Authenticator Examples

Authenticator Type

Description

Examples

Replay Resistant?

Supports Phishing Resistance?

Password

Memorizable secret (something you know) used for repeated authentications

  • Password

  • Passphrase

No

No

Look-up secret

One-time authentication secret, typically printed for later use by subscriber

  • Printed one-time passwords

  • Grid cards

Yes

No

Out-of-band device

Device having a communication channel independent of the authentication session through which an authentiction secret is conveyed

  • SMS

  • Push notification

Yes

No

Single-factor OTP

Device or application that generates a single-use authentication secret

  • TOTP hardware device (e.g., SecureID)

  • TOTP smartphone app (e.g., Google Authenticator)

Yes

No

Multi-factor OTP

Device or application that generates a single-use authentication secret when provided with a memorized or biometric activation factor

  • OTP hardware device with PIN keypad

Yes

No

Single-factor cryptographic

Device or application that generates a cryptographically computed response to a challenge nonce from the verifier

  • FIDO U2F

  • Client certificate

  • Smartcards

  • Passkeys (without user verification)

Yes

Yes

Multi-factor cryptographic

Device or application that generates a cryptographically computed response to a challenge nonce from the verifier when provided with a memorized or biometric activation factor

  • FIDO2 passkeys with user verification

  • Client certificate with unlock secret

  • PIV

  • CAC

  • PIV-I

Yes

Yes

Community Resources

Passkeys Developer Site: https://passkeys.dev/

Representations and Warranties

Certain commercial entities, equipment, or materials may be identified in this Web site or linked Web sites in order to support Framework understanding and use. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.