The requirement of a Government-wide means of authenticating federal employees and contractors stated by HSPD-12 is traditionally met by PIV smartcards in civilian agencies and CAC smartcards in the Department of Defense. But there are substantial obstacles to using a smartcard for authentication when an information system is accessed via a mobile device. NIST is investigating alternative authentication methods that rely on derived credentials not contained in smartcards. In this paper we propose three techniques that can facilitate the implementation, deployment and use of derived credentials. The rst technique eliminates the administrative cost that would be incurred by having to issue certicates to the mobile devices owned by