FIDO White Papers - Authoritative FIDO reports & positioning https://fidoalliance.org/content/white-paper/ Tue, 27 Jun 2023 13:39:18 +0000 en-US hourly 1 https://wordpress.org/?v=6.3 215978836 White Paper: High Assurance Enterprise FIDO Authentication https://fidoalliance.org/high-assurance-enterprise-fido-authentication/ Tue, 27 Jun 2023 13:11:14 +0000 https://fidoalliance.org/?p=41591 This white paper addresses specific considerations for determining the appropriate type of passkey for enterprises that require high levels of identity assurance, have internal security policies, or need to meet […]

The post White Paper: High Assurance Enterprise FIDO Authentication appeared first on FIDO Alliance.

]]>
This white paper addresses specific considerations for determining the appropriate type of passkey for enterprises that require high levels of identity assurance, have internal security policies, or need to meet regulatory requirements.

The post White Paper: High Assurance Enterprise FIDO Authentication appeared first on FIDO Alliance.

]]>
41591
White Paper: FIDO Authentication for Moderate Assurance Use Cases https://fidoalliance.org/fido-authentication-for-moderate-assurance-use-cases/ Tue, 27 Jun 2023 13:10:20 +0000 https://fidoalliance.org/?p=41590 This white paper provides guidance for organizations as they analyze the abilities and features of both device-bound passkeys and synced passkeys to determine how both credential types can be utilized […]

The post White Paper: FIDO Authentication for Moderate Assurance Use Cases appeared first on FIDO Alliance.

]]>
This white paper provides guidance for organizations as they analyze the abilities and features of both device-bound passkeys and synced passkeys to determine how both credential types can be utilized in a moderate assurance environment. The paper compares features and requirements that are supported by device-bound and synced passkeys, providing a vision of how both types of credentials can be utilized together in an organization that has moderate assurance needs.

The post White Paper: FIDO Authentication for Moderate Assurance Use Cases appeared first on FIDO Alliance.

]]>
41590
White Paper: Replacing Password-Only Authentication with Passkeys in the Enterprise https://fidoalliance.org/replacing-password-only-authentication-with-passkeys-in-the-enterprise/ Tue, 27 Jun 2023 13:09:30 +0000 https://fidoalliance.org/?p=41589 This white paper describes the need for a more secure and convenient solution for authentication. Passwords have long been the standard for authentication, but the risks inherent to passwords reduce […]

The post White Paper: Replacing Password-Only Authentication with Passkeys in the Enterprise appeared first on FIDO Alliance.

]]>
This white paper describes the need for a more secure and convenient solution for authentication. Passwords have long been the standard for authentication, but the risks inherent to passwords reduce their efficacy as an authentication mechanism. Multi-factor authentication (MFA) solutions have been on market for some time, but their widespread adoption has been slow due to various barriers. Passkeys are an authentication solution that reduces the adoption barriers of traditional MFA mechanisms, while offering improved security, ease of use, and scalability over passwords and classic MFA solutions. Passkeys utilize on-device biometrics or PINs for authentication and provide a seamless user experience. This white paper outlines the benefits of passkeys, the user experience, and adoption considerations for enterprises.

The post White Paper: Replacing Password-Only Authentication with Passkeys in the Enterprise appeared first on FIDO Alliance.

]]>
41589
White Paper: Introduction: Deploying Passkeys in the Enterprise https://fidoalliance.org/introduction-deploying-passkeys-in-the-enterprise/ Tue, 27 Jun 2023 13:08:42 +0000 https://fidoalliance.org/?p=41588 This introductory paper provides an overview of the benefits of passkeys in the enterprise and provides a glossary of common terms to be used in conjunction with the other papers […]

The post White Paper: Introduction: Deploying Passkeys in the Enterprise appeared first on FIDO Alliance.

]]>
This introductory paper provides an overview of the benefits of passkeys in the enterprise and provides a glossary of common terms to be used in conjunction with the other papers in this series.

The post White Paper: Introduction: Deploying Passkeys in the Enterprise appeared first on FIDO Alliance.

]]>
41588
White Paper: Using FIDO for the EUDI Wallet https://fidoalliance.org/white-paper-using-fido-for-the-eudi-wallet/ Thu, 20 Apr 2023 14:43:14 +0000 https://fidoalliance.org/?p=40511 This white paper describes the eIDAS2 ecosystem and how to use the FIDO standard with the EU Digital Identity (EUDI) Wallet. This white paper is aimed at governmental agencies that […]

The post White Paper: Using FIDO for the EUDI Wallet appeared first on FIDO Alliance.

]]>
This white paper describes the eIDAS2 ecosystem and how to use the FIDO standard with the EU Digital Identity (EUDI) Wallet.

This white paper is aimed at governmental agencies that are interested in using FIDO for the EUDI Wallet according to the eIDAS2 regulation. The intended readers are project managers, technical experts, and developers.

The post White Paper: Using FIDO for the EUDI Wallet appeared first on FIDO Alliance.

]]>
40511
White Paper: FIDO for e-Government Services https://fidoalliance.org/white-paper-fido-for-e-government-services/ Tue, 13 Dec 2022 22:55:13 +0000 https://fidoalliance.org/?p=38926 The global COVID-19 pandemic closed offices and forced governments to rapidly move services online, if they weren’t already, to serve its citizens. Although usernames and passwords are easy to deploy […]

The post White Paper: FIDO for e-Government Services appeared first on FIDO Alliance.

]]>
The global COVID-19 pandemic closed offices and forced governments to rapidly move services online, if they weren’t already, to serve its citizens. Although usernames and passwords are easy to deploy and easy for citizens to use, they leave systems and users vulnerable to cyberattacks. They are especially vulnerable to phishing attacks designed to steal login credentials and compromise legacy multi-factor authentication (MFA) tools like those using one-time passwords (OTP) and push notifications. With phishing attacks on the rise, it is imperative for governments to support “phishing-resistant” MFA technology that is also accessible, efficient, and cost-effective.

Enterprises and governments around the globe are turning to modern online authentication solutions featuring FIDO specifications based on public key cryptography. Governments and industries have embraced FIDO as the preferred way to deliver high-assurance MFA to consumers. Notably, the Cybersecurity & Infrastructure Security Agency (CISA), a component of the U.S. Department of Homeland Security (DHS), refers to FIDO security keys as the gold standard of MFA1

Several governments globally have deployed and/or supported FIDO authentication for citizens to securely conduct government transactions, including making tax payments and applying for and accessing government benefits. Governments leveraging FIDO authentication solutions have realized reduced operational costs and increased consumer satisfaction.

This white paper provides guidance for policymakers and department/agency heads seeking to learn about FIDO authentication to support or deploy FIDO for e-government services.

The post White Paper: FIDO for e-Government Services appeared first on FIDO Alliance.

]]>
38926
White Paper:  Guidance for Making FIDO Deployments Accessible to Users with Disabilities  https://fidoalliance.org/white-paper-guidance-for-making-fido-deployments-accessible-to-users-with-disabilities/ Thu, 13 Oct 2022 22:30:32 +0000 https://fidoalliance.org/?p=38090 In achieving FIDO Alliance’s mission of more secure and password-free authentication, we must ensure the needs and preferences of people with disabilities—an estimated 15% of the world’s population—are taken into […]

The post White Paper:  Guidance for Making FIDO Deployments Accessible to Users with Disabilities  appeared first on FIDO Alliance.

]]>
In achieving FIDO Alliance’s mission of more secure and password-free authentication, we must ensure the needs and preferences of people with disabilities—an estimated 15% of the world’s population—are taken into account. This white paper is intended to provide guidance on planning FIDO deployments accessible to users with a wide range of disabilities. 

This white paper is intended for information security executives, product owners, identity and access management, attorneys, accessibility practitioners, and others who are considering deploying FIDO Authenticators across their enterprises. This white paper may also help hardware manufacturers identify opportunities to deliver more accessible external authenticators. 

The post White Paper:  Guidance for Making FIDO Deployments Accessible to Users with Disabilities  appeared first on FIDO Alliance.

]]>
38090
White Paper: FIDO Authentication in Digital Payment Security https://fidoalliance.org/white-paper-fido-authentication-in-digital-payment-security/ Thu, 08 Sep 2022 23:27:24 +0000 https://fidoalliance.org/?p=37489 The Indian Payments ecosystem is going through rapid change and advancement. The Reserve Bank of India (Digital Payment Security Controls) Directions 2020 were issued for regulated entities to set up […]

The post White Paper: FIDO Authentication in Digital Payment Security appeared first on FIDO Alliance.

]]>
The Indian Payments ecosystem is going through rapid change and advancement. The Reserve Bank of India (Digital Payment Security Controls) Directions 2020 were issued for regulated entities to set up a robust governance structure for such systems and implement common minimum standards of security controls for channels like internet, mobile banking, and card payments, among others. In this paper, we demonstrate how FIDO Authentication represents the best way for organizations to implement simpler, stronger authentication that meets Reserve Bank of India’s Master Direction on Digital Payment Control requirements, while also enhancing the user experience.

The post White Paper: FIDO Authentication in Digital Payment Security appeared first on FIDO Alliance.

]]>
37489
White Paper: Multi-Device FIDO Credentials https://fidoalliance.org/white-paper-multi-device-fido-credentials/ Thu, 17 Mar 2022 12:13:23 +0000 https://fidoalliance.org/?p=36193 The FIDO standards, together with their companion WebAuthn specification, are on the cusp of an important new development: evolutionary changes to the standards proposed by the FIDO Alliance and the […]

The post White Paper: Multi-Device FIDO Credentials appeared first on FIDO Alliance.

]]>
The FIDO standards, together with their companion WebAuthn specification, are on the cusp of an important new development: evolutionary changes to the standards proposed by the FIDO Alliance and the W3C WebAuthn community aim to markedly improve the usability and deployability of FIDO-based authentication mechanisms. As a result, FIDO-based secure authentication technology will for the first time be able to replace passwords as the dominant form of authentication on the Internet. 

In this paper, we explain how FIDO and WebAuthn standards previously enabled low-cost deployments of authentication mechanisms with very high assurance levels. While this has proved an attractive alternative to traditional smart card authentication, and even opened the door to high-assurance authentication in the consumer space, we haven’t attained large-scale adoption of FIDO-based authentication in the consumer space. We explain how the introduction of multi-device FIDO credentials will enable FIDO technology to supplant passwords for many consumer use cases as they make the FIDO credentials available to users whenever they need them—even if they replace their device.

The post White Paper: Multi-Device FIDO Credentials appeared first on FIDO Alliance.

]]>
36193
White Paper: Choosing FIDO Authenticators for Enterprise Use Cases  https://fidoalliance.org/white-paper-choosing-fido-authenticators-for-enterprise-use-cases-2/ Sat, 12 Mar 2022 14:15:46 +0000 https://fidoalliance.org/?p=36159 Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the […]

The post White Paper: Choosing FIDO Authenticators for Enterprise Use Cases  appeared first on FIDO Alliance.

]]>

Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the FIDO Alliance has developed open and scalable advancements to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, the FIDO Alliance has established a series of best practices and how-to white papers that align the Alliance’s goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within the enterprise. 

This white paper is intended for IT administrators and Enterprise Security Architects who are considering deploying FIDO Authenticators across their enterprise and defining life cycle management policies. In this paper, we provide an overview of the different use cases for multi-factor authentication and the FIDO Authenticator choices administrators have. The intent is to help and guide administrators in choosing the right authenticator types for their specific environment.

The post White Paper: Choosing FIDO Authenticators for Enterprise Use Cases  appeared first on FIDO Alliance.

]]>
36159
White Paper: Choosing FIDO Authenticators for Enterprise Use Cases https://fidoalliance.org/white-paper-choosing-fido-authenticators-for-enterprise-use-cases/ Tue, 21 Sep 2021 23:02:25 +0000 https://fidoalliance.org/?p=35170 Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the […]

The post White Paper: Choosing FIDO Authenticators for Enterprise Use Cases appeared first on FIDO Alliance.

]]>
Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the FIDO Alliance has developed open and scalable advancements to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, the FIDO Alliance has established a series of best practices and how-to white papers that align the Alliance’s goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within the enterprise.

This white paper is intended for IT administrators and enterprise security architects who are considering deploying FIDO Authenticators across their enterprises and defining life cycle management policies. In this paper, we provide an overview of the different use cases for multi-factor authentication and the FIDO Authenticator choices administrators have. The intent is to help and guide administrators in choosing the right authenticator types for their specific environment.

The post White Paper: Choosing FIDO Authenticators for Enterprise Use Cases appeared first on FIDO Alliance.

]]>
35170
White Paper: FIDO Authenticator Lifecycle Management for IT Administrators https://fidoalliance.org/fido-authenticator-lifecycle-management-for-it-administrators/ Thu, 22 Apr 2021 11:30:02 +0000 https://fidoalliance.org/?p=33801 Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the […]

The post White Paper: FIDO Authenticator Lifecycle Management for IT Administrators appeared first on FIDO Alliance.

]]>
Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the FIDO Alliance has developed open and scalable advancements to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, the FIDO Alliance has established a series of best practices and how-to white papers that align the Alliance’s goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within the enterprise.

This white paper targets IT administrators and Enterprise Security Architects considering deploying FIDO Authenticators across their enterprises and defining lifecycle management policies.

The post White Paper: FIDO Authenticator Lifecycle Management for IT Administrators appeared first on FIDO Alliance.

]]>
33801
FIDO Device Onboard: A Specification for Automated, Secure IoT Provisioning Technology https://fidoalliance.org/intro-to-fido-device-onboard/ Tue, 20 Apr 2021 11:17:47 +0000 https://fidoalliance.org/?p=33748 In the world of IoT, the first thing referenced is often the size of the market opportunity. Numbers in billions are often presented in terms of volume of units. IDC […]

The post FIDO Device Onboard: A Specification for Automated, Secure IoT Provisioning Technology appeared first on FIDO Alliance.

]]>
In the world of IoT, the first thing referenced is often the size of the market opportunity. Numbers in billions are often presented in terms of volume of units. IDC expects the IoT market to maintain a double-digit annual growth rate and surpass the $1 trillion mark in 2022. Talked about less is what it will take for the opportunity of IoT to be realized. At the heart of this are costs and complexities of ‘onboarding’ IoT devices in industrial, enterprise or consumer applications. IoT device onboarding involves the installation of the physical device and the setup of credentials so that it can securely communicate with its target cloud or platform. 

Today, this onboarding process is usually done manually by a technician – a process that is slow, expensive, and insecure. Industry sources have said that it is not uncommon for the cost of installation and setup to exceed the cost of the device itself. Although multiple companies have worked to automate the onboarding process, there wasn’t a widely accepted industry standard. Also, many proprietary solutions that do exist require that the end customer be known at the time of the device manufacture so that the device can be pre-configured. This creates friction and cost in the supply chain. 

The FIDO Alliance stepped up in the summer of 2019 to address this industry challenge. With its broad membership of leading cloud service providers, semiconductor companies and security companies, the Alliance is well positioned to bring together those that create and supply the technologies in the IoT ecosystem. The FIDO Alliance formed its IoT Technical Working Group (IoT TWG) with these stakeholders to define a new standard for automated, secure IoT onboarding. Less than 2 years after the working group formed, the FIDO Alliance is now releasing to the industry the FIDO Device Onboarding (FDO) specification.

Read the paper for a full introduction to FDO.

The post FIDO Device Onboard: A Specification for Automated, Secure IoT Provisioning Technology appeared first on FIDO Alliance.

]]>
33748
White Paper: FIDO for SCA Delegation to Merchants or Wallet Providers https://fidoalliance.org/white-paper-fido-for-sca-delegation-to-merchants-or-wallet-providers/ Tue, 16 Mar 2021 15:50:02 +0000 https://fidoalliance.org/?p=33121 The authentication of consumers during remote transactions has undeniable benefits in terms of security and approval rates but raises concerns of transactions being abandoned by consumers, as those consumers are […]

The post White Paper: FIDO for SCA Delegation to Merchants or Wallet Providers appeared first on FIDO Alliance.

]]>

The authentication of consumers during remote transactions has undeniable benefits in terms of security and approval rates but raises concerns of transactions being abandoned by consumers, as those consumers are not always able to authenticate properly to their banks.

Merchants and wallet providers have an existing relationship with consumers, and there is an opportunity to leverage authentication mechanisms established during that relationship to authenticate to remote transactions as a delegation of the bank’s authentication.

This white paper reviews the different authentication mechanisms that can be used by merchants or wallet providers in the context of Strong Customer Authentication (SCA) Delegation and explains why FIDO is best positioned to meet the requirements from regulatory authorities, banks, merchants, or wallet providers.

The post White Paper: FIDO for SCA Delegation to Merchants or Wallet Providers appeared first on FIDO Alliance.

]]>
33121
White Paper: Considerations for Deploying FIDO Servers in the Enterprise https://fidoalliance.org/white-paper-considerations-for-deploying-fido-servers-in-the-enterprise/ Wed, 21 Oct 2020 17:27:50 +0000 https://fidoalliance.org/?p=31848 Today, secure access to online applications and services has evolved into a model based on devices, public key cryptography and biometrics to replace the anachronistic use of passwords as shared […]

The post White Paper: Considerations for Deploying FIDO Servers in the Enterprise appeared first on FIDO Alliance.

]]>

Today, secure access to online applications and services has evolved into a model based on devices, public key cryptography and biometrics to replace the anachronistic use of passwords as shared secrets. Since 2013, the FIDO Alliance has developed open and scalable advancements to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, FIDO Alliance has developed a series of best practices and how-to white papers that match the Alliance’s goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within all companies. 

A FIDO server is a necessary component in a FIDO implementation. The FIDO server stores the user’s public key credential and account information. During a FIDO Authentication or registration flow, the server generates a cryptographic challenge in response to a request from the application. The server then verifies the signature provided by the client using the server’s corresponding public key, and logs the user in. 

This white paper is intended for IT professionals and identity architects to guide them in choosing the right FIDO server implementation and deployment architecture when integrating and enabling FIDO-based authentication in enterprise applications. Enterprises must consider several factors in their planning to select and deploy a FIDO server, including build vs. buy assessment (and the risks and benefits associated with each), the desired deployment model, the required server capabilities, and the security and privacy requirements. 

The post White Paper: Considerations for Deploying FIDO Servers in the Enterprise appeared first on FIDO Alliance.

]]>
31848
White Paper: Accepting FIDO Credentials in the Enterprise https://fidoalliance.org/white-paper-accepting-fido-credentials-in-the-enterprise/ Mon, 19 Oct 2020 14:42:04 +0000 https://fidoalliance.org/?p=31838 Today, secure access to online applications and services has evolved into a framework reliant on devices, public key cryptography and biometrics to replace the shared secrets of aging passwords. Since […]

The post White Paper: Accepting FIDO Credentials in the Enterprise appeared first on FIDO Alliance.

