Language

Identity Authentication

What is identity authentication?

Identity authentication is the process of checking that someone requesting access controls the credentials associated with an existing digital account. Those credentials may include a password, a security key, or a passkey.
Successful authentication gives the service confidence that the requester can use that account. The strength of this confidence depends on the authentication method, how the credentials were registered, and whether they have been compromised.

How does identity authentication work?

A typical authentication process includes four steps:
  • Identify the account: A username, account identifier, or credential tells the service which account the requester wants to use
  • Request proof: The service asks for a password, a one-time code, or a cryptographic response from a registered authenticator
  • Check the response: The service validates the evidence using the relevant method, such as checking a password hash or verifying a digital signature
  • Establish a session: If the requirements are met, the service creates an authenticated session and records the event
Authorization rules determine which resources and actions the account can access. Session protection, timeouts, and revocation help maintain security after the initial login.

When should a business require additional authentication?

Additional authentication may be appropriate before sensitive actions, such as changing payment details, accessing confidential records, or adding an administrator. An unfamiliar device or unusual account activity can also prompt another check. Requiring a stronger authentication method is commonly called step-up authentication.
The required evidence should address the suspected risk. If a password may have been stolen, requesting that password again provides little additional protection. The service may instead require a registered security key or another independent factor.

How can Regula help with identity authentication?

Regula Face SDK can compare a returning user's facial image with an enrolled reference and perform active or passive liveness detection. These capabilities support authentication designs that include a remote face check.
When account recovery requires renewed identity proofing, Regula Document Reader SDK can check the person's identity document and extract its portrait for comparison. The organization then uses the verification results when deciding whether to restore access or register replacement credentials.

FAQ

Does a successful login prove the customer's legal identity?

No. A login can succeed for an account that was created using unverified information. Establishing a person's legal identity requires suitable identity evidence and verification. Authentication subsequently checks credentials connected to that account.

What makes authentication multi-factor?

Multi-factor authentication combines at least two distinct factor types: something the user knows, possesses, or is. A password and a PIN are both knowledge factors, so combining them does not constitute MFA. Factor independence and secure enrollment also affect protection.

Can passkeys replace passwords for customer authentication?

Yes. Passkeys authenticate through cryptographic keys associated with the service. Users commonly approve their use with a device PIN or biometric check. Businesses should assess device compatibility, credential recovery, and fallback methods when introducing them.

Does single sign-on require a new identity check for every application?

Usually, the application accepts an authentication assertion or token from a trusted identity provider. It must validate that information and apply its own access rules. A sensitive action may still require fresh authentication or a stronger method.

How should businesses authenticate users during account recovery?

Recovery should use evidence that remains trustworthy after the reported loss or compromise. Options may include a previously registered backup authenticator, recovery codes, or renewed identity verification. Restoring access should also address compromised credentials and existing sessions.

Which authentication records should a business retain?

Useful records include the account identifier, time, authentication method, success or failure, and relevant risk or recovery decisions. Logs should exclude passwords, private keys, and usable session secrets. Retention should support investigation while meeting applicable data-handling requirements.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules