Strong Authentication and US Federal Digital Services

19
Strong Authentication and US Federal Digital Services Paul Grassi, Senior Standards and Technology Advisor, NIST

Transcript of Strong Authentication and US Federal Digital Services

Page 1: Strong Authentication and US Federal Digital Services

Strong Authentication and US Federal

Digital ServicesPaul Grassi, Senior Standards and Technology Advisor, NIST

Page 2: Strong Authentication and US Federal Digital Services

current state

Page 3: Strong Authentication and US Federal Digital Services

based on

Page 4: Strong Authentication and US Federal Digital Services

It gets worse

Page 5: Strong Authentication and US Federal Digital Services

everyone else

Page 6: Strong Authentication and US Federal Digital Services

where does FIDO fit in?

Page 7: Strong Authentication and US Federal Digital Services

Privacy Enhancing & Voluntary

Secure & Resilient

Interoperable

Cost-Effective & Easy to Use

Page 8: Strong Authentication and US Federal Digital Services
Page 9: Strong Authentication and US Federal Digital Services
Page 10: Strong Authentication and US Federal Digital Services

Authenticator Assurance

Levels

AA

L1 A

AL2 A

AL3

Page 11: Strong Authentication and US Federal Digital Services

Authenticator Assurance Level 3(formerly known as LOA4)

AAL 3 is intended to provide the highest practical remote network

authentication assurance. Authentication at AAL 3 is based on proof of

possession of a key in a physical authenticator through a

cryptographic protocol. AAL 3 is similar to AAL 2 except that

only hardware cryptographic authenticators (in conjunction

with a memorized secret for single-factor cryptographic devices) and

multi-factor OTP devices are allowed. The authenticator SHALL be a

hardware cryptographic module validated at Federal

Information Processing Standard (FIPS) 140 Level

2 or higher overall (Level 1 for single-factor

authenticators) with at least FIPS 140 Level 3

physical security.

Page 12: Strong Authentication and US Federal Digital Services

always supported

Page 13: Strong Authentication and US Federal Digital Services

newly supported

Page 14: Strong Authentication and US Federal Digital Services

USG Use Cases

?M-05-24

Page 15: Strong Authentication and US Federal Digital Services

So we need a

new

interoperability

target?

Page 16: Strong Authentication and US Federal Digital Services

what else?

Page 17: Strong Authentication and US Federal Digital Services

strength of authentication (SOFA)

https://pages.nist.gov/SOFA

Page 18: Strong Authentication and US Federal Digital Services
Page 19: Strong Authentication and US Federal Digital Services

[email protected]

[email protected]

https://www.nist.gov/itl/tig

@TrustedIDsNIST

https://service.govdelivery.com/accounts/USNIST/subscriber/new?topic_id=USNIST_213

http://trustedidentities.blogs.govdelivery.com

https://github.com/usnistgov/800-63-3