
Initially designed for the consumer market, the FIDO (Fast IDentity Online) standard aims to replace passwords with more secure authentication methods for online services. While recent versions, like FIDO2.1, have begun to address enterprise needs, significant gaps remain that organizations must address to simplify, accelerate, and secure their deployment.
Enterprises face unique challenges compared to consumers when deploying FIDO security keys. For instance, they must secure a range of digital resources, from legacy systems to modern cloud applications. Also, employees use an array of computing devices, further complicating the integration of FIDO keys.
In addition, the sheer number of users in an enterprise makes the deployment and management of FIDO keys complex. Finally, enterprises must adhere to stringent security and data privacy regulations, which FIDO standards must support.
There are several challenges IT security professionals in large organizations face when deploying FIDO keys regarding user experience, administrative overheads, and security. These include:
Assisting users who misuse FIDO keys through loss, forgotten PINs, or accidental resets creates substantial administrative overhead. Each incident requires intervention from IT support, which can be time-consuming and resource heavy. This burden is amplified in large enterprises with multiple users and devices, as the volume of support requests can quickly escalate. Managing these issues on a large scale involves resolving individual problems and implementing processes and policies to prevent them, further adding to the administrative burden.
Weak Initial Authentication: Relying on less secure methods such as username/password combinations or SMS one-time passwords (OTPs) for FIDO authenticator registration exposes the system to phishing attacks, account takeovers, and fraudulent activities. These vulnerabilities can undermine the security benefits of FIDO authentication from the start.
PIN Length: The FIDO 2.0 standard allows users to set PINs with 4 digits which do not meet the high-security assurance levels many organizations require, especially in regulated markets. Although FIDO 2.1 introduces the ability to enforce minimum PIN length settings and increase to 6 digits or more, organizations must ensure that these settings cannot be bypassed during key resets. Proper enforcement of PIN length is crucial to maintaining strong security.
Lack of 2FA: Certain online services may not always prompt users to provide their PIN or biometric data during authentication, reducing overall security. IT security professionals must regularly audit these authentication processes and enforce two-factor authentication (2FA) wherever necessary to ensure robust protection.
Lost/Stolen Keys: Firms must establish a clear and efficient process for revoking lost or stolen FIDO keys to prevent unauthorized access. This includes having protocols for users to report lost keys and for administrators to swiftly deactivate them, helping to mitigate the risk of security breaches.
When implementing FIDO security keys within an enterprise, it is crucial to not only focus on the authentication step, but to strengthen each step of the lifecycle, from FIDO Key activation to revocation.
CISO’s and IT security professionals have two options:
1. Benefit from FIDO 2.1 standard (i.e., CTAP2.1 Enterprises standard capabilities) and enforce standard features such as PIN change at first use, enforce user verification or minimum PIN length.
To accomplish that, they need to equip their end users with FIDO keys supporting FIDO2.1 and fully certified by FIDO Alliance, such as the new SafeNet Token Fusion NFC PIV, provided by Thales.
2. Go beyond FIDO 2.1 standard and benefit from Thales unique FIDO enterprise features, in addition to FIDO2.1 standard features
In this option, organizations need to equip their end users with Thales FIDO keys in the Enterprise Edition, such as SafeNet eToken Fusion NFC PIV Enterprise, that support FIDO 2.1 Standard and Thales FIDO Enterprise Features.
Thales FIDO Enterprise features
Centralized FIDO key management enables organizations to control the key lifecycle and reduce gaps that could turn into security risks or low end-user adoption. Thales innovates in FIDO key management with robust enterprise features that are unique to the market.
Thales end-to-end solution, that combines an interoperable management platform with Thales FIDO security keys specifically designed for use in large organizations, helps Enterprises accelerate and secure their passwordless journey:
Want to know more? Watch our joint webinar “The Secret to Scalable FIDO Success” together with experts from Microsoft and Versasec now.