{"id":19075,"date":"2026-09-17T12:19:09","date_gmt":"2026-09-17T15:19:09","guid":{"rendered":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=19075"},"modified":"2026-09-17T12:19:09","modified_gmt":"2026-09-17T15:19:09","slug":"directrices-para-proteger-la-identidad-en-linea-y-los-tokens-de-acceso","status":"publish","type":"post","link":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=19075","title":{"rendered":"Directrices para proteger la identidad en l\u00ednea y los tokens de acceso"},"content":{"rendered":"<p>El NIST (<i>National Institute of Standards and Technology<\/i> o Instituto Nacional de Est\u00e1ndares y Tecnolog\u00eda) es una agencia del Departamento de Comercio de Estados Unidos que crea normas y gu\u00edas t\u00e9cnicas para la ciencia, la industria y la tecnolog\u00eda. Un informe recientemente finalizado puede ayudar a los proveedores de servicios en la nube y a sus clientes a proteger mejor la identidad y los tokens de acceso, que se utilizan ampliamente al acceder a aplicaciones en l\u00ednea. En manos de un adversario, los tokens pueden ser peligrosos, y esta publicaci\u00f3n est\u00e1 dise\u00f1ada para ayudar a las organizaciones a tomar medidas efectivas para evitar exponerlos a los atacantes.<\/p>\n<hr \/>\n<p>When you sign in to an online service like webmail, behind the scenes is often a token \u2014 a snippet of information identifying you and what online resources you are permitted to use, such as your inbox, contacts or other potentially sensitive information. Keeping these tokens safe is critical for protecting against unauthorized access, and it\u2019s the goal of a newly finalized publication from the National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA).<\/p>\n<p>The publication, whose full title is\u00a0<a href=\"https:\/\/csrc.nist.gov\/pubs\/ir\/8587\/final\" target=\"_blank\" rel=\"noopener\"><em>Protecting Tokens and Assertions from Forgery, Theft, and Misuse<\/em>\u00a0(NIST IR 8587)<\/a>, provides implementation guidelines to help maintain the security of tokens, which are widely used in digital systems. The publication responds to NIST\u2019s tasking in\u00a0<a href=\"https:\/\/www.whitehouse.gov\/presidential-actions\/2025\/06\/sustaining-select-efforts-to-strengthen-the-nations-cybersecurity-and-amending-executive-order-13694-and-executive-order-14144\/\" target=\"_blank\" rel=\"noopener\">Executive Order 14306<\/a>\u00a0and builds on recent updates to\u00a0<a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/upd1\/final\" target=\"_blank\" rel=\"noopener\">Special Publication 800-53<\/a>, NIST\u2019s catalog of security and privacy tools, for the purpose of enhancing the security of tokens and token management.<\/p>\n<p>While the document is primarily written for federal agencies and the cloud service providers (CSPs) they work with, it can help any organization that handles identity tokens and related forms of identity assertions, said NIST Digital Identity Program Lead Ryan Galluzzo.<\/p>\n<p>\u201cThis publication provides implementation considerations for protecting tokens appropriately,\u201d said Galluzzo, one of the publication\u2019s authors. \u201cAnyone who is using tokens as part of their access management infrastructure can look to this for insights, whether they are in government or commercial industry.\u201d<\/p>\n<p>Many of the services we use online \u2014 from web-based email to data backup \u2014 are based in \u201cthe cloud,\u201d which is made up of remote computer servers that require authorization to access. Tokens are a key part of the access management infrastructure at most major CSPs. They contain cryptographically protected information about a user that can be used as part of authentication. They can also enable things such as single sign-on, which allows a user to use multiple applications without having to constantly reauthenticate. If you like the convenience of single sign-on, thank a token.