Authentication - Acceptable Use of Attestation, v1.0

Authenticator verifiers may rely on attestation data conveyed to the verifier from a directly connected authenticator or endpoint. That attestation data must be digitally signed appropriately.

Assessment Step

1
Attestation (Attestation)
Is all attestation information protected with a digital signature of sufficient strength?
Artifact
A1
Provide evidence (e.g. policies, operational details, processes) that any attestation data conveyed to an authenticator verifier is appropriately digitally signed.

Conformance Criteria (1)

C1
An attestation is information conveyed to the verifier regarding a directly-connected authenticator or the endpoint involved in an authentication operation. If this attestation is signed, it SHALL be signed using a digital signature that provides at least the minimum security strength specified in the latest revision of SP 800-131A (112 bits as of the date of this publication).
Citation
NIST SP 800-63B
Section 5.2.4