Download - Strong Authentication and US Federal Digital Services

Transcript
Page 1: Strong Authentication and US Federal Digital Services

Strong Authentication and US Federal

Digital ServicesPaul Grassi, Senior Standards and Technology Advisor, NIST

Page 2: Strong Authentication and US Federal Digital Services

current state

Page 3: Strong Authentication and US Federal Digital Services

based on

Page 4: Strong Authentication and US Federal Digital Services

It gets worse

Page 5: Strong Authentication and US Federal Digital Services

everyone else

Page 6: Strong Authentication and US Federal Digital Services

where does FIDO fit in?

Page 7: Strong Authentication and US Federal Digital Services

Privacy Enhancing & Voluntary

Secure & Resilient

Interoperable

Cost-Effective & Easy to Use

Page 8: Strong Authentication and US Federal Digital Services
Page 9: Strong Authentication and US Federal Digital Services
Page 10: Strong Authentication and US Federal Digital Services

Authenticator Assurance

Levels

AA

L1 A

AL2 A

AL3

Page 11: Strong Authentication and US Federal Digital Services

Authenticator Assurance Level 3(formerly known as LOA4)

AAL 3 is intended to provide the highest practical remote network

authentication assurance. Authentication at AAL 3 is based on proof of

possession of a key in a physical authenticator through a

cryptographic protocol. AAL 3 is similar to AAL 2 except that

only hardware cryptographic authenticators (in conjunction

with a memorized secret for single-factor cryptographic devices) and

multi-factor OTP devices are allowed. The authenticator SHALL be a

hardware cryptographic module validated at Federal

Information Processing Standard (FIPS) 140 Level

2 or higher overall (Level 1 for single-factor

authenticators) with at least FIPS 140 Level 3

physical security.

Page 12: Strong Authentication and US Federal Digital Services

always supported

Page 13: Strong Authentication and US Federal Digital Services

newly supported

Page 14: Strong Authentication and US Federal Digital Services

USG Use Cases

?M-05-24

Page 15: Strong Authentication and US Federal Digital Services

So we need a

new

interoperability

target?

Page 16: Strong Authentication and US Federal Digital Services

what else?

Page 17: Strong Authentication and US Federal Digital Services

strength of authentication (SOFA)

https://pages.nist.gov/SOFA

Page 18: Strong Authentication and US Federal Digital Services
Page 19: Strong Authentication and US Federal Digital Services

[email protected]

[email protected]

https://www.nist.gov/itl/tig

@TrustedIDsNIST

https://service.govdelivery.com/accounts/USNIST/subscriber/new?topic_id=USNIST_213

http://trustedidentities.blogs.govdelivery.com

https://github.com/usnistgov/800-63-3