FIDO2 is both a project and an authentication method for developing strong authentication solutions, jointly promoted by the FIDO Alliance—an industry association driving the standardization of password-independent authentication—and the World Wide Web Consortium (W3C), the organization responsible for the technical standardization of the Internet (World Wide Web). FIDO2 is based on the FIDO U2F (Universal 2nd Factor) authentication standard and represents an evolution of that standard.
What Is FIDO2 Authentication?
As its slogan “Moving the World Beyond Password Using” suggests, the FIDO2 authentication standard represents authentication that goes beyond password use—in other words, passwordless authentication. The core technologies behind FIDO2 are “WebAuthn,” which has been approved as a standard by the W3C, and “CTAP (Client to Authenticator Protocol),” a protocol that complements WebAuthn. Both were developed by the FIDO2 project.
FIDO2 consists of a device used by the user, such as a smartphone or physical security key, and a WebAuthn relying party (the FIDO2 server), with the web browser acting as the intermediary between the two.
FIDO2-Compatible Devices (Authenticators)
Since FIDO2 was introduced, OS developers and many device manufacturers have obtained FIDO2 certification. Because of their large user bases, two certifications have had a particularly significant impact on FIDO2 adoption: Windows Hello, the facial recognition technology in Windows 10, and Android devices running Android 7.0 or later.
FIDO2 Authentication Servers
Companies that implement FIDO2 authentication are not required to set up their own FIDO2 authentication server (FIDO2 server); instead, they can use a FIDO2 server operated by a third party, much like a SaaS offering. As of May 2019, dozens of companies worldwide had deployed FIDO2 servers. The companies that had done so in Japan are as follows.
- KDDI Corporation
- LINE Corporation
- NEC Corporation
- Soft Giken Co., Ltd.
- Yahoo Japan Corporation
FIDO2-Compatible Browsers
Major browsers—Google Chrome, Firefox, Microsoft Edge, and Safari—all support FIDO2, together accounting for roughly 85% of browser usage worldwide.
Benefits of FIDO2 Authentication
There are two main benefits.
(1) Low Barrier to Adoption
With FIDO U2F, the predecessor to FIDO2, adopting a dedicated FIDO U2F-compatible device (authenticator) was mandatory, which made the cost of using FIDO U2F a significant barrier.
Dedicated FIDO2-compatible devices are also available for FIDO2, but what matters most is that Windows Hello (standard on Windows), Android, and all major browsers now support it.
With Windows Hello, users can take advantage of FIDO2 at no additional cost simply by using the Windows Hello-compatible camera already built into their PC. The same applies to Android: smartphones and tablets running Android 7.0 or later can perform FIDO2 authentication using their built-in fingerprint reader or other authentication features as-is.
Furthermore, communication between these devices and the FIDO2 authentication server can be handled by the ordinary browser already installed on every device, rather than requiring a dedicated application.
(2) Strengthening Authentication to Prevent Unauthorized Access
ID and password authentication is a frequent target of attacks such as credential stuffing, brute-force attacks, and password spraying. This is due to the persistent problems of weak passwords and password reuse, as well as a fundamental weakness of password authentication: anyone who obtains the password string can log in.
With FIDO2, taking fingerprint authentication as an example, no two people in the world share the same fingerprint, so there is no such thing as a “weak fingerprint.” While fingerprint authentication does mean reusing the same fingerprint, a fingerprint cannot be carried around and copied unless it is captured using specialized methods. Additionally, because a fingerprint cannot be used apart from the person it belongs to, hackers cannot obtain a specific individual’s fingerprint remotely. These characteristics make it more secure than passwords.
Furthermore, FIDO2 registers both a “fingerprint” and a “device,” and the two are always used together. Even if an attacker manages to steal the fingerprint data alone, authentication cannot be completed without the device. Conversely, even if the device alone is stolen, authentication cannot be completed without the fingerprint data.
Introducing FIDO2 also makes it possible to eliminate password authentication entirely and rely solely on FIDO2 authentication, or alternatively to use password authentication alongside FIDO2 authentication. In the latter case, the combination becomes two-factor authentication—using the knowledge factor of a password together with the biometric factor of FIDO2 (in this case, biometric authentication)—which further strengthens security.
Applications of FIDO2 Authentication
On any website that requires authentication, ID and password-only authentication can be replaced with FIDO2-based authentication. Examples include shopping sites, video streaming sites, news and other information sites, and various cloud services such as IaaS, PaaS, and SaaS. In this case, the operator of each website contracts with a company that provides a FIDO2 authentication server, and authentication for the operator’s site is handled by that external FIDO2 authentication server.
As a result of this increased security strength, a reduction in unauthorized access and in harm to registered users from personal information leaks can be expected. It also helps companies avoid the reputational risk and financial risk of compensating for damages that would arise from a personal information leak.