Loading [MathJax]/extensions/MathZoom.js
Revisiting Multi-Factor Authentication Token Cybersecurity: A TLS Identity Module Use Case | IEEE Conference Publication | IEEE Xplore

Revisiting Multi-Factor Authentication Token Cybersecurity: A TLS Identity Module Use Case


Abstract:

Multi-factor authentication (MFA) procedures are widely used by digital systems. There are usually performed by hardware tokens comprising a microcontroller and an USB in...Show More

Abstract:

Multi-factor authentication (MFA) procedures are widely used by digital systems. There are usually performed by hardware tokens comprising a microcontroller and an USB interface. The security level is increased by computing cryptographic procedures in secure elements such as smartcards. Authenticity of MFA token is a critical topic since hardware or software components may be cloned or modified, for example through supply chain. Due to industrial competition cyber security aspects of MFA token are not generally in the public domain, and therefore somewhat relies on security by obscurity (SbO). In this paper we present an original MFA token built with open hardware (Arduino) and javacard, which realizes a TLS pre-shared-key identity module (TLS-IM). The microcontroller is authenticated by SRAM dynamic PUF features, its software is checked by attestation procedure based on the bijective MAC time stamped algorithm. The javacard application is authenticated by PKI means, and manages a TLS-PSK channel for remote administration.
Date of Conference: 19-22 February 2024
Date Added to IEEE Xplore: 21 June 2024
ISBN Information:

ISSN Information:

Conference Location: Big Island, HI, USA

I. Introduction

Multi-Factor Authentication (MFA) is a technique [1] [2] that enables the computing of cryptographic procedures involved in authentication processes, thanks to authentication credentials bound to human user, according to several factors. For example, something user has, something user known, something user does.

Contact IEEE to Subscribe

References

References is not available for this document.