Section 79 of 101
78. User and Service Authentication
Stable section ID: S05-CON-006-SECTION-79 · 25 content blocks
Every human user, software service, robot, AI agent, remote platform, and maintenance tool requesting protected BIOS access shall be authenticated.
Human authentication may include:
password or passphrase;
physical credential;
cryptographic device credential;
biometric factor where appropriate;
local approval;
multi-factor authentication;
- emergency responder credential.
- Service authentication shall use unique machine identities rather than shared general-purpose accounts.
Every authenticated principal shall have:
unique identity;
identity type;
issuing authority;
assigned organization;
permitted authentication methods;
credential status;
validity period;
current session status;
audit history.
Authentication requirements shall reflect consequence. Reading public product information may require little or no authentication, while changing structural configuration, disabling alarms, updating BIOS software, or issuing emergency commands shall require stronger verification.
Remote authentication shall not automatically provide the same authority as authenticated local physical presence.
Shared maintenance accounts shall be avoided because they prevent individual accountability. Where temporary service access is necessary, credentials shall be time-limited and scoped to the relevant equipment.
Authentication sessions shall expire according to risk. Critical actions may require reauthentication even during an active session.
Failed, unusual, or repeated authentication attempts shall be recorded and evaluated for possible attack or credential misuse.