Authentication in the real world

Imagine you lock your home's front door and hide the key under the doormat. The person who finds and uses the key to unlock the front door has access to the entire house.

A simple lock does not have any mechanisms to determine wheather the key holder is the home's owner or a thief.

If you replace a simple lock with an iris scanner, you can both authorize and authenticate the user at the same time.

An iris scanner first determines the user (authentication), and, second, determines permissions (authorization) to allow or deny the user access to the home.

Get ASP.NET Core MVC 2.0 Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.