Unequivocally, a single man in possession of a strong password is not enough to solve the issue of security. Studies indicate that passwords have been subjected to various attacks, regardless of the applied protection mechanisms due to the human factor. The keystone for the adoption of more efficient authentication methods by the different markets is the trade-off between security and usability. To bridge the gap between user-friendly interfaces and advanced security features, the Fast Identity Online (FIDO) alliance defined several authentication protocols. Although FIDO's biometric-based authentication is not a novel concept, still daunts end users and developers, which may be a contributor factor obstructing FIDO's complete dominance of the digital authentication market. This paper traces the evolution of FIDO protocols, by identifying the technical characteristics and security requirements of the FIDO protocols throughout the different versions while providing a comprehensive study on the different markets (e.g., digital banking, social networks, e-government, etc.), applicability, ease of use, extensibility and future security considerations. From the analysis, we conclude that there is currently no dominant version of a FIDO protocol and more importantly, earlier FIDO protocols are still applicable to emerging vertical services.
翻译:研究显示,密码受到各种攻击,而不管出于人的因素而采用何种保护机制。不同市场采用更有效的认证方法的关键在于安全与可用性之间的权衡。为了缩小方便用户的界面与先进的安全特征之间的差距,快速身份在线联盟界定了若干认证协议。虽然基于生物鉴别的认证不是一个新概念,但最终用户和开发商仍然在躲藏,这可能是阻碍FIDO在数字认证市场中完全占支配地位的一个因素。本文记录了FIDO协议的演变过程,通过查明不同版本FIDO协议的技术特点和安全要求,同时对不同的市场(例如数字银行、社会网络、电子政府等)、适用性、易用性、可扩展性和未来安全考虑进行全面研究。我们从分析中得出结论,目前FIDO协议没有主导版本,而且更重要的是,远前的FIDO协议正在成为纵向协议。