]]>

Today, secure access to online applications and services has evolved into a framework reliant on devices, public key cryptography and biometrics to replace the shared secrets of aging passwords. Since 2013, the FIDO Alliance has developed and advanced open and scalable standards to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, FIDO Alliance has developed a series of best practices and how-to white papers that match the Alliance’s goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within all companies. 

Enterprises that accept FIDO credentials are participating in a digital credential exchange. This white paper is intended for CISOs and IT professionals who are considering deploying FIDO across their enterprise. In this paper, we provide a high-level overview of the most common digital exchange – the authentication exchange. We will examine the participants, protocols, and decisions that enterprises must make regarding the creation, management, and usage of FIDO credentials. 

The post White Paper: Accepting FIDO Credentials in the Enterprise appeared first on FIDO Alliance.

]]>
31838
Technical Note: FIDO Authentication and EMV 3-D Secure – Using FIDO for Payment Authentication https://fidoalliance.org/technical-note-fido-authentication-and-emv-3-d-secure-using-fido-for-payment-authentication/ Tue, 29 Sep 2020 15:17:54 +0000 https://fidoalliance.org/?p=31691 The FIDO Alliance defines standards that enable strong consumer authentication and seeks to use those standards to improve security on the internet. EMV 3-D Secure (EMV 3DS) is a payment […]

The post Technical Note: FIDO Authentication and EMV 3-D Secure – Using FIDO for Payment Authentication appeared first on FIDO Alliance.

]]>
The FIDO Alliance defines standards that enable strong consumer authentication and seeks to use those standards to improve security on the internet. EMV 3-D Secure (EMV 3DS) is a payment industry standard for performing consumer verification and authentication within the context of online payments via credit cards. EMV 3DS also standardizes payment transaction information which is sent from a merchant to the issuing bank and includes data about the cardholder account, payment environment, and actions taken during payment. Using this data, the card issuing bank or a party operating on their behalf can perform transaction risk assessment and minimize the need to apply unnecessary friction to a payment transaction when it is deemed low risk. This is also known as “frictionless authentication” within the EMV 3DS standard. 

This document focuses on the role of the merchant as the FIDO or WebAuthn relying party and defines the methods for the merchant to leverage EMV 3DS as the conduit to report FIDO Authentication Data to the issuing bank. This data, along with the other transaction details sent using EMV 3DS messaging via the 3DS Authentication Request message, can help ensure minimized friction through risk-based authentication at the time of online payment. Although the resultant assurance level is reduced using this method, as opposed to an issuer-managed credential, and it will need to be viewed within the context of the entire EMV 3DS message, it can provide an approach that can be more easily deployed at scale than issuer-managed FIDO Authentication methods. 

The post Technical Note: FIDO Authentication and EMV 3-D Secure – Using FIDO for Payment Authentication appeared first on FIDO Alliance.

]]>
31691
White Paper: FIDO Transaction Confirmation https://fidoalliance.org/white-paper-fido-transaction-confirmation/ Fri, 21 Aug 2020 16:02:03 +0000 https://fidoalliance.org/?p=31502 Besides generic session authentication, there is an increasing need to gather explicit user consent for a specific action, i.e. “Transaction Confirmation”. Transaction Confirmation allows a relying party to not only […]

The post White Paper: FIDO Transaction Confirmation appeared first on FIDO Alliance.

]]>

Besides generic session authentication, there is an increasing need to gather explicit user consent for a specific action, i.e. “Transaction Confirmation”. Transaction Confirmation allows a relying party to not only determine if a user is involved in a transaction, but also confirm that the transaction is what the user actually intended – for example, whether they intended to pay $1000 to company X for purchasing product Y, or whether they consent to have specific data shared with another party, such as test results with a doctor.

This paper provides an overview on Transaction Confirmation and the drivers for its support including: regulatory requirements (PSD2, eIDAS); addressing friendly and mobile fraud; and to enable online binding agreements. It explains current approaches for Transaction Confirmation, including through FIDO protocols for native applications, and the value of adding support for it directly in web browsers. It concludes with a call for feedback from relying parties on whether they would like to see Transaction Confirmation should be supported directly in web browsers.

The post White Paper: FIDO Transaction Confirmation appeared first on FIDO Alliance.

]]>
31502
White Paper: CXO Explanation: Why Use FIDO for Passwordless Employee Logins? https://fidoalliance.org/white-paper-cxo-explanation-why-use-fido-for-passwordless-employee-logins/ Wed, 22 Jul 2020 12:16:13 +0000 https://fidoalliance.org/?p=31205 Today, secure access to online applications and services has evolved into a framework reliant on devices, public key cryptography and biometrics to replace the shared secrets of aging passwords. Since […]

The post White Paper: CXO Explanation: Why Use FIDO for Passwordless Employee Logins? appeared first on FIDO Alliance.

]]>

Today, secure access to online applications and services has evolved into a framework reliant on devices, public key cryptography and biometrics to replace the shared secrets of aging passwords. Since 2013, the FIDO Alliance has developed open and scalable advancements to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, FIDO Alliance has developed a series of best practices and how-to white papers that match the Alliance’s goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within all companies. 

This white paper answers the most common questions from CXOs about the value proposition of FIDO Authentication and how the FIDO2 passwordless framework addresses the authentication needs and challenges of companies for the modern workforce. The goal of this document is to guide executive leaders within an organization as to why they should invest in FIDO2 deployment for their employees. 

The post White Paper: CXO Explanation: Why Use FIDO for Passwordless Employee Logins? appeared first on FIDO Alliance.

]]>
31205
White Paper: Multiple Authenticators for Reducing Account-Recovery Needs for FIDO-Enabled Consumer Accounts https://fidoalliance.org/white-paper-multiple-authenticators-for-reducing-account-recovery-needs-for-fido-enabled-consumer-accounts/ Thu, 04 Jun 2020 20:24:16 +0000 https://fidoalliance.org/?p=30793 When a service deploys FIDO Authentication, it must have a secure account recovery process to address lost, damaged or stolen FIDO authenticators. A previous FIDO Alliance white paper, Recommended Account […]

The post White Paper: Multiple Authenticators for Reducing Account-Recovery Needs for FIDO-Enabled Consumer Accounts appeared first on FIDO Alliance.

