Federal Information Processing Standards Publication 190 A. Fips Pub 46-2, Data Encryption Standard. B. Fips Pub 48, Guidelines on Evaluation of Techniques for Automated Personal Identification. C. Fips Pub 74, Guidelines for Implementing and Using the Nbs Data Encryption Standard
Federal Information Processing Standards Publication 190 A. Fips Pub 46-2, Data Encryption Standard. B. Fips Pub 48, Guidelines on Evaluation of Techniques for Automated Personal Identification. C. Fips Pub 74, Guidelines for Implementing and Using the Nbs Data Encryption Standard
复制标题
DOI:
--
复制
发表时间:
--
期刊:
影响因子:
--
通讯作者:
中科院分区:
文献类型:
--
作者:
3. Explanation. This Guideline describes the primary alternative methods for verifying the identities of computer system users, and provides recommendations to Federal agencies and departments for the acquisition and use of technology which supports these methods. Although the traditional approach to authentication relies primarily on passwords, it is clear that password-only authentication often fails to provide an adequate level of protection. Stronger authentication techniques become increasingly more important as information processing evolves toward an open systems environment. Modern technology has produced authentication tokens and biometric devices which are reliable, practical, and cost-effective. Passwords, tokens, and biometrics can be used in various combinations to provide far greater assurance in the authentication process than can be attained with passwords alone. Other NIST publications may be applicable to the use of this guideline. A list (NIST Publications List 91) of currently available computer security publications, including ordering information, can be obtained from NIST. 7. Applicability. This guideline is applicable to all Federal departments and agencies that use authentication systems to protect unclassified information within computer and telecommunication systems (including voice systems) that are not subject to Section 2315 of Title 10, U.S. Code, or Section 3502(2) of Title 44, U.S. Code. This guideline may be used by all Federal departments and agencies in designing, acquiring and implementing authentication systems within computer and telecommunication systems (including voice systems) that they operate or that are operated for them under contract. Non-Federal government organizations are encouraged to use this guideline when it provides the desired security for protecting valuable or sensitive information. 8. Applications. Authentication systems may be utilized in various computer and telecommunication (including voice) applications and in various environments (e.g., centralized computer facilities, office environments, hostile environments). The strength of an authentication system should be chosen to provide a degree of assurance appropriate for the security requirements of the application and environment in which the system is to be utilized and the security services which the system is to provide. 10. Export Control. Many of the authentication systems discussed in this guideline make use of cryptographic techniques to strengthen the security of the authentication process. Certain cryptographic devices and technical data regarding them are deemed to be defense articles (i.e., inherently military in character) and are subject to Federal government export controls as specified in Title 22, Code of Federal Regulations, Parts 120-128. Some exports of cryptographic systems and technical data regarding them must …