2014 IoT Forum_ Fido Alliance

20
STRONG AUTHENTICATION & THE CLOUD – FIDO ALLIANCE RAMESH KESANUPALLI, FOUNDER, NOK NOK LABS FIDO VISIONARY
  • date post

    21-Oct-2014
  • Category

    Technology

  • view

    11.653
  • download

    2

description

Topic: Scaling Authentication to the Internet of Things Speaker: Ramesh Kesanupalli (Visionary Fido Alliance)

Transcript of 2014 IoT Forum_ Fido Alliance

Page 1: 2014 IoT Forum_ Fido Alliance

STRONG AUTHENTICATION & THE CLOUD – FIDO ALLIANCE

RAMESH KESANUPALLI, FOUNDER, NOK NOK LABS FIDO VISIONARY

Page 2: 2014 IoT Forum_ Fido Alliance

CONNECTED WORLD

2

Everything Authenticates

50 Billion Connected Devices

(by 20201)

Internet of Things

Mobile Payments

Books

60 Billion Apps downloaded

(Apple App Store, Oct 20132)

Personalized content

M-Commerce

Music

Cloud Services

Social networks Financial services Medical records

Connected Devices Hub

Page 3: 2014 IoT Forum_ Fido Alliance

RAMPANT ONLINE ATTACKS

3

•  Major hacks have been targeted at password databases within Online Gaming, Financial Services, Social Media organizations

•  Password Re-use is a

significant problem – technical analysis of data breaches have shown that 76% of passwords used across multiple sites.

Page 4: 2014 IoT Forum_ Fido Alliance

IDENTITY AND AUTHENTICATION LANDSCAPE •  99% OF ONLINE ATTACKS AND IDENTITY THEFT ARE CONNECTED TO

PASSWORD THEFT •  CURRENT TWO FACTOR SOLUTIONS RIDE ON TOP OF PASSWORDS AND

ARE: •  EXPENSIVE •  COMPLEX •  DO NOT SCALE •  PROPRIETARY •  TO COMPLICATED TO DEPLOY OR SWITCH

•  NO SCALABLE CONSUMER AUTHENTICATION SOLUTION •  HIGHER SECURITY TODAY REQUIRES MORE TRANSACTION FRICTION

ACCOUNT NAME AND PASSWORDS DO NOT WORK ON MOBILE DEVICES CLOUD SERVICES NEED STRONG AUTHENTICATION TO MITIGATE RISKS

Authentication is KEY - whether it is User to Device, User to Service, Device to Device, Device to Service

Page 5: 2014 IoT Forum_ Fido Alliance

TODAY’S AUTHENTICATION SOLUTIONS FALL SHORT

5

Easy but

WEAK

DIFFICULT but

Strong

Easy to Use AND

Strong

Desired !!

Page 6: 2014 IoT Forum_ Fido Alliance

COMMON AUTHENTICATION PLUMBING

6

Users

Cloud/Enterprise

Devices

Federation

Open Standard Plug-In Approach

Interoperable Ecosystem

Usable Authentication

WHAT IS NEEDED

Page 7: 2014 IoT Forum_ Fido Alliance

7

MICHAEL BARRETT

FORMER CHIEF INFORMATION SECURITY OFFICER

RAMESH KESANUPALLI

FORMER CTO

TAHER ELGAMAL

INVENTOR OF SSL

CURRENTLY FOUNDER, CHIEF ALLIANCES OFFICER AND FIDO VISIONARY

CURRENTLY CTO SECURITY

CURRENTLY BOARD MEMBER

VISIONARIES

PHIL DUNKELBERGER

FORMER CEO

CURRENTLY PRESIDENT AND CEO

Page 8: 2014 IoT Forum_ Fido Alliance

8

INDUSTRY COOPERATION REQUIRED NO ONE COMPANY CAN FIX THE PROBLEM

15 MONTHS AGO

PUBLIC LAUNCH

Page 9: 2014 IoT Forum_ Fido Alliance

FIDO’S EXPLOSIVE GROWTH

9

Industry Standard

Feb 2013 May 2014 Next

6     118  

Companies Companies

Public Launch

Public Review Spec

Companies

Page 10: 2014 IoT Forum_ Fido Alliance

10

Page 11: 2014 IoT Forum_ Fido Alliance

THE FIDO ALLIANCE AND NOK NOK LABS

11

Standards   Products  

Industry Standard Protocol

“FIDO Ready™”

