Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1185-1216 of 1801 terms

P
32

Possession Factor

An authentication factor based on something you have, a hardware key, phone, smart card, that demonstrates possession to verify identity. One of the three classic factor types alongside knowledge and inherence.

The possession factor authenticates by proving you hold a specific device or token: a hardware security key, a phone receiving a code or push, a smart card. Because attackers must physically obtain (or compromise) the device to use it, possession factors are stronger than knowledge factors alone and central to multi-factor authentication. The strongest possession factors, like FIDO2 hardware keys, are phishing-resistant; weaker ones (SMS codes) can be intercepted or socially engineered.

Introduced in: Identity and Access Management, Security Foundations

Examples

  • Approving a sign-in via a push on a phone as a possession factor.
  • Using a hardware security key to prove device possession.
  • Combining a possession factor with a password for MFA.

No related terms linked yet.