authentication
Term · Cybersecurity · MLC-T-CYB-000324
1. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.
2. The process of establishing confidence of authenticity; in this case, the validity of a person’s identity and an authenticator (e.g., PIV Card or derived PIV credential).
3. A security measure designed to protect a communications system against acceptance of fraudulent transmission or simulation by establishing the validity of a transmission, message, originator, or a means of verifying an individual's eligibility to receive specific categories of information.
4. Security measures designed to establish the validity of a transmission, message, or originator, or a means of verifying an individual’s authorization to receive specific categories of
information.
5. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system.
6. The process a VPN uses to limit access to protected services by forcing users to identify themselves.
7. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to a system’s resources.
8. Provides assurance of the authenticity and, therefore, the integrity of data.
9. A process that provides assurance of the source and integrity of information in communications sessions, messages, documents or stored data or that provides assurance of the identity of an entity interacting with a system.
10. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to a system’s resources
11. The process of establishing confidence of authenticity. In this case, it is the validity of a person’s identity and the PIV Card.
12. A process that provides assurance of the source and integrity of information that is communicated or stored or the identity of an entity interacting with a system.
13. Note that in common practice, the term "authentication" is used to mean either source or identity authentication only. This document will differentiate the multiple uses of the word by the terms source authentication, identity authentication, or integrity authentication, where appropriate.
14. A process that provides assurance of the source and integrity of information in communications sessions, messages, documents or stored data or that provides assurance of the identity of an entity interacting with a system. See Source authentication, Identity authentication, and Integrity authentication.
15. The process of verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.
16. The act of verifying that the subject has been authorized to use the presented identifier by a trusted identity provider organization.
17. The corroboration that a person is the one claimed.
18. As used in this document, a process that provides assurance of the source and integrity of information that is communicated or stored, or that provides assurance of an entity’s identity.
19. The process by which a claimant proves possession and control of one or more authenticators bound to a subscriber account to demonstrate that they are the subscriber associated with that account.
20. The process of establishing confidence in the identity of users or information systems.
21. The process of verifying a claimed identity of a user, device, or other entity in a computer system
22. the process of verifying the integrity of data that has been stored, transmitted, or otherwise exposed to possible unauthorized access.
23. The process of proving the claimed identity of an individual user, machine, software component or any other entity. Typical authentication mechanisms include conventional password schemes, biometrics devices, cryptographic methods, and onetime passwords (usually implemented with token based cards.)
24. The process of establishing confidence in the claimed identity of a user or system
25. Verifying the identity of a user, process, or device, often as a prerequisite for allowing access to resources in an information system.
26. measures the number of times an attacker must authenticate to a target in order to exploit a vulnerability.
27. The process by which a claimant proves possession and control of one or more authenticators bound to a subscriber account to demonstrate that they are the subscriber associated with that account and involves one or more of the following factors:
i. something you know (e.g., password/personal identification number (PIN) );
ii. something you have (e.g., cryptographic identification device, token); or
iii. something you are (e.g., biometric).
| Identifier | MLC-T-CYB-000324 |
|---|---|
| Field | Cybersecurity |
| Synonyms | authenticate |
| References | FIPS 200; NIST SP 1800-10B from FIPS 200; NIST SP 1800-21C; NIST SP 800-128 from FIPS 200; NIST SP 800-137 from FIPS 200; NIST SP 800-30 Rev. 1 from FIPS 200; NIST SP 800-39 from FIPS 200; NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200; NIST SP 800-60 Vol. 2 Rev. 1 from FIPS 200; NIST SP 800-82r3 from FIPS 200; FIPS 201-3; CNSSI 4009-2022 from CNSSI 4005; NIST SP 800-59; NIST SP 800-12 Rev. 1 from FIPS 200; NIST SP 800-128 from FIPS 200; NIST SP 800-171r3 from FIPS 200 (adapted); NIST SP 800-172r3 from FIPS 200 (adapted); NIST SP 800-37 Rev. 2 from FIPS 200; NIST SP 800-53 Rev. 5 from FIPS 200; NISTIR 7316; NIST SP 800-113; NIST SP 1800-16B; NIST SP 1800-16C; NIST SP 1800-16D; NIST SP 1800-17c; NIST SP 800-67 Rev. 2; NIST SP 800-57 Part 2 Rev.1; NIST SP 1800-17b; NIST SP 1800-12b; NIST SP 800-175B Rev. 1; NIST SP 800-57 Part 1 Rev. 5; NIST SP 1800-27B from FIPS 200; NIST SP 1800-27C from FIPS 200; NIST SP 800-162; NIST SP 800-66r2 from HIPAA Security Rule (§164.304); NIST SP 800-175A; NIST SP 800-63-4; NIST SP 800-63A-4; NISTIR 8149; NISTIR 4734; NISTIR 5153; NISTIR 7682; NISTIR 8301 from FIPS 200; NISTIR 7864; NISTIR 7946; NIST IR 8523 from NIST SP 800-63-4 (adapted); NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000324",
"term": "authentication",
"field": "Cybersecurity",
