Affiliation:
1. Digital Systems, University of Piraeus, Piraeus, Greece
2. InQbit Innovations SRL, Bucharest Romania
3. University of Piraeus, Piraeus Greece
Abstract
To overcome the security vulnerabilities caused by weak passwords, thus bridge the gap between user friendly interfaces and advanced security features, the Fast IDentity Online (FIDO) alliance defined a number of authentication protocols. The existing literature leverages all versions of the FIDO protocols, without indicating the reasons behind the choice of each individual FIDO protocol (i.e., U2F, UAF, FIDO2). Inevitably, the question “which protocol is more suitable per case” becomes significant. To provide an answer to the previous question, this article performs a thorough comparative analysis on the different protocol specifications and their technological and market support, to identify whether any protocol has become obsolete. To reach to a conclusion, the proposed approach (i) explores the existing literature, (ii) analyses the specifications released by the FIDO Alliance, elaborating on the security characteristics, (iii) inspects the technical adoption by the industry and (iv) investigates the compliance of the FIDO with standards, regulations and other identity verification protocols. Our results indicate that FIDO2 is the most widely adopted solution; however, U2F remains supported by numerous web services as a two-factor authentication (2FA) choice, while UAF continues to be utilised in mobile clients seeking to offer the Transaction Confirmation feature.
Publisher
Association for Computing Machinery (ACM)
Reference148 articles.
1. 2021. Can I use: WebAuthn. Retrieved 14 April 2024 from https://caniuse.com/?search=webauthn
2. 2015. USB-Dongle Authentication. Retrieved 14 April 2024 from https://www.dongleauth.info/
3. Dipankar Dasgupta Arunava Roy and Abhijit Nag. 2016. Toward the design of adaptive selection strategies for multi-factor authentication. Computers & Security 63 (2016) 85–116. 10.1016/j.cose.2016.09.004
4. Poster
5. FIDO Alliance. 2023. Conformance Self-Validation Testing. Retrieved 14 April 2024 from https://fidoalliance.org/certification/functional-certification/conformance/