Cybersecurity
Published on
01.09.2020

What are the best authentication methods?

Peter Knight

Quick reply

Certificates, two-factor, contextual authentication, biometrics: what each method is worth and which to favour for a given level of risk.

In this article

Using secure passwords is the most widespread authentication method on the web. For some years, though, the hacking of personal data protected by passwords has kept rising. Powerful as the method is when used properly, password protection has flaws that attackers can easily exploit. IT security specialists know that very well, which is why modern authentication methods such as 2FA and the use of tokens have emerged. Here are the most secure authentication methods available today.

Authentication through security certificates

This method is based on using electronic certificates to secure IT resources. It confirms a person's identity before giving them access to a website, a network or a database. The principle rests on a public key and a private key: the first encrypts, the second decrypts.

Only users holding a private key matching the public key of a certificate can therefore reach the content it encrypted. To use this method, companies have to obtain a certificate from a certification authority.

Two-step verification (2FA)

Two-step verification, or 2FA, was created to strengthen the classic single authentication method. It adds a further protective layer to your data. In practice, the locked system asks for two proofs of identity before the user can reach the resource they have requested.

When the user enters the username and password to sign in to their account, a one-time access code is sent automatically to their phone number. They then have to enter that code to open their session. As a rule, the access key has a short lifespan, beyond which it becomes void. Logically enough, without the one-time code nobody can reach the account or the protected data.

This locking method is built into the professional storage platform NetExplorer puts at your disposal. It secures access to your sensitive files and guarantees optimal protection for your collaborative workspace. We also offer encryption with a 2048-bit key to reduce the risk of hacking and traffic interception.

Two-step verification can also draw on authentication factors of different kinds. It might be based on physical proof the user holds (a card, for instance) and a factor inseparable from the person themselves (biometrics). That form of two-factor authentication is the one IT security specialists recommend most, because it almost entirely removes the risk of hacking or of fraudulent access to a private space.

password authentication

Contextual multi-factor authentication

Like classic two-step verification, this technique makes up for the shortcomings of password protection. It lets people sign in whenever and wherever they like, without risk.

Authentication based on risk

Before asking for a further identification factor, a multi-factor authentication tool assesses the risk that the person signing in is not the true owner of the account. To do so, it draws on logical information such as:

  • geolocation,
  • the IP address,
  • the time of the sign-in,
  • the identifiers of the device being used.

So when someone tries to sign in to your company's database from a computer other than the usual one, at a different time of day, a further authentication step kicks in. The system might ask for confidential information only the account owner is supposed to know, for instance. The same happens if someone tries to sign in from a city other than the one the user normally connects from.

A simple method with clear benefits

Because multi-factor authentication measures the level of risk before asking for a more demanding identification step, it makes life easier for people who do not have to identify themselves over and over. When working remotely, they can reach their workspace securely. What is more, with this method you can identify the place, the time and the type of device each person signs in with, which makes fraud easier to spot.

Biometric solutions on the rise

Considered "the authentication method of the future" a few years ago, biometric authentication is now a reality. Easier and safer, the technique relies on the user's unique biological traits to give them access to the contents of a document, for instance. Because biometric information is particular to each individual, the method is all but infallible from a technical point of view.

Depending on the biometric identifier used, there are several authentication methods:

  • fingerprint identification,
  • facial recognition,
  • retinal recognition,
  • voice recognition.

Made possible by special scanners, fingerprint recognition was originally used to secure server rooms and archives. Today, fingerprint scanners are widely deployed in smaller companies, whether for access control or for recording attendance.

Facial recognition is a form of authentication based on analysing facial features that do not change, even with age: cheekbones, the width of the nose, the distance between the eyes, the eyebrows. In a matter of seconds, a facial recognition tool can determine whether a person's face matches the one held in its database. The same principle applies to iris recognition or hand geometry. Voice biometrics, while still evolving, is already in use in several companies: a voice scanner can identify and authenticate a person within seconds.

fingerprint authentication

Unlike classic authentication methods, biometric authentication has the advantage of being quick and therefore less stressful. It has to be used with care, though: a person's biometric data can indeed be stolen, which can harm their privacy and the company along with it.

Conclusion

While no authentication method is 100% safe, some innovative techniques have proved more practical and more secure than the classic approaches. Biometric authentication, which relies solely on what is particular to the individual, is one of them, as is certificate-based authentication. For optimal protection, opt for multi-factor identity verification: the variety of processes makes hacking far more complex.

No items found.
No items found.

Definition

No items found.

FAQ

No questions found.

Best practices / Common pitfalls

No items found.

Key figures

No items found.

Key takeaways

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

You could keep all your documents on a floppy disk.
Vintage office chair with a pile of folders and a beige corded telephone, handset off the hook on red carpet.

But let's be honest, our cloud-based file storage and sharing solution is much easier.