organization "Shall" verify that the pre-registered telephone number being used is actually associated with a mobile network and not with a VoIP (or other software-based) service. It then sends the SMS message to the pre-registered telephone number. Changing the pre-registered telephone number "Shall Not" be possible without two-factor authentication at the time of the change. Out of Band using SMS is deprecated.)