User authentication is the process of verifying that a person claiming a digital identity is who they assert to be, by validating one or more authentication factors: something they know (password, PIN), something they have (hardware token, mobile device), or something they are (biometric). It is the gateway control between unauthenticated network access and authorised use of a system or resource, and its assurance level — defined by standards such as NIST SP 800-63 — must be calibrated to the sensitivity of protected resources. Modern implementations favour phishing-resistant factors (passkeys, hardware security keys) over knowledge-based authentication.
Content
- User authentication is as old as computing systems that required accountability: CTSS (Compatible Time-Sharing System) at MIT introduced password-based login in 1961, establishing a paradigm that persisted for decades. The fundamental problem — shared secrets stored server-side are breach targets — became catastrophically visible with the LinkedIn (2012, 117 million hashes), Yahoo (2013-2014, 3 billion accounts), and RockYou2021 (8.4 billion plaintext passwords) breaches. Password-based authentication at scale requires careful salting and key derivation (bcrypt, Argon2), but server-side credential databases remain high-value targets.
- Modern user authentication has diversified into multiple factor categories: knowledge factors (passwords, PINs, security questions — weakest tier); possession factors (TOTP apps like Google Authenticator, SMS OTP — vulnerable to SIM-swapping, TOTP-based phishing); hardware security keys (FIDO U2F, now FIDO2/WebAuthn — phishing-resistant because authentication is bound to origin); biometric factors (fingerprint, face, iris — convenient but cannot be revoked if compromised). The FIDO2 standard, combining WebAuthn (W3C browser API) and CTAP2 (device protocol), allows users to authenticate with a platform authenticator (device TPM, Secure Enclave) or roaming authenticator (YubiKey) using public-key cryptography where the private key never leaves the device.
- Passkeys — discoverable FIDO2 credentials synced across a user’s devices via cloud keychain (Apple iCloud Keychain, Google Password Manager) — represent the current paradigm shift. Passkeys eliminate passwords entirely: registration creates a public/private key pair, the private key is stored in the device’s secure element, and authentication proves possession by signing a challenge. Major platforms (Apple, Google, Microsoft) have deployed passkeys for hundreds of millions of accounts, and the FIDO Alliance reports that passkey authentication success rates (95%+) exceed password success rates substantially.
- In 2024-2025, enterprise user authentication is converging on phishing-resistant MFA mandated by government frameworks (US CISA, UK NCSC, EU NIS2). Conditional access policies in Azure AD and Okta enforce step-up authentication based on risk signals (device health, location anomaly, behaviour baseline). Decentralised identity approaches are moving authentication towards user-controlled wallets where credentials are presented via OpenID Connect extensions (SIOP v2) or OpenID4VP — removing the identity provider as a centralised dependency. AI-driven continuous authentication (behavioural biometrics, keystroke dynamics) is being deployed as a risk signal layer on top of primary authentication factors.