03.05.04: Replay-Resistant Authentication
Control Family:
Previous Version:
- NIST Special Publication 800-171 Revision 2:
- 3.5.4: Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts
Requirements
- Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.
Discussion
Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges, such as time synchronous or challenge-response one-time authenticators.