Overview

Security Requirements for 03.05.04 Replay-Resistant Authentication

Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges such as time synchronous or challenge-response one-time authenticators.[SP 800-63-3] provides guidance on digital identities.

Evidence

  1. 03.05.04.a

    Replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts