What Is Multi-Factor Authentication?
Multi-factor authentication (MFA) is an authentication method that requires two or more factors when accessing a device or server, logging in to an internet service, and so on.
Using two or more authentication factors provides stronger security and makes unauthorized access more difficult than relying on a single factor alone — this is the main reason multi-factor authentication has become so widely adopted.
What Are the Three Authentication Factors?
Authentication can broadly be divided into three types, or three factors.
(1) Biometric Information
An authentication method that uses the human body, such as fingerprints, veins, face, voice, or iris.
(2) Knowledge Information
An authentication method that uses information known only to the individual, such as a password, personal attributes, or a secret question.
(3) Possession Information
An authentication method that uses a physical device (or information received on a physical device), such as a hardware token, mobile phone or smartphone, an IC chip card, or a code sent via SMS.
Multi-factor authentication requires combining two or three of these three factors.
What Are Some Common Types of Multi-Factor Authentication?
The following are examples of multi-factor authentication used in everyday life. These are typically used together with an ID and password.
(1) Random Number Table (e.g., Shinsei Bank)
Branch number and account number (ID information)
Login password (password information)
+
Enter the three cells specified from a 50-cell random number table
(2) One-Time Password (e.g., Japan Net Bank)
Branch number and account number (ID information)
Login password (password information)
+
A one-time password shown on a hardware token is required when transferring funds
(3) SMS (e.g., Google Account)
Registered email address (ID information)
Login password (password information)
+
When logging in from an IP address that has not been used before, you must enter the number sent via SMS
(4) QR Code (e.g., accessing WeChat from a PC)
Enter your ID when registering the app on your smartphone (ID information)
Enter your password when registering the app on your smartphone (password information)
+
Scan the QR code shown on the PC screen using the WeChat app on your smartphone
+
Tap the authentication approval button on your smartphone
(5) IC Card (e.g., an employee accessing the company intranet from the internet)
Registration number or corporate email address (ID information)
Login password (password information)
+
Authentication of the physical chip using an IC card reader
(6) Fingerprint (e.g., iPhone and iPad authentication)
Enter a password when starting up the smartphone (password)
+
Fingerprint authentication when making a purchase on the App Store
As shown above, security is strengthened by requiring an additional piece of information — obtained from another source — on top of the standard "ID + password" combination.
Note: As of January 2018, the SMS-based authentication described in (3) above is the most widely used. It is typically triggered when a service provider detects unusual access — such as a login from an unfamiliar IP address, a country with no prior login history, or a long gap since the last login — as a way to prevent unauthorized access. Entering the 5- to 6-digit number sent via SMS on the login screen allows the user to log in, and subsequent access from the same IP address or country generally does not require another SMS to be sent.
Methods (1) and (2) above are commonly used by financial institutions such as online banks and online securities firms. If a financial account is accessed without authorization, the funds in the account can be stolen, resulting in far greater damage than unauthorized access to other types of services. With this method, after entering an ID and password at login, the user provides additional information from a plastic card printed with a random number table or a hardware token displaying a one-time password, further strengthening security.
QR code authentication, as described in (4), became common after the rise of smartphones. By scanning a QR code with a smartphone's QR code reader at login, a service can verify whether the access is coming from a registered smartphone, which has driven its increasing adoption.
The use of IC card readers, as described in (5), has been widespread since the early 2000s. When connecting via VPN to a company's internal intranet, users insert a card containing an IC chip into a card reader attached to their PC to authenticate. This method assumes the use of a PC.
Method (6) uses biometric authentication such as fingerprints, and is mainly used for authentication on smartphones. Biometric authentication commonly relies on fingerprints, facial recognition, or veins; fingerprint authentication is currently the most common, and facial recognition — adopted in the latest iPhone models — is expected to grow in popularity going forward.
In addition to the methods above, there is also USB dongle authentication (authentication using only a dongle, or a dongle combined with a dedicated password).
How Should We Understand the Strength of Multi-Factor Authentication?
The strength of multi-factor authentication is addressed in the latest version of the "Electronic Authentication Guideline" (hereafter, "the Guideline"), published in June 2017 by the U.S. National Institute of Standards and Technology (commonly known as NIST).
According to the Guideline, there are nine specific authentication methods in total, tied to biometric, knowledge, and possession information. If the specific authentication methods used satisfy two or three of these three categories — biometric, knowledge, and possession — the result qualifies as multi-factor authentication.
Depending on the type of information that needs to be protected, the Guideline defines three levels: (1) "a single authentication type is sufficient" (this is single-factor authentication, not multi-factor authentication), (2) "two authentication types are required," and (3) "two authentication types are required, one of which must involve a physical device."
In terms of security strength, (3) is the highest, followed by (2), with (1) being the lowest.
Does this mean every authentication process should require the highest security level, (3)? Not necessarily. What needs to be considered here is that multi-factor authentication adds friction for the user.
For example, the extent of the damage caused by a data breach or unauthorized access varies greatly depending on whether it results only in the leak of an ID, password, and email address, or whether it also leads to unauthorized transfers from a bank account.
As a result, single-factor authentication is generally considered sufficient in cases where a data leak would cause only limited damage. Conversely, when unauthorized access could lead to substantial financial loss, it is common to require "two authentication types, one of which involves a physical device." The appropriate choice depends on what needs to be protected.
For more details, please refer to the article we have published on this topic.
Reference page:
How the World's Electronic Authentication Standards Are Changing: Understanding NIST SP 800-63-3
What Is the Difference Between Multi-Factor Authentication, Single-Factor Authentication, Two-Factor Authentication, and Two-Step Authentication?
This section explains two separate concepts: the "number of authentication factors" and the "number of authentication steps."
First, regarding authentication factors: if only one factor is used, it is called single-factor authentication. If two factors are used, it is called multi-factor authentication or two-factor authentication. Because "multi-factor authentication" applies whenever multiple factors are used, the term can refer to either two or three factors.
Next, regarding the number of authentication steps, it is helpful to think in terms of one step versus two steps. If entering an ID and password logs you into a system or service immediately, that is single-step authentication. If, after entering an ID and password, the screen changes and you are prompted for additional information — without which you cannot log in — that is two-step authentication.
Based on this, the terms that apply to each situation are as follows.
- If there is one authentication factor and one step: single-factor authentication.
- If there is one authentication factor and two steps: single-factor authentication and two-step authentication.
- If there are two authentication factors and one step: multi-factor authentication and two-factor authentication.
- If there are two authentication factors and two steps: two-step authentication, multi-factor authentication, and two-factor authentication.
- If there are three authentication factors and one step: multi-factor authentication.
- If there are three authentication factors and two steps: two-step authentication and multi-factor authentication.
Changes in Multi-Factor Authentication Methods and Future Outlook
The fact that far more smartphones are shipped than PCs, and that smartphones are now used to access a wide variety of online services, has brought about many changes in multi-factor authentication as well.
Because smartphones are typically operated with one or both hands and are not normally connected to external devices, card readers with IC chips and hardware tokens are being used less often as multi-factor authentication factors. In addition, as smartphones have grown larger, it has become harder to hold something else in one hand while operating the phone with the other, so plastic random-number-table cards are also used less than before.
Conversely, methods that work well with smartphones are those that use a phone's built-in call and camera functions to perform multiple authentication steps on a single device — such as SMS-based authentication and QR code authentication. In addition, since many new iPhone and Android models now include fingerprint authentication, it has become more common to combine a password with fingerprint authentication when approving transactions. The iPhone X, released in 2017, further added facial recognition as a new biometric authentication method.
Given this trend, it has become common for multi-factor authentication to be completed entirely on a single smartphone, and new services now generally design their multi-factor authentication around smartphone use. As smartphones gain new features going forward, authentication methods that take advantage of those new capabilities are expected to be introduced as well.