FIDO2 Authentication & passkeys | OneSpan (2024)

Traditional password-based authentication methods, once considered the cornerstone of online security, are increasingly falling short in the face of sophisticated cyberattacks. Often, the first hurdle in user engagement is the login password. Not only is creating and managing passwords a major annoyance, the login password is also notoriously vulnerable to data breaches.

The FIDO (Fast Identity Online) Alliance is at the forefront of a transformative movement in online security, dedicated to revolutionizing authentication protocols. The FIDO Alliance has developed authentication standards that use public key cryptography to create a more secure and user-friendly alternative to traditional passwords and one-time passcodes (OTP) sent by SMS.

FIDO Authentication is a global authentication standard. With FIDO Authentication, traditional authentication methods such as passwords stored on servers, SMS OTP, and knowledge-based authentication (KBA) are replaced by on-device authentication. This ensures that authentication data remains stored on the user's device – not on a server. Whether your user is a customer or employee, they can now access cryptographic login credentials using local biometrics, PINs, or other mechanisms.

In essence, FIDO Authentication offers an interoperable and standardized ecosystem of authenticators. With it, organizations can deploy strong authentication (also known as multi-factor authentication or MFA) for login, without the incremental cost of in-house development.

Introducing FIDO2 passkeys

The Alliances’ latest addition, FIDO2 passkeys, signifies a departure from conventional password-based authentication methods. FIDO2 passkeys offer a passwordless authentication solution that is both highly secure and user-friendly.

At the heart of FIDO2 passkeys lies public key cryptography, an encryption method that uses pairs of cryptographic keys to authenticate users.

When setting up a FIDO2 passkey, a unique pair of keys is generated: a public key stored securely with the online service and a private key retained by the user's device.

During authentication, the user's device signs a challenge issued by the service using the private key, and the service verifies the signature using the stored public key. This process eliminates the need for passwords entirely, greatly reducing the risk of unauthorized access. Hence why we refer to it as phishing resistant.

Benefits of FIDO2 passkeys

  • Enhanced Security: FIDO2 ensures that cryptographic login credentials are unique for each website, remain on the user's device, and are never stored on a server. This approach stops phishing, password theft, credential stuffing and replay attacks.
  • Convenience: Users can authenticate via simple, built-in methods such as fingerprint readers or facial recognition, or through FIDO security keys tailored to individual preferences. They no longer need to remember complex passwords.
  • Privacy: FIDO Authentication safeguards privacy by ensuring that cryptographic keys are website-specific, preventing cross-site tracking. When biometrics are used, the data does not leave the user's device.
  • Interoperability: FIDO2 passkeys are supported by a growing number of online services and platforms, making them a versatile authentication solution for both consumers and enterprises.
  • Scalability: Enabling FIDO2 on websites is straightforward, requiring just a simple JavaScript API call. This is supported across leading browsers and platforms, making it accessible on billions of devices globally.

How FIDO2 passkeys and passwordless authentication work with WebAuthn CTAP

FIDO2 combines the W3C's (World Wide Web Consortium) Web Authentication (WebAuthn) specification and the FIDO Alliance's Client-to-Authenticator Protocol (CTAP). Together, these specifications enable FIDO2 passkeys to seamlessly integrate with web-based authentication workflows. The result is a secure, straightforward, and scalable authentication process.

Here’s how they work together:

  • WebAuthn enables passwordless authentication experiences on the web, eliminating the reliance on passwords and enhancing security. WebAuthn is a W3C standard, implemented in major web browsers such as Microsoft Edge, Google Chrome, and Apple’s Safari. It defines a web API for creating and using strong, public-key-based credentials for authenticating users.

    With WebAuthn, websites can request and obtain cryptographic credentials (public and private key pairs) from FIDO2 authenticators during user registration. During authentication, WebAuthn allows websites to challenge users by sending a cryptographic challenge to the authenticator, which the user's device signs with the private key and sends back to the website for verification.

  • The CTAP (Client-to-Authenticator Protocol) is defined by the FIDO Alliance and facilitates communication between client devices, such as computers or mobile devices, and authenticator devices, such as USB security keys or biometric sensors. CTAP is responsible for handling the communication between the user's device (client) and the FIDO2 authenticator during authentication transactions. When a website initiates a WebAuthn authentication request, the client device communicates with the FIDO2 authenticator using CTAP to perform the necessary cryptographic operations.

Combat social engineering with phishing-resistant FIDO2 passkeys

FIDO2 passkeys are often referred to as the gold standard in protecting employees and consumers against phishing attacks. Unlike passwords, which can be easily phished or intercepted, FIDO2 passkeys rely on public key cryptography to authenticate users securely. This means that even if a malicious actor attempts to trick someone into providing their passkey through a phishing website or email, the cryptographic nature of FIDO2 passkeys safeguards that sensitive authentication information.

We live in a time when generative AI and machine learning are exploited by fraudsters to create more sophisticated and personalized phishing campaigns. The cryptographic underpinnings of FIDO2 passkeys make them resistant to automated phishing attempts. As an additional security measure, FIDO2 passkeys can be setup to require user interaction at the time of authentication, thwarting malicious bots seeking to exploit vulnerabilities.

