What is the difference between an authentication means and a credential?
The authentication means is what the subject holds and presents (a password, a token, a certificate with its private key); the credential is what the identity provider stores to verify it (the password hash, the registered public key). Authentication compares the two.
* The subject holds the means, the IdP holds the credential; authentication compares the two. *
The two words are often used loosely, but the IdP's definition keeps them apart:
- Authentication means (Authentifizierungsmittel) belong to the subject. The IdP issues, renews, replaces and revokes them.
- Credentials are held by the IdP and link a digital identity to its authentication means. The IdP must protect their confidentiality, integrity and availability.
At login the authentication service "verifies the authentication means presented by the subject with the help of the stored credentials". With a password the two are the same secret in different forms (plain text versus salted hash); with a security key they are a key pair (private key on the token, public key in the credential). The strength of authentication depends on how well this binding resists copying or guessing.
Go deeper:
Authenticator (NIST glossary) — NIST's word for the authentication means: something the claimant possesses and controls.
Credential (NIST glossary) — the object that binds an identity to an authenticator.