FB pixel

FIDO Alliance paper details extending PKI security with authentication standards

 

The FIDO Alliance has released a new white paper in support of the U.S. Commission on Enhancing National Cybersecurity’s recommendations for all agencies to use strong authentication across all government systems.

Titled “Leveraging FIDO Standards to Extend the PKI Security Model in United States Government Agencies,” the paper describes the use of FIDO solutions to improve cybersecurity within the government environment and act as a complement to traditional PKI.

Developed by FIDO’s Public Policy and Privacy Working Group (P3WG), the paper outlines the many benefits of a FIDO-inclusive method of providing other authentication solutions that are both easier to use and to integrate with legacy applications.

These authentication solutions still provide the same core security associated with asymmetric public key cryptography

Though the Derived PIV Credential (DPC) program allows the issuance of a separate PKI certificate by proving possession of a PIV Card, the DPC workflow detailed in NIST 800-157 can be used to issue a FIDO public/private key pair, linked to the same identity record associated with the PIV card.

The main difference is that the key pair is part of a “lightweight” key pair instead of a “full” public key infrastructure.

For individuals in the government ecosystem that are not required to obtain a PIV, FIDO offers an alternative method that is more affordable, management and easier to use.

Using this method would ensure that individuals have a strong authentication based on public key cryptography.

The paper emphasizes that PIV is still the highest standard for authentication in the U.S. government, and will remain an essential aspect of the federal enterprise.

But as agencies work towards fulfilling the Commission’s recommendations, facilitating a method that extends PIV solutions with FIDO can improve the security across the Federal enterprise and help the U.S. to more effectively secure digital assets.

FIDO asserts that while eliminating password-based breaches by 2021 would be a significant challenge, it is not an entirely impossible goal.

Previously reported, the new FIDO Certified showcase provides deploying organizations with a one-stop shop to learn about the companies and products that can bring FIDO Authentication to their users.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Report demystifies India’s unique face biometrics market beyond the benchmarks

Biometric authentication is taking off in India as the country’s government and market align around identity as a trust layer…

 

Trust inevitable in building human rights-sensitive digital ID systems

Some digital rights advocates who spoke at the recent ID4Africa 2026 AGM in Abidjan emphasized that for African governments to…

 

Nepalese raise concerns over new DPI loans amid previous project failures

Some experts have expressed apprehensions that the government of Nepal has contracted a new loan for the implementation of a…

 

GripID introduces ultra-compact multimodal biometric enrollment kit

France-based GripID has unveiled the compact V10 multimodal biometric enrollment kit for registration to national ID and civil digital identity…

 

Australia opens feedback on verifiable credential policy, trust framework proposals

Australia’s Department of Finance is inviting community feedback on a policy for using verifiable credentials proposed by the Commonwealth. The…

 

FBI warning on Kali365 phishing kit exposes limits of weaker authentication

A new Federal Bureau of Investigation (FBI) warning about a phishing-as-a-service kit targeting Microsoft 365 accounts is underscoring why major…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events