Comparison of Authentication Security Solutions

Authentication is the act of confirming the truth of an attribute of a single piece of data (a datum) claimed true by an entity. Out of different types of authentication Two-factor authentication is a technology that provides identification of users by means of the combination of two different components. There are number of Two-factor authentication and Multi-factor authentication providers around us. Multi factor authentication products can provide significant benefits to an enterprise, but the technology is complex and the tools themselves can vary greatly from provider to provider.[1]

Threat coverage

Provider Phishing Malware Password guessing Man in the middle Re-used password attacks Serverside Database Breaking Shoulder Surfing Theft of Authenticator OTP Interception Side Channel vulnerabilitiess
Authenticator Plus N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Authentify IncYes N/A N/AYes N/A N/A N/A N/A N/A N/A
AuthyYes[2]Yes[2]Yes}[3]Yes[3] N/A N/A N/A N/A N/A N/A
Azure Multi-Factor AuthenticationYes[4]Yes[5] N/A N/A N/A N/A N/A N/A N/A N/A
ClefYes[6] N/AYes[6] N/A N/AYes[6] N/AYes N/A N/A
Cognalys Inc N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
CryptoPhotoYes[7]Yes[7] N/A N/A N/A N/AYes[7] N/A N/A N/A
Duo SecurityYes N/A N/AYes[8] N/A N/A N/A N/A N/A N/A
FreeOTP N/A N/A N/AYes N/A N/A N/A N/A N/A N/A
Google AuthenticatorNo N/A N/A N/A N/A N/A N/A N/A N/A N/A
Latch N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
LaunchKey N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
LoginTCYes N/A N/AYes N/A N/A N/A N/A N/A N/A
MePIN N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Nexmo N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Ping Identity N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
PortalGuardYes[9] N/A N/AYes[9] N/A N/A N/A N/A N/A N/A
privacyIDEA N/A N/AYes N/AYes N/A N/A N/A N/A N/A
Protectimus N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Rublon N/AYes[10]Yes[10] N/A N/A N/A N/A N/A N/A N/A
SAASPASSYesYes N/AYes N/A N/A N/A N/A N/A N/A
SAT Mobile ID N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
SecSignYes[11]Yes[11]Yes[11] N/A N/A N/A N/A N/A N/A N/A
SecureAuthYes N/A N/A N/A N/A N/A N/A N/A N/A N/A
SecurePass N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
SmartSign N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Solidpass[12]YesYes N/AYes N/A N/A N/A N/A N/A N/A
SyferLock GridGuard[13]YesYesYesYesYes N/AYes N/AYesYes
Symantec/Verisign VIP N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
TeleSignYes[14] N/AYes[14] N/AYes[14] N/A N/A N/A N/A N/A
TextPower N/AYes[15] N/AYes[16] N/A N/A N/A N/A N/A N/A
Token2 N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Toopher N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Totp.Me N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
TransaktYes[17]Yes[17]Yes[17]Yes[17] N/A N/A N/A N/A N/A N/A
VASCO Data SecurityYes N/A N/AYes N/A N/A N/A N/A N/A N/A
WWPassYesYes N/AYes N/A N/A N/A N/A N/A N/A
WiKID Systems N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
YubicoYesYes N/AYes N/A N/A N/A N/A N/A N/A

Transport Methods

Provider SMS Phone Call Email Hardware token Software implementation Recovery method
Authenticator Plus[18]NoNoNoNoYesEmail
Authentify Inc[19]YesYesNoYesYesEmail
Authy[20]YesYesNoYesYesEmail[21]
Azure Multi-Factor Authentication[22]YesYesNoNoYesEmail
Clef[23]NoNoNoNoYesEmail
Cognalys IncNoYesNoNoYesEmail
CryptoPhotoNoNoNoNoYesPaper TAN
Duo SecurityYesYesNoYesYesEmail[21]
FreeOTPNoNoNoNoYesEmail
Google AuthenticatorYesYesNoNoYesPaper TAN[21]
LatchNoNoNoNoYesEmail
LaunchKeyNoNoNoNoYesEmail
LoginTCNoNoNoNoYesEmail
MePINYesNoNoYesYesEmail
NexmoYesYesNoNoNoEmail
Ping IdentityYesYesNoNoYesEmail
PortalGuardNoYesNoNoYesEmail
privacyIDEAYesNoYesYesYesEmail / helpdesk
ProtectimusYesNoYesYesYesEmail
RublonNoNoYesNoYesEmail
SAASPASSNoNoNoNoYesEmail
SAT Mobile IDYesYesNoYesYesEmail
SecSignNoNoNoNoYesEmail
SecureAuthYesYesYesYesYesEmail
SecurePassNoNoNoYesYesEmail
SmartSignNoNoYesNoYesEmail
Solidpass[12]YesNoNoYesYesEmail
SyferLock GridGuardYesNoYesNoYesEmail
Symantec/Verisign VIP YesYesYesYesYesEmail
TeleSignYesYesNoNoYesEmail
TextPowerYesNoNoNoNoEmail
Token2YesNoNoYesYesEmail
ToopherYesNoNoNoYesEmail
Totp.MeNoNoNoNoYesEmail
TransaktNoNoNoNoYesEmail
VASCO Data SecurityYesYesYesYesYesEmail
WWPassNoNoNoYesYesEmail
WiKID SystemsNoNoNoNoYesEmail
YubicoNoNoNoYesYesEmail

