Skip to main content

← Back to glossary

Term · 2. Authentication & Authorization

Authentication Information

IDM/IGA Domain

Definition

Data the principal uses to prove identity during authentication — passwords, OTP codes, biometric templates, FIDO2 credentials, certificates, security tokens. Must be protected at rest (hashing/encryption) and in transit (TLS). Compromise of authentication information enables impersonation attacks.

Application
Storage best practices: bcrypt/Argon2 for password hashes, hardware-backed biometric templates (Secure Enclave, TPM), per-credential salts, no plaintext logging. NIST SP 800-63B prohibits storing reversible password forms.