RSA introduces the fourth-factor authentication

Opinion
Jan 24, 20072 mins

* Somebody you know

Burton Group analyst Mark Diodati pointed me to a paper presented last fall at the 13th ACM (Association for Computing Machinery) Conference on computer and communications security. It was written and presented by a group from RSA Labs and explored a fourth authentication method, one we all know and use but which hadn’t before been included in the traditional three methods: something you know, something you have, and something you are.

“Something you know” is a password or passphrase and has been an authentication token for millennia. “Something you have” refers to tokens of one sort or another, such as physical tokens (a key or a badge, for example) or a virtual token (kerberos or SAML, for example). “Something you are” is the biometric factor for authentication – a fingerprint, facial scan, even a DNA check.

But the guys from RSA have now codified what they call the “fourth-factor authentication: somebody you know.”

In the paper’s abstract they set out what they wish to codify: “Human authentication through mutual acquaintance is an age-old practice. In the arena of computer security, it plays roles in privilege delegation, peer-level certification, help-desk assistance, and reputation networks. As a direct means of logical authentication, though, the reliance of human being on another has little supporting scientific literature or practice. In this paper, we explore the notion of vouching, that is, peer-level, human-intermediated authentication for access control. We explore its use in emergency authentication, when primary authenticators like passwords or hardware tokens become unavailable. We describe a practical, prototype vouching system based on SecurID, a popular hardware authentication token. We address traditional, cryptographic security requirements, but also consider questions of social engineering and user behavior.”

The paper outlines another touchpoint between social networking and corporate networking. The ideas can be immediately useful for streamlining your emergency procedures but are also noteworthy for their long-term implications for tying together the so-called “user-centric” and “enterprise-centric” identity systems.

Get the paper and see how it can be adapted to your situation. But also read what Burton’s Diodati has to say about what the analyst group calls “Peer to Peer Identity Proofing.”