Monday, October 7, 2013

the CIA triad and two-factor authentication

More from the book I'm reading... the CIA triad:

  1. confidentiality – let only the authorized see the private
  2. integrity – guard against inappropriate edits/deletes ensuring data stays valid (nonrepudiation)
  3. availability – uptime for access

 
 

Authentication can be based on three different factors (and if you require two of the three then you have two-factor authentication).

  1. knowledge – you must recall a password
  2. ownership – you have a token or a certificate
  3. inherence – validation based on something uniquely of you such as your DNA or a fingerprint (not inheritance but inherence)

 
 

Two-factor authentication acronyms:

  • TFA
  • 2FA

No comments:

Post a Comment