Client certificate authentication is a type of digital certificate used on a client device to send an authentication request to a server. It plays an important role in designing authentication systems between servers and clients, verifying the identity of the device making the authentication request.
The Role of Client Certificates
The most commonly used method of authentication when using a system is entering an ID and password. Because only the legitimate user is supposed to know the password, a user who enters the password to make an authentication request is regarded as a legitimate requester.
Even today, ID and password authentication alone is used in many cases, but passwords have inherent vulnerabilities. For example, because a password is simply a string of characters, an authorized person could easily share it with someone else, or if a password is written down and the note is stolen, the password could be compromised. In addition, if the same password is used across multiple systems, a malicious hacker who steals one password could attempt unauthorized access to multiple systems using that same password.
Furthermore, unauthorized access can occur even when a password has not been leaked or stolen. If a simple, commonly used password that is easy to attack is used, hackers can carry out password brute-force attacks, which may result in unauthorized access being allowed.
・Reference article
How to Prevent Brute-Force Attacks
To protect companies and organizations from such unauthorized access attacks, the idea emerged of "allowing authentication only from specific devices on which a digital certificate has been preinstalled." This is what is now known as a client certificate.
With a client certificate, even if a network attack occurs, the digital certificate cannot be stolen from the device and used elsewhere. In addition, even if a password is leaked, it is extremely rare for the device with the client certificate installed to be stolen at the same time, which helps prevent unauthorized access.
Although client certificates themselves have been in use as a technology for more than 20 years, their usefulness is widely understood, and they continue to be actively used today.
Client Certificates and Server Certificates Use the Same Underlying Technology
Certificates are used to have a trusted third party, known as a certificate authority, certify that the "individual or organization performing authentication" is trustworthy. In addition to client certificates, there is also the "server certificate (SSL)," which encrypts communications while also guaranteeing that the server the user is accessing is a trustworthy server.
Client certificates and server certificates function in much the same way, with almost no technical differences between them. When installed on a client, a certificate proves that the client is a device with legitimate authorization; when installed on a server, it proves that the server is operated by the correct organization.
Certificate Authorities Guarantee the Trustworthiness of Certificates
Client certificates are an important function that underpins the very foundation of information security. For this reason, the organizations permitted to issue certificates are limited, so that untrustworthy companies cannot freely issue certificates or forge them. An organization authorized to issue digital certificates is called a "certificate authority." Our company, GMO GlobalSign, is also one such certificate authority.
After verifying whether an organization or individual is trustworthy, a certificate authority encrypts the public key certificate for that individual or organization, signs it, and distributes it. Because a certificate authority assigns an expiration date to each certificate, a certificate becomes unusable once it expires. As a result, certificates with a new expiration date must be installed periodically, which also serves as a mechanism for preventing unauthorized access.
According to a survey from February 2019, the top five certificate authorities, including our company, account for more than 97% of the global certificate authority market share.
Strengthening Various Types of Authentication with Client Certificates
Client certificates are often used, for example, as "certificates for logging in to a company or organization's systems," but they can also be used to strengthen authentication when using other systems and services.
For example, our single sign-on service, "TrustLogin," provides single sign-on access to various cloud services as well as internal systems. Before a user can perform single sign-on, they must first authenticate to TrustLogin, and a client certificate can be used at this stage.
Because TrustLogin single sign-on cannot be used from a device on which the client certificate is not installed, even if a TrustLogin password were to be leaked, a hacker attempting unauthorized access would not be able to log in. In this way, for any product or service that supports client certificates, a client certificate installed once can be used for multiple products and services.
The Future of Client Certificates
Today, authentication methods such as FIDO UAF, which assumes operation on a smartphone, FIDO U2F, which uses multiple devices, and multi-factor authentication, which uses multiple authentication factors, are becoming increasingly common.
However, the advantages inherent to client certificates—"once installed, they remain valid until expiration without requiring any procedure at each authentication" and "they can be installed on a specific, identified device"—remain unshaken. Going forward, a variety of authentication methods will continue to be adopted and used, but client certificates are expected to remain in high demand as well.