80_FR_48980 80 FR 48823 - National Cybersecurity Center of Excellence, Derived Personal Identity Verification Credentials Building Block

80 FR 48823 - National Cybersecurity Center of Excellence, Derived Personal Identity Verification Credentials Building Block

DEPARTMENT OF COMMERCE
National Institute of Standards and Technology

Federal Register Volume 80, Issue 157 (August 14, 2015)

Page Range48823-48825
FR Document2015-20039

The National Institute of Standards and Technology (NIST) invites organizations to provide products and technical expertise to support and demonstrate security platforms for the Derived Personal Identity Verification (PIV) Credentials Building Block. This notice is the initial step for the National Cybersecurity Center of Excellence (NCCoE) in collaborating with technology companies to address cybersecurity challenges identified under the Derived PIV Credentials Building Block. Participation in the building block is open to all interested organizations.

Federal Register, Volume 80 Issue 157 (Friday, August 14, 2015)
[Federal Register Volume 80, Number 157 (Friday, August 14, 2015)]
[Notices]
[Pages 48823-48825]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2015-20039]


-----------------------------------------------------------------------

DEPARTMENT OF COMMERCE

National Institute of Standards and Technology

[Docket No.: 150805680-5680-01]


National Cybersecurity Center of Excellence, Derived Personal 
Identity Verification Credentials Building Block

AGENCY: National Institute of Standards and Technology, Department of 
Commerce.

ACTION: Notice.

-----------------------------------------------------------------------

SUMMARY: The National Institute of Standards and Technology (NIST) 
invites organizations to provide products and technical expertise to 
support and demonstrate security platforms for the Derived Personal 
Identity Verification (PIV) Credentials Building Block. This notice is 
the initial step for the National Cybersecurity Center of Excellence 
(NCCoE) in collaborating with technology companies to address 
cybersecurity challenges identified under the Derived PIV Credentials 
Building Block. Participation in the building block is open to all 
interested organizations.

DATES: Interested parties must contact NIST to request a letter of 
interest template to be completed and submitted to NIST that identifies 
the organization requesting participation in the NCCoE Derived PIV 
Credentials Building Block and the capabilities and components that are 
being offered to the collaborative effort. Letters of interest will be 
accepted on a first come, first served basis. Collaborative activities 
will commence as soon as enough completed and signed letters of 
interest have been returned to address all the necessary components and 
capabilities, but no earlier than September 14, 2015. When the building 
block has been completed, NIST will post a notice on the NCCoE Derived 
PIV Credentials Building Block Web site at http://nccoe.nist.gov/derivedcredentials/ announcing the completion of the building block and 
informing the public that it will no longer accept letters of interest 
for this Derived PIV Credentials building block.

ADDRESSES: The NCCoE is located at 9600 Gudelsky Drive, Rockville, MD 
20850. Letters of interest may be submitted to piv-nccoe@nist.gov or 
via hardcopy to National Institute of Standards and Technology, NCCoE; 
9600 Gudelsky Drive; Rockville, MD 20850. Organizations whose letters 
of interest are accepted in accordance with the process set forth in 
the SUPPLEMENTARY INFORMATION section of this notice will be asked to 
sign a Cooperative Research and Development Agreement (CRADA) with 
NIST. A CRADA template can be found at: http://nccoe.nist.gov/node/138.

FOR FURTHER INFORMATION CONTACT: Tim McBride via email to piv-nccoe@nist.gov; by telephone 240-314-6811; or by mail to National 
Institute of Standards and Technology, NCCoE; 9600 Gudelsky Drive; 
Rockville, MD 20850. Additional details about the Derived PIV 
Credentials Building Block are available at http://nccoe.nist.gov/derivedcredentials/.

SUPPLEMENTARY INFORMATION: 

Background

    The NCCoE, part of NIST, is a public-private collaboration for 
accelerating the widespread adoption of integrated cybersecurity tools 
and technologies. The NCCoE brings together experts from industry, 
government, and academia under one roof to develop practical, 
interoperable cybersecurity approaches that address the real-world 
needs of complex Information Technology (IT) systems. By accelerating 
dissemination and use of these integrated tools and technologies for 
protecting IT assets, the NCCoE will enhance trust in U.S. IT 
communications, data, and storage systems; reduce risk for companies 
and individuals using IT systems; and encourage development of 
innovative, job-creating cybersecurity products and services.

