Authentication

Authentication is the process of verifying the identity of a user or system. The aim is to ensure that a person or a service actually possesses the identity that it claims.

The verification relies on factors from three categories: knowledge (password, PIN), possession (smartphone, hardware token, certificate) and inherence (biometric features). While the password dominated for a long time, multi-factor authentication and passwordless methods are now considered the state of the art for protecting accounts. Authentication must be distinguished from authorization: the former clarifies who is accessing a system – the latter, what that user may access.

As the first protective mechanism against unauthorized access, authentication is the foundation of every Identity Security strategy. In modern architectures, authentication is no longer understood as a one-time event at login, but is repeated depending on context and adapted in strength to the respective risk.