Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper...

12
Strong Authentication: What’s Beyond Usernames and Passwords? Rob Zivney Sr. Consultant IDentification Technology Partners

Transcript of Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper...

Page 1: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Strong Authentication: What’s Beyond Usernames and Passwords? § Rob Zivney § Sr. Consultant § IDentification Technology Partners

Page 2: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Displace Ø Paper Ø Plastic Ø Photos Ø Leather

I Have Memorized My AMEX I have digitized my important info into one file

Ø Organized so I can find stuff

True Digital Wallet

Page 3: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Analog and Digital Like a “Wearable”

Ø Possession Auto - Pushbutton Start Backup USB

Ø Important Stuff File Ø Encrypted Ø List of UN & PW

Most Have No Batteries

Keys

Page 4: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Identities are Just a Record In a Database Ø Just a number string somewhere

You Can Have Many Identities Ø Each requires its own Authentication

Each Identity has Its Own Privileges Linkage is Key

Ø Link to Master Secure Identity Ø Link to Communications (including Cloud) Ø Link to Power Source

Internet of Things Can Be Less “Personal” Ø PACS Authenticates System Components

What Does It Matter?

Page 5: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Authentication to the OS or the App? Ø Hardware Ø GUI Ø Convenience Ø Client, Server, Workstation

Every App is Different Ø Different Rules for Authentication (Password, etc.)

Too Many Passwords Ø To Remember Ø To Manage

It’s About Who Has Control

Page 6: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Cryptography Ø With Some form of Keyboard Entry

Biometrics Ø Not a secret, but…

4 Factor Ø What You Have Ø What You Know Ø What You Are Ø What Someone Else Knows About You (PKI)

Strength thru Multifactor vs. Strong Passwords

Multifactor Authentication

Page 7: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Biometrics Ø Finger Ø Face Ø Templates

“Wearables” Physical Access How to Do Mutual Authentication? Ø  Smarter Readers Ø  Smarter PACS Ø NFC SE for Reader

Consumer Market - Mobile

Page 8: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

PACS Industry Had Little Input Developed for eGovernment

Ø Remote IT Login via PKI Access is both Authentication & Authorization

Ø PACS takes a systems approach Ø Authentication is not always done 1st

Struggling for Interoperability Ø Gen 2 Test Cards - Finally Ø Now Industry can build Systems for PIV

Will have to get Quicker for PACS Ø Contactless

Not the Game Changer Expected Ø Not Using the Power of the Smart Card Ø Too Many “Options”

Government Market - PIV

Page 9: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Ultimately: A Question of Trust PIV Now Requires PKI at the Door New Processes:

Ø Signature Checking of Signer Ø Challenge/Response to Card Ø Certificate Check with Path Validation Ø All Require FIPS 140-2 Somewhere in the “System”

New Encryption Algorithms Ø RSA-2048 & ECC

Must Validate: Ø Cardholder Ø Card Ø Credential

CA

Page 10: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Leadership

What’s Next?

Page 11: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

Need a Market Leader Ø Rules of the Game

Convenience – Not Price Ø Smartphones are Expensive Ø Form Factor Ø Speed Ø Sign On to OS – Not the App

Design Aesthetics Long Battery Life

Ø Short Recharge Time

One Global Market Technology Cybersecurity Reactions The Consumer Will Lead

Market Drivers

Page 12: Secure Technology Alliance - Strong Authentication: What’s … · 2020-01-16 · Displace " Paper " Plastic " Photos " Leather I Have Memorized My AMEX I have digitized my important

§ Smart Card Alliance § 191 Clarksville Rd. · Princeton Junction, NJ 08550 · (800) 556-6828 § www.smartcardalliance.org

Rob Zivney IDentification Technology Partners [email protected] Office 1 301 990-9061 Mobile 1 949 283-1126