]]>

When a service deploys FIDO Authentication, it must have a secure account recovery process to address lost, damaged or stolen FIDO authenticators. A previous FIDO Alliance white paper, Recommended Account Recovery Practices for FIDO Relying Parties, recommends two strategies:

  1. Require the user to register multiple authenticators, to reduce the need for account recovery; 

if #1 is not feasible:

  1. Re-run the initial identity proofing or user onboarding process to recover the account.

The first strategy, to require multiple authenticators, plays a very important role for FIDO-enabled consumer-facing accounts where the number of account recovery options can be limited. This includes scenarios where the password has been disabled after FIDO credentials are registered, or where passwords and FIDO credentials are registered for two-step authentication. 

This paper focuses on the first strategy and provides guidance on how to deploy FIDO Authentication with multiple authenticators. It discusses how to register new authenticators bound to an already-registered authenticator, security considerations, coverage/authenticator options, usability, and policy, based on FIDO-enabled browsers and platforms. It provides recommendations for registration methods and policy examples for deploying the solution.

The post White Paper: Multiple Authenticators for Reducing Account-Recovery Needs for FIDO-Enabled Consumer Accounts appeared first on FIDO Alliance.

]]>
30793
White Paper: PSD2 Support: Why Change to FIDO https://fidoalliance.org/white-paper-psd2-support-why-change-to-fido/ Thu, 04 Jun 2020 19:53:14 +0000 https://fidoalliance.org/?p=30802 Banks in Europe have deployed customer authentication solutions for several years. These solutions have served their purpose well and enabled customers to safely log in to their bank accounts. In […]

The post White Paper: PSD2 Support: Why Change to FIDO appeared first on FIDO Alliance.

]]>

Banks in Europe have deployed customer authentication solutions for several years. These solutions have served their purpose well and enabled customers to safely log in to their bank accounts. In the world of e-commerce, these solutions, when used, have been successful in combatting online payment fraud. 

The Second Payment Services Directive (PSD2) and its associated Regulatory Technical Standards (RTS) dramatically change the payment landscape, considering:

  • The mandate for strong, multi-factor authentication, 
  • The emergence of Third Party Providers (TPP) accessing accounts via open APIs

The success of PSD2 will ultimately be determined by how well banks can balance user convenience with security obligations, while maximizing reach. As such, they may want to evaluate how well their legacy authentication solutions meet this new need. 

FIDO authentication standards have been proposed as a way for banks to meet all requirements in a PSD2 world — but is the change from a legacy method to FIDO worthwhile? This paper proposes guidance to banks to help them decide. 

The paper describes FIDO Authentication standards and compares it with legacy authentication methods used to access an account or secure an online payment. The methods compared are SMS OTPs, hardware OTP generators, CAP readers, and proprietary smartphone and biometrics-based solutions in terms of PSD2 compliance, security, usability and scalability. Ultimately, the paper answers the question: Why change to FIDO?

The post White Paper: PSD2 Support: Why Change to FIDO appeared first on FIDO Alliance.

]]>
30802
White Paper: Introduction of FIDO & eIDAS Services https://fidoalliance.org/white-paper-introduction-of-fido-eidas-services/ Wed, 29 Apr 2020 00:59:30 +0000 http://fidoalliance.org/?p=30445 eIDAS stands for “electronic identification, authentication and trust services” It builds the legal basis for cross-border interoperability of electronic identification, authentication, and electronic signatures amongst EU Member States. This introductory […]

The post White Paper: Introduction of FIDO & eIDAS Services appeared first on FIDO Alliance.

]]>

eIDAS stands for “electronic identification, authentication and trust services” It builds the legal basis for cross-border interoperability of electronic identification, authentication, and electronic signatures amongst EU Member States.

This introductory white paper describes the relationship between FIDO2 standards and eIDAS compliant schemes that can accommodate modern authentication protocols. The paper includes:

  • An introduction to eIDAS
  • An overview on how to use FIDO as part of an eID scheme
  • An overview on using FIDO2 for authentication to Qualified Trust Service Providers (QTSPs)

This paper is intended for governmental agencies that are interested in using FIDO2 as part of an eIDAS notified eID scheme, and QTSPs who are interested in deploying eIDAS remote signing services that leverage the FIDO2 standard.

For details, including architectural concepts for integration of FIDO2 into the eIDAS interoperability framework, please read the complementary white paper, “Using FIDO with eIDAS Services.”

The post White Paper: Introduction of FIDO & eIDAS Services appeared first on FIDO Alliance.

]]>
30445
White Paper: Using FIDO with eIDAS Services https://fidoalliance.org/white-paper-using-fido-with-eidas-services/ Wed, 29 Apr 2020 00:14:14 +0000 http://fidoalliance.org/?p=30435 eIDAS stands for “electronic identification, authentication and trust services” It builds the legal basis for cross-border interoperability of electronic identification, authentication, and electronic signatures amongst EU Member States. This white […]

The post White Paper: Using FIDO with eIDAS Services appeared first on FIDO Alliance.

]]>

eIDAS stands for “electronic identification, authentication and trust services” It builds the legal basis for cross-border interoperability of electronic identification, authentication, and electronic signatures amongst EU Member States.

This white paper describes how to use FIDO2 standards with eIDAS compliant schemes and Qualified Trust Service Providers (QTSPs), including architectural concepts for integration of FIDO2 into the eIDAS interoperability framework. The paper includes: 

  • An introduction to eIDAS
  • Detailed information on how FIDO as part of an eID scheme
  • Detailed information on how to use FIDO2 for secured access to QTSPs

This paper is intended for governmental agencies that are interested in using FIDO2 as part of an eIDAS notified eID scheme, and QTSPs who are interested in deploying eIDAS remote signing services that leverage the FIDO2 standard.

For introductory level information on the relationship between FIDO and eIDAS, please read the complementary white paper, “Introduction to FIDO and eIDAS.”

The post White Paper: Using FIDO with eIDAS Services appeared first on FIDO Alliance.

]]>
30435
White Paper: FIDO and PKI Integration in the Enterprise https://fidoalliance.org/white-paper-fido-and-pki-integration-in-the-enterprise/ Tue, 30 Apr 2019 14:12:40 +0000 http://fidoalliance.org/?p=27534 FIDO Enterprise Adoption Best Practices This white paper is aimed at enterprises and government agencies looking to expand their authentication capabilities to include FIDO technology, and have FIDO work in […]

The post White Paper: FIDO and PKI Integration in the Enterprise appeared first on FIDO Alliance.

