Thursday, January 20, 2011

CompTIA Security+ Objectives 3.8

3.8 Explain the difference between identification and authentication (identity proofing).

While they are two similar words, it’s important to note that identification and authentication are not the same. When examining the two, identification is a more broad word that covers a general topic while authentication is specific and often refers to identity authentication. When it comes to authentication, there is a need for 100% proof that cannot be proven wrong. At the same time, identification is simply a match between data sets, which can or cannot be refuted.

In dictionary terms, identification is “the act of recognizing specific objects as a result of remembering.” On the other hand, authentication is “the proof that something is genuine.” Think of it this way. When something is identified you are only placing a label on it. Yes, a computer can identify a user trying to access a resource, but the important part is authenticating the user. Authentication means not only identifying the user, but ensuring that the user’s identity has been verified to be accurate.

Identification on its own can be false. Think of a birth certificate. People can forge them, and make fake ones, and so on. Though it is an obvious way of identifying someone, there isn’t any proof that the identity they are using is true.

GetCertify4Less and GetCertified4Less

No comments: