Separate the objects
An authenticator is something the claimant possesses and controls that can produce authentication output. Its secret can be memorized, stored as a key, or derived from a biometric characteristic through an activation process. A credential is the data object that binds an identity or account to one or more authenticators. A factor type describes the evidence: something known, possessed, or inherent.
Binding and use
Enrollment binds the authenticator to the subscriber account. During authentication, the claimant proves control through a protocol. The verifier validates the output and its context. A public-key authenticator can keep the private key on the device and send a signature instead of a reusable shared secret.
Lifecycle controls
Protect issuance, binding, activation, storage, replacement, duplication, suspension, revocation, and recovery. Record which authenticators are active. Notify the subscriber of changes. Require suitable authentication before adding or replacing an authenticator.
Failure and residual risk
A possession factor can be copied when its secret is exportable. A biometric is not a secret and can be difficult to replace. A one-time code can still be phished in real time. Recovery or authenticator replacement can provide an easier takeover path than normal authentication.
Pomerium boundary
The identity provider verifies the user's authenticators. Pomerium receives the resulting federated authentication and creates a Pomerium session. Pomerium does not make a weak provider enrollment or recovery process stronger.
Evaluation checklist
- Is each authenticator bound to the intended subscriber account?
- Can its secret be copied, exported, replayed, or phished?
- Which independent factor types does the ceremony use?
- How are authenticators added, replaced, suspended, and revoked?
- Is recovery at least as well controlled as ordinary authentication?
