Traditionally Authenticating users is nothing but validating username and
password. Increasingly username and password are not sufficient especially for
applications that has sensitive or confidential data. When the username and
passwords are not just sufficient, it opens up a whole new world of other
options right from One time password to smart card to biometric, traditionally
used as second factor or multi factor authentication.
In additional to the second factor authentication, increasingly customers are
concerned about phishing attacks and need some assurance that they are dealing
with the legitimate web site before giving the password. Some options in the
next level of Authentication are:
One Time Password
Smart Cards
Biometrics
Knowledge based or Risk based
Digital Watermarking of web site
Device Identification
I will discuss more about these authentication options in the next few blog
entries.