Process

    NIST is soliciting responses from all sources of relevant security 
capabilities (see below) to enter into a Cooperative Research and 
Development Agreement (CRADA) to provide products and technical 
expertise to support and demonstrate security platforms for the Derived 
PIV Credentials building block. The full Derived Personal Identity 
Verification (PIV) Credentials building block can be viewed at: http://nccoe.nist.gov/derivedcredentials/.
    Interested parties must contact NIST to request a letter of 
interest template to be completed and submitted to NIST that identifies 
the organization requesting participation in the NCCoE Derived PIV 
Credentials Building Block and the capabilities and components

[[Page 48824]]

that are being offered to the collaborative effort. NIST will contact 
interested parties if there are questions regarding the responsiveness 
of the letters of interest to the Derived PIV Credentials building 
block objective or requirements identified below and to obtain 
additional information. NIST will select participants who have 
submitted responsive letters of interest on a first come, first served 
basis within each category of product components or capabilities listed 
below up to the number of participants in each category necessary to 
carry out this Derived PIV Credentials building block. However, there 
may be continuing opportunity to participate even after initial 
activity commences. Selected participants will be required to enter 
into a consortium CRADA with NIST (for reference, see ADDRESSES section 
above). NIST published a notice in the Federal Register on October 19, 
2012 (77 FR 64314) inviting U.S. companies to enter into National 
Cybersecurity Excellence Partnerships (NCEPs) in furtherance of the 
NCCoE. For this demonstration project, NCEP partners will not be given 
priority for participation.

Derived PIV Credentials Building Block Objective

    Organizations protect their information systems, in part, by 
limiting access to the minimum set of users required to perform a 
function. This principle of ``least privilege'' requires both 
authentication and authorization processes. Federal Information 
Processing Standards Publication 201-2, ``Personal Identity 
Verification (PIV) of Federal Employees and Contractors,'' recommends 
using smart cards with user data in conjunction with passwords to 
provide two-factor authentication to federal information systems. While 
many desktop and laptop computers have built-in card readers, 
enterprises today rely heavily on the productivity of mobile devices 
(i.e., smartphones and tablets) that do not easily accommodate card 
readers. Organizations reliant on smart-card-and-password two-factor 
authentication need to authenticate users of mobile devices in a way 
that is more tamper-resistant than a password and as easy to use as a 
smart card. However, it is challenging to use smart card on the various 
mobile devices due to their form factor. Attaching or tethering a 
separate external smart card reader to the mobile phones or tablets 
creates usability and portability challenges and makes the card an 
impractical authentication token.
    This building block will demonstrate, using smart cards, initially 
PIV cards, how derived smart card credentials can be added to mobile 
devices so that they may be used for remote authentication to 
information technology systems in operational environments. An initial 
derived credentials proof of concept platform has been developed by 
NIST ITL's Computer Security Division. Personal identification in 
mobile device environments is important in Federal (PIV), Federal 
Contractor (PIV-Interoperable or PIV-I), and general business (PIV-
Compatible or CIV) environments. The goal of the building block effort 
is to demonstrate a feasible security platform based on Federal 
identity verification standards and guidelines and the NIST-developed 
existing demonstration prototype proof of concept that can support 
operations in PIV, PIV-I, and CIV environments. This building block 
will use commercially available technologies to demonstrate a public 
key infrastructure (PKI) credentials derived from a PIV-compatible card 
that is consistent with the requirements in NIST Special Publication 
800-157, ``Guidelines for Derived Personal Identity Verification (PIV) 
Credentials.'' The derived PIV X.509-based credentials will be used for 
logical access to remote resources hosted within an on-premises data 
center or in the public cloud. The corresponding derived private key 
will be stored in a cryptographic module with alternative form factor 
such as embedded hardware or software in a mobile device or a removable 
token such as a secure digital (SD) card, universal integrated circuit 
card (UICC, the new generation of SIM cards), or USB token.
    A detailed description of the Derived PIV Credentials Building 
Block is available at: http://nccoe.nist.gov/derivedcredentials/.

