ปัจจัยการยืนยันตัวตนและการยืนยันตัวตนหลายปัจจัย
เรียนรู้ปัจจัยการยืนยันตัวตนสามประเภท และวิธีผสานปัจจัยเหล่านี้เป็นการยืนยันตัวตนหลายปัจจัยเพื่อยกระดับความปลอดภัยอย่างมาก
ปัจจัยการยืนยันตัวตนและการยืนยันตัวตนหลายปัจจัย เป็นบทเรียน OAuth2 & OpenID Connect Deep Dive ฟรีบน CoddyKit นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน OAuth2 & OpenID Connect Deep Dive และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส OAuth2 & OpenID Connect Deep Dive มีบทเรียนทั้งหมด 4 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
Proving Who You Are
Authentication asks "are you really you?" — and answers it by checking authentication factors, pieces of evidence tied to your identity.
Three Factor Categories
Every factor fits one of three categories: something you know, something you have, or something you are.
Something You Know
Knowledge factors are secrets you remember — passwords, PINs, security answers. Cheap, but easily phished, guessed, or reused.
Something You Have
Possession factors are things you hold: a phone getting a code, a hardware key, or an authenticator app spitting out rotating codes like this one.
// TOTP code shown by an authenticator app
// changes every 30 seconds
482913Something You Are
Inherence factors are biometrics — fingerprint, face, voice. Convenient and hard to share, but you can't change them once compromised.
Single-Factor Weakness
Leaning on a single factor, usually a password, is fragile — one leak hands over full access. Most major breaches trace back to single-factor logins.
What MFA Means
Multi-factor authentication requires factors from two or more different categories. Password plus phone code is MFA; two passwords is not — both are knowledge.
Why MFA Is Stronger
MFA is stronger because an attacker must defeat several independent factors at once — stealing your password and your phone — making remote attacks far harder.
TOTP One-Time Passwords
A TOTP is a common possession factor: the server and app share a secret and both compute the same code, which rotates every 30 seconds.
// pseudo: code = HOTP(secret, floor(time / 30))
String code = totp(secret, System.currentTimeMillis());Push and Passkeys
Modern logins cut friction with push approvals on a trusted device and passkeys — combining a device (have) with biometrics (are) to resist phishing.
Adaptive Authentication
Adaptive authentication asks for extra factors only when risk spikes — a new device or odd location — balancing security against user convenience.
Quick Check
A login requires a password and a fingerprint. Why does this count as multi-factor?
Recap
Recap: the three factor categories are know, have, and are. Password-only is weak; MFA mixes categories, and TOTP, passkeys, and adaptive auth raise the bar.
คำถามที่พบบ่อย
บทเรียน “ปัจจัยการยืนยันตัวตนและการยืนยันตัวตนหลายปัจจัย” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “ปัจจัยการยืนยันตัวตนและการยืนยันตัวตนหลายปัจจัย” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส OAuth2 & OpenID Connect Deep Dive ให้อัปเกรดเป็น CoddyKit PRO คอร์ส OAuth2 & OpenID Connect Deep Dive มีบทเรียนทั้งหมด 4 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “ปัจจัยการยืนยันตัวตนและการยืนยันตัวตนหลายปัจจัย”
เรียนรู้ปัจจัยการยืนยันตัวตนสามประเภท และวิธีผสานปัจจัยเหล่านี้เป็นการยืนยันตัวตนหลายปัจจัยเพื่อยกระดับความปลอดภัยอย่างมาก คุณปฏิบัติ OAuth2 & OpenID Connect Deep Dive ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน OAuth2 & OpenID Connect Deep Dive หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน OAuth2 & OpenID Connect Deep Dive บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน
บทเรียน “ปัจจัยการยืนยันตัวตนและการยืนยันตัวตนหลายปัจจัย” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน OAuth2 & OpenID Connect Deep Dive นี้ได้ไหม
ได้ บทเรียน OAuth2 & OpenID Connect Deep Dive ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- อธิบาย AuthN กับ AuthZ
- วิวัฒนาการของการจัดการอัตลักษณ์
- แนวคิดและคำศัพท์พื้นฐานด้านความปลอดภัย
- ปัจจัยการยืนยันตัวตนและการยืนยันตัวตนหลายปัจจัย