Skip to main content
Alignment, not accreditation. NIST SP 800-63B specifies requirements for authenticators in a federal digital-identity context and defines Authenticator Assurance Levels (AAL). ZeroKeyUSB is a credential store, not an accredited authenticator, and makes no AAL claim. This page shows how it helps subscribers and organizations follow 800-63B’s good practices.

Where ZeroKeyUSB helps

Honest gaps versus a formal 800-63B authenticator

  • ZeroKeyUSB is not a phishing-resistant cryptographic authenticator (e.g. a FIDO2 key); it types passwords, which are a “memorized secret / look-up secret” style factor.
  • It does not perform online proof-of-possession with a relying party; it augments password-based auth rather than replacing it.
  • The PIN hash is single-pass SHA-256 (not a heavy KDF) and is readable over I²C, so its offline-resistance depends on the physical encapsulation and PIN length — see the Threat model.

Suggested statement

ZeroKeyUSB’s design aligns with NIST SP 800-63B guidance on strong, unique authentication secrets, protected secret storage and rate-limited verification. It is a credential-protection device, not an accredited authenticator, and makes no Authenticator Assurance Level claim.