The Best Cybersecurity Solution for the Internet Era (1): An In-Depth Look at FIDO (Part 1)

The Best Cybersecurity Solution for the Internet Era (1) An In-Depth Look at FIDO (Part 1)1200

Introduction to FIDO

FIDO stands for Fast IDentity Online. It replaces traditional password-based logins with a fast and secure sign-in experience that works across websites and applications.

In practice, FIDO is not a specific product. Instead, it is an open technical standard developed by the FIDO Alliance, defining authentication solutions that reduce reliance on passwords. Only solutions that meet the standard can be called FIDO Certified.

The core idea behind FIDO is: user credentials are stored on the user’s hardware device, not on an online server. During authentication, there is no transmission of sensitive verification data—so the chance of data theft can be minimized.

FIDO can be applied broadly. Anywhere passwords and authentication are required, FIDO can be used, balancing both security and convenience. As a result, it is increasingly adopted in industries with high security requirements, such as finance and technology.

What Is FIDO?

As technology advances, passwords are used more and more frequently. But traditional passwords come with many problems, for example:

  • Password rules can be so complex that users easily forget them

  • Requirements like mixing letters, numbers, and symbols make them inconvenient

  • Even with complexity, passwords still may not fully block online threats

To improve security, service providers often add a “second door,” such as OTP verification or two-step verification, on top of the password. However, this typically improves security at the cost of convenience, and still doesn’t eliminate the fundamental weaknesses of passwords.

As mentioned in earlier articles, even two-factor verification cannot completely prevent threats. Verification codes may still be stolen through phishing, allowing attackers to take over accounts and steal data.

To address these issues, cybersecurity experts continually refine login and verification methods. Roughly every 10 years, a new wave of change emerges to solve password security problems. The latest trend is to abandon traditional passwords and move toward solutions based on passwordless authentication and zero-trust security models. FIDO is a standards-based solution that was created under these two concepts.

Traditional password login works by comparing the username and password a user enters with stored verification data. After identification and verification, the user is allowed to log in. This means that anyone who knows the username and password can pass authentication, even if they are not the real account owner. And aside from IP location, it can be difficult to trace which endpoint performed the login.

FIDO’s advantage is that authentication is performed by the user’s hardware device, and identity is verified online through a public–private key mechanism. Because the data needed for verification is stored on the user’s device and is not transmitted over the network, it is less likely to be leaked.

At this point, two questions may arise:

  1. If a physical device is lost, wouldn’t data leak, how is that secure?

  2. If authentication requires a physical device, doesn’t that add burden and reduce convenience?

In reality, the widespread adoption of mobile devices addresses these concerns well. Today, almost everyone has a smartphone, and phones can also be used with FIDO, so users don’t need to buy or carry extra devices, achieving both convenience and security. In addition, advances in biometrics mean that most phones can be unlocked using “inherence factors” such as fingerprints or facial recognition. FIDO can integrate with these mechanisms, making it difficult for others to access data even if the device is lost.

The FIDO Alliance

When talking about FIDO, you can’t ignore the FIDO Alliance:

The FIDO Alliance is an open, non-profit industry consortium. Its founders include PayPal and the founder of Lenovo, and it was established in February 2013. Other well-known members include major service providers such as Google, Apple, and Microsoft.

The FIDO Alliance aims to achieve its main mission in the following ways: develop and promote authentication standards to help industries and services worldwide reduce reliance on passwords.

  • Define technical standards to establish an open, scalable, interoperable mechanism that reduces dependence on passwords for user authentication

  • Implement an industry certification program to help ensure successful global adoption of the standards

  • Submit mature technical standards to recognized standards bodies to formalize FIDO as an official standard

In 2018, the International Telecommunication Union (ITU) also adopted FIDO UAF and FIDO2 CTAP2/U2F as official standards.

Thanks to the standards established by the FIDO Alliance, diverse passwordless solutions around the world can follow a unified standard—helping enterprises choose solutions that fit their needs and providing stronger protection for end users.

FIDO Specifications

FIDO is a solution standard with a variety of specifications for web and mobile environments. Key components include:

  • U2F: Standard specifications for physical two-factor authentication (2FA) security keys

  • UAF: Standard specifications for passwordless authentication technologies

  • FIDO 2.0:

    • WebAuthn: A standardized set of Web APIs that enable passwordless authentication in browsers

    • CTAP1: The U2F standard from FIDO 1.0, retained in FIDO2 and renamed

CTAP2: Specifications enabling 2FA and passwordless authentication using physical keys and mobile authenticator applications

UAF and U2F

The standards commonly referred to as “FIDO” were released in 2014 and consisted of:

  • Universal Authentication Framework (UAF)

  • Universal 2nd Factor (U2F)

This was FIDO’s first iteration as a unified industry standard to enable passwordless experiences.

UAF

UAF is a standard that allows services to adopt passwordless and multi-factor authentication. When registering an account, users can register a device they own and specify a local authentication method such as fingerprint, facial recognition, voice recognition, or entering a PIN.

Like U2F, UAF creates a key pair: the private key is stored on the device, and the public key is stored on the service’s server. When users log in to a UAF-enabled service, they don’t need to enter a password, they simply repeat the authentication method they registered, such as using facial recognition.

U2F

U2F is the standard for physical security keys. U2F keys are typically connected to a computer via USB, but there are also models that support NFC and Bluetooth Low Energy (BLE) for mobile devices.

U2F devices protect accounts using public key cryptography. The private key is stored only on the U2F device and never leaves it. This makes U2F more secure than SMS- or time-based multi-factor authentication (2FA), because those codes can be obtained via phishing.

FIDO2

Compared with the more conceptual FIDO1, FIDO2 is more concrete and practical. The FIDO Alliance states that FIDO2 can address challenges in traditional authentication related to security, usability, privacy, and scalability, and can become the industry’s answer to the global password problem.

FIDO2 is built around two core components, WebAuthn and CTAP, which together form three key elements.

WebAuthn

The WebAuthn API is a JavaScript API that allows developers to add FIDO-based authentication to browsers or cloud platforms that support FIDO. This means users can log in to services using biometrics, apps, and other methods.

All major browsers support WebAuthn, including Chrome, Safari, and Edge. Even Windows 10 and Android provide native WebAuthn support.

CTAP

The Client-to-Authenticator Protocol (CTAP) enables external authentication for FIDO2 devices such as NFC, USB, or Bluetooth authenticators, and can be used together with WebAuthn to serve as an authenticator for desktop applications or web services.

In FIDO2, the FIDO Alliance retained the U2F standard and renamed it, and also introduced CTAP2. CTAP2 is broadly similar to U2F but has more flexible requirements, allowing mobile devices and other form factors to serve as external authenticators.

The greatest significance of FIDO2 is that it became an official standard recognized by international standards organizations. Users can authenticate to websites through browsers using fingerprints or facial recognition, or use CTAP with devices such as USB security keys and mobile apps (including hardware containing security keys) as authentication devices at login.

WebComm Technology helps you proactively deploy FIDO identity authentication solutions to meet both cybersecurity and convenience needs, protecting enterprise information and customer data security. Contact us.

訂閱偉康科技洞察室部落格,掌握最新科技趨勢!

專人協助

由偉康業務人員為您詳細說明偉康的解決方案,以及相關產業經驗。

立即訂閱電子報

掌握最新科技趨勢!