"definition": "1. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.\n\n2. The process of establishing confidence of authenticity; in this case, the validity of a person’s identity and an authenticator (e.g., PIV Card or derived PIV credential).\n\n3. A security measure designed to protect a communications system against acceptance of fraudulent transmission or simulation by establishing the validity of a transmission, message, originator, or a means of verifying an individual's eligibility to receive specific categories of information.\n\n4. Security measures designed to establish the validity of a transmission, message, or originator, or a means of verifying an individual’s authorization to receive specific categories of\ninformation.\n\n5. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system.\n\n6. The process a VPN uses to limit access to protected services by forcing users to identify themselves.\n\n7. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to a system’s resources.\n\n8. Provides assurance of the authenticity and, therefore, the integrity of data.\n\n9. A process that provides assurance of the source and integrity of information in communications sessions, messages, documents or stored data or that provides assurance of the identity of an entity interacting with a system.\n\n10. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to a system’s resources\n\n11. The process of establishing confidence of authenticity. In this case, it is the validity of a person’s identity and the PIV Card.\n\n12. A process that provides assurance of the source and integrity of information that is communicated or stored or the identity of an entity interacting with a system.\n\n13. Note that in common practice, the term \"authentication\" is used to mean either source or identity authentication only. This document will differentiate the multiple uses of the word by the terms source authentication, identity authentication, or integrity authentication, where appropriate.\n\n14. A process that provides assurance of the source and integrity of information in communications sessions, messages, documents or stored data or that provides assurance of the identity of an entity interacting with a system. See Source authentication, Identity authentication, and Integrity authentication.\n\n15. The process of verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.\n\n16. The act of verifying that the subject has been authorized to use the presented identifier by a trusted identity provider organization.\n\n17. The corroboration that a person is the one claimed.\n\n18. As used in this document, a process that provides assurance of the source and integrity of information that is communicated or stored, or that provides assurance of an entity’s identity.\n\n19. The process by which a claimant proves possession and control of one or more authenticators bound to a subscriber account to demonstrate that they are the subscriber associated with that account.\n\n20. The process of establishing confidence in the identity of users or information systems.\n\n21. The process of verifying a claimed identity of a user, device, or other entity in a computer system\n\n22. the process of verifying the integrity of data that has been stored, transmitted, or otherwise exposed to possible unauthorized access.\n\n23. The process of proving the claimed identity of an individual user, machine, software component or any other entity. Typical authentication mechanisms include conventional password schemes, biometrics devices, cryptographic methods, and onetime passwords (usually implemented with token based cards.)\n\n24. The process of establishing confidence in the claimed identity of a user or system\n\n25. Verifying the identity of a user, process, or device, often as a prerequisite for allowing access to resources in an information system.\n\n26. measures the number of times an attacker must authenticate to a target in order to exploit a vulnerability.\n\n27. The process by which a claimant proves possession and control of one or more authenticators bound to a subscriber account to demonstrate that they are the subscriber associated with that account and involves one or more of the following factors:\ni. something you know (e.g., password/personal identification number (PIN) );\nii. something you have (e.g., cryptographic identification device, token); or\niii. something you are (e.g., biometric).",
"synonyms": [
"authenticate"
],
"references": [
"FIPS 200; NIST SP 1800-10B from FIPS 200; NIST SP 1800-21C; NIST SP 800-128 from FIPS 200; NIST SP 800-137 from FIPS 200; NIST SP 800-30 Rev. 1 from FIPS 200; NIST SP 800-39 from FIPS 200; NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200; NIST SP 800-60 Vol. 2 Rev. 1 from FIPS 200; NIST SP 800-82r3 from FIPS 200",
"FIPS 201-3",
"CNSSI 4009-2022 from CNSSI 4005",
"NIST SP 800-59",
"NIST SP 800-12 Rev. 1 from FIPS 200; NIST SP 800-128 from FIPS 200; NIST SP 800-171r3 from FIPS 200 (adapted); NIST SP 800-172r3 from FIPS 200 (adapted); NIST SP 800-37 Rev. 2 from FIPS 200; NIST SP 800-53 Rev. 5 from FIPS 200; NISTIR 7316",
"NIST SP 800-113",
"NIST SP 1800-16B; NIST SP 1800-16C; NIST SP 1800-16D; NIST SP 1800-17c",
"NIST SP 800-67 Rev. 2",
"NIST SP 800-57 Part 2 Rev.1",
"NIST SP 1800-17b",
"NIST SP 1800-12b",
"NIST SP 800-175B Rev. 1",
"NIST SP 800-57 Part 1 Rev. 5",
"NIST SP 1800-27B from FIPS 200; NIST SP 1800-27C from FIPS 200",
"NIST SP 800-162",
"NIST SP 800-66r2 from HIPAA Security Rule (§164.304)",
"NIST SP 800-175A",
"NIST SP 800-63-4; NIST SP 800-63A-4",
"NISTIR 8149",
"NISTIR 4734",
"NISTIR 5153",
"NISTIR 7682",
"NISTIR 8301 from FIPS 200",
"NISTIR 7864; NISTIR 7946",
"NIST IR 8523 from NIST SP 800-63-4 (adapted)",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/authentication/"
}
Record 324 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.