FIDO, which is an acronym that stands for “Fast ID Online”, is a set of open technical specifications for mechanisms of authenticating users to online services that are independent of passwords. These specifications were created and set forth by a non-profit organization named FIDO Alliance, founded in the year 2013. The goal of FIDO Alliance is to set standards for authentication at the client and protocol layers and eliminate the overuse of passwords by organizations. Overall they seek to address the many concerns and dilemmas involved in the utilization of passwords, such as creating remebering multiple usernames and passwords. FIDO establishes two important protocols, UAF(Universal Authentication Framework) and U2F(Universal 2nd Factor). UAF protocol allows organizations to offer mutli-factor and passwordless security. In using UAF protocol, users register their device to the online service and as well as utilizing a local authentication. Local authentication includes mechanisms such as, swiping a finger, speaking into a mic, looking into a camera, entering a pin, etc. U2F protocol is designed to allow online services to supplement their typical password-based authentication with the second factor of authentication that is introduced by means of NFC interface of a USB device. FIDO makes an attempt to alleviate the concerns that some users and organizations have with storing personal data on an external server in the cloud. It does so by storing biometrics and other personal identification locally. Work is required of developers to create secure logins for mobile clients running different operating systems on different types of hardware. FIDO helps to
reduce developers’ work load by abstracting the protocol implementation with application programming interfaces(API). FIDO uses asymmetric cryptography to make certain that biometric prints, images, secrets, and other sensitive data remains on a device all the time and are not transmitted to the authenticating service.