Introducing PIV
The Personal Identity Verification (PIV) specification is a security model published by the National Institutes of Standards and Technology (NIST) designed to solve the security vulnerabilities impacting identity systems while also ensuring interoperability.
Why Use PIV?
PIV drastically increases security by using advanced identity proofing techniques to verify the user, separation of duties to prevent collusion, and an enhanced credential distribution model to prevent an unauthorized user from using a stolen MFA credential.
Finally, the PIV MFA credential can support physical access controls, encryption transactions, and other security features to allow the MFA token to be used for many different security needs.
How PIV Strengthens Traditional MFA
As described previously, the traditional MFA issuance model is typically comprised of a two step issuance model where the credential is given to the user after a basic request. PIV significantly strengthens this model by incorporating three additional security
processes to accurately identify the user, prevent collusion and ensure the token is distributed, and initialized for the proper user.