论文标题
FIDO2无密码身份验证是炒作还是真实的?:位置纸
Is FIDO2 Passwordless Authentication a Hype or for Real?: A Position Paper
论文作者
论文摘要
FIDO2标准和生物识别用户验证选项越来越多地提供的操作系统和浏览器支持使每个人(尤其是大型科技公司)对无密码的未来感到兴奋。梦想成真,我们终于完全摆脱了密码吗?在该职位论文中,我们认为,尽管在某些情况下可能会优选无密码的身份验证,但是在可预见的将来,仍然无法在网络上消除密码。我们以五个主要原因来捍卫自己的立场,这要么受到最近文献的结果或我们自己的技术和业务经验的支持。我们认为,我们的讨论也可以作为一个研究议程,其中包括(无密码)用户身份验证的有希望的未来工作指示。
Operating system and browser support that comes with the FIDO2 standard and the biometric user verification options increasingly available on smart phones has excited everyone, especially big tech companies, about the passwordless future. Does a dream come true, are we finally totally getting rid of passwords? In this position paper, we argue that although passwordless authentication may be preferable in certain situations, it will be still not possible to eliminate passwords on the web in the foreseeable future. We defend our position with five main reasons, supported either by the results from the recent literature or by our own technical and business experience. We believe our discussion could also serve as a research agenda comprising promising future work directions on (passwordless) user authentication.