Introduction
Quick Authentication, or Quick Auth, enables you to create a faster authentication experience for users in areas with slow networks or who use low-bandwidth devices. Regular authentication requires two round trips between the App SDK and the Auth Server. Quick Auth cuts out one of those round trips.
Control Quick Authentication through a FIDO policy. Quick Auth applies to the UAF and FIDO2 authenticators. Quick Authentication can be used during regular authentication and Adaptive Authentication. Configure Quick Auth by setting a value for the Quick Authentication attribute in a FIDO policy.
The table below shows what each value means when the Auth Server receives a Quick Auth request for both a regular authentication and Adaptive Authentication request.
Value | Regular Authentication | Adaptive Authentication |
|---|---|---|
allow | Processes the Quick Auth payload, verifies the signature. If the authenticator matches what is approved in the policy, then authentication succeeds. Otherwise, it fails. | Same as regular authentication. If Quick Auth succeeds and there are other auth methods contained in the sequence, then authentication continues with the next method. |
ignore | Ignores the Quick Auth payload in the request and falls back to doing regular authentication with the current authentication method. | Ignores the Quick Auth payload in the request and falls back to doing normal Adaptive Authentication with the current authentication method. |
disallow | Authentication fails, no processing is done. | Authentication fails, no processing is done. |
When you use Quick Auth with Adaptive Authentication, you must pay careful attention to the Adaptive Rules you create. Quick Auth only makes sense in an authentication sequence that contains a single FIDO authentication method or External Authentication method. Creating an authentication sequence with multiple FIDO authentication methods and non-FIDO authentication methods eliminates the advantages of Quick Auth.