Showing posts with label transactions. Show all posts
Showing posts with label transactions. Show all posts

Tuesday, February 5, 2013

The 4th Factor? - 3 Factors of Fail (part 5)

   Welcome to the next installment of my ramblings on authentication, 3 Factors of Fail.  So far we have discussed the classic 3 factors of authentication in parts 1, 2, 3 and 4.

   In recent years some additional authentication assurance methods have been grouped to form what some call the 4th factor of authentication.  This is also called risk-based, location-based or adaptive authentication.  It could also be called "somewhere you are" or "something you are doing".

   The basis of this method is in establishing a rich profile of the user.  This can include:
  • the machine used for access;
  • software used;
  • time or day of accesses;
  • IP address(es) used;
  • what country the connection comes from, or;
  • what actions the user attempts.