Roland van Rijswijk roland.vanrijswijk@surfnet.nl
c b
tiqr: a novel take on two-factor authentication
LISA 2011, Boston, MA
c b roland.vanrijswijk@surfnet.nl Overview - Introduction - The - - PowerPoint PPT Presentation
tiqr: a novel take on two-factor authentication LISA 2011, Boston, MA Roland van Rijswijk c b roland.vanrijswijk@surfnet.nl Overview - Introduction - The 2-factor landscape - Something we all have - - Comparison of 2-factor AuthN
Roland van Rijswijk roland.vanrijswijk@surfnet.nl
tiqr: a novel take on two-factor authentication
LISA 2011, Boston, MA
c b
2
3
4
c b
known...
5
Does anybody remember these guys?
c b
6
c b
7
c b
8
SMS from SURFnet - your login code is 32vj6k
c b
users need to carry around
workstations
with each other
use bank A’s token for bank B as well)
9
c b
10
subscribers in a country with 16.5 million people
with them
people notice their phone is missing in under an hour
/bit.ly/mobile-pki)
c b
brainstorming...
solutions: Having to re-type complicated codes
started thinking...
11
c b
12
13
source: http:/ /www.dickestel.com/images/expo175.jpg
♫
14
c b
Authentication (OATH) initiative
http:/ /code.google.com/p/zxing/
15
c b
16
Method Hardware Indep. Software Indep. Security Cost Open Standards Ease-of-use Username/ Password
++ ++
= +/-
OTP token
+
C/R token
+
PKI Token
+
Mobile PKI
+ + ++ ? + ++
SMS OTP
+ =
+ +/= + +/= +/= = + +/= + + ++ ++
c b
/tiqr.org/audit/
17
c b
✔
✔
✔
✔
in progress
you? we?
Q4 2011 - Q1 2012
18
nl.linkedin.com/in/rolandvanrijswijk @reseauxsansfil roland.vanrijswijk@surfnet.nl
Questions? Comments? Please contact me or visit https:/ /tiqr.org/