Top Banner
1 © SURFnet 1998 Smart Access: Strong Authentication on the Web [email protected] TNC Dresden 5-8 October 1998
22

Smart Access: Strong Authentication on the Web [email protected]

Feb 06, 2016

Download

Documents

Wyatt

Smart Access: Strong Authentication on the Web [email protected] TNC Dresden 5-8 October 1998. What’s the problem?. Authentication solutions. ROM. EEPROM. I/O etc. R A M. CPU. Introducing…the smartcard. IBM MFC smartcard: 8 bit P rocessor 2K ROM (OS) 10K EEPROM (Apps) - PowerPoint PPT Presentation
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

1 © SURFnet 1998

Smart Access: Strong Authentication on the

Web

[email protected]

TNC Dresden 5-8 October 1998

Page 2: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

2 © SURFnet 1998

What’s the problem?

Page 3: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

3 © SURFnet 1998

Authentication solutions

IP-based spoofing/proxies username /

passwordsniffing

SSL certificatesserver & client

CertificateAuthorities

Page 4: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

4 © SURFnet 1998

Introducing…the smartcard

EEPROM

ROM

RAMCPU

I/Oetc

IBM MFC smartcard:

•8 bit Processor•2K ROM (OS)•10K EEPROM (Apps)•<1K RAM•3,64Mhz clockspeed

Page 5: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

5 © SURFnet 1998

Smartcard intro (Cont’d)

EF EF

MF

EF EF

DF

EF EF

DF

EF EF

DF

EF EF

DF

• MF Master File• DF Dedicated File• EF Elementary Files

Page 6: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

6 © SURFnet 1998

Access conditionsFor each command on a file:• ALW (Always)• CHV (CardHolder Verification)• PRO (Protected with key X)

– Secure handshake with MAC• AUT (External Authentication)• ENC (Enciphered)

– PRO plus encrypted data• NEV (never)

(triple) DES !

Page 7: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

7 © SURFnet 1998

Student Smartcard• College pass• library pass• loan/grant registration number• membership data• e-purse (Chipper)

Page 8: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

8 © SURFnet 1998

Our model is ISI

WWW

SAS

ApplicationServer

ApplicationServer

Client

Client

trustedcommunication

lines

trustedcommunication

lines

APPLICATIONPROVIDER

ENVIRONMENT

Page 9: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

9 © SURFnet 1998

ISI Protocol

Page 10: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

10 © SURFnet 1998

Current applications• Downloading of commercial software

(Smart Server)• Access to exam results database• Student grants/loans system• StudyNet:

– registration for courses and exams– access to exam results

Page 11: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

11 © SURFnet 1998

Issues• Java implementations in browsers• Support for smartcard readers (com port)• Use of DES in public key world• Scaling of DES-based two-party

authentication

Page 12: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

12 © SURFnet 1998

Tree-party Authentication

WWW

SAS

ApplicationServer

ApplicationServer

Client

Client

trustedcommunication

lines

trustedcommunication

lines

APPLICATIONPROVIDER

ENVIRONMENT

AS

Page 14: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

14 © SURFnet 1998

References• http://www.surfnet.nl/surfnet/projects/home-office/• http://www.surfnet.nl/projecten/surf-ace/homeoffice/

(dutch)• http://www.iscit.surfnet.nl/• http://www.chipcard.ibm.com/

Page 15: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

15 © SURFnet 1998

Be Smart!

Page 16: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

16 © SURFnet 1998

Page 17: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

17 © SURFnet 1998

Offline demo

Page 18: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

18 © SURFnet 1998

Offline Demo (cont’d)

Page 19: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

19 © SURFnet 1998

Offline Demo (cont’d)

Page 20: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

20 © SURFnet 1998

Offline Demo (cont’d)

Page 21: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

21 © SURFnet 1998

Offline Demo (cont’d)

Page 22: Smart Access:  Strong Authentication on the Web Ton.Verschuren@SURFnet.NL

22 © SURFnet 1998

Offline Demo (cont’d)