Authentication is a fundamental process in IT security that ensures only authorized users gain access to systems and data. It involves various methods, including passwords, biometrics, and multi-factor authentication.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Authentication checks whether a claimed identity can be confirmed with a reliable proof before access or further processing is allowed.
As a security problem, authentication arose from the need to verify a claimed identity over open or otherwise untrusted networks without permanently exposing the underlying secret. NIST SP 800-63B defines technical requirements for digital identity services, including assurance levels and credential lifecycle management. W3C WebAuthn standardizes strong, public key-based web authentication on top of that foundation.
Think of authentication as a security checkpoint: a person or system presents proof, the target system verifies it against a trusted reference, and only then does an identity signal exist. Different proofs have different strength. Passwords, tokens, biometrics, and public-key-based methods shift the balance between usability, protection, and attack surface.
A claimed identity is accepted only when there is a verifiable proof.
Secrets, keys, tokens, or biometric traits act as evidence for identity.
The device, app, or service creates, stores, or presents the proof.
Multiple independent factors reduce the chance that one stolen item is enough.
After successful verification, the system can decide which rights and resources apply.
Authentication matters before login, API access, privileged actions, tenant separation, and federated identity flows. The chosen method affects security, user effort, and operating model: passwords are simple but vulnerable; cryptographic or biometric methods are stronger, but they require device binding, recovery, and privacy design. Authentication does not replace authorization or session management.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.