Definition of Two-Step Verification
A login authentication method that is split into two separate steps is called two-step verification.
Most common online services use "single-step verification," where authentication is granted and login is completed as soon as you enter your ID and password. Two-step verification, by contrast, requires you to enter and authenticate some piece of information—such as your ID and password—after which the screen changes and you're prompted for additional information; authentication isn't completed until you enter that additional information. This method is generally used by systems and services that require a higher level of security than single-step verification provides.
Examples of Two-Step Verification in Everyday Life
The following are examples of two-step verification that we encounter in everyday life. Below are cases that are typically used together with an ID and password.
(1) Random Number Table (e.g., SBI Sumishin Net Bank)
Branch number and account number
Login password
+
When transferring funds, enter the two values specified from an 18-cell random number table (each cell containing a two-digit number)
(2) One-Time Password (e.g., Bank of Tokyo-Mitsubishi UFJ)
Branch number and account number
Login password
+
Enter the one-time password displayed on a token when performing procedures such as bank transfers or address changes
(3) IC Card (e.g., an employee accessing the intranet from the internet)
ID number or email address
Login password
+
Authentication by reading a card with an embedded IC chip through a card reader connected to the computer
As described above, efforts to strengthen security and prevent unauthorized access are made by requiring an additional authentication step on top of the single-step "ID + password" authentication, thereby creating two-step verification.
Examples (1) and (2) are often used by financial institutions, where money changes hands. Because unauthorized access to a financial account can result in stolen funds—and therefore substantial financial damage—these institutions adopted such measures early on as part of strengthening security. Two-step verification for online banking has been in place since the early 2000s and was designed with computer access in mind (SMS-based verification did not yet exist at the time). After entering an ID and password at login, users provide additional information—such as a value from a random number table printed on a plastic card, or a one-time password displayed on a physical token—to strengthen security.
Example (3), the use of IC card readers, is often used when employees connect to a company's internal intranet over the internet from a laptop or similar device. A card with an embedded IC chip is inserted into the computer's card reader, and authentication is performed together with an ID and password.
Beyond the above, other authentication methods include biometric authentication using fingerprints or facial recognition, and USB dongle authentication (using the dongle alone, or the dongle together with a dedicated password). In addition, SMS-based authentication has been declining in use since the National Institute of Standards and Technology (NIST) recommended against it.
Does Two-Step Verification Provide Strong Security?
In June 2017, the National Institute of Standards and Technology (NIST) released the latest version of its "Electronic Authentication Guideline" (hereafter, "the Guideline").
The Guideline discusses strengthening authentication by combining multiple "authentication factors"—biometric information (fingerprint, face, veins, etc.), knowledge information (passwords, secret questions, etc.), and possession information (random number tables, one-time passwords, SMS, etc.)—but it does not address strengthening security by increasing the number of authentication steps.
Strengthening security by increasing authentication factors is categorized into three levels based on the number of factors used and whether a physical device is required: (1) "only one authentication factor," (2) "two authentication factors combined," and (3) "two authentication factors combined, one of which requires a physical device." Security strength is highest for (3), followed by (2), with (1) being the lowest.
Does this mean two-step verification, which isn't addressed in the Guideline, is useless for strengthening security? Not at all. This is because what's commonly referred to as "two-step verification" is, in practice, often implemented and provided as "two-step verification that is also two-factor (or multi-factor) verification."
For example, the SBI Sumishin Net Bank (random number table), Bank of Tokyo-Mitsubishi UFJ (one-time password), Office 365 (SMS), and IC card examples described above all require two steps of authentication while also combining two authentication factors, making them "two-factor verification." These correspond to level (2) or (3) in the Guideline, meaning they provide strong security.
For more details on the Guideline, please refer to the article below.
・Reference page
Global Electronic Authentication Standards Are Changing: Understanding NIST SP 800-63-3
How Will Two-Step Verification Evolve Going Forward?
From the early 2000s until the rise of smartphones, two-step verification generally meant authentication that also relied on a physical device, such as a random number table, a physical token, or an IC-chip card. However, since smartphones became widespread, carrying around a separate physical device in addition to the smartphone itself for "two-step verification" has become far too cumbersome, and the trend has shifted toward two-step verification methods that don't require a physical device.
Specifically, this includes SMS-based verification and QR code-based verification. Because these use the smartphone's own phone and camera functions, two-step verification becomes possible without needing a separate physical device, making it highly convenient.
In recent years, biometric authentication using fingerprints has rapidly become widespread. Since the majority of best-selling smartphones now come equipped with fingerprint readers, this method has spread quickly for use in on-device payments. In this way, how two-step verification is carried out appears to depend heavily on what features are built into smartphones and how those features are leveraged for authentication.