NIST drafts security building blocks

From: GCN


The draft building block “Domain Name System-Based Security for Electronic Mail” proposes using the DNS-based Authentication of Named Entities (DANE) protocol to help prevent unauthorized parties from reading or modifying an organization’s email or using it as a vector for malware.

The draft building block “Derived Personal Identity Verification (PIV) Credentials” proposes a way for mobile devices to use two-factor authentication without specialized card readers, which read the identity credentials embedded in on-card computer chips to ensure authorized access to computer systems or facilities. With derived credentials, mobile device users could get the same level of security with their mobile devices that desktop users get with card-reader access.

