The Basics of Multi-Factor Authentication

Share:

Are you who you say you are?

It sounds dramatic, but you’re asked this question hundreds of times a month by your company network, your phone, your bank, your email account and more. Authentication is the “assurance and confirmation of a user’s identity.”1

3 Factors of Authentication

It’s always more secure to use two or multiple factors of authentication instead of one. For example, an ATM uses two-factor authentication, since it requires your debit card (something you have) and your PIN (something you know).

illustration of a man that has three factors of authentication
The Federal Financial Institutions Examination Council (FFIEC) defines three factors of authentication. The factors are something the user:2

  • Knows – A password, PIN or an answer to a secret question.
  • Has – An access card or USB key.
  • Is – Facial features, eye structure or fingerprints.

In its guide to authentication, Okta adds a type – something the user does, also called behavioral biometrics.3 To discuss the types of authentication, I’ll use the FFIEC’s framework and combine what a user is and what a user does into one category.

Type 1: Something the User Knows

Password

Password authentication uses the Password Authentication Protocol (PAP), which sends the username and password to the server to check its validity.4

According to a study from NordPass, the average person has 100 passwords to remember.5 The sheer number of online accounts (for work and personal life) can tempt users to create guessable passwords, compromising security. It’s important for organizations to encourage users to create complex, long and unique passwords.

One-Time Password (OTP)

In one-time password (OTP) authentication, the user receives a unique password from a text message, application or email.

The time-based one-time password (TOTP) adds a time limit to the password, making it more secure.6

CAPTCHA and reCAPTCHA

CAPTCHA stands for the Completely Automated Public Turing test to tell Computers and Humans Apart.7 Created in 2000,8 its purpose is to distinguish human website visitors from bots by giving a task that people can pass easily but bots cannot.

reCAPTCHA has a “risk analysis engine” that can predict whether a user is human or not. If it can’t decide, it prompts a CAPTCHA.9

Single Sign-On (SSO)

With single sign-on, users use one password to authenticate with and access multiple applications and websites.10 To use SSO, organizations choose an identity provider, which exchanges a certificate with the application or website to authenticate.

SSO has strong advantages and disadvantages. By only using one password, employees can focus more on their work and avoid constantly resetting passwords. However, if employees use weak passwords, a hacker can access multiple systems quickly.

Type 2: Something the User Has

Certificate

To access resources from servers, a client receives a physical or electronic certificate from the network’s security server. Any other server in the network can validate the certificate and establish the connection.11

Security Token

Security tokens are like certificates, but they include information about what the user can access. The user plugs a USB key or other device into their laptop to get access to a network.12

Public Key and Private Key

Public key authentication includes two types of keys: one public and one private. Anyone can see the public key, but the private key is secret. The private key generates a signature that can’t be created by anyone who doesn’t have it. The public key is used to verify the signature’s authenticity.

Public key authentication is preferred over password authentication because signatures can’t be reused. Hackers who find used signatures can’t access the server.

Type 3: Something the User Is or Does

Physical Biometrics

Physical biometrics include facial features, eye structure, fingers (especially fingerprints), hand shape and more. Because physical biometrics are inseparable from the user, they provide more certainty and less risk than other types of authentication.13

Behavioral Biometrics

Behavioral biometrics track a user’s unique actions – their typing speed or force of pressing keys, for example – to verify identity. To implement behavioral biometrics, devices record how a user typically behaves and compare it to the user’s actions throughout the session.14

The Future of Authentication

Microsoft and Apple are taking steps toward a passwordless future, but it may take years before passwords are fully replaced.15 Some experts are interested in replacing passwords with biometrics for authentication.

Regardless of which type of authentication is preferred in the future, its importance will only grow as data security becomes a bigger concern. As a managed file transfer (MFT) company, the security of our customers’ data is crucial.

illustration of login screen on monitor surrounded around fingerprint key certificates lockWe support these types of authentication:

  • Multi-factor
  • Single sign-on (SSO)
  • Password
  • Key
  • Certificates

Learn more about our secure file transfer and compliance stance.

 

1 https://www.sangfor.com/en/info-center/blog-center/cyber-security/the-basics-of-authentication-in-cyber-security
2 https://www.ffiec.gov/pdf/authentication_guidance.pdf
3 https://www.okta.com/blog/2019/02/the-ultimate-authentication-playbook/
4 Pastore, Mike, and Emmett Dulaney. CompTIA Security+ Study Guide, 3rd Edition for Exam SYO-101. Sybex, 2006.
5 https://tech.co/news/average-person-100-passwords
6 https://www.thalesgroup.com/en/markets/digital-identity-and-security/technology/otp
7 https://www.imperva.com/learn/application-security/what-is-captcha/
8 https://phys.org/news/2012-06-captcha-story-squiggly-letters.html
9 https://security.googleblog.com/2014/12/are-you-robot-introducing-no-captcha.html
10 https://www.onelogin.com/learn/how-single-sign-on-works
11 Pastore, Mike, and Emmett Dulaney. CompTIA Security+ Study Guide, 3rd Edition for Exam SYO-101. Sybex, 2006.
12 Pastore, Mike, and Emmett Dulaney. CompTIA Security+ Study Guide, 3rd Edition for Exam SYO-101. Sybex, 2006.
13 https://recfaces.com/articles/types-of-biometrics#3
14 https://recfaces.com/articles/types-of-biometrics#3
15 https://www.wired.com/story/passwords-not-dead-yet-authentication/

Share:
Scroll to Top