Mobile Application Single Sign-On

Download the Practice Guide

The NCCoE has released a second draft of NIST Cybersecurity Practice Guide SP 1800-13, Mobile Application Single Sign-On. Use the buttons below to view this publication in its entirety, or scroll down for links to individual sections.

Download PDF » Open Web Version »

Current Status

The NCCoE recently released a second draft of NIST Cybersecurity Practice Guide SP 1800-13, Mobile Application Single Sign-On: Improving Authentication for Public Safety First Responders. This revision of the guide was updated at request of the public safety community to incorporate iOS version 12. The project's public comment period closed on June 28, 2019. 

  • SP 1800-13A: Executive Summary (PDF) (web page)
  • SP 1800-13B: Approach, Architecture, and Security Characteristics (PDF) (web page)
  • SP 1800-13C: How-To Guides (PDF) (web page)

Or download the complete guide (PDF).

If you have questions or suggestions, please email us at psfr-nccoe@nist.gov.

Summary

On-demand access to public safety data is critical to ensuring that public safety and first responder (PSFR) personnel can deliver the proper care and support during an emergency. This requirement necessitates heavy reliance on mobile platforms that may be used by PSFR personnel to access sensitive information, such as personally identifiable information, law enforcement sensitive information, and protected health information. However, complex authentication requirements can hinder the process of providing emergency services, and any delay—even seconds—can become a matter of life or death.

In collaboration with NIST’S Public Safety Communications Research lab and industry stakeholders, the NCCoE aims to help PSFR personnel efficiently and securely gain access to mission data via mobile devices and applications. This practice guide describes a reference design for multifactor authentication and mobile single sign-on for native and web applications while improving interoperability among mobile platforms, applications, and identity providers, regardless of the application development platform used in their construction. This NCCoE practice guide details a collaborative effort between the NCCoE and technology providers to demonstrate a standards-based approach that uses commercially available and open‑source products.

Watch our RSA Conference 2018 project presentation and demonstration on mobile SSO for the public safety sector

Watch our RSA Conference 2018 project presentation and demonstration on mobile SSO for the public safety sector

Collaborating Vendors

Organizations participating in this project submitted their capabilities in response to an open call in the Federal Register for all sources of relevant security capabilities from academia and industry (vendors and integrators). The following respondents with relevant capabilities or product components (identified as “Technology Partners/Collaborators” herein) signed a Cooperative Research and Development Agreement to collaborate with NIST in a consortium to build this example solution.

Motorola Solutions logo
Nok Nok Labs logo
Ping Identity logo
StrongKey logo
Yubico logo