Device Authentication
What is Device Authentication?
The process of verifying the identity of a hardware device connecting to a network or system before granting it access to resources.
Terms that appear alongside device authentication
Each of these is named in at least one of the same controls as device authentication. The number is how many controls name both.
- authentication 12 shared controls
- access control 4 shared controls
- oauth 2 shared controls
- multi factor authentication 2 shared controls
- saml 2 shared controls
- tls 2 shared controls
- biometric authentication 2 shared controls
- nist 2 shared controls
Frameworks that govern device authentication
What the standards actually require on device authentication
Requirements naming device authentication across 6 standards, quoted from the control text.
Validate device identity and posture during enrollment and at access time before granting access to enterprise resources.
800-124r2-3.2 · Device Authentication and Enrollment →POI devices must authenticate to the decryption environment or processor using strong cryptographic mechanisms to prevent rogue device connections from injecting fraudulent transactions.
Domain-2.2 · POI Device Authentication →Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →Deploy port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication.
CIS-13.9 · Deploy Port-Level Access Control →CTAP2 transports define how the client communicates with the authenticator. USB-HID: USB Human Interface Device class for security keys (YubiKey + Token2 + Feitian + SoloKeys + Trezor + others); FIDO2 HID protocol with CTAPHID frames.
FIDO2-CTAP2-Transport · CTAP2 Transports (USB-HID, NFC, BLE, Hybrid / caBLE, Platform-internal) →UR E26 Goal 2 (Protect) requires access control + authentication + authorization mechanisms for all CBS. Unique user identification (no shared accounts where feasible); strong password policy (per NIST SP 800-63B + IEC 62443 + ship operational reality);
IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles · IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management →Questions people ask about device authentication
What is Device Authentication?
Why is Device Authentication important for compliance?
Which compliance frameworks address Device Authentication?
Where can I learn more about Device Authentication?
See how Device Authentication applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.