Comparative Security Analysis of FIDO2/WebAuthn versus Traditional Multi-Factor Authentication: A Systematic Review
Description
Multi-factor authentication (MFA) has become a
cornerstone of modern cybersecurity, yet traditional implementations
remain vulnerable to sophisticated phishing attacks.
This paper presents a comprehensive comparative analysis of
FIDO2/WebAuthn cryptographic authentication versus traditional
MFA methods including SMS OTP, TOTP, push notifications,
and email verification codes. Through systematic review
of 81 peer-reviewed academic papers and industry reports,
we evaluate security effectiveness across ten critical attack
vectors and six security dimensions. Our findings demonstrate
that FIDO2/WebAuthn achieves a security effectiveness score
of 8.8/10 compared to 2.0-3.8/10 for traditional methods, providing
90% phishing resistance versus 20-30% for conventional
approaches. We quantify attack vector vulnerabilities, analyze
the security-usability trade-off, and provide evidence-based recommendations
for enterprise deployment. The results indicate
that FIDO2/WebAuthn represents a fundamental paradigm shift
in authentication security, offering 4Å~ superior protection while
maintaining acceptable usability. This research contributes to the
growing body of evidence supporting phishing-resistant authentication
as the next generation standard for identity verification.
Files
FIDO is Phishing resistant.pdf
Files
(1.6 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:49ba7494fa55d3a72708ff286f2175cf
|
1.6 MB | Preview Download |