← Back to catalogue
Research draft

authentication

vr.tr.authentication · ACT.ACT

Let an agent explain authentication and its methods, relay standards and best practice from security sources at a defensive level, describe forensic and physical authentication, and distinguish authentication from authorisation, identification and the health authority sense of the HBA alias, without providing guidance on bypassing authentication.

Thing Registry Activities and processes

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify

Researched by: Claude

Purpose and description

Let an agent explain authentication and its methods, relay standards and best practice from security sources at a defensive level, describe forensic and physical authentication, and distinguish authentication from authorisation, identification and the health authority sense of the HBA alias, without providing guidance on bypassing authentication.

The process of verifying that a person, device or message is what it claims to be, in computer security through username and password authentication, multi-factor methods, cryptographic message authentication codes and deniable authentication protocols, in telecommunications through SIM unlock codes such as the PUK2, and, in the questioned document sense, through forensic examination of documents; authentication is a security control distinct from authorisation and identification.

What it is for: Verifying identity and integrity.

It can be explain methods; relay standards and practice; describe forensic authentication; distinguish related concepts.

Distinguishing features

Identity verification

Multiple factors

Cryptographic and physical forms

Security control

What it looks like

Not a visible object; a login, a code, a signature check.

Physical character

authentication factors: knowledge, possession, inherence list

NIST SP 800-63: digital identity guidelines note

PUK2: unlocks PIN2 on a SIM note

How it is recognised

Verifying a claimed identity or origin

Password authentication, multi-factor, message authentication codes, deniable authentication, PUK2, questioned document examination

Authorisation grants rights; identification states who; the HBA alias is a health professional card, not a method

Related models

is a kind of - in registry terms

security control

is a kind of - in registry terms

verification

is contrasted with - which grants access rights

authorization

is standardised by - among others

NIST SP 800-63

In practice

Families and kinds

password and knowledge-based authentication

multi-factor and passwordless authentication

message authentication with MACs and signatures

deniable authentication protocols

device and SIM authentication including PUK codes

forensic authentication of documents and objects

Standards and regulation

NIST SP 800-63 digital identity guidelines

FIDO2 and WebAuthn standards

PSD2 strong customer authentication rules

eIDAS in the EU

Failure modes and hazards

Agents providing bypass or attack guidance

Weak passwords and phishing

Registry aliases naming unrelated identifiers

Also called

message authenticationdeniable authenticationusername/password authenticationquestioned document examinationPUK2HBAWindows Hello for Business Multi Factor Unlockuser authentizationpublic key authenticationkey authenticationWindows Helloelectronic authenticationemail authenticationForm-based authenticationHTTP+HTML form-based authenticationmutual authenticationRisk-based authenticationViolin authenticationpersonal unblocking keypasswordless authenticationSSH public key authenticationWindows Hello for Business

Where this came from

wikidata · CC0 1.0

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.

Understand What authentication is.

Definition.

Definition

Definition.

Definition

Definition.

  1. What is authentication, and how does it differ from authorisation and identification? definition
  2. Is the question about the concept, a method, forensics, or bypassing controls, which the model does not assist? boundary

Methods

Methods.

Methods

Methods.

  1. What are password, multi-factor, passwordless, message and deniable authentication? definition
  2. Which entry fits the specific method? action
Practice Defensive practice.

Regulation.

Standards

Standards.

Standards

Standards.

  1. What do NIST, FIDO and regulatory standards recommend for strong authentication? provenance
  2. Which references are standard? provenance

Threats

Threats and defences.

Threats

Threats.

  1. What threats such as phishing and credential stuffing exist, and how are they defended against at a general level? provenance
  2. Is the presentation defensive and non-operational? boundary
Other Other senses.

Sources.

Telecom

SIM and device codes.

Telecom

Telecom.

  1. What are PIN, PUK and PUK2 codes, and how are they used legitimately? provenance
  2. Which sources are cited? provenance

Forensic

Forensic authentication.

Forensic

Forensic.

  1. How does questioned document examination authenticate documents, and how are artworks authenticated? provenance
  2. Which entry fits questioned document examination? action
Context Cryptography and history.

Context.

Cryptography

Message authentication.

Cryptography

Cryptography.

  1. How do message authentication codes and digital signatures work? provenance
  2. Which entry fits message authentication code? action

History

History.

History

History.

  1. How has authentication developed from seals and passwords to biometrics and passkeys? provenance
  2. Which entry fits the history of computer security? action

What the second pass must settle

  • Should multi-factor authentication and questioned document examination be separate primary entries?
  • How should security standards be linked?
  • The registry entry has merged aliases naming a SIM code and a health card; should they be split off?