Federal Information Processing Standards Publication 190 A. Fips Pub 46-2, Data Encryption Standard. B. Fips Pub 48, Guidelines on Evaluation of Techniques for Automated Personal Identification. C. Fips Pub 74, Guidelines for Implementing and Using the Nbs Data Encryption Standard

Federal Information Processing Standards Publication 190 A. Fips Pub 46-2, Data Encryption Standard. B. Fips Pub 48, Guidelines on Evaluation of Techniques for Automated Personal Identification. C. Fips Pub 74, Guidelines for Implementing and Using the Nbs Data Encryption Standard
复制标题

DOI:
--
复制
发表时间:
--
期刊:
--
影响因子:
--
通讯作者:
--
中科院分区:
其他
文献类型:
--
作者:

文献摘要

被引文献

相似文献

3. 解释。本指南描述了验证计算机系统用户身份的主要替代方法,并为联邦机构和部门提供了获取和使用支持这些方法的技术的建议。尽管传统的身份验证方法主要依赖于密码,但很明显,仅使用密码的身份验证通常无法提供足够的保护。随着信息处理向开放系统环境发展,更强的身份验证技术变得越来越重要。现代技术已经产生了可靠、实用和具有成本效益的认证令牌和生物识别设备。密码、令牌和生物识别技术可以以各种组合使用,从而在身份验证过程中提供比单独使用密码更大的保证。其他NIST出版物可能适用于本指南的使用。当前可用的计算机安全出版物的列表(NIST出版物列表91),包括排序信息,可以从NIST获得。7. 适用性。本指南适用于所有使用认证系统来保护计算机和电信系统(包括语音系统)中的非机密信息的联邦部门和机构,这些信息不受美国法典第10编第2315条或美国法典第44编第3502(2)条的约束。本指南可用于所有联邦部门和机构在其操作或根据合同为其操作的计算机和电信系统(包括语音系统)中设计、获取和实施认证系统。鼓励非联邦政府组织使用本指南,当它为保护有价值或敏感的信息提供所需的安全性时。8. 应用程序。认证系统可用于各种计算机和电信(包括语音)应用和各种环境(例如,集中式计算机设施、办公环境、敌对环境)。应该选择认证系统的强度,以提供适当程度的保证,以满足使用系统的应用程序和环境的安全要求,以及系统要提供的安全服务。10. 出口控制。本指南中讨论的许多身份验证系统都使用加密技术来增强身份验证过程的安全性。某些加密设备和与之相关的技术数据被视为国防物品(即本质上具有军事性质),并受联邦政府出口管制,如联邦法规第22章第120-128部分所述。某些密码系统的输出和与之相关的技术数据必须…
3. Explanation. This Guideline describes the primary alternative methods for verifying the identities of computer system users, and provides recommendations to Federal agencies and departments for the acquisition and use of technology which supports these methods. Although the traditional approach to authentication relies primarily on passwords, it is clear that password-only authentication often fails to provide an adequate level of protection. Stronger authentication techniques become increasingly more important as information processing evolves toward an open systems environment. Modern technology has produced authentication tokens and biometric devices which are reliable, practical, and cost-effective. Passwords, tokens, and biometrics can be used in various combinations to provide far greater assurance in the authentication process than can be attained with passwords alone. Other NIST publications may be applicable to the use of this guideline. A list (NIST Publications List 91) of currently available computer security publications, including ordering information, can be obtained from NIST. 7. Applicability. This guideline is applicable to all Federal departments and agencies that use authentication systems to protect unclassified information within computer and telecommunication systems (including voice systems) that are not subject to Section 2315 of Title 10, U.S. Code, or Section 3502(2) of Title 44, U.S. Code. This guideline may be used by all Federal departments and agencies in designing, acquiring and implementing authentication systems within computer and telecommunication systems (including voice systems) that they operate or that are operated for them under contract. Non-Federal government organizations are encouraged to use this guideline when it provides the desired security for protecting valuable or sensitive information. 8. Applications. Authentication systems may be utilized in various computer and telecommunication (including voice) applications and in various environments (e.g., centralized computer facilities, office environments, hostile environments). The strength of an authentication system should be chosen to provide a degree of assurance appropriate for the security requirements of the application and environment in which the system is to be utilized and the security services which the system is to provide. 10. Export Control. Many of the authentication systems discussed in this guideline make use of cryptographic techniques to strengthen the security of the authentication process. Certain cryptographic devices and technical data regarding them are deemed to be defense articles (i.e., inherently military in character) and are subject to Federal government export controls as specified in Title 22, Code of Federal Regulations, Parts 120-128. Some exports of cryptographic systems and technical data regarding them must …