Electronic Authentication Guidelines

Remote commerce and personally identifiable data (PID) management requires a level of e-authentication that often goes well beyond the simple password. This research note looks at approaches that rely on users knowing "secrets."


Partner logo

NIST is a non-regulatory federal agency within the U.S. Department of Commerce. NIST's mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards and technology in ways that enhance economic security and improve our quality of life.

All IT Downloads from National Institute of Standards and Technology » | Visit National Institute of Standards and Technology »

From National Institute of Standards and Technology | Dec 1, 2010

Electronic authentication (E-authentication) is the process of establishing confidence in user identities electronically presented to an information system. E-authentication presents a technical challenge when this process involves the remote authentication of individual people over a network for the purposes of electronic government and commerce. This recommendation provides technical guidelines to agencies to allow an individual to remotely authenticate his or her identity to a Federal IT system. These guidelines address only traditional, widely implemented methods for remote authentication based on secrets. With these methods, the individual to be authenticated proves that he or she knows or possesses some secret information.

The attached Zip file includes:

  • Intro Page.doc
  • Cover Sheet and Terms.doc
  • Electronic Authentication Guidelines.pdf
IT Downloads help you save time and money while executing essential IT management tasks. Download this useful resource now and put it to work for your business.

Proving Identity and Establishing Trust for Online Transactions

This technical brief explains why two-factor authentication is superior to password authentication for proving identity and establishing trust.

Addressing Active Directory Recovery and Availablility Needs in the Enterprise

In this on-demand webcast, discover the challenges of backing up and recovering Active Directory (AD). Also, learn how to rapidly recover from an AD disaster while ensuring business continuity and minimizing system downtime and data loss.