By mitigating the risk of phishing attacks, FIDO2 passkeys bolster online security, providing a better user experience and greater peace of mind for business and government organizations.

FIDO2 Authentication from OneSpan

As a board member of the FIDO Alliance and an active participant in various FIDO2 working groups, OneSpan is part of FIDO’s initiative to standardize the authentication industry. OneSpan first addition to its FIDO2 passkey portfolio is DIGIPASS FX1 BIO. This cutting-edge physical passkey with fingerprint scan empowers organizations to embrace passwordless authentication while providing the strongest security against social engineering and account takeover attacks.

We also offer full FIDO capabilities as part of OneSpan Mobile Security Suite. This means organizations can implement passwordless authentication to enhance customer and employee experience by replacing static passwords with modern capabilities such as biometrics, while also protecting their mobile apps against phishing, adversary-in-the-middle, and replay attacks.

FIDO-certified authentication methods are supported out-of-the box as they come to market. Because of standardization, any application can work with any of the user's devices (iOS and Android), operating systems, and any authenticator. This gives organizations and service providers a plethora of choices on how to approach passwordless authentication. Visit our FIDO authentication page to learn more about FIDO for passwordless login, including FIDO2, FIDO U2F (universal second factor), and FIDO UAF (universal authentication framework) solutions.

Visit our FIDO authentication page to learn more about FIDO for passwordless login, including FIDO2, FIDO U2F (universal second factor), and FIDO UAF (universal authentication framework) solutions.

FIDO2 Authentication & passkeys | OneSpan (1)

FIDO AUTHENTICATION

Solutions based on the FIDO standard for simpler, stronger authentication using an open, scalable, and interoperable approach

Learn more

FIDO2 Authentication & passkeys | OneSpan (2024)
Top Articles
Will This Affect My Credit Score? Find Out What's NOT Included. | myFICO
If You'd Bought $1,000 Worth of Stellar (XLM) 5 Years Ago, Here's How Much You'd Have Now
Sound Of Freedom Showtimes Near Governor's Crossing Stadium 14
Best Big Jumpshot 2K23
Mate Me If You May Sapir Englard Pdf
³µ¿Â«»ÍÀÇ Ã¢½ÃÀÚ À̸¸±¸ ¸íÀÎ, ¹Ì±¹ Ķ¸®Æ÷´Ï¾Æ ÁøÃâ - ¿ù°£ÆÄ¿öÄÚ¸®¾Æ
Fort Carson Cif Phone Number
Davante Adams Wikipedia
Hawkeye 2021 123Movies
Umn Pay Calendar
Lesson 3 Homework Practice Measures Of Variation Answer Key
Jet Ski Rental Conneaut Lake Pa
Jessica Renee Johnson Update 2023
World History Kazwire
Facebook Marketplace Charlottesville
Pro Groom Prices – The Pet Centre
Nwi Arrests Lake County
Viprow Golf
iLuv Aud Click: Tragbarer Wi-Fi-Lautsprecher für Amazons Alexa - Portable Echo Alternative
Leader Times Obituaries Liberal Ks
How Much You Should Be Tipping For Beauty Services - American Beauty Institute
Effingham Bookings Florence Sc
1989 Chevy Caprice For Sale Craigslist
Noaa Duluth Mn
Euro Style Scrub Caps
Morse Road Bmv Hours
TeamNet | Agilio Software
Elbert County Swap Shop
Colonial Executive Park - CRE Consultants
1979 Ford F350 For Sale Craigslist
Is Henry Dicarlo Leaving Ktla
Cylinder Head Bolt Torque Values
Jailfunds Send Message
Albertville Memorial Funeral Home Obituaries
897 W Valley Blvd
Promatch Parts
Stolen Touches Neva Altaj Read Online Free
Bus Dublin : guide complet, tarifs et infos pratiques en 2024 !
404-459-1280
No Hard Feelings Showtimes Near Tilton Square Theatre
Gets Less Antsy Crossword Clue
Htb Forums
968 woorden beginnen met kruis
Elven Steel Ore Sun Haven
Gas Buddy Il
RubberDucks Front Office
Germany’s intensely private and immensely wealthy Reimann family
ESPN's New Standalone Streaming Service Will Be Available Through Disney+ In 2025
Dmv Kiosk Bakersfield
99 Fishing Guide
Coldestuknow
Latest Posts
Article information

Author: Jonah Leffler

Last Updated:

Views: 6105

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Jonah Leffler

Birthday: 1997-10-27

Address: 8987 Kieth Ports, Luettgenland, CT 54657-9808

Phone: +2611128251586

Job: Mining Supervisor

Hobby: Worldbuilding, Electronics, Amateur radio, Skiing, Cycling, Jogging, Taxidermy

Introduction: My name is Jonah Leffler, I am a determined, faithful, outstanding, inexpensive, cheerful, determined, smiling person who loves writing and wants to share my knowledge and understanding with you.