Requirements

    Each responding organization's letter of interest should identify 
which security platform component(s) or capability(ies) it is offering. 
Letters of interest should not include company proprietary information, 
and all components and capabilities must be commercially available. 
Components are listed in section 6 of the Derived Personal Identity 
Verification (PIV) Credentials Building Block description (for 
reference, please see the link in the PROCESS section above) and 
include, but are not limited to:

 Client systems
 Server systems
 Cloud computing services
 DNS/DNSSEC services
 Removable MicroSD tokens
 Removable USB security tokens
 Removable UICC tokens
 Embedded Mobile Device Software tokens
 Embedded Hardware
 Virtual private network service
 Domain name services
 Windows domain controllers
 Active Directory Federation Servers
 Identity management system
 Cards management system
 Certificate authorities for PIV and Derived PIV Credentials
 Application Proxy Servers
 PIV/PIV-I/CIV Card Management Systems
 PIV/PIV-I/CIV smart card writers and printer
 PIV/PIV-I/CIV compliant smart card readers
 PIV/PIV-I/CIV compliant Smart cards
 Mobile devices
 Operating Systems
 Laptop computer
    Each responding organization's letter of interest should identify 
how their products address one or more of the desired solution 
characteristics in section 3 of the Derived Personal Identity 
Verification (PIV) Credentials Building Block description (for 
reference, please see the link in the PROCESS section above).
    Additional details about the Derived PIV Credentials Building Block 
are available at: http://nccoe.nist.gov/derivedcredentials/.
    NIST cannot guarantee that all of the products proposed by 
respondents will be used in the demonstration. Each prospective 
participant will be expected to work collaboratively with NIST staff 
and other project participants under the terms of the consortium CRADA 
in the development of the Derived PIV Credentials Building Block. 
Prospective participants' contribution to the collaborative effort will 
include assistance in establishing the necessary interface 
functionality, connection and set-up capabilities and procedures, 
demonstration harnesses, environmental and safety conditions for use, 
integrated platform user instructions, and demonstration plans and 
scripts necessary to demonstrate the desired capabilities. Each 
participant will train NIST personnel, as necessary, to operate its 
product in capability demonstrations. Following successful 
demonstrations, NIST will publish a description of the security 
platform and its performance characteristics sufficient to permit other 
organizations to develop and deploy security platforms that meet the 
security objectives of the Derived PIV Credentials Building Block. 
These descriptions will be public information.
    Under the terms of the consortium CRADA, participants will commit 
to providing:


[[Page 48825]]


1. Access for all participants' project teams to component interfaces 
and the organization's experts necessary to make functional connections 
among security platform components
2. Support for development and demonstration of the Derived PIV 
Credentials Building Block in NCCoE facilities which will be conducted 
in a manner consistent with Federal requirements (e.g., FIPS 200, FIPS 
201, SP 800-53, and SP 800-63)
    In addition, NIST will support development of interfaces among 
participants' products by providing IT infrastructure, laboratory 
facilities, office facilities, collaboration facilities, and staff 
support to component composition, security platform documentation, and 
demonstration activities.
    The dates of the demonstration of the Derived PIV Credentials 
Building Block capability will be announced on the NCCoE Web site at 
least two weeks in advance at http://nccoe.nist.gov/. The expected 
outcome of the demonstration is to improve Derived PIV Credentials 
within the enterprise. Participating organizations will gain from the 
knowledge that their products are interoperable with other 
participants' offerings.
    For additional information on the NCCoE governance, business 
processes, and NCCoE operational structure, visit the NCCoE Web site 
http://nccoe.nist.gov/.

Richard Cavanagh,
Acting Associate Director for Laboratory Programs.
[FR Doc. 2015-20039 Filed 8-13-15; 8:45 am]
 BILLING CODE P



                                                                                  Federal Register / Vol. 80, No. 157 / Friday, August 14, 2015 / Notices                                            48823