Feature Support

Provider TOTP EOTP Mutual authentication PIN protection Biometrics Separate Channel Scalability Transaction Signing Coverage Revocation
Authenticator PlusYes N/A N/AYes N/A N/A N/A N/A N/A N/A
Authentify Inc N/A N/A N/A N/A N/AYes N/AYes N/A N/A
AuthyYes N/A N/A N/AYes[24] N/A N/AYes[25] N/A N/A
Azure Multi-Factor Authentication N/A N/A N/A N/AYes N/A N/A N/A N/A N/A
Clef N/A N/A N/A N/AYes N/A N/A N/A N/A N/A
Cognalys Inc N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
CryptoPhoto N/A N/A N/AYes[26]Yes[26] N/A N/A N/A N/AYes[26]
Duo SecurityYes N/A N/A N/AYes N/A N/A N/A N/A N/A
FreeOTPYes[27] N/A N/A N/A N/A N/A N/A N/A N/A N/A
Google AuthenticatorYes N/A N/A N/A N/A N/A N/A N/A N/A N/A
Latch N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
LaunchKey N/A N/A N/A N/AYes N/A N/A N/A N/A N/A
LoginTC N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
MePINYes N/A N/A N/AYes N/A N/A N/A N/A N/A
Nexmo N/A N/A N/A N/A N/A N/AYes[28] N/A N/A N/A
Ping Identity N/A N/A N/A N/AYes[29] N/A N/A N/A N/A N/A
PortalGuardYes[9] N/A N/A N/A N/A N/A N/A N/A N/A N/A
privacyIDEAYesYes N/A N/A N/A N/A N/AYes N/A N/A
ProtectimusYesYes N/A N/A N/A N/A N/A N/A N/A N/A
Rublon N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
SAASPASSYes N/AYes N/A N/A N/A N/A N/A N/A N/A
SAT Mobile ID N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
SecSign N/A N/A N/AYes[11] N/A N/A N/A N/A N/A N/A
SecureAuth N/A N/A N/A N/AYes[30] N/A N/A N/A N/A N/A
SecurePass N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
SmartSign N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Solidpass[12]YesYesYes N/AYes N/A N/AYes N/A N/A
SyferLock GridGuard N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Symantec/Verisign VIP N/A N/A N/A N/AYes N/A N/A N/A N/A N/A
TeleSignYes[14] N/A N/A N/A N/A N/A N/A N/A N/A N/A
TextPower N/A N/A N/A N/AYes[31] N/A N/A N/A N/A N/A
Token2Yes[32] N/A N/A N/A N/A N/A N/A N/A N/A N/A
Toopher N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
Totp.MeYes N/A N/A N/A N/A N/A N/A N/A N/A N/A
TransaktYes[17] N/A N/A N/AYes[17]Yes[17] N/AYes[17] N/A N/A
VASCO Data SecurityYes N/A N/A N/AYes N/A N/A N/A N/A N/A
WWPass N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
WiKID Systems N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
YubicoYes N/A N/A N/A N/A N/A N/A N/A N/A N/A

References

  1. "Comparing the top multifactor authentication vendors". November 2014.
  2. 1 2 "INTRODUCING AUTHY FOR YOUR PERSONAL COMPUTER".
  3. 1 2 "SECURITY NOTICE: OPENSSH PASSWORDS VULNERABLE".
  4. Larry Seltzer (30 April 2014). "Microsoft Azure is phishing-friendly". Retrieved 27 April 2016.
  5. Yuri Diogenes (22 March 2016). "Microsoft Antimalware for Azure Cloud Services and Virtual Machines". Retrieved 27 April 2016.
  6. 1 2 3 "Clef".
  7. 1 2 3 "CryptoPhoto Features". Retrieved 18 April 2016.
  8. Jon Oberheide (6 June 2014). "Duo Patches for the Latest OpenSSL Vulnerabilities". Retrieved 18 April 2016.
  9. 1 2 3 "Two factor Authentication:Flexible Options" (PDF).
  10. 1 2 "Rublon".
  11. 1 2 3 4 "SecSign".
  12. 1 2 3 "Solid Pass".
  13. "GridGuard Overview".
  14. 1 2 3 4 "TeleSign_US_Datasheet_Push_Verify_20161" (PDF). 2016. Retrieved 27 April 2016.
  15. NEIL J. RUBENKING (20 May 2014). ""Hack-Proof" TextKey Turns SMS Authentication on Its Head". Retrieved 1 May 2016.
  16. "TextKey Scores Well in Network World Review of Authentication Solutions".
  17. 1 2 3 4 5 6 7 8 "Build in trust with the Transakt SDK" (PDF).
  18. "Authenticator plus".
  19. "Authentify Two-Factor Authentication".
  20. "Authy: Two-Factor Authentication Made Easy".
  21. 1 2 3 Matthew Prince (28 November 2012). "Choosing a Two-Factor Authentication System". Retrieved 16 April 2016.
  22. "What is Azure Multi-Factor Authentication?".
  23. "Clef Two-Factor Authentication".
  24. "AUTHY two factor authentication". Retrieved 27 April 2016.
  25. Dan Killmer. "AUTHY ONETOUCH: SIMPLY STRONG SECURITY". Retrieved 18 April 2016.
  26. 1 2 3 "Two Factor and Multifactor Authentication by CryptoPhoto". Retrieved 18 April 2016.
  27. "FreeOTP".
  28. "Nexmo".
  29. "PingID Multi-factor Authentication".
  30. "SecureAuth" (PDF).
  31. "GET AN INDUSTRY LEADING MULTI-FACTOR AUTHENTICATION SOLUTION".
  32. "TOKEN2".
This article is issued from Wikipedia - version of the Sunday, May 01, 2016. The text is available under the Creative Commons Attribution/Share Alike but additional terms may apply for the media files.