]]>
FIDO Enterprise Adoption Best Practices

This white paper is aimed at enterprises and government agencies looking to expand their authentication capabilities to include FIDO technology, and have FIDO work in conjunction with other authentication systems such as a Public Key Infrastructure (PKI), Kerberos, and Lightweight Directory Access Protocol (LDAP) that may be in place at the organization.  This document specifically focuses on the use and coexistence of FIDO with a PKI, and answers the following questions:

  • How can FIDO protocols deliver new and/or enhanced business benefits to the enterprise?
  • Which enterprise applications (and application layer protocols) can use PKI?
  • Can FIDO be used to provide similar services as PKI for applications that use or can use public key cryptography?
  • Which enterprise security needs and security threats are best addressed using FIDO?
  • How can an expanded public-key cryptographic system incorporating PKI and FIDO benefit an enterprise?
  • What are the business implications for adding FIDO technology within an enterprise that already operates other authentication systems?

This document covers enterprise and government use cases. Consumer use cases are not in the scope of the whitepaper.

The post White Paper: FIDO and PKI Integration in the Enterprise appeared first on FIDO Alliance.

]]>
27534
Recommended Account Recovery Practices for FIDO Relying Parties https://fidoalliance.org/recommended-account-recovery-practices/ Wed, 06 Feb 2019 20:45:57 +0000 http://fidoalliance.org/?p=25422 In 2019, strong customer authentication is expected to ramp up rapidly, driven by support from regulatory initiatives such as Payment Services Directive 2 (PSD2), industry standards such as those from FIDO […]

The post Recommended Account Recovery Practices for FIDO Relying Parties appeared first on FIDO Alliance.

]]>
In 2019, strong customer authentication is expected to ramp up rapidly, driven by support from regulatory initiatives such as Payment Services Directive 2 (PSD2), industry standards such as those from FIDO Alliance and the World Wide Web Consortium (W3C) and also through platform vendors. But adoption will be limited without mechanisms to recover accounts when authenticators are lost. The entire ecosystem is only as strong as the weakest link, so account-recovery mechanisms and policies must be clearly defined. These approaches need to provide secure and acceptable user experiences. This document briefly summarizes recommended practices for all service providers (also referred to as Relying Parties or RPs), including banks and merchants.

The post Recommended Account Recovery Practices for FIDO Relying Parties appeared first on FIDO Alliance.

]]>
25422
How FIDO Standards Meet PSD2’s Regulatory Technical Standards Requirements On Strong Customer Authentication https://fidoalliance.org/how_fido_meets_the_rts_requirements/ Thu, 20 Dec 2018 14:46:55 +0000 https://fidoalliance.org/?p=23614 This document provides a detailed review of the security requirements listed in the Regulatory Technical Standards For Strong Customer Authentication and Common and Secure Open Standards Of Communication under PSD2 […]

The post How FIDO Standards Meet PSD2’s Regulatory Technical Standards Requirements On Strong Customer Authentication appeared first on FIDO Alliance.

]]>
This document provides a detailed review of the security requirements listed in the Regulatory Technical Standards For Strong Customer Authentication and Common and Secure Open Standards Of Communication under PSD2 (the RTS) and describes how the FIDO standards meet such requirements.

The document analyses articles in the following relevant sections of the RTS:

  • [RTS Chapter I] General provisions
  • [RTS Chapter II] Security measures for the application of Strong Customer Authentication
  • [RTS Chapter IV] Confidentiality and integrity of the Payment Service User’s security credentials

The post How FIDO Standards Meet PSD2’s Regulatory Technical Standards Requirements On Strong Customer Authentication appeared first on FIDO Alliance.

]]>
23614
White Paper: Enterprise Adoption Best Practices – Integrating FIDO & Federation Protocols https://fidoalliance.org/white-paper-enterprise-adoption-best-practices-integrating-fido-federation-protocols/ Wed, 28 Nov 2018 19:04:12 +0000 http://fidoalliance.wpengine.com/?p=20863 This white paper outlines how the FIDO standards compliment federation protocols. It also provides guidelines on how to integrate the two in order to add support for FIDO-based MFA  and […]

The post White Paper: Enterprise Adoption Best Practices – Integrating FIDO & Federation Protocols appeared first on FIDO Alliance.

]]>
This white paper outlines how the FIDO standards compliment federation protocols. It also provides guidelines on how to integrate the two in order to add support for FIDO-based MFA  and replace or supplement traditional authentication methods in federation environments.

This white paper is aimed at enterprises deploying FIDO for strong authentication. It is intended to provide guidance to architects and developers on how to integrate FIDO authentication and existing federation protocols, namely SAML and OpenID Connect.

It is assumed that the reader has an understanding of FIDO architecture and protocols.

The post White Paper: Enterprise Adoption Best Practices – Integrating FIDO & Federation Protocols appeared first on FIDO Alliance.

]]>
20863
White Paper: FIDO UAF and PKI in Asia – Case Study and Recommendations https://fidoalliance.org/white-paper-fido-uaf-and-pki-in-asia-case-study-and-recommendations/ Wed, 28 Nov 2018 18:49:23 +0000 http://fidoalliance.wpengine.com/?p=20837 This paper depicts three possible scenarios for integrating FIDO UAF and PKI in Asian countries, along with recommendations for how the two technologies can work together to bring innovation to […]

The post White Paper: FIDO UAF and PKI in Asia – Case Study and Recommendations appeared first on FIDO Alliance.

]]>
This paper depicts three possible scenarios for integrating FIDO UAF and PKI in Asian countries, along with recommendations for how the two technologies can work together to bring innovation to the authentication marketplace and to pave the way for deploying better authentication solutions to the public.

The post White Paper: FIDO UAF and PKI in Asia – Case Study and Recommendations appeared first on FIDO Alliance.

]]>
20837
White Paper: FIDO & PSD2 – Providing for a Satisfactory Customer Journey https://fidoalliance.org/white-paper-fido-psd2-providing-for-a-satisfactory-customer-journey/ Thu, 13 Sep 2018 17:53:00 +0000 http://fidoalliance.wpengine.com/?p=20842 This white paper examines the different authentication models that could apply within the interactions of a Third Party Provider and an Account Servicing Payment Service Provider. It proposes the FIDO […]

The post White Paper: FIDO & PSD2 – Providing for a Satisfactory Customer Journey appeared first on FIDO Alliance.

