Top Banner
1 CAN HARDWARE MFA MOVE FROM MEH TO AHA? Stina Ehrensvard CEO & Founder, Yubico
10
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

1

CAN HARDWARE MFA MOVE FROM MEH TO AHA?

Stina Ehrensvard

CEO & Founder, Yubico

Page 2: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

2

Stats Protecting identities

Page 3: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

3

History

PKI OTP

Page 4: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

4

Phone authenticator

Page 5: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

5

Driverless authenticator

Page 6: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

6

PKI without the “I” -  No drivers, no client

-  No limits on number of supported services

-  No shared secrets

-  No heavyweight CA

Page 7: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

7

U2F sample login

1. Enter password 2. Insert U2F Key 3. Touch device

Page 8: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

8

Sample authenticators

Page 9: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

9

Identity ecosystem

RP RP

IDP

RP RP

Page 10: CIS 2015-Can Hardware MFA Move from Meh to Aha?- Stina Ehrensvard

10

A User owned identities