The preceding section established Identity as a Fact used to record who is performing an Action. However, an Actor merely claiming an Identity does not establish that the Identity is correct. This is where Authentication becomes necessary.
Authentication is the verification process that transforms a Claimed Identity into a Verified Identity. For example, if an Actor claims, “I am Yommy from UH Corp.,” that Identity can be verified through MFA, Credentials, Certificates, or other authentication mechanisms. Once authentication succeeds, the Identity can be treated as a Verified Identity rather than a self-declared claim.
Information associated with Authentication can have different characteristics. Organization, Role, Credential, and Claimed Identity may be registered or provided in advance. By contrast, Actor ID, Authentication Method, Timestamp, Authentication Result, System, and Device describe what actually occurred during the Authentication Event.
In I2EA, these elements can be associated at the time of the relevant Event and recorded as a Fact Tag. This makes it possible to trace who claimed the Identity, how and when Authentication was performed, which System or Device was involved, and what the Authentication Result was.
However, Authentication and Authority are distinct. Authentication verifies the Identity of an Actor; it does not determine what that Actor is authorized to do.
Even if Yommy is successfully verified as Yommy from UH Corp., this does not automatically grant Authority to access particular data or perform a particular Action. The Verified Identity established through Authentication is subsequently evaluated in relation to Authority, Policy, Context, and other relevant elements within the Governance Process.
The basic flow is therefore:
Claimed Identity → Authentication → Verified Identity → Fact Tag
Authentication is the process through which a claimed Identity is verified and established as a Fact that can be referenced for Governance purposes.