Alignment, not accreditation. NIST SP 800-63B specifies requirements for
authenticators in a federal digital-identity context and defines Authenticator
Assurance Levels (AAL). ZeroKeyUSB is a credential store, not an accredited
authenticator, and makes no AAL claim. This page shows how it helps
subscribers and organizations follow 800-63B’s good practices.
Where ZeroKeyUSB helps
Honest gaps versus a formal 800-63B authenticator
- ZeroKeyUSB is not a phishing-resistant cryptographic authenticator (e.g. a FIDO2 key); it types passwords, which are a “memorized secret / look-up secret” style factor.
- It does not perform online proof-of-possession with a relying party; it augments password-based auth rather than replacing it.
- The PIN hash is single-pass
SHA-256(not a heavy KDF) and is readable over I²C, so its offline-resistance depends on the physical encapsulation and PIN length — see the Threat model.
Suggested statement
ZeroKeyUSB’s design aligns with NIST SP 800-63B guidance on strong, unique authentication secrets, protected secret storage and rate-limited verification. It is a credential-protection device, not an accredited authenticator, and makes no Authenticator Assurance Level claim.