Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

A Framework for Multi-mode Authentication: Overview and Implementation Guide

Published

Author(s)

Wayne Jansen, Vladimir Korolev, Serban I. Gavrila, T Heute, Clement Seveillac

Abstract

The use of mobile handheld devices within the workplace is expanding rapidly. These devices are no longer viewed as coveted gadgets for early technology adopters, but have instead become indispensable tools that offer competitive business advantages for the mobile workforce. While these devices provide productivity benefits, they also pose new risks to an organization's security. Enabling adequate user authentication is the first line of defense against unauthorized use of a lost or stolen handheld device. Multiple modes of authentication increase the work factor needed to attack a device, however, few devices support more than one mode, usually password-based authentication. This report describes a general Multi-mode Authentication Framework (MAF) for applying organizational security policies, organized into distinct policy contexts known as echelons, among which a user may transition. The approach is aimed at helping users easily comply with their organization's security policy, yet be able to exercise a significant amount of flexibility and discretion. The design of the framework allows various types of authentication technologies to be incorporated readily and provides a simple interface for supporting different types policy enforcement mechanisms. Details of the implementation of the framework are provided, as well as two example authentications mechanisms.
Citation
NIST Interagency/Internal Report (NISTIR) - 7046
Report Number
7046

Keywords

authentication, MAF, mobile devices, Multi-mode Authentication Framework, PDA, Personal Digital Assistant, security policy

Citation

Jansen, W. , Korolev, V. , Gavrila, S. , Heute, T. and Seveillac, C. (2003), A Framework for Multi-mode Authentication: Overview and Implementation Guide, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.7046 (Accessed April 26, 2024)
Created August 1, 2003, Updated November 10, 2018