Hardware-based Cryptography
Smart cards, YubiKeys & more
Karol Babioch Security Engineer kbabioch@suse.de
Hardware-based Cryptography Smart cards, YubiKeys & more Karol - - PowerPoint PPT Presentation
Hardware-based Cryptography Smart cards, YubiKeys & more Karol Babioch Security Engineer kbabioch@suse.de Rationale - Computers running general purpose software can be compromised hacked Offline-access, etc. -
Karol Babioch Security Engineer kbabioch@suse.de
2
3
4
Karol Babioch Security Engineer kbabioch@suse.de
6
7
8
9
10
11
12
13
Karol Babioch Security Engineer kbabioch@suse.de
15
– Allows for external authenticators (tokens, phones, smart cards, etc.)
Karol Babioch Security Engineer kbabioch@suse.de
17
– Stores a reference to smart card in keyring
18
Karol Babioch Security Engineer kbabioch@suse.de
20
– Slot 9a: PIV Authentication – Slot 9c: Digital Signature – Slot 9d: Key Management – Slot 9e: Card Authentication – Slot 82-95: Retired Key Management – Slot f9: Attestation
21
– Supported on all major operating systems
– OS login – SSH – Browser – Code signing – OpenSSL
Karol Babioch Security Engineer kbabioch@suse.de
23
– e.g. Infineon RSA key generation → Also affected YubiKeys
– e.g. X41 security announcements → fuzzing
Karol Babioch Security Engineer kbabioch@suse.de
26