immo.quick Serverless Edition
PUBLIC ARCHITECTURE EXPLAINER

Authentication ≠ Authority.

A password can be correct. An OTP can be valid. A session can be technically active. A device can be successfully linked. And the Execution Right for the concrete effect can still be absent.

ENCRYPTION PROTECTS THE CHANNEL · AUTHENTICATION PROVES POSSESSION · ENDPOINT SECURITY PROTECTS THE DEVICE · EXECUTION RIGHTS DETERMINE WHETHER CONSEQUENCE IS AUTHORIZED
THE DISTINCTION

Four assurance objects. Four different questions.

ENCRYPTION

Can someone read the content?

Protects confidentiality of channel and message within the applicable cryptographic model.

AUTHENTICATION

Who or what presents the factor?

Confirms identity or possession signals. That is not universal authority to act.

ENDPOINT SECURITY

Is the device and session trustworthy enough?

Reduces technical risk but does not replace the authority decision for a specific effect.

EXECUTION RIGHTS

May this consequence happen now?

Binds Authority, Rule, Jurisdiction, Time, Dependencies and Endpoint State to the concrete effect.

EXAMPLES

What changes across real attack patterns.

STOLEN OTP

Factor present, enrollment authority absent

The OTP may be correct. It must not alone establish a new endpoint as authorized.

LINKED DEVICE PERSISTENCE

Session present, Continuing Authority absent

A previously valid device link must not continue after revocation or material state change.

INTEROPERABILITY

Path present, authority transfer absent

Technical interoperability must not create external provider authority or administrative rights.

DEEN