Posted in

5 Multi-factor Authentication Strategies Enterprises Can Use

In 2016 alone, more than 2.2 billion records were exposed in data breaches. Using a password-based authentication with a good hashing scheme like Bcrypt is perfectly fine as long as you can guarantee that your users wont use easy to guess passwords or reuse passwords at many portals. Both of these assumptions turn out to be wrong in a substantial number of cases, however. There are ample reasons to require using multi-factor authentication. Other than asking your employees and users to use a password manager, here are five strategies that a business can use to protect themselves (that SMS as a second factor is not recommended because of some serious security implications):

HOTP/TOTP

This is the second most common way of providing multi-factor authentication (after SMS). HOTP and TOTP are One-Time-Password strategies that generate a secret code to be entered by the user to log in. This secret code has a time-based expiry. The code is shared with the user using an already authenticated application that is installed on the users mobile device. Google Authenticator is an example of one such application. Note that any application that supports HOTP/TOTP can be used to login to multiple services, you do not need a new application for each service.

Magic Link Login

In this login scheme, once the user enters the correct user id, instead of entering the password, the user is provided with a direct login link. This link is sent to the users verified email account. The user is required to go to their email account and click on the received link. This login strategy was recently introduced by Slack. Enterprises can implement it for their users as detailed in this guide.

Yubikey

Yubikey is a small USB and NFC enabled device that supports multiple authentication and cryptographic protocols. Yubikey protects you from downgrading and MITM (Man In The Middle) attacks. Each user can program their Yubikey on their own or enterprises can do it in bulk for their employees. It can be used with password managers, internet services, for computer login and for disk encryption. It works with hundreds of applications right out of the box. Businesses can be in good company of the likes of Google and Facebook by using Yubikey for access management. All of their applications are open sourced.

Access Tokens

Another possible strategy for access management can be using access tokens. This strategy is important in controlling access to critical information and infrastructure in high-security risk environments. Access should be granted only when it is expected. The user is required to request access to a service from a control center. This request can either be at the physical level or can be done by using a web portal. A web portal access request would subject to manual verification or pre-determined expectancy of the request.

If the user is expected to have made that request, they are provided with an access token. The user authenticates normally using their username and password on the service and enters the access token to access the service. Access tokens also provide the added facility to limit the scope of features in a service a user has access to, as well as limiting the time a user can use that service for.

Biometric Identification

Biometric identification has been used as an authentication factor for a long time. But now consumer devices are being equipped with fingerprint and retina sensors, making biometric authentication accessible to the masses. Windows 10 provides an authentication strategy called Windows Hello based on face recognition. Apple provides a biometric authentication using fingerprints as Touch ID on its devices. Several other mobile device manufacturers now support these features on their devices in some form. There are several concerns about using biometric authentication that make it somewhat less effective than other schemes mentioned above.

Multi-factor authentication is no longer to be considered an add-on to the first line of defense for users credentials. Due to recent hacks, companies like Ashley Madison, Sony, JP Morgan, Ebay, Yahoo, and LinkedIn would know that.

Aditya Rana is a business development professional and former analyst who is based in Delhi. He has previously helped companies such as HP reduce their overhead using basic statistical analysis to optimize supply chain and inventory management. More recently, he has forayed into the healthcare SaaS space with Lybrate. He has a degree in Molecular Biology and has a logical data-intensive approach to manage his key accounts.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.