Skip to main content

Passwordless


1. Overview

  • Function Name: Passwordless Authentication
  • Introduction Background
    • To complement the security vulnerabilities of existing ID/PW based authentication and improve the user authentication experience.Passwordless AuthenticationIntroduction
  • Target System: SHIELD ID Authentication Platform
  • Applicable subjects: Users holding SHIELD ID accounts among those to whom the relevant authentication policy applies.
  • Main Delivery Method
    • FIDO2 WebAuthn

2. Authentication Method

2.1 FIDO2 WebAuthn

  • Function Purpose
    • Without a password when logging in to SHIELD ID**Authentication through registered authentication devices (security key or biometric information)**support to perform
    • Enhancing Security and Improving User Authentication Experience
  • Scope of Application
itemContent
Authentication TargetUsers who have registered a FIDO2 device among those registered with SHIELD ID
Supported DevicesWindows Hello (PIN or fingerprint recognition), Yubikey (security key), etc.
  • Device Registration Workflow
info

Registration is mandatoryIn the Edge browsermust be carried out, and after registration, authentication isIn Edge or Chrome browserYou can use it freely.

  1. Perform SHIELD ID authentication using the password method.
  2. As per the policy, it asks the user whether to set up a Passwordless authentication device.
  3. The user나중에 하기options and설정Select an option.
    • Do later
      • Since the ID / PW entry is complete, the authentication is successful at that time, but the same registration query window appears during the next SHIELD ID authentication.
      • 오늘 하루 보지 않기When using the checkbox option, you can prevent the window from appearing for a day.
    • Settings
      • It will proceed with flow number 4.
  4. Register a passkey through Windows Hello or a security key in the Edge browser.
    • Restrictions: When registered in Chrome, the passkey is saved in the Google Password Manager and cannot be used in Edge.
    • (Optional) By registering Windows Hello (PIN or fingerprint) in advance, you can log in faster and more conveniently during authentication.
  5. Once the passkey registration is complete, a notification will appear to the user indicating that the setup is complete.
  6. The user will be subject to Passwordless authentication starting from the next authentication.
  • Registration failure:재설정 (다시 등록)or나중에 하기Provides options.
    • Reset: Proceeding with registration again.
    • Later: The certification is successful as above, but a re-registration request is mandatory for the next certification.
  • Device Authentication Workflow
  1. Performing SHIELD ID authentication.
    • Enter user ID.
  2. **Passwordless authentication is prioritized.**Requests Passwordless authentication from the user.
    • The user is at the bottom of the screen.다른 방법으로 로그인Press the buttonPassword authentication methodYou can switch to.
    • On the contrary, in the Password input screen as well보안 키 또는 생체 인식 프로그램으로 인증You can press the button to switch back to the Passwordless method.
  3. Users perform authentication according to the window provided by the browser based on the registered device.
    • Select an authentication method when registering multiple times.
  4. A notification window indicating that the authentication has been successfully completed will be provided, and the authentication will be completed.
    • Authentication failed
      • You need to retry or perform authentication through login in another way.
      • Representative cases where authentication may be recognized as a failure can be broadly classified into the following two categories.
        • user취소In case of pressing the button
        • If the authentication time has expired
          • The browser and platform authenticators use their own defaults.
          • Although the official specifications or documents do not have fixed numbers, based on actual measurements and various data, it can be estimated as follows.
EnvironmentDefault timeout (estimated value)Basis and Explanation
Chrome (Windows Hello)about 60 secondsChromium-based Testing and FIDO Forum Standards
Edge (Windows Hello)about 60 secondsMicrosoft Community Feedback Criteria