                                                    Access Control Building Block.                          the NCCoE Web site http://                            20850. Letters of interest may be
                                                    Prospective participants’ contribution to               nccoe.nist.gov/.                                      submitted to piv-nccoe@nist.gov or via
                                                    the collaborative effort will include                                                                         hardcopy to National Institute of
                                                                                                            Richard Cavanagh,
                                                    assistance in establishing the necessary                                                                      Standards and Technology, NCCoE;
                                                                                                            Acting Associate Director for Laboratory              9600 Gudelsky Drive; Rockville, MD
                                                    interface functionality, connection and                 Programs.
                                                    set-up capabilities and procedures,                                                                           20850. Organizations whose letters of
                                                                                                            [FR Doc. 2015–20041 Filed 8–13–15; 8:45 am]
                                                    demonstration harnesses, environmental                                                                        interest are accepted in accordance with
                                                                                                            BILLING CODE 3510–13–P                                the process set forth in the
                                                    and safety conditions for use, integrated
                                                    platform user instructions, and                                                                               SUPPLEMENTARY INFORMATION section of
                                                    demonstration plans and scripts                                                                               this notice will be asked to sign a
                                                                                                            DEPARTMENT OF COMMERCE
                                                    necessary to demonstrate the desired                                                                          Cooperative Research and Development
                                                    capabilities. Each participant will train               National Institute of Standards and                   Agreement (CRADA) with NIST. A
                                                    NIST personnel, as necessary, to operate                Technology                                            CRADA template can be found at:
                                                    its product in capability                                                                                     http://nccoe.nist.gov/node/138.
                                                                                                            [Docket No.: 150805680–5680–01]
                                                    demonstrations. Following successful                                                                          FOR FURTHER INFORMATION CONTACT: Tim
                                                    demonstrations, NIST will publish a                     National Cybersecurity Center of                      McBride via email to piv-nccoe@
                                                    description of the security platform and                Excellence, Derived Personal Identity                 nist.gov; by telephone 240–314–6811; or
                                                    its performance characteristics sufficient              Verification Credentials Building Block               by mail to National Institute of
                                                    to permit other organizations to develop                                                                      Standards and Technology, NCCoE;
                                                    and deploy security platforms that meet                 AGENCY: National Institute of Standards               9600 Gudelsky Drive; Rockville, MD
                                                    the security objectives of the Attribute                and Technology, Department of                         20850. Additional details about the
                                                    Based Access Control Building Block.                    Commerce.                                             Derived PIV Credentials Building Block
                                                    These descriptions will be public                       ACTION: Notice.                                       are available at http://nccoe.nist.gov/
                                                    information.                                                                                                  derivedcredentials/.
                                                                                                            SUMMARY:    The National Institute of
                                                                                                                                                                  SUPPLEMENTARY INFORMATION:
                                                       Under the terms of the consortium                    Standards and Technology (NIST)
                                                    CRADA, participants will commit to                      invites organizations to provide                      Background
                                                    providing:                                              products and technical expertise to                     The NCCoE, part of NIST, is a public-
                                                    1. Access for all participants’ project                 support and demonstrate security                      private collaboration for accelerating the
                                                         teams to component interfaces and                  platforms for the Derived Personal                    widespread adoption of integrated
                                                                                                            Identity Verification (PIV) Credentials               cybersecurity tools and technologies.
                                                         the organization’s experts necessary
                                                                                                            Building Block. This notice is the initial            The NCCoE brings together experts from
                                                         to make functional connections
                                                                                                            step for the National Cybersecurity                   industry, government, and academia
                                                         among security platform
                                                                                                            Center of Excellence (NCCoE) in                       under one roof to develop practical,
                                                         components
                                                                                                            collaborating with technology                         interoperable cybersecurity approaches
                                                    2. Support for development and                          companies to address cybersecurity                    that address the real-world needs of
                                                         demonstration of the Attribute                     challenges identified under the Derived               complex Information Technology (IT)
                                                         Based Access Control Building                      PIV Credentials Building Block.                       systems. By accelerating dissemination
                                                         Block in NCCoE facilities which                    Participation in the building block is                and use of these integrated tools and
                                                         will be conducted in a manner                      open to all interested organizations.                 technologies for protecting IT assets, the
                                                         consistent with Federal                            DATES: Interested parties must contact                NCCoE will enhance trust in U.S. IT
                                                         requirements (e.g., FIPS 200, FIPS                 NIST to request a letter of interest                  communications, data, and storage
                                                         201, SP 800–53, and SP 800–63)                     template to be completed and submitted                systems; reduce risk for companies and
                                                       In addition, NIST will support                       to NIST that identifies the organization              individuals using IT systems; and
                                                    development of interfaces among                         requesting participation in the NCCoE                 encourage development of innovative,
                                                    participants’ products by providing IT                  Derived PIV Credentials Building Block                job-creating cybersecurity products and
                                                    infrastructure, laboratory facilities,                  and the capabilities and components                   services.
                                                    office facilities, collaboration facilities,            that are being offered to the
                                                                                                            collaborative effort. Letters of interest             Process
                                                    and staff support to component
                                                    composition, security platform                          will be accepted on a first come, first                 NIST is soliciting responses from all
                                                    documentation, and demonstration                        served basis. Collaborative activities                sources of relevant security capabilities
                                                    activities.                                             will commence as soon as enough                       (see below) to enter into a Cooperative
                                                                                                            completed and signed letters of interest              Research and Development Agreement
                                                       The dates of the demonstration of the                have been returned to address all the                 (CRADA) to provide products and
                                                    Attribute Based Access Control Building                 necessary components and capabilities,                technical expertise to support and
                                                    Block capability will be announced on                   but no earlier than September 14, 2015.               demonstrate security platforms for the
                                                    the NCCoE Web site at least two weeks                   When the building block has been                      Derived PIV Credentials building block.
                                                    in advance at http://nccoe.nist.gov/. The               completed, NIST will post a notice on                 The full Derived Personal Identity
                                                    expected outcome of the demonstration                   the NCCoE Derived PIV Credentials                     Verification (PIV) Credentials building
                                                    is to improve Attribute Based Access                    Building Block Web site at http://                    block can be viewed at: http://
asabaliauskas on DSK5VPTVN1PROD with NOTICES




