Why password-only authentication is passe

News
Jun 10, 20137 mins

Mobility, cloud, BYOD lead to surge in two-factor authentication schemes  

The rapid growth of mobile devices that can access corporate networks and data, the expanding use of cloud-based IT services, and the increasing popularity of apps such as online banking mean that IT needs to pay closer attention to authentication.

Ensuring that users are who they claim to be can keep enterprises from experiencing damaging security breaches and the loss or theft of data.

For many companies, the multi-factor (or two-factor) approach to authentication — the process of identifying an individual based on more than one factor such as a user name, password, smartcard or biometric attribute — promises the best way to ensure someone’s true identity.

While multi-factor authentication has been around for years (think of automated teller machines that require ATM cards and personal identification numbers), things are quickly changing and demand for stronger authentication is on the rise.

Two main trends are having an impact on authentication, says Forrester analyst Eve Maler. One is the increasing frequency of security breaches that expose user passwords, other security data, and personally identifiable information. The other is the ubiquity of mobile devices.

[TEST: Smartphones take center stage in two-factor authentication schemes]

“While password-only authentication is still the norm for many online services, more services are enabling optional two-factor authentication,” Maier says. “Mobile devices have two roles in this landscape: new platforms for online apps that users need to log in to, and new tools that can be used to assist authentication into other channels, such as a browser on a laptop.”

In a recent report on authentication, IDC said that the security authentication market is poised for change based on a number of market disruptions and technological advancements in the “identity ecosystem.”

These include:

  • The explosion of social networking and the increasing number of identities online, including those considered duplicates, misclassified and undesirable.
  • The use of consumer devices in the enterprise.
  • The need for and ability to add contextual awareness to the identity and transaction ecosystem.
  • The proliferation and maturation of authentication standards (including OpenID Connect, OAuth, Simple Cloud Identity Management, Security Assertion Markup Language and others) driving interoperability between internal and external identity systems.
  • Public sector initiatives sponsored by the National Strategy for Trusted Identities that are aimed at accelerating progress toward interoperability between legacy identity and trusted online credentials.
  • The emergence of authentication services, both on-premise and off-premise, from various providers.
  • And the use of multi-layered authentication approaches and techniques that include content delivery networks, electronic credentials, shared secrets, alternative channels, analytic systems and managed services.

The demand for stronger authentication has developed at all levels of society and business interaction, IDC says. Form factors for multi-factor authentication have “morphed from traditional tokens to USB devices to smart cards to fingerprint readers, soft tokens and scanning devices,” the firm says.

Interest in biometrics continues to rise, and the need for advances in identity and authentication techniques has become a matter of both national security and corporate/consumer protection.

At the same time, IDC notes, the growing number of online interactions each day requires that identities be validated securely in the context of online interactions, yet with minimal disclosure of personal information when conducting transactions. And the rapid rise of mobile technology and the bring your own device (BYOD) trend has put a greater focus on strong authentication.

Enhanced Methods

Two-factor authentication has gained a lot of ground over the years. But the number of authentication factors is not necessarily the point, experts say.

“Counting factors is a poor way to estimate authentication strength,” says Gartner analyst Ant Allan. “With so many ‘two-factor’ methods available, there are clearly differences in the levels of assurance and accountability they afford.”

Some Gartner clients are looking at “enhanced password” methods to provide incremental improvements where two-factor methods are too costly or have poor user experience, Allan says. Companies are paying more attention to total cost of ownership (TCO), he says.

“Many incumbent solutions were chosen when the range of options was limited,” Allan says. “Now, there is a fuller spectrum of methods, and some clients see that they don’t really need the higher-assurance method they have. They just need good-enough assurance, optimizing the balance with TCO” and user experience.

Among the authentication methods that are growing in popularity are the phone-as-a-token solutions, which Allan says over the past few years have overtaken one-time password (OTP) hardware tokens in terms of new and refreshed deployments. Mobile has been an enabler of lower TCO and better user experience, he says.

When higher-assurance authentication is needed, companies “will increasingly resist using a dedicated device for authentication,” Allan says. “However, biometric authentication can provide a higher level of assurance with improved [user experience], and a growing number of vendors offer products that exploit the phone as a biometric capture device,” he says.

Suitable biometric authentication modes include typing rhythm, voice recognition, face topography and iris structure (using user-facing cameras), Allan says. “Multiple modes may be combined in a solution to provide broader options, or to support progressive, risk-appropriate authentication,” he says.

Gartner has predicted increasing use of biometric authentication for access to enterprise networks or high-value Web applications from smartphones or tablets, and Allan expects to see increasing support for biometric authentication methods among the mainstream vendors and adoption by enterprises, especially with mobile devices.

The firm also predicts that contextual authentication will likely also play a significant part in mobile user authentication, “especially since the phone itself provides a rich node of identity-relevant contextual data that can be used to increase the confidence in the claimed identity,” Allan says.

Contextual authentication, which is based on the analytics of behavior patterns and other information, “is growing in importance outside its historic base in Internet banking,” Allan says. “It’s not yet mainstream, but interest is growing across other industry verticals and use cases, and more vendors are offering it as part of their core user authentication offering.”

A combination of passive/transparent biometric authentication methods (not requiring special action by the user) and contextual authentication ”can provide sufficient assurance for all but the highest-risk use cases,” Allan says. This will create “the possibility of a world without passwords and tokens.”

Cloud-delivered user authentication is also becoming more widely adopted, Allan says. Traditional hosted managed services are having the most traction among small and mid-sized businesses, he says, with enterprise adoption mainly in vertical industries such as higher education, where TCO is a more significant consideration.

“Multi-tenanted cloud-based [authentication] services are growing across enterprises in all verticals,” Allan says.

Gartner has predicted that by 2017 more than 50% of enterprises will choose cloud-based services as the delivery option for new or refreshed user authentication implementations, up from less than 10% today.

Maier agrees that the cloud, along with mobile devices, will play a huge role in shaping two-factor authentication methods and scenarios.

“As companies increasingly move to SaaS [software-as-a-service] applications and as employees bring their own devices and work remotely — which is all part of the ‘extended enterprise’ imperative — some authentication methods that are tightly bound to company-installed hardware, such as smart cards, are only applicable to smaller and smaller corporate subpopulations,” Maier says.

Cloud- and mobile-enabled authentication that works across Internet domains becomes more necessary in more circumstances, she says.

Violino is a freelance writer. He can be reached at bviolino@optonline.net.