Browse Definitions :
Definition

Universal 2nd Factor (U2F)

Universal 2nd Factor (U2F) is a type of physical authentication device that uses encryption and private keys to protect and unlock supported accounts. Typically seen as a USB, Near-Field Communication (NFC), or Bluetooth device, two-factor authentication is simplified and strengthened with the use of smart chip technology.

Two-factor authentication (2FA) is used as a basic way to protect sensitive information and relies on an internal and external factor. The internal factor is a basic password or PIN, something that is entered on the platform. The second, and external, factor can be receiving an SMS message or phone call with a temporary code or relying on connected authenticator applications. However, depending on cellular devices for authentication creates a large amount of risk and no two account verifications are alike. Therefore, Universal 2nd Factor is a universal standard created by Google and Yubico for streamlining two-factor authentication with any service or account.

U2F devices are connected to a computer via a USB port or smartphone and can be turned on with certain applications or websites. After the initial password to an account is entered, the device communicates to the host computer via the HID protocol, or the standard that simplifies the transmission of external devices to the computer. Once the line of communication is initiated, a challenge-response authentication mechanism (CRAM) sends the private key on the device to the public key on the computer to unlock it. If the U2F key is not present, access will not be granted. In addition, the information stored on the key is encrypted, diminishing the risk of keylogger, phishing, man-in-the-middle (MitM), malware and session hijacking attacks.

The U2F standard is supported by the  FIDO Alliance, with includes compatibility with major companies. Chrome, Firefox and Opera have already supported U2F within their browsers along with major applications such as Facebook, Github and Dropbox. Large banking corporations like PayPal, MasterCard, American Express, VISA and Bank of America have also begun offering U2F security solutions.

Advantages of Universal 2nd Factor

  • Stronger security: U2F devices use encryption to ensure the website is real and send information directly to the website, cutting down the risk of attacks such as phishing and man-in-the-middle.
  • Simplicity: U2F is already incorporated into popular platforms and browsers, making installation easy.
  • Consumer choice: Since U2F is a standard of authentication, it can be found in a range of device types and communication methods, allowing the user to choose the best fit.
  • Low-cost solution: Keys and drivers with U2F technology are relatively inexpensive and Yubico provides a free, open source server software for back-end integration.
  • Private identity: Users are able to control their online identity and customize it to their needs or privacy level.
This was last updated in September 2018

Continue Reading About Universal 2nd Factor (U2F)

SearchNetworking
  • network security

    Network security encompasses all the steps taken to protect the integrity of a computer network and the data within it.

  • cloud-native network function (CNF)

    A cloud-native network function (CNF) is a service that performs network duties in software, as opposed to purpose-built hardware.

  • Wi-Fi 6E

    Wi-Fi 6E is one variant of the 802.11ax standard.

SearchSecurity
  • incident response

    Incident response is an organized approach to addressing and managing the aftermath of a security breach or cyberattack, also ...

  • MICR (magnetic ink character recognition)

    MICR (magnetic ink character recognition) is a technology invented in the 1950s that's used to verify the legitimacy or ...

  • What is cybersecurity?

    Cybersecurity is the protection of internet-connected systems such as hardware, software and data from cyberthreats.

SearchCIO
  • privacy compliance

    Privacy compliance is a company's accordance with established personal information protection guidelines, specifications or ...

  • contingent workforce

    A contingent workforce is a labor pool whose members are hired by an organization on an on-demand basis.

  • product development (new product development -- NPD)

    Product development, also called new product management, is a series of steps that includes the conceptualization, design, ...

SearchHRSoftware
  • talent acquisition

    Talent acquisition is the strategic process employers use to analyze their long-term talent needs in the context of business ...

  • employee retention

    Employee retention is the organizational goal of keeping productive and talented workers and reducing turnover by fostering a ...

  • hybrid work model

    A hybrid work model is a workforce structure that includes employees who work remotely and those who work on site, in a company's...

SearchCustomerExperience
  • digital marketing

    Digital marketing is a general term for any effort by a company to connect with customers through electronic technology.

  • hockey stick growth

    Hockey stick growth is a growth pattern in a line chart that shows a sudden and extremely rapid growth after a long period of ...

  • Salesforce Trailhead

    Salesforce Trailhead is a series of online tutorials that coach beginner and intermediate developers who need to learn how to ...

Close