                                                    Control within the enterprise.                          nccoe.nist.gov/derivedcredentials/                    nccoe.nist.gov/derivedcredentials/.
                                                    Participating organizations will gain                   announcing the completion of the                        Interested parties must contact NIST
                                                    from the knowledge that their products                  building block and informing the public               to request a letter of interest template to
                                                    are interoperable with other                            that it will no longer accept letters of              be completed and submitted to NIST
                                                    participants’ offerings.                                interest for this Derived PIV Credentials             that identifies the organization
                                                       For additional information on the                    building block.                                       requesting participation in the NCCoE
                                                    NCCoE governance, business processes,                   ADDRESSES: The NCCoE is located at                    Derived PIV Credentials Building Block
                                                    and NCCoE operational structure, visit                  9600 Gudelsky Drive, Rockville, MD                    and the capabilities and components


                                               VerDate Sep<11>2014   18:50 Aug 13, 2015   Jkt 235001   PO 00000   Frm 00020   Fmt 4703   Sfmt 4703   E:\FR\FM\14AUN1.SGM   14AUN1


                                                    48824                         Federal Register / Vol. 80, No. 157 / Friday, August 14, 2015 / Notices

                                                    that are being offered to the                           be added to mobile devices so that they               • Embedded Mobile Device Software
                                                    collaborative effort. NIST will contact                 may be used for remote authentication                    tokens
                                                    interested parties if there are questions               to information technology systems in                  • Embedded Hardware
                                                    regarding the responsiveness of the                     operational environments. An initial                  • Virtual private network service
                                                    letters of interest to the Derived PIV                  derived credentials proof of concept                  • Domain name services
                                                    Credentials building block objective or                 platform has been developed by NIST                   • Windows domain controllers
                                                    requirements identified below and to                    ITL’s Computer Security Division.                     • Active Directory Federation Servers
                                                    obtain additional information. NIST will                Personal identification in mobile device              • Identity management system
                                                    select participants who have submitted                  environments is important in Federal                  • Cards management system
                                                    responsive letters of interest on a first               (PIV), Federal Contractor (PIV-                       • Certificate authorities for PIV and
                                                    come, first served basis within each                    Interoperable or PIV–I), and general                     Derived PIV Credentials
                                                    category of product components or                       business (PIV-Compatible or CIV)                      • Application Proxy Servers
                                                    capabilities listed below up to the                     environments. The goal of the building                • PIV/PIV–I/CIV Card Management
                                                    number of participants in each category                 block effort is to demonstrate a feasible                Systems
                                                    necessary to carry out this Derived PIV                 security platform based on Federal                    • PIV/PIV–I/CIV smart card writers and
                                                    Credentials building block. However,                    identity verification standards and                      printer
                                                    there may be continuing opportunity to                  guidelines and the NIST-developed                     • PIV/PIV–I/CIV compliant smart card
                                                    participate even after initial activity                 existing demonstration prototype proof                   readers
                                                    commences. Selected participants will                   of concept that can support operations                • PIV/PIV–I/CIV compliant Smart cards
                                                    be required to enter into a consortium                  in PIV, PIV–I, and CIV environments.                  • Mobile devices
                                                    CRADA with NIST (for reference, see                     This building block will use                          • Operating Systems
                                                    ADDRESSES section above). NIST
                                                                                                                                                                  • Laptop computer
                                                                                                            commercially available technologies to
                                                                                                                                                                     Each responding organization’s letter
                                                    published a notice in the Federal                       demonstrate a public key infrastructure
                                                                                                                                                                  of interest should identify how their
                                                    Register on October 19, 2012 (77 FR                     (PKI) credentials derived from a PIV-
                                                    64314) inviting U.S. companies to enter                                                                       products address one or more of the
                                                                                                            compatible card that is consistent with
                                                    into National Cybersecurity Excellence                                                                        desired solution characteristics in
                                                                                                            the requirements in NIST Special
                                                    Partnerships (NCEPs) in furtherance of                                                                        section 3 of the Derived Personal
                                                                                                            Publication 800–157, ‘‘Guidelines for
                                                    the NCCoE. For this demonstration                                                                             Identity Verification (PIV) Credentials
                                                                                                            Derived Personal Identity Verification
                                                    project, NCEP partners will not be given                                                                      Building Block description (for
                                                                                                            (PIV) Credentials.’’ The derived PIV
                                                    priority for participation.                                                                                   reference, please see the link in the
                                                                                                            X.509-based credentials will be used for
