The FIDO UAF Client permission of the mobile application refers to the Online Fast Identity Authentication Alliance client.
FIDO (Fast Identity Online) Alliance, the Fast Identity Verification Alliance. The FIDO Alliance is an industry association established in July 2012. Its purpose is to meet market needs and meet online verification requirements. Members of the FIDO Alliance will help define market needs and contribute to the FIDO Open Protocol.
The protocol is the first open industry standard for online and digital authentication, improving security, protecting privacy and simplifying the user experience. Through the FIDO open protocol, users can log in using various methods such as smartphone fingerprint collectors and USB tokens, and service providers no longer need to maintain a complex and costly authentication backend.
FIDO implements secure login (verification) through two sub-protocols. The U2F standard is about using a PIN and USB stick or an NFC-enabled mobile phone; the second related protocol, UAF, supports biometric identification technologies such as fingerprints, voice, iris scans, etc.
The picture below shows two user experience application scenarios of FIDO, one is a smartphone fingerprint collector and the other is a USB token.
Extended information:
How the FIDO protocol works
The FIDO protocol uses standard public key encryption technology to provide stronger authentication.
During registration for an online service, the user's client device creates a new key pair. It keeps the private key and registers the public key with an online service. Authentication is accomplished by the client device by signing a challenge to prove possession of the service's private key.
The client's private key can only be used if the user unlocks it locally on the device. Local unlocking is accomplished through user-friendly and secure actions such as swiping a finger, entering a PIN, speaking into the microphone, plugging in a secondary device, or pressing a button.
The FIDO protocol is designed to protect user privacy. The Agreement does not provide information that can be used by different online services to collaborate and track users across services. Biometric information, if used, never leaves the user's device.
Baidu Encyclopedia - FIDO
FIDO - Specifications Overview (FIDO protocol working principle)