Quiz Entry - updated: 2026.09.17
Differentiate the four terms: registering, identifying, authenticating and authorising.
Registering takes a subject into the system, identifying establishes with certainty which natural person it is, authenticating checks on each access that the presented identity belongs to the subject, and authorising decides what the authenticated identity may do.
* Registering and identifying happen once; authenticating and authorising happen on every access. *
| Term | When | Question answered | Typical means |
|---|---|---|---|
| Registering | Once, at onboarding | "Let us create your account" | Creating the digital identity, assigning attributes, roles and authentication means |
| Identifying | Usually during registration | "Which real person are you?" | Biometric comparison with a passport, ID card or E-ID |
| Authenticating | Every access | "Are you really the owner of this account?" | Password, token, certificate, biometrics |
| Authorising | Every access, after authentication | "May you perform this operation on this resource?" | Roles, attributes, policies applied by the application |
A useful way to see the relationships: identification is an optional but quality-defining part of registration; authentication reuses the binding created at registration; authorisation presupposes a successful authentication but is decided by a different party (the relying party).