Skip to content

Passwordless authentication

Authentication that verifies a claimant without requiring entry of a memorized knowledge secret, usually through a registered device, cryptographic key or inherence factor.

Version
v1 · 2026-09-08 · History
Domain-specific #
6008
Origin domain
identity security
Subdomain
identity security

Core Idea

A biometric that merely unlocks a local private key differs from a biometric sent to a server, recovery can reintroduce weak knowledge factors and OTP email links can remain phishable. Enrollment binds an account to a possession or inherence-backed authenticator, a fresh challenge is approved or signed locally and the verifier checks the proof and context without receiving a reusable password. The abstraction is therefore identified by a declared carrier, a transformation or constraint over that carrier, and an invariant that tells an analyst whether the named structure is genuinely present.

Scope of Application

Passwordless authentication belongs to identity security and is useful where the analyst can specify the typed identity security carrier, including objects, relations, parameters, conventions, evidence, boundaries, and comparison targets, then evaluate the claimant account and verifier, enrollment and binding, authenticator and factor category, public and private key or one-time proof, challenge freshness and origin binding, local user verification, server verification, recovery and revocation and phishing replay and device-loss threat model are explicit.

Clarity

The abstraction clarifies a crowded vocabulary by making the claimant account and verifier, enrollment and binding, authenticator and factor category, public and private key or one-time proof, challenge freshness and origin binding, local user verification, server verification, recovery and revocation and phishing replay and device-loss threat model are explicit the center of the account. A claim should name the carrier, the governing operation or relation, the applicable assumptions, and the recognition test.

Manages Complexity

Without the abstraction, an analyst must reason directly over many local details: the carrier roles, admissibility assumptions, competing conventions, derived invariants, boundary cases, and proof or validation obligations specific to Passwordless authentication. Passwordless authentication compresses them into the roles in the structural signature. That compression permits comparison across instances without erasing the variables that determine validity. It also exposes which details may be varied safely and which are constitutive.

Abstract Reasoning

  1. Identify the carrier. State what the elements, states, objects, or observations are: the typed identity security carrier, including objects, relations, parameters, conventions, evidence, boundaries, and comparison targets. Reject examples whose alleged carrier belongs to a different problem. 2. Lock the constitutive rule. Express the claimant account and verifier, enrollment and binding, authenticator and factor category, public and private key or one-time proof, challenge freshness and origin binding, local user verification, server verification, recovery and revocation and phishing replay and device-loss threat model are explicit independently of one notation or implementation.

Knowledge Transfer

Knowledge transfers strongly among subfields of identity security because they reuse the typed identity security carrier, including objects, relations, parameters, conventions, evidence, boundaries, and comparison targets, Enrollment binds an account to a possession or inherence-backed authenticator, a fresh challenge is approved or signed locally and the verifier checks the proof and context without receiving a reusable password., and type the carrier, state every parameter and convention in the definition, test that the claimant account and verifier, enrollment and binding, authenticator and factor category, public and private key or one-time proof, challenge freshness and origin binding, local user verification, server verification, recovery and revocation and phishing replay and device-loss threat model are explicit, compare the nearest accepted identity, and report counterexamples, uncertainty, and limiting cases.

Relationships to Other Abstractions

Local relationship map for Passwordless authenticationParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.PasswordlessauthenticationDOMAINPrime abstraction: Authentication — is a kind ofAuthenticationPRIME

Current abstraction Passwordless authentication Domain-specific

Parents (1) — more general patterns this builds on

  • Passwordless authentication is a kind of Authentication Prime

    The proposed strict upward parent is prime:authentication.

Hierarchy path (1) — routes to 1 parentless root

Neighborhood in Abstraction Space

Passwordless authentication sits in a moderately populated region (57th percentile for distinctiveness): it has near-neighbors but no dense thicket of look-alikes.

Family — Algorithms, Proofs & Computational Decisions (25 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-09-08