I wrote a 1-page article for this in a small obscure, local-language magazine. The title of which was, translated in English (OMG, I should have also published in English) - Re-factor the factors.
I think the 3-factor authentication (3FA) model of "know, have and are" is up for a revision. Knowing that all models are wrong, I hope my suggestion as at least useful. These were really rough thoughts, and I was hoping to spark some discussion of it, but unfortunately that never happened.
Anyway, I think the 3FA model has several problems.
1) there is no clear category for recent "ambient" auth factors that are getting very popular, like if one logs into a website on a browser and its fingerprint is unknown, that a "step-up" authentication is required.
2) Authentication is proving that you are who you say you are (you prove an identityclaim), a factor called "are" make the cognitive shortcut of equating the inherence factor to the identity proof very very tempting (and I think many people in the field have fallen for it, given the prevalence of biometrics as sole authentication.
3) Behavioural biometrics like keystroke dynamics do not neatly fall into one of the three categories (it is a little bit of knowledge, it is a little bit of "inherence")
I also take major offense to the statement that follows from it, that I AM my fingerprint, or I AM my Iris. NO, I can _prove_ who I am by presenting my fingerprint or iris.
To fix this, in the article I suggested moving to a 2-dimensional model of authentication (2DA), that is reminiscent of but not quite the same as the 3FA model.
The two dimensions were:
Dimension 1: Knowledge vs Possession. A factor is somewhere on this dimension, and my thought was which is which could be tested by the colloquial language use of "know". I can always say I have a password, I have a way of using my phone, but additionally I "know" my password, and I "know" my way of using my phone (even if implicitly). On the otherhand, I have a smartcard, but I do not know it, nor do I know my fingerprint.
The SSH private key would in my opinion fall in the "have" part of this dimension.
Dimension 2: Transferability. The degree to which the factor is transferable to someone else, to which ownership of the factor can be "bestowed" on someone else. Smartcards are highly transferable, as are passwords, however fingerprints generally are not expected to be transferable, neither are the way I use my phone nor from what browser and what location I log-in.
Naturally, 4 relatively distinct quadrants in this space arise, which I tried to label indepently with a single word:
possession, high transferability: carry
possesion, low transferability: show
knowledge, high transfer: tell
knowledge, low transfer: do.
So, the catchy phrase for the 2DA model would be, things that you "carry, show, tell and do".