Identity Authentication
What is identity authentication?
How does identity authentication work?
- Identify the account: A username, account identifier, or credential tells the service which account the requester wants to use
- Request proof: The service asks for a password, a one-time code, or a cryptographic response from a registered authenticator
- Check the response: The service validates the evidence using the relevant method, such as checking a password hash or verifying a digital signature
- Establish a session: If the requirements are met, the service creates an authenticated session and records the event
When should a business require additional authentication?
How can Regula help with identity authentication?
FAQ
Does a successful login prove the customer's legal identity?
No. A login can succeed for an account that was created using unverified information. Establishing a person's legal identity requires suitable identity evidence and verification. Authentication subsequently checks credentials connected to that account.
What makes authentication multi-factor?
Multi-factor authentication combines at least two distinct factor types: something the user knows, possesses, or is. A password and a PIN are both knowledge factors, so combining them does not constitute MFA. Factor independence and secure enrollment also affect protection.
Can passkeys replace passwords for customer authentication?
Yes. Passkeys authenticate through cryptographic keys associated with the service. Users commonly approve their use with a device PIN or biometric check. Businesses should assess device compatibility, credential recovery, and fallback methods when introducing them.
Does single sign-on require a new identity check for every application?
Usually, the application accepts an authentication assertion or token from a trusted identity provider. It must validate that information and apply its own access rules. A sensitive action may still require fresh authentication or a stronger method.
How should businesses authenticate users during account recovery?
Recovery should use evidence that remains trustworthy after the reported loss or compromise. Options may include a previously registered backup authenticator, recovery codes, or renewed identity verification. Restoring access should also address compromised credentials and existing sessions.
Which authentication records should a business retain?
Useful records include the account identifier, time, authentication method, success or failure, and relevant risk or recovery decisions. Logs should exclude passwords, private keys, and usable session secrets. Retention should support investigation while meeting applicable data-handling requirements.