Organizations in both public and private sectors are seeking modular authentication services to modernize legacy IAM stacks amid rising data leaks and fraud. Stronger authentication—especially risk-adaptive and multi-factor methods—improves security while enabling personalization for consumer and government-to-citizen scenarios, with privacy controls supported through consent management. Authentication has advanced beyond passwords through varied authenticators (biometrics, out-of-band apps, push notifications, hardware tokens) and “invisible” controls such as behavioral analysis, device identity and health, and contextual signals like network and location. These background checks enable continuous, risk-adaptive authentication that only prompts users when anomalies occur.
Regulatory pressure is accelerating adoption. In the EU, PSD2 requires Strong Customer Authentication, and in the US the New York SHIELD Act can impose significant penalties for unauthorized access to personal information. Rather than replacing full IAM suites, many organizations are adopting modular authentication components deployable on-premises or in the cloud. This aligns with the “Identity Fabric” approach: composable, service-based architectures that integrate disparate capabilities, increasingly delivered via containers across IaaS/PaaS/SaaS models.
HID Global (ASSA ABLOY) offers a containerized Authentication Platform spanning authenticators, adaptive risk, recovery, identity vetting, credential provisioning, and consent management, with emphasis on finance, healthcare, and government. It supports interoperability standards (OAuth/OIDC, SAML, RADIUS) and provisioning via LDAP/SCIM. Workforce options include FIDO2-certified Crescendo keys, smart cards, X.509, biometrics, and Windows Hello integration; consumer options include OTP, KBA, and FIPS 140-2-based HID Approve push with transaction signing to meet PSD2 requirements. The platform provides extensive risk policy controls, remote identity proofing via document scan plus selfie matching, developer APIs (REST, WebAuthn), and token exchange for downstream assurance signaling, while noting gaps such as limited third-party compromised-credential intelligence and missing CIAM social login and SaaS/IGA/PAM connectors.
See All Locations
See All Locations