Identification and Authentication
Bruce Schneier · 2015
Traditionally, identification and authentication measures have centered on one of three things: something you know, something you are, or something you have. These roughly translate to “passwords”, “biometrics”, and “access tokens”. Sometimes systems use two of these things together. Paranoid systems use all three. Biometric identification systems have gotten better at detecting both false positives and false negatives. Authentication protocols are cryptographic ways for Alice to authenticate herself across a network. Kerberos is a more complicated authentication protocol. One thing that has annoyed computer users in large secure environments is the large number of passwords. Users might have to type in one password to log on to their computers, another to log on to the network, a third to log on to a particular server on the network, and so on. Single sign-on is the solution to the usability problem.