]]>
This white paper examines the different authentication models that could apply within the interactions of a Third Party Provider and an Account Servicing Payment Service Provider. It proposes the FIDO standards as a solution to simplify the user experience, for any of these models, in a way that meets the Strong Customer Authentication requirements of PSD2.

When PSD2 is deployed in Europe, users will be able to take advantage of services offered by Third Party Providers (TPPs) to trigger payments or to view account information. These users will typically start interacting on the TPP’s user interface. However, at the point when a TPP will request from an Account Servicing Payment Service Provider (ASPSP) access to a user’s account(s), the PSD2 Regulatory Technical Standards (RTS) for Strong Customer Authentication (SCA) require that the user be strongly authenticated by the ASPSP and demonstrate that he/she has provided consent for the operation that the TPP is requesting to execute.

The Strong Customer Authentication requirement introduces challenges in the customer experience as there are no longer just two parties involved, the user and its bank, but three: The end user journey starts and ends on the TPP’s user interface.

TPPs will interface with the ASPSPs via open APIs. A number of standardization bodies have released drafts of such Open APIs, for example, the Open Banking Implementation Entity (OBIE) in the UK, STET in France and the Berlin Group for various European countries.

These specifications describe how Strong Customer Authentication should be implemented and several models have been defined, if not (yet) fully specified: the redirection, decoupled and embedded models. At the time of this paper’s release, a potential delegated model is also being discussed. These models vary in the way the user interacts with the TPP and the ASPSP and have a deep impact on both the user experience and the security of the user’s financial accounts.

This paper examines the advantages and drawbacks of the different SCA compliant authentication models and outlines how FIDO compliant solutions deliver the best user experience in any of these models, in a way that meets the needs of TPPs and ASPSPs.

The post White Paper: FIDO & PSD2 – Providing for a Satisfactory Customer Journey appeared first on FIDO Alliance.

]]>
20842
FAQ on FIDO Relevance for the GDPR https://fidoalliance.org/faq-on-fido-relevance-for-the-gdpr/ Sat, 01 Sep 2018 16:19:16 +0000 http://fidoalliance.wpengine.com/?p=15940 This document provides answers to questions on authentication, user consent, use of biometrics…in the context of the European General Data Protection Regulation. It shows how FIDO authentication can help service […]

The post FAQ on FIDO Relevance for the GDPR appeared first on FIDO Alliance.

]]>
This document provides answers to questions on authentication, user consent, use of biometrics…in the context of the European General Data Protection Regulation. It shows how FIDO authentication can help service providers comply with the regulation.

The post FAQ on FIDO Relevance for the GDPR appeared first on FIDO Alliance.

]]>
15940
White Paper: Hardware-backed Keystore Authenticators (HKA) on Android 8.0 or Later Mobile Devices https://fidoalliance.org/white-paper-hardware-backed-keystore-authenticators-hka-on-android-8-0-or-later-mobile-devices/ Thu, 28 Jun 2018 17:18:37 +0000 http://fidoalliance.wpengine.com/?p=20822 Enabling Any Relying Parties to Create FIDO UAF (1.1 or later) Client Apps This paper introduces the details of a hardware-backed Keystore authenticators (HKA) implementation approach, based on the first […]

The post White Paper: Hardware-backed Keystore Authenticators (HKA) on Android 8.0 or Later Mobile Devices appeared first on FIDO Alliance.

]]>
Enabling Any Relying Parties to Create FIDO UAF (1.1 or later) Client Apps

This paper introduces the details of a hardware-backed Keystore authenticators (HKA) implementation approach, based on the first commercial deployment. It takes advantage of secure Android Keystore with key attestation and fingerprint sensors in hardware on standard off-the-shelf Android 8.0 or later mobile devices. Since it is enabled only by Android applications, any RPs and application developers can develop their own secure FIDO UAF 1.1 authenticators.

The post White Paper: Hardware-backed Keystore Authenticators (HKA) on Android 8.0 or Later Mobile Devices appeared first on FIDO Alliance.

]]>
20822
White Paper: FIDO Authentication and the General Data Protection Regulation https://fidoalliance.org/white-paper-fido-authentication-and-the-general-data-protection-regulation/ Mon, 28 May 2018 17:32:36 +0000 http://fidoalliance.wpengine.com/?p=20826 This white paper explores three key areas of the EU’s General Data Protection Regulation that deal with authentication, including exploring how FIDO uniquely solves these issues.

The post White Paper: FIDO Authentication and the General Data Protection Regulation appeared first on FIDO Alliance.

]]>
This white paper explores three key areas of the EU’s General Data Protection Regulation that deal with authentication, including exploring how FIDO uniquely solves these issues.

The post White Paper: FIDO Authentication and the General Data Protection Regulation appeared first on FIDO Alliance.

]]>
20826
White Paper: Enterprise Adoption Best Practices – Managing FIDO Credential Lifecycle for Enterprises https://fidoalliance.org/white-paper-enterprise-adoption-best-practices-managing-fido-credential-lifecycle-for-enterprises/ Sat, 28 Apr 2018 17:36:22 +0000 http://fidoalliance.wpengine.com/?p=20831 This white paper provides guidance to IT and Security professionals on how manage FIDO authentication credentials throughout their full lifecycle­.

The post White Paper: Enterprise Adoption Best Practices – Managing FIDO Credential Lifecycle for Enterprises appeared first on FIDO Alliance.

]]>
This white paper provides guidance to IT and Security professionals on how manage FIDO authentication credentials throughout their full lifecycle­.

The post White Paper: Enterprise Adoption Best Practices – Managing FIDO Credential Lifecycle for Enterprises appeared first on FIDO Alliance.

]]>
20831
FIDO & PSD2: Meeting the needs for Strong Consumer Authentication https://fidoalliance.org/fido-psd2-meeting-the-needs-for-strong-consumer-authentication/ Fri, 01 Sep 2017 23:02:13 +0000 http://fidoalliance.wpengine.com/?p=20898 This white paper outlines how the FIDO standards can facilitate the implementation of the new disruptive PSD2 regulation with user-friendly secure solutions.

The post FIDO & PSD2: Meeting the needs for Strong Consumer Authentication appeared first on FIDO Alliance.

]]>
This white paper outlines how the FIDO standards can facilitate the implementation of the new disruptive PSD2 regulation with user-friendly secure solutions.

The post FIDO & PSD2: Meeting the needs for Strong Consumer Authentication appeared first on FIDO Alliance.

