Evaluating the Android Security Key Scheme: An Early Usability, - - PowerPoint PPT Presentation

evaluating the android security key scheme an early
SMART_READER_LITE
LIVE PREVIEW

Evaluating the Android Security Key Scheme: An Early Usability, - - PowerPoint PPT Presentation

Evaluating the Android Security Key Scheme: An Early Usability, Deployability, Security Evaluation with Comparative Analysis Robbie MacGregor 5 th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019. I did a thing so


slide-1
SLIDE 1

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

Robbie MacGregor

Evaluating the Android Security Key Scheme: An Early Usability, Deployability, Security Evaluation with Comparative Analysis

slide-2
SLIDE 2

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

‘I did a thing so you don’t have to.’

  • Me
slide-3
SLIDE 3

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

Authentication and Passwords Want to talk about passwords, password managers, password reuse, MFA, etc.?

  • Convince your advisor/readers/audience that

PASSWORDS AREN’T GOING ANYWHERE

  • Address the ‘new hotness’
slide-4
SLIDE 4

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

Android Security Keys

  • Very new
  • Very hot
  • Is that even what they’re called?

Source: https://cloud.withgoogle.com/next/sf/sessions?session=SEC200

slide-5
SLIDE 5

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

ASKs v. USB Security Keys

  • Claim similar security benefits
  • More convenient, etc.

Let’s prove it… UDS style!

slide-6
SLIDE 6

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

Usability, Deployability, Security

slide-7
SLIDE 7

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

Subjectively Similar

  • Usability

– convenience of quasi-nothing-to-carry – less efficient login task

  • Deployability

– differ or defer?

  • Security

– time for a closer look

slide-8
SLIDE 8

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

A Closer Look

  • No physical connection (I/O)
  • No pairing

– caBLE

slide-9
SLIDE 9

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

Up Next

  • Formal verifications

– caBLE – unlinkability – POP

  • Availability
  • Interoperability
slide-10
SLIDE 10

5th Who Are You?! Adventures in Authentication (WAY), Santa Clara, CA, USA, 2019.

QUESTION TIME!

(Robbie MacGregor | macg@dal.ca)