Derived Personal Identity Verification (PIV) credentials:

William Newhouse, Michael Bartock, Jeffrey Cichonski, Hildegard Ferraiolo, Murugiah Souppaya, Christopher Brown, Spike E Dog, Susan Buckles Prince, Julian Sexton · 2019

 Misuse of identity, especially through stolen passwords, is a primary source for cyber breaches.Enabling stronger processes to recognize a user's identity is a key component to securing an organization's information systems. Access to federal information systems relies on strong authentication of the user with a Personal Identity Verification (PIV) Card.This "smart card" contains identifying information about the user that enables stronger authentication to federal facilities, information systems, and applications. Today, access to information systems is increasingly from mobile phones, tablets, and some laptops that lack an integrated smart card reader found in older, stationary computing devices, forcing organizations to have separate authentication processes for these devices. Derived PIV Credentials (DPCs) leverage identity proofing and vetting results of current and valid credentials used in PIV Cards for issuing credentials that are securely stored on devices without PIV Card readers. The National Cybersecurity Center of Excellence (NCCoE) at the National Institute of Standards and Technology (NIST) built a laboratory environment to explore development of a security architecture that uses commercially available technology to manage the life cycle of DPCs. This NIST Cybersecurity Practice Guide demonstrates how organizations can provide multifactor authentication for users to access PIV-enabled websites from mobile devices that lack PIV Card readers. CHALLENGEIn accordance with Homeland Security Presidential Directive 12, the PIV standard was created to enhance national security by establishing a set of common authentication mechanisms that provide logical access to federal systems on PIV-Compatible (PIV-C) desktop and laptop computers.With the federal government's increased reliance on mobile computing devices that cannot accommodate PIV Card readers, the mandate to use PIV has created the need to derive credentials for use in mobile devices in a manner that enforces the same security policies established for the life-cycle credentials in a PIV Card.NIST has published guidance on DPCs, including a proof-of-concept research paper.Expanding upon this work, the NCCoE used common mobile devices available in the market today to demonstrate the use of DPCs in a manner that meets existing security policies.The flexibility of the technologies that support PIV, along with a growing understanding of the value of strong digital authentication practices, has resulted in an ecosystem of vendors able to provide digital authentication solutions with the capacity to adhere to the policies outlined in NIST guidance for DPCs.These mobile PIV standards-based credentials carry the designation of Derived PIV.With experts from the federal sector and technology collaborators who provided the requisite equipment and services, we developed representative use-case scenarios to describe user authentication security challenges based on normal day-to-day business operations.The use cases include issuance, maintenance, and termination of the DPC.

Read the paper · More papers on PaperTik