What is Two-factor Authentication (2FA)? How does it work? | Fortinet (2024)

Different Types of Two-Factor Authentication

There are several types of 2FA that can be used to further confirm that a user is who they claim to be. Some of the simpler examples include answering security questions and providing one-time codes. Others use various types of tokens and smartphone applications. Common 2FA types include the following:

1. Hardware tokens for 2FA

Hardware tokens are one of the original types of 2FA formats. They are typically small key-fob devices that generate a unique numerical code every 30 seconds. When a user submits their first authentication request, they can head over to the key fob and issue the code it is displaying. Other forms of hardware tokens include universal serial bus (USB) devices that, when inserted into a computer, automatically transfer an authentication code.

An example of this is YubiKey, which is short for ubiquitous key, a security key that enables users to add a second factor of authentication to services like Amazon, Google, Microsoft, and Salesforce. The USB device is used when users log in to a service that supports one-time passwords (OTPs), such as GitHub, Gmail, or WordPress. The user plugs the YubiKey into their USB port, enters their password, clicks the YubiKey field, and touches a button on the device. It generates a 44-character OTP and automatically enters it on the user’s device to verify them with a possession 2FA factor.

Hardware token devices are generally expensive for organizations to distribute. Furthermore, they are easily lost by users and can themselves be cracked by hackers, making them an insecure authentication option.

2. Text message and SMS 2FA

Short message service (SMS) and text message 2FA factors are generated when a user attempts to log in to an application or service. An SMS message will be sent to their mobile device containing a unique code that the user then enters into the application or service. This 2FA factor type has been used by banks and financial services to verify purchases or changes that customers made to their online banking accounts. However, they are generally moving away from this option, given the ease with which text messages can be intercepted.

Similar to the SMS factor is voice call 2FA. When a user enters their login credentials, they will receive a call to their mobile device that tells them the 2FA code they need to enter. This factor is used less frequently but is deployed by organizations in countries that have low smartphone usage levels.

3. Push notifications for 2FA

A more commonly used passwordless two-step authentication format is push notifications. Rather than receiving a code on their mobile device via SMS or voice, which can be hacked, users can instead be sent a push notification to a secure app on the device registered to the authentication system. The notification informs the user of the action that has been requested and alerts them that an authentication attempt has taken place. Then, they simply approve or deny the access request.

This authentication format creates a connection between the app or service the user is attempting to access, the 2FA service provider, the user themselves, and their device. It is user-friendly and reduces the possibility of security risks like phishing, man-in-the-middle (MITM) attacks, social engineering, and unauthorized access attempts.

This authentication format is more secure than SMS or voice calls but still carries risks. For example, it is easy for a user to accidentally confirm an authentication request that has been fraudulently requested by quickly tapping the approve button when the push notification appears.

4. 2FA for mobile devices

Smartphones offer a variety of possibilities for 2FA, enabling companies to use what works best for them. Some devices are capable of recognizing fingerprints. A built-in camera can be used for facial recognition or iris scanning, and the microphone can be used for voice recognition. Smartphones equipped with a Global Positioning System (GPS) can verify location as an additional factor. Voice or SMS may also be used as a channel forout-of-band authentication.

A trusted phone number can be used to receive verification codes by text message or automated phone call. A user has to verify at least one trusted phone number to enroll in 2FA.Apple iOS, Google Android, and Windows 10 all have applications that support 2FA, enabling the phone itself to serve as the physical device to satisfy the possession factor.

Ann Arbor, Michigan-based Duo Security, which was purchased by Cisco in 2018 for $2.35 billion, is a 2FA platform vendor whose product enables customers to use their trusted devices for 2FA. Duo's platform first establishes that a user is trusted before verifying that the mobile device can also be trusted for authenticating the user.

Authenticator applications replace the need to obtain a verification code via text, voice call, or email. For example, to access a website or web-based service that supports Google Authenticator, users type in their username and password—a knowledge factor. Users are then prompted to enter a six-digit number. Instead of having to wait a few seconds to receive a text message, an authenticator generates the number for them. These numbers change every 30 seconds and are different for every login. By entering the correct number, users complete the verification process and prove possession of the correct device—an ownership factor.

Figure 1. Demonstarting SD WAN Use

What is Two-factor Authentication (2FA)? How does it work? | Fortinet (2024)
Top Articles
BPI Help And Support
Early findings from the world’s largest UBI study | GiveDirectly
Places 5 Hours Away From Me
Television Archive News Search Service
Missing 2023 Showtimes Near Cinemark West Springfield 15 And Xd
Craigslist Benton Harbor Michigan
Arrests reported by Yuba County Sheriff
Horned Stone Skull Cozy Grove
Scentsy Dashboard Log In
Natureza e Qualidade de Produtos - Gestão da Qualidade
Alaska Bücher in der richtigen Reihenfolge
litter - tłumaczenie słowa – słownik angielsko-polski Ling.pl
What’s the Difference Between Cash Flow and Profit?
Zendaya Boob Job
Bros Movie Wiki
How Many Slices Are In A Large Pizza? | Number Of Pizzas To Order For Your Next Party
Builders Best Do It Center
Hair Love Salon Bradley Beach
Gon Deer Forum
Bfg Straap Dead Photo Graphic
Payment and Ticket Options | Greyhound
Po Box 35691 Canton Oh
Mals Crazy Crab
Water Days For Modesto Ca
Kirksey's Mortuary - Birmingham - Alabama - Funeral Homes | Tribute Archive
Walmart Car Department Phone Number
Optum Urgent Care - Nutley Photos
All Breed Database
Construction Management Jumpstart 3Rd Edition Pdf Free Download
Cain Toyota Vehicles
kvoa.com | News 4 Tucson
Word Trip Level 359
Gwen Stacy Rule 4
Of An Age Showtimes Near Alamo Drafthouse Sloans Lake
Gideon Nicole Riddley Read Online Free
Haley Gifts :: Stardew Valley
Senior Houses For Sale Near Me
Metro 72 Hour Extension 2022
Stafford Rotoworld
Main Street Station Coshocton Menu
Walgreens Agrees to Pay $106.8M to Resolve Allegations It Billed the Government for Prescriptions Never Dispensed
Wasmo Link Telegram
Bob And Jeff's Monticello Fl
Kenner And Stevens Funeral Home
Quick Base Dcps
Why Are The French So Google Feud Answers
Southwest Airlines Departures Atlanta
Human Resources / Payroll Information
Costner-Maloy Funeral Home Obituaries
El Patron Menu Bardstown Ky
Bama Rush Is Back! Here Are the 15 Most Outrageous Sorority Houses on the Row
Ciara Rose Scalia-Hirschman
Latest Posts
Article information

Author: Carmelo Roob

Last Updated:

Views: 5812

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Carmelo Roob

Birthday: 1995-01-09

Address: Apt. 915 481 Sipes Cliff, New Gonzalobury, CO 80176

Phone: +6773780339780

Job: Sales Executive

Hobby: Gaming, Jogging, Rugby, Video gaming, Handball, Ice skating, Web surfing

Introduction: My name is Carmelo Roob, I am a modern, handsome, delightful, comfortable, attractive, vast, good person who loves writing and wants to share my knowledge and understanding with you.