The FIDO standards, together with their companion WebAuthn specification, are on the cusp of an important new development: evolutionary changes to the standards proposed by the FIDO Alliance and the W3C WebAuthn community aim to markedly improve the usability and deployability of FIDO-based authentication mechanisms. As a result, FIDO-based secure authentication technology will for the first time be able to replace passwords as the dominant form of authentication on the Internet. 

In this paper, we explain how FIDO and WebAuthn standards previously enabled low-cost deployments of authentication mechanisms with very high assurance levels. While this has proved an attractive alternative to traditional smart card authentication, and even opened the door to high-assurance authentication in the consumer space, we haven’t attained large-scale adoption of FIDO-based authentication in the consumer space. We explain how the introduction of multi-device FIDO credentials will enable FIDO technology to supplant passwords for many consumer use cases as they make the FIDO credentials available to users whenever they need them—even if they replace their device.


More

Passkeys and Verifiable Digital Credentials: A Harmonized Path to Secure Digital Identity

Editors Christine Owen, 1Kosmos Teresa Wu, IDEMIA Public Security Abstract Around the world, government entities…

Read More →

White Paper: Addressing Cybersecurity Challenges in the Automotive Industry

Abstract As the automotive industry transitions toward software-defined vehicles, autonomous technologies, and connected services, cybersecurity…

Read More →

White Paper: DBSC/DPOP as Complementary Technologies to FIDO Authentication

Editors Shane Weeden, IBMAn Ho, IBM Abstract Session hijacking is a growing initial attack vector…

Read More →


12316 Next