]]>
20898
White Paper: Korean FIDO Deployment Case Study- Accredited Certification System for Safe Usage of Accredited Certificate using FIDO in Smartphone in Korea (K-FIDO) https://fidoalliance.org/white-paper-korean-fido-deployment-case-study-accredited-certification-system-for-safe-usage-of-accredited-certificate-using-fido-in-smartphone-in-korea-k-fido/ Fri, 01 Sep 2017 22:58:49 +0000 http://fidoalliance.wpengine.com/?p=20897 This case study describes a Korean deployment that combines the FIDO UAF specification and PKI to enable authentication, identify verification and interoperability among various Fintech services for increased user convenience.

The post White Paper: Korean FIDO Deployment Case Study- Accredited Certification System for Safe Usage of Accredited Certificate using FIDO in Smartphone in Korea (K-FIDO) appeared first on FIDO Alliance.

]]>
This case study describes a Korean deployment that combines the FIDO UAF specification and PKI to enable authentication, identify verification and interoperability among various Fintech services for increased user convenience.

The post White Paper: Korean FIDO Deployment Case Study- Accredited Certification System for Safe Usage of Accredited Certificate using FIDO in Smartphone in Korea (K-FIDO) appeared first on FIDO Alliance.

]]>
20897
FIDO Alliance Letter Regarding Payment Services Directive 2 https://fidoalliance.org/fido-alliance-letter-regarding-payment-services-directive-2/ Tue, 01 Aug 2017 23:04:35 +0000 http://fidoalliance.wpengine.com/?p=20899 FIDO Alliance’s letter to European Commission and European Parliament on whether screen scraping should be allowed as a fallback option under PSD2

The post FIDO Alliance Letter Regarding Payment Services Directive 2 appeared first on FIDO Alliance.

]]>
FIDO Alliance’s letter to European Commission and European Parliament on whether screen scraping should be allowed as a fallback option under PSD2

The post FIDO Alliance Letter Regarding Payment Services Directive 2 appeared first on FIDO Alliance.

]]>
20899
White Paper: Leveraging FIDO Standards to Extend the PKI Security Model in United States Government Agencies https://fidoalliance.org/white-paper-leveraging-fido-standards-to-extend-the-pki-security-model-in-united-states-government-agencies/ Thu, 02 Mar 2017 00:06:12 +0000 http://fidoalliance.wpengine.com/?p=20900 The post White Paper: Leveraging FIDO Standards to Extend the PKI Security Model in United States Government Agencies appeared first on FIDO Alliance.

]]>
The post White Paper: Leveraging FIDO Standards to Extend the PKI Security Model in United States Government Agencies appeared first on FIDO Alliance.

]]>
20900
White Papers https://fidoalliance.org/white-papers/ Sun, 22 Jan 2017 00:21:27 +0000 http://fidoalliance.wpengine.com/?page_id=5912 We post relevant papers and presentations here that may be of help to the industry at large.  You may also want to view our TechNotes, which are technical blog posts […]

The post White Papers appeared first on FIDO Alliance.

]]>
We post relevant papers and presentations here that may be of help to the industry at large.  You may also want to view our TechNotes, which are technical blog posts covering a variety of topics related to FIDO Authentication. Download all the current FIDO White Papers & Public Documents here, or click a link below for the desired file.

FIDO White Papers & Public Documents

The post White Papers appeared first on FIDO Alliance.

]]>
5912
White Paper: FIDO UAF Metadata Service https://fidoalliance.org/white-paper-fido-uaf-metadata-service/ Tue, 02 Feb 2016 00:09:59 +0000 http://fidoalliance.wpengine.com/?p=20906 The post White Paper: FIDO UAF Metadata Service appeared first on FIDO Alliance.

]]>
The post White Paper: FIDO UAF Metadata Service appeared first on FIDO Alliance.

]]>
20906
Response to the European Banking Authority (EBA) Discussion Paper on Future Draft Regulatory Technical Standards on Strong Customer Authentication and Secure Communication Under the Revised Payment Services Directive (PSD2) https://fidoalliance.org/response-to-the-european-banking-authority-eba-discussion-paper-on-future-draft-regulatory-technical-standards-on-strong-customer-authentication-and-secure-communication-under-the-revised-payment-se/ Tue, 02 Feb 2016 00:07:13 +0000 http://fidoalliance.wpengine.com/?p=20901 The post Response to the European Banking Authority (EBA) Discussion Paper on Future Draft Regulatory Technical Standards on Strong Customer Authentication and Secure Communication Under the Revised Payment Services Directive (PSD2) appeared first on FIDO Alliance.

]]>
The post Response to the European Banking Authority (EBA) Discussion Paper on Future Draft Regulatory Technical Standards on Strong Customer Authentication and Secure Communication Under the Revised Payment Services Directive (PSD2) appeared first on FIDO Alliance.

]]>
20901
White Paper: FIDO & Privacy https://fidoalliance.org/white-paper-fido-privacy/ Sat, 02 Jan 2016 00:11:05 +0000 http://fidoalliance.wpengine.com/?p=20907 The post White Paper: FIDO & Privacy appeared first on FIDO Alliance.

]]>
The post White Paper: FIDO & Privacy appeared first on FIDO Alliance.

]]>
20907
White Paper: Bluetooth & NFC Transport for FIDO U2F https://fidoalliance.org/white-paper-bluetooth-nfc-transport-for-fido-u2f/ Wed, 01 Jul 2015 23:12:34 +0000 http://fidoalliance.wpengine.com/?p=20912 The post White Paper: Bluetooth & NFC Transport for FIDO U2F appeared first on FIDO Alliance.

]]>
The post White Paper: Bluetooth & NFC Transport for FIDO U2F appeared first on FIDO Alliance.

]]>
20912
Whitepaper on FIDO 1.0 Final Specifications https://fidoalliance.org/whitepaper-on-fido-1-0-final-specifications/ Tue, 02 Dec 2014 00:16:20 +0000 http://fidoalliance.wpengine.com/?p=20918 This whitepaper explores the background of FIDO authentication: the needs, benefits and early deployments.

The post Whitepaper on FIDO 1.0 Final Specifications appeared first on FIDO Alliance.

]]>
This whitepaper explores the background of FIDO authentication: the needs, benefits and early deployments.

The post Whitepaper on FIDO 1.0 Final Specifications appeared first on FIDO Alliance.

]]>
20918