                                                                                                                                                                  PROCESS section above).
                                                    Derived PIV Credentials Building Block                  logical access to remote resources                       Additional details about the Derived
                                                    Objective                                               hosted within an on-premises data                     PIV Credentials Building Block are
                                                                                                            center or in the public cloud. The                    available at: http://nccoe.nist.gov/
                                                       Organizations protect their                          corresponding derived private key will
                                                    information systems, in part, by limiting                                                                     derivedcredentials/.
                                                                                                            be stored in a cryptographic module                      NIST cannot guarantee that all of the
                                                    access to the minimum set of users                      with alternative form factor such as
                                                    required to perform a function. This                                                                          products proposed by respondents will
                                                                                                            embedded hardware or software in a                    be used in the demonstration. Each
                                                    principle of ‘‘least privilege’’ requires               mobile device or a removable token
                                                    both authentication and authorization                                                                         prospective participant will be expected
                                                                                                            such as a secure digital (SD) card,                   to work collaboratively with NIST staff
                                                    processes. Federal Information                          universal integrated circuit card (UICC,
                                                    Processing Standards Publication 201–2,                                                                       and other project participants under the
                                                                                                            the new generation of SIM cards), or                  terms of the consortium CRADA in the
                                                    ‘‘Personal Identity Verification (PIV) of               USB token.
                                                    Federal Employees and Contractors,’’                                                                          development of the Derived PIV
                                                                                                              A detailed description of the Derived
                                                    recommends using smart cards with                                                                             Credentials Building Block. Prospective
                                                                                                            PIV Credentials Building Block is
                                                    user data in conjunction with passwords                                                                       participants’ contribution to the
                                                                                                            available at: http://nccoe.nist.gov/
                                                    to provide two-factor authentication to                                                                       collaborative effort will include
                                                                                                            derivedcredentials/.
                                                    federal information systems. While                                                                            assistance in establishing the necessary
                                                    many desktop and laptop computers                       Requirements                                          interface functionality, connection and
                                                    have built-in card readers, enterprises                    Each responding organization’s letter              set-up capabilities and procedures,
                                                    today rely heavily on the productivity of               of interest should identify which                     demonstration harnesses, environmental
                                                    mobile devices (i.e., smartphones and                   security platform component(s) or                     and safety conditions for use, integrated
                                                    tablets) that do not easily accommodate                 capability(ies) it is offering. Letters of            platform user instructions, and
                                                    card readers. Organizations reliant on                  interest should not include company                   demonstration plans and scripts
                                                    smart-card-and-password two-factor                      proprietary information, and all                      necessary to demonstrate the desired
                                                    authentication need to authenticate                     components and capabilities must be                   capabilities. Each participant will train
                                                    users of mobile devices in a way that is                commercially available. Components are                NIST personnel, as necessary, to operate
                                                    more tamper-resistant than a password                   listed in section 6 of the Derived                    its product in capability
                                                    and as easy to use as a smart card.                     Personal Identity Verification (PIV)                  demonstrations. Following successful
                                                    However, it is challenging to use smart                 Credentials Building Block description                demonstrations, NIST will publish a
                                                    card on the various mobile devices due                  (for reference, please see the link in the            description of the security platform and
                                                    to their form factor. Attaching or                                                                            its performance characteristics sufficient
asabaliauskas on DSK5VPTVN1PROD with NOTICES




                                                                                                            PROCESS section above) and include,
                                                    tethering a separate external smart card                but are not limited to:                               to permit other organizations to develop
                                                    reader to the mobile phones or tablets                  • Client systems                                      and deploy security platforms that meet
                                                    creates usability and portability                       • Server systems                                      the security objectives of the Derived
                                                    challenges and makes the card an                        • Cloud computing services                            PIV Credentials Building Block. These
                                                    impractical authentication token.                       • DNS/DNSSEC services                                 descriptions will be public information.
                                                       This building block will demonstrate,                • Removable MicroSD tokens                               Under the terms of the consortium
                                                    using smart cards, initially PIV cards,                 • Removable USB security tokens                       CRADA, participants will commit to
                                                    how derived smart card credentials can                  • Removable UICC tokens                               providing:


