Techniques for Implementing Derived Credentials
Francisco Corella, Karen Lewison · 2012
The requirement of a Government-wide means of authenticating federal employ-ees and contractors stated by HSPD-12 is traditionally met by PIV smartcards in civilian agencies and CAC smartcards in the Department of Defense. But there are substantial obstacles to using a smartcard for authentication when an information system is accessed via a mobile device. NIST is investigating alternative authentica-tion methods that rely on derived credentials not contained in smartcards. In this paper we propose three techniques that can facilitate the implementation, deployment and use of derived credentials. The first technique eliminates the administrative cost that would be incurred by having to issue certificates to the mobile devices owned by users in addition to issuing certificates to the users themselves, by dispensing with client certificates. The second technique makes it possible to provide two- and three-factor authentication on a mobile device by using a PIN and/or a biometric sample to regenerate a key pair, obviating the need for tamper-resistant storage, which is not generally available on today’s mobile devices. The third technique relieves developers from having to incorporate cryptographic and/or biometric functionality into mobile apps by outsourcing authentication to a prover black box and a verifier black box. These techniques would allow federal agencies to develop mobile apps quickly and inexpensively while complying with the authentication requirements of HSPD-12. 1