<\/p>\n<p>Tokens are widely used in many other ways in digital infrastructure, and they are an important part of\u00a0<a title=\"NIST Offers 19 Ways to Build Zero Trust Architectures\" href=\"https:\/\/www.nist.gov\/news-events\/news\/2025\/06\/nist-offers-19-ways-build-zero-trust-architectures\" target=\"_blank\" rel=\"noopener\" data-entity-type=\"node\" data-entity-uuid=\"0b728547-c9ee-46c6-949f-de96960cbbe3\" data-entity-substitution=\"canonical\">zero trust architectures<\/a>. However, without proper protection, a bad actor can exploit tokens to break into sensitive systems. In\u00a0<a class=\"ext\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/14\/analysis-of-storm-0558-techniques-for-unauthorized-email-access\/\" target=\"_blank\" rel=\"noopener\" data-extlink=\"\">one attack<\/a>\u00a0the report cites, foreign actors accessed agency email systems using forged tokens derived from a single stolen commercial signing key. The attackers stole more than 60,000 emails from a single agency.<\/p>\n<p>The report\u2019s intended audience is both federal agencies, which need to understand how to configure services from their CSPs appropriately, and the CSPs themselves, which need to deliver secure products to these agencies. The publication lays out a set of principles for both parties, delineating what provider and consumer organizations should do to ensure that data remains protected.<\/p>\n<p>Galluzzo said the authors revised the\u00a0<a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2025\/NIST.IR.8587.ipd.pdf\" target=\"_blank\" rel=\"noopener\">initial draft<\/a>\u00a0of the publication in response to reader feedback. Among the most notable changes are:<\/p>\n<ul>\n<li>Guidelines regarding cryptographic key protection are now less prescriptive and more outcome-based, focusing on organizations\u2019 overall capabilities. More advice is also included on cryptographic key usage, protection and storage.<\/li>\n<li>New high-level considerations for handling AI and migration to post-quantum cryptography (<a title=\"What Is Post-Quantum Cryptography?\u00a0 \" href=\"https:\/\/www.nist.gov\/cybersecurity-and-privacy\/what-post-quantum-cryptography\" target=\"_blank\" rel=\"noopener\" data-entity-type=\"node\" data-entity-uuid=\"9f2f6ed0-b8b5-4d2a-bd0b-ead8906fd5fd\" data-entity-substitution=\"canonical\">PQC<\/a>) standards are now included. The publication does not offer a comprehensive set of tools for either topic. (NIST\u2019s National Cybersecurity Center of Excellence (<a href=\"https:\/\/www.nccoe.nist.gov\/\" target=\"_blank\" rel=\"noopener\">NCCoE<\/a>) recently published a\u00a0<a href=\"https:\/\/www.nccoe.nist.gov\/projects\/software-and-ai-agent-identity-and-authorization\" target=\"_blank\" rel=\"noopener\">concept paper<\/a>\u00a0on applying identity standards and best practices to AI agents, and it has launched a\u00a0<a href=\"https:\/\/www.nccoe.nist.gov\/applied-cryptography\/migration-to-pqc\" target=\"_blank\" rel=\"noopener\">PQC migration project<\/a>\u00a0as well.)<\/li>\n<li>New references to current and emerging standards are now included so that organizations can find different ways to achieve their desired outcomes. More options are now available for tasks such as token revocation and sharing signals around tokens.<\/li>\n<\/ul>\n<p>Galluzzo highlighted the critical support NIST and CISA received from industry partners such as the Joint Cyber Defense Collaborative, which provided critical feedback.<\/p>\n<p>\u201cThis document consolidates insights from across the cybersecurity community to help improve our ability to protect government data, resources and systems from the evolving threats they face today,\u201d he said.<\/p>\n<p><strong>Fuente: <\/strong><a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/09\/nist-finalizes-guidelines-protecting-online-identity-and-access-tokens\" target=\"_blank\" rel=\"noopener\"><em>https:\/\/www.nist.gov<\/em><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>El NIST (National Institute of Standards and Technology o Instituto Nacional de Est\u00e1ndares y Tecnolog\u00eda) es una agencia del Departamento de Comercio de Estados Unidos&hellip; <\/p>\n","protected":false},"author":1,"featured_media":19076,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[37,23,28],"tags":[],"_links":{"self":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/19075"}],"collection":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19075"}],"version-history":[{"count":1,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/19075\/revisions"}],"predecessor-version":[{"id":19077,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/19075\/revisions\/19077"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/media\/19076"}],"wp:attachment":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}