                                               VerDate Sep<11>2014   18:50 Aug 13, 2015   Jkt 235001   PO 00000   Frm 00021   Fmt 4703   Sfmt 4703   E:\FR\FM\14AUN1.SGM   14AUN1


                                                                                  Federal Register / Vol. 80, No. 157 / Friday, August 14, 2015 / Notices                                           48825

                                                    1. Access for all participants’ project                 Building Block. This notice is the initial            The NCCoE brings together experts from
                                                         teams to component interfaces and                  step for the National Cybersecurity                   industry, government, and academia
                                                         the organization’s experts necessary               Center of Excellence (NCCoE) in                       under one roof to develop practical,
                                                         to make functional connections                     collaborating with technology                         interoperable cybersecurity approaches
                                                         among security platform                            companies to address cybersecurity                    that address the real-world needs of
                                                         components                                         challenges identified under the Mobile                complex Information Technology (IT)
                                                    2. Support for development and                          Device Security Building Block.                       systems. By accelerating dissemination
                                                         demonstration of the Derived PIV                   Participation in the building block is                and use of these integrated tools and
                                                         Credentials Building Block in                      open to all interested organizations.                 technologies for protecting IT assets, the
                                                         NCCoE facilities which will be                     DATES: Interested parties must contact                NCCoE will enhance trust in U.S. IT
                                                         conducted in a manner consistent                   NIST to request a letter of interest                  communications, data, and storage
                                                         with Federal requirements (e.g.,                   template to be completed and submitted                systems; reduce risk for companies and
                                                         FIPS 200, FIPS 201, SP 800–53, and                 to NIST that identifies the organization              individuals using IT systems; and
                                                         SP 800–63)                                         requesting participation in the NCCoE                 encourage development of innovative,
                                                       In addition, NIST will support                       Mobile Device Security Building Block                 job-creating cybersecurity products and
                                                    development of interfaces among                         and the capabilities and components                   services.
                                                    participants’ products by providing IT                  that are being offered to the                         Process
                                                    infrastructure, laboratory facilities,                  collaborative effort. Letters of interest
                                                    office facilities, collaboration facilities,            will be accepted on a first come, first                  NIST is soliciting responses from all
                                                    and staff support to component                          served basis. Collaborative activities                sources of relevant security capabilities
                                                    composition, security platform                          will commence as soon as enough                       (see below) to enter into a Cooperative
                                                    documentation, and demonstration                        completed and signed letters of interest              Research and Development Agreement
                                                    activities.                                             have been returned to address all the                 (CRADA) to provide products and
                                                       The dates of the demonstration of the                necessary components and capabilities,                technical expertise to support and
                                                    Derived PIV Credentials Building Block                  but no earlier than September 14, 2015.               demonstrate security platforms for the
                                                    capability will be announced on the                                                                           Mobile Device Security Building Block.
                                                                                                            When the building block has been
                                                    NCCoE Web site at least two weeks in                                                                          The full building block can be viewed
                                                                                                            completed, NIST will post a notice on
                                                    advance at http://nccoe.nist.gov/. The                                                                        at: http://nccoe.nist.gov/sites/default/
                                                                                                            the NCCoE Mobile Device Security
                                                    expected outcome of the demonstration                                                                         files/nccoe/MobileDeviceBuildingBlock_
                                                                                                            Building Block Web site at http://
                                                                                                                                                                  20140912.pdf.
                                                    is to improve Derived PIV Credentials                   nccoe.nist.gov/?q=content/mobile-                        Interested parties should contact NIST
                                                    within the enterprise. Participating                    device-security announcing the                        using the information provided in the
                                                    organizations will gain from the                        completion of the building block and                  FOR FURTHER INFORMATION CONTACT
                                                    knowledge that their products are                       informing the public that it will no                  section of this notice. NIST will then
                                                    interoperable with other participants’                  longer accept letters of interest for this            provide each interested party with a
                                                    offerings.                                              building block.                                       letter of interest template, which the
                                                       For additional information on the                    ADDRESSES: The NCCoE is located at                    party must complete, certify that it is
                                                    NCCoE governance, business processes,                   9600 Gudelsky Drive, Rockville, MD                    accurate, and submit to NIST and which
                                                    and NCCoE operational structure, visit                  20850. Letters of interest must be                    identifies the organization requesting
                                                    the NCCoE Web site http://                              submitted to mobile-nccoe@nist.gov or                 participation in the Mobile Device
                                                    nccoe.nist.gov/.                                        via hardcopy to National Institute of                 Building Block and the capabilities and
                                                    Richard Cavanagh,                                       Standards and Technology, NCCoE;                      components that are being offered to the
                                                    Acting Associate Director for Laboratory
                                                                                                            9600 Gudelsky Drive; Rockville, MD                    collaborative effort. NIST will contact
                                                    Programs.                                               20850. Organizations whose letters of                 interested parties if there are questions
                                                    [FR Doc. 2015–20039 Filed 8–13–15; 8:45 am]
                                                                                                            interest are accepted in accordance with              regarding the responsiveness of the
                                                                                                            the process set forth in the                          letters of interest to the building block
                                                    BILLING CODE P
                                                                                                            SUPPLEMENTARY INFORMATION section of                  objective or requirements identified
                                                                                                            this notice will be asked to sign a                   below and to obtain additional
                                                    DEPARTMENT OF COMMERCE                                  Cooperative Research and Development                  information. NIST will select
                                                                                                            Agreement (CRADA) with NIST. A                        participants who have submitted
                                                    National Institute of Standards and                     CRADA template can be found at:                       complete letters of interest on a first
                                                    Technology                                              http://nccoe.nist.gov/node/138.                       come, first served basis within each
                                                                                                            FOR FURTHER INFORMATION CONTACT:                      category of product components or
                                                    [Docket No.: 141110948–5504–01]                                                                               capabilities listed below up to the
                                                                                                            Joshua Franklin via email at nccoe-
                                                    National Cybersecurity Center of                        mobile@nist.gov; by telephone 240–314–                number of participants in each category
                                                                                                            6800; or by mail to National Institute of             necessary to carry out the Mobile Device
                                                    Excellence, Mobile Device Security
                                                                                                            Standards and Technology, NCCoE;                      Security Building Block. However, there
                                                    Building Block
                                                                                                            9600 Gudelsky Drive; Rockville, MD                    may be continuing opportunity to
                                                    AGENCY: National Institute of Standards                 20850. Additional details about the                   participate even after initial activity
                                                    and Technology, Department of                           Mobile Device Security Building Block                 commences. Selected participants will
                                                    Commerce.                                               are available at http://nccoe.nist.gov/               be required to enter into a consortium
asabaliauskas on DSK5VPTVN1PROD with NOTICES




                                                    ACTION: Notice.                                         ?q=content/mobile-device-security.                    CRADA with NIST (for reference, see
                                                                                                            SUPPLEMENTARY INFORMATION:                            ADDRESSES section above). NIST
                                                    SUMMARY:   The National Institute of                                                                          published a notice in the Federal
                                                    Standards and Technology (NIST)                         Background                                            Register on October 19, 2012 (77 FR
                                                    invites organizations to provide                          The NCCoE, part of NIST, is a public-               64314) inviting U.S. companies to enter
                                                    products and technical expertise to                     private collaboration for accelerating the            into National Cybersecurity Excellence
                                                    support and demonstrate security                        widespread adoption of integrated                     Partnerships (NCEPs) in furtherance of
                                                    platforms for the Mobile Device Security                cybersecurity tools and technologies.                 the NCCoE. For this demonstration


                                               VerDate Sep<11>2014   18:50 Aug 13, 2015   Jkt 235001   PO 00000   Frm 00022   Fmt 4703   Sfmt 4703   E:\FR\FM\14AUN1.SGM   14AUN1



Document Created: 2018-02-23 10:59:18
Document Modified: 2018-02-23 10:59:18
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice.
DatesInterested parties must contact NIST to request a letter of interest template to be completed and submitted to NIST that identifies the organization requesting participation in the NCCoE Derived PIV Credentials Building Block and the capabilities and components that are being offered to the collaborative effort. Letters of interest will be accepted on a first come, first served basis. Collaborative activities will commence as soon as enough completed and signed letters of
ContactTim McBride via email to piv- [email protected]; by telephone 240-314-6811; or by mail to National Institute of Standards and Technology, NCCoE; 9600 Gudelsky Drive; Rockville, MD 20850. Additional details about the Derived PIV Credentials Building Block are available at http://nccoe.nist.gov/ derivedcredentials/.
FR Citation80 FR 48823 

2024 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR