
The National Institute of Standards and Technology (NIST) released draft guidance Friday on derived credentials for authenticating mobile devices on federal networks. Users who want to logon to a sensitive federal computer typically must insert their Personal Identity Verification (PIV) cards--called Common Access Cards (CAC) at the Department of Defense--into the machine. This creates a challenge for smartphones and tablets that are too small for an internal card reader. A derived credential solves this problem by storing the authenticating information…