Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    W3C WebAuthn to Advance FIDO Protocols for Strong Authentication

    Written by

    Sean Michael Kerner
    Published April 12, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The new WebAuthn standard is coming to the web as the W3C is working to bring the latest generation of the FIDO strong authentication specifications forward into the standards realm.

      The FIDO (Fast Identity Online) Alliance has been building strong authentication specifications including the Universal Second Factor (U2) and Universal Authentication Framework (UAF) since 2012. With the W3C, FIDO is evolving its FIDO2 specification to become an official web standard that will be supported by all the major web browsers.

      “The W3C’s Web Authentication Working Group is responsible for defining the Web API to strong authentication, so we started with a submission from FIDO and worked to address the feedback from implementors such as web browsers and additional participants and reviewers,” Wendy Seltzer, W3C strategy lead, told eWEEK.

      The FIDO Alliance finalized its first set of strong authentication specifications in December 2014 with the U2F and UAF 1.0 releases. The early promise of the specifications was to enable secure authentication that goes beyond the basic username and password paradigm to provide stronger authentication options including two-factor and biometrics. Among the early backers of the U2F 1.0 specification was Google, which implemented support for FIDO into Chrome back in 2014 as well.

      “By partnering with W3C to standardize FIDO Authentication for the entire web platform, the FIDO ecosystem grows by more than just one or two leading web browsers,” Brett McDowell, executive director of the FIDO Alliance, told eWEEK. “We expect to benefit from the entire community of web browsers and web application servers supporting the standard. W3C is simply where the web community produces their standards, so it was more practical to work on this set of web technologies in that forum.”

      FIDO2

      The W3C WebAuthn standards effort involves the FIDO2 specification project, which is a next generation of the U2F and UAF specifications that have been in the market since 2014.

      McDowell said that if you look at the use cases that U2F/UAF standards enabled, then FIDO2 represents a new set of specifications that enable the superset of those use cases. That said, he noted that the technical specifications are in fact a bit different in one important way: FIDO2 was designed from day one to be implemented by platforms. 

      “The FIDO2 Project is a set of interlocking initiatives that together create a FIDO Authentication standard for platforms such as the web and native operating systems,” McDowell said. “By optimizing FIDO Authentication for platform implementation, we greatly expand the FIDO ecosystem as browsers and operating systems push out updates to billions of devices.”

      CTAP

      The U2F protocol that FIDO first released back in 2014 is now part of Client to Authenticator Protocols (CTAP) specification set and is now referred to as CTAP1 . McDowell said that CTAP2 is the new protocol that accommodates an expanded set of capabilities in next generation external authenticators. 

      “With CTAP1/U2F, the external authenticator was only expected to be able to provide the second factor of authentication,” he said. “That meant a CTAP1/U2F solution needed to get its first factor of authentication the old fashion way, with a match-on-server password.”  

      With CTAP2, the external authenticator can provide both factors of authentication, not just one, according to McDowell. The next-generation external authentication devices will be able to accommodate a biometric or PIN unlock mechanism to add a second factor that is matched on-device, not in the cloud. 

      “In this way, a CTAP2 authenticator removes the previous implicit dependency on legacy passwords,” he said.

      There is already a large ecosystem of vendors and users of FIDO-compliant devices. but that market will be even larger with WebAuthn. To prepare the market to take full advantage of the growth in the addressable market of FIDO-enabled devices, McDowell said the FIDO Alliance is providing testing tools and launching certification programs for FIDO2 specifications (CTAP + WebAuthn).

      “FIDO technology providers will be introducing FIDO Certified Universal Servers that support FIDO2 and all prior UAF and U2F devices, enabling full backwards compatibility for all previously certified FIDO authenticators,” McDowell said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.