The Best Cybersecurity Solution for the Internet Era (1): An In-Depth Look at FIDO (Part 2)

The Best Cybersecurity Solution for the Internet Era (1) An In-Depth Look at FIDO (Part 2)200

How FIDO Registration Works

When a user wants to register for a FIDO-enabled service, the overall process is roughly as follows:

  1. The user fills in the registration information. The service application then asks the user to choose a FIDO authenticator device that can be used for FIDO authentication, such as a smartphone, a security key, or a TPM.

  2. After the user selects an authenticator device, the FIDO device generates a secure key pair.

  3. The user’s device sends the public key to the service application. The public key is then registered in the user database and linked to the user’s account.

  4. The authentication process is performed by the user’s security key. The private key and the user’s personal information—such as fingerprint or facial data—never leave the user’s device for transmission.

FIDO Authentication Process

The core of a FIDO solution is that the user and the server never exchange sensitive information such as passwords or private keys, ensuring maximum protection of user data.

Therefore, FIDO authentication involves three key elements: a FIDO authentication server, a FIDO client, and an authenticator. When a user logs in, the process is as follows:

  1. The user submits a login request using an account name or email address.

  2. The service application provides an encrypted authentication challenge (signature).

  3. The user uses an app or key on the FIDO authenticator device to sign the challenge.

  4. After signing, the user sends the signed response back to the service application.

  5. The service application verifies the signature using the public key corresponding to the user’s private key. If verification succeeds, the user is granted access.

Security Levels of FIDO Authenticator Devices

Although all FIDO authenticators provide security, they are classified into different levels. The most secure level is Level 3 or above, which can prevent physical tampering and data extraction.

Level 1

Any software- or hardware-based authenticator that implements FIDO2, UAF, or U2F standards. This is the baseline level for FIDO authenticators and helps protect users against phishing, server breaches, and Man-in-the-Middle (MitM) attacks.

Level 2

Level 2 adds extra measures beyond Level 1 to protect security keys against more advanced attacks. FIDO solutions at this level can defend against malware that attempts to obtain data by accessing the device.

Level 3

Authenticators at this level can protect the user’s security keys against basic hardware attacks. They can prevent physical modification or hardware manipulation by attackers. If an attack occurs, it will at least leave clear evidence.

Level 3+

This is the highest security level among FIDO authenticators. Devices at this level must store security keys in a Trusted Platform Module (TPM), preventing any type of physical tampering or data extraction.

The Value and Future Development of FIDO

In the past, one challenge for the FIDO standard was that even though it was strongly supported by industry, it still lacked sufficient common standards in some areas. With the involvement of international internet organizations such as W3C and ITU, the influence of the FIDO Alliance has expanded, driving new global thinking about password usage and drawing more attention to the potential of FIDO identity solutions.

Today, for example, the messaging platform LINE, which has a large user base, has begun offering passwordless solutions based on the FIDO standard. This allows users to log in using fingerprint authentication or facial recognition to address security concerns.

The financial sector, with its strict security requirements, has also adopted FIDO. In Taiwan, applications such as CTBC Bank’s Home Bank App and Cathay United Bank’s KOKO App have completed implementation, allowing users to log in or transfer funds using FIDO solutions.

For enterprise users, FIDO solutions provide strong security protection and are currently most commonly adopted in B2B scenarios. However, FIDO also offers enormous potential for convenience. For B2C businesses such as e-commerce and shopping platforms, reducing friction in customer journeys—such as login and payment—can improve shopping experiences and increase conversion opportunities. The same idea applies across many other industries.

In the future, as more FIDO solutions are deployed, the world will become more convenient and secure. It is easy to imagine a time when we no longer need to remember countless passwords, while still achieving strong personal data protection.

訂閱偉康科技洞察室部落格,掌握最新科技趨勢!

專人協助

由偉康業務人員為您詳細說明偉康的解決方案,以及相關產業經驗。

立即訂閱電子報

掌握最新科技趨勢!