全网唯一标准王
NIST SPECIAL PUBLICATION 1800 -17 Multifactor Authentication for E-Commerce Risk-Based, FIDO Universal Second Factor Implementations for Purchasers I ncludes Executive Summary (A); Approach, Architecture, and Security Characteristics (B); and How -To Guides (C) W illiam Newhouse Brian Johnson Sarah Kinling Jason Kuruvilla Blaine Mulugeta Kenneth Sandlin This publication is available free of charge from https://doi.org/10.6028/NIST.SP.1800- 17 T he first draft of this publication is available free of charge from https://www.nccoe.nist.gov/sites/default/files/library/sp1800/cr -mfa-nist-sp1800- 17.pdf NIST SPECIAL PUBLICATION 1800 -17 Multifactor Authentication for E-Commerce Includes Executive Summary (A); Approach, Architecture, and Security Characteristics (B ); and How -To Guides (C) William Newhouse Information Technology Laboratory National Institute of Standards and Technology Brian Johnson Sarah Kinling Jason Kuruvilla Blaine Mulugeta Kenneth Sandlin The MITRE Corporation McLean, Virginia July 2019 U.S. Department of Commerce Wilbur Ross , Secretary National Institute of Standards and Technology Walter Copan, NIST Director and Undersecretary of Commerce for Standards and Technology NIST SPECIAL PUBLICATION 1800 -17A Multifactor Authentication for E-Commerce Risk-Based, FIDO Universal Second Factor Implementations for Purchasers Volume A : Executive Summary William Newhouse Information Technology Laboratory National Institute of Standards and Technology Brian Johnson Sarah Kinling Jason Kuruvilla Blaine Mulugeta Kenneth Sandlin The MITRE Corporation McLean, Virginia July 2019 This publication is available free of charge from https://doi.org/10.6028/NIST.SP.1800- 17 The first draft of this publication is available free of charge from https://www.nccoe.nist.gov/sites/default/files/library/sp1800/cr -mfa-nist-sp1800- 17.pdf NIST SP 1800-17A: Multifactor Authentication for E- Commerce 1 Executive Summary  Retailers can implement multifactor authentication (MFA) to reduc e the opportunity for a customer’s online account to be used for fraudulent purchases .  MFA is a security enhancement that allows a user to present several pieces of evidence when logging into an account. This evidence falls into three categories: something you know (e.g. , password), something you have (e.g. , smart card), and something you are (e.g. , fingerprint). The presented evidence must come from at least two different categories to enhance security.  The National Cybersecurity Center of Excellence (NCCoE) at the National Institute of Standards and Technology ( NIST ) built a laboratory environment to explore MFA options available to retailers today , and documented the example implementations that retailers can consider for their environment .  This NIST Cybersecurity Practice Guide demonstrates how online retailers can implement MFA to help reduce electronic commerce ( e-commerce ) fraud. CHALLENGE Smart chip credit cards and terminals work together to protect in -store payments. The in -store security adva nces were introduced in 2015, and those have pushed malicious actors who possess stolen credit card data to perform payment card fraud online. This guide describes implementing stronger user- authentication techniques to reduce the risk of e -commerce fraud. The guide documents a system in which risk determines when to trigger MFA challenges to existing customers. SOLUTION This project’s example implementation s analyze risk to prompt returning purchas ers with additional authentication requests when risk elements are exceeded during the online shopping session . Risk elements may include contextual data related to the returning purchaser and the current shopping transaction . The example implementation s will prompt a

pdf文档 NIST.SP.1800-17 Multifactor Authentication for E-Commerce

文档预览
中文文档 248 页 50 下载 1000 浏览 0 评论 0 收藏 3.0分
温馨提示:本文档共248页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
NIST.SP.1800-17 Multifactor Authentication for E-Commerce 第 1 页 NIST.SP.1800-17 Multifactor Authentication for E-Commerce 第 2 页 NIST.SP.1800-17 Multifactor Authentication for E-Commerce 第 3 页
下载文档到电脑,方便使用
本文档由 思安 于 2022-12-05 09:11:43上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。