पाठ 2 / 25
Principals, Credentials and Factors
The vocabulary of identity.
The core terms
A principal is any entity that can be authenticated: a person, a service, a device. An identifier names it (email, username, client ID); a credential is the evidence it presents (password, private key, token). Authentication factors fall into three categories: something you know (password, PIN), something you have (phone, security key, passkey on a device) and something you are (biometrics, usually unlocking a local key rather than being sent to the server). Multi-factor authentication combines different categories; two passwords are still one factor. After authentication, systems usually issue a session or token so the principal does not re-present credentials on every request.
Mapping the terms
Examples of principals, identifiers and credentials.
principal identifier credential / factor
--------- ---------- -------------------
human user alice@example.com password (know) + passkey (have)
mobile app user user id from IdP session cookie or access token
backend service OAuth client_id client secret or private-key JWT
CI pipeline workload identity short-lived OIDC token from CI provider
IoT device device serial X.509 client certificateSeparate identifiers from credentials
Treat email addresses and usernames as public. Security must never depend on an identifier being secret; it depends on the credential.
त्वरित जाँच: Which combination is genuine multi-factor authentication?
- A password plus a code from an authenticator app
- A password plus a security question
- Two different passwords
- A username plus a password
Answer
A password plus a code from an authenticator app — MFA needs factors from different categories: know plus have.