Authenticator

Something a subscriber possesses and controls, such as a password, OTP device or cryptographic key, that is bound to their account and used to prove their identity.

In NIST terminology, an authenticator is something the subscriber possesses and controls, such as a password or a cryptographic module, that is used to authenticate a claimant’s identity. It is bound to the subscriber account at identity enrolment or later, and proving control of it is what authentication means. SP 800-63B-4 describes seven authenticator types: passwords, look-up secrets, out-of-band devices, single-factor and multi-factor one-time password devices, and single-factor and multi-factor cryptographic authenticators such as a smart card or FIDO2 security key.

The authenticator and the authentication factor are easily confused. The factor is the type of evidence; the authenticator is the thing that supplies it. A password is an authenticator providing something you know. A security key unlocked by a fingerprint is one multi-factor authenticator providing two factors. A biometric characteristic on its own is not accepted as an authenticator under SP 800-63B-4; it is used together with a physical authenticator. The word has a second, unrelated meaning in Kerberos, where an authenticator is a timestamped record that the client encrypts with the session key to prove it holds that key.

Exam relevance: questions in this area tend to turn on vocabulary. Candidates are expected to separate the authenticator from the factor it supplies, and to recognise which meaning applies when a Kerberos scenario uses the word.