FIDO is an authentication technology that uses private and public key pairs, established by FIDO Alliance, an industry association for authentication. Its name is an acronym for "Fast IDentity Online." FIDO is the technology closest to being a "standard" for password-independent authentication, and both Windows and Android already support it.
What Is FIDO Alliance?
FIDO Alliance was launched in 2013 to reduce reliance on passwords in authentication. It is an industry association founded by three companies: Nok Nok Labs (an authentication technology developer), PayPal (an online payment company), and Lenovo (a PC manufacturer). Since then, FIDO Alliance has continued to expand, and as of February 2019, it has 38 Board Level Members (the highest tier of membership), 63 Sponsor Level Members (the next tier), and 155 other general members.
FIDO Alliance includes not only overseas companies such as Google, Amazon, and Facebook, but also many Japanese companies. As of February 2019, Board Level Members include LINE, NTT DOCOMO, and Yahoo Japan, while Sponsor Level Members include Dai Nippon Printing, Fujitsu, Hitachi, JCB, KDDI, Mitsubishi UFJ Bank, NEC, NTT, and SoftBank.
Notably, FIDO Alliance members are not limited to so-called "IT companies" or "internet companies"; many members are financial institutions and credit card companies that handle payments, as well as mobile carriers that handle communications.
FIDO Alliance was launched in 2013, and even at that time, the problems with passwords and one-time password delivery via SMS (SMS OTP) were already apparent. For this reason, FIDO Alliance's goal was to develop an open, interoperable authentication technology specification and to standardize it.
Note that Apple, which develops and sells iPhone, iPad, and Mac and holds significant influence worldwide, is not a member of FIDO Alliance.
What Is FIDO UAF?
UAF is an abbreviation for Universal Authentication Framework, a mechanism that primarily uses biometric information to achieve passwordless authentication. This requires a FIDO UAF-compatible device (such as a smartphone) and client (app, browser). Note that UAF is intended for use on smartphones, and authentication is not performed using a separate physical device other than the smartphone.
Authentication methods used in FIDO UAF include biometric authentication such as "fingerprint authentication," "voiceprint authentication," "facial authentication," and "iris authentication," as well as "PIN code authentication." FIDO UAF can authenticate using just one authentication method (for example, "fingerprint authentication only"), but it is also possible to combine multiple authentication methods available in FIDO UAF, such as "fingerprint authentication and PIN entry" (combining multiple authentication mechanisms is effective for increasing authentication strength).
Note: while FIDO's vision is "authentication that does not rely on passwords," it is also possible to combine password entry with FIDO UAF, such as "fingerprint authentication and password entry" or "facial authentication and password entry."
What Is FIDO U2F?
U2F stands for Universal 2nd (Second) Factor, a mechanism that combines password authentication with one other type of authentication for a total of two authentication factors. The major difference from UAF is that the FIDO client is hardware rather than software. Physical clients that can be used include FIDO U2F-compatible PIN entry devices, NFC or Bluetooth authentication keys, and USB tokens.
Note that 2nd (Second) Factor means the second authentication factor, implying the use of an authentication factor (a possession factor or biometric factor) other than password authentication (a knowledge factor), in combination. The difference between general "two-factor authentication" and "FIDO U2F" lies in whether a U2F-compatible device is used: without a U2F-compatible device it is simply "two-factor authentication," and with one it becomes "FIDO U2F."
Although the price of FIDO U2F-compatible authentication devices has fallen compared to a few years ago, most U2F-compatible devices still cost several thousand yen each, so the cost burden for large-scale deployments is not insignificant. Going forward, as adoption expands, the unit price of compatible devices is expected to decrease.
Apple Devices Are Not Supported
FIDO is, so to speak, an industry-standard authentication specification promoted with the participation of nearly all major IT companies, but Apple, which produces iOS and Mac, is not a member of FIDO Alliance. As of February 2019, authentication for iOS devices such as iPhone and iPad, as well as for Mac, uses Apple's own authentication specifications—"Touch ID (fingerprint authentication)" and "Face ID (facial authentication)"—rather than FIDO.
Unlike Windows and Android, which have adopted authentication methods compatible with FIDO, neither Touch ID nor Face ID is compatible with FIDO, creating a challenge in that interoperability is not possible. For example, in an organization where Apple and non-Apple products coexist, it is not possible to apply uniform authentication enhancement across all devices.
However, Apple has made Safari FIDO-compatible (Chrome, Firefox, and Edge also support it). Since there is no need to join FIDO Alliance in order to release FIDO-compatible products, FIDO support for next-generation Touch ID and Touch ID is hoped for going forward.