FIRST FIDO Ready™ Server and Client Software:

NNL S3 Suite

Key Industry Partnerships

Page 12: 2014 IoT Forum_ Fido Alliance

FIDO - UNIQUE APPROACH Any Device. Any Application. Any Authenticator.

12

Standardized Protocols

Local authentication unlocks app specific key

Key used to authenticate to server

Page 13: 2014 IoT Forum_ Fido Alliance

MORE SECURE AUTHENTICATION

13

Unique Cryptographic Secrets

Feature   Security  Benefit    

Unique key per user/device/site Segmentation of risk

High-entropy asymmetric keys instead of passwords

Protection against dictionary, brute force attacks

Secrets not exposed to user Protection against phishing, key logging, shoulder surfing

User Account Device Site

Page 14: 2014 IoT Forum_ Fido Alliance

FUTURE PROOF

14

Standardized Protocol

Plugin any authentication method on device

? Decouple Method <-> Protocol Standardize Protocol

1 2

Authentication clients for any device

Page 15: 2014 IoT Forum_ Fido Alliance

Single Infrastructure

REDUCED COST & COMPLEXITY

15

Any Device Risk Appropriate

Lower Cost & Complexity

Page 16: 2014 IoT Forum_ Fido Alliance

USABILITY & DIVERSITY

16

Usability Usage

•  No passwords •  Existing devices •  Flexible authentication

•  Engagement •  Completed transactions •  Security compliance

Drives  

Aspirational Goal

Page 17: 2014 IoT Forum_ Fido Alliance

FIDO SOLUTIONS DEMONSTRATED AT INDUSTRY EVENTS

SIM  as  Secure  Element  

Fingerprint,  TEE,  Mobile  

Speaker  Recogni<on  

Mobile  via  NFC  

PIN  +  MicroSD  

USB  

Page 18: 2014 IoT Forum_ Fido Alliance

FIDO-READYTM PRODUCTS SHIPPING TODAY

OEM  Enabled:  Lenovo  ThinkPads  with    Fingerprint  Sensors  

OEM  Enabled:  Samsung  Galaxy  S5  

Clients  available  for  these  opera<ng  systems:  

SoNware  Authen<cator  Examples:  Speaker/Face  recogni<on,  PIN,  QR  Code,  etc.  

ANermarket  Hardware  Authen<cator  Examples:  USB  fingerprint  scanner,  MicroSD  Secure  Element  

Page 19: 2014 IoT Forum_ Fido Alliance

CALL TO ACTION •  AUTHENTICATION IS A FUNDAMENTAL PROBLEM AND IT IS AN

INDUSTRY PROBLEM •  NO ONE COMPANY CAN FIX THIS PROBLEM, JOIN THE FIDO

ALLIANCE & HELP FIX IT TOGETHER •  OPPORTUNITY TO CREATE NEW SERVICES, NEW MARKETS, NEW

INNOVATIONS, NEW BUSINESSES AND NEW REVENUE MODELS •  TAKE THE LEADERSHIP, INCLUDE FIDO SUPPORT AT THE

SOURCE ON YOUR DEVICES •  FIDO READY TM COMMERCIAL PRODUCTS ARE AVAILABLE IN THE

MARKET

•  MAKE THE CONNECTED WORLD SECURE, PRIVATE, FRAUD FREE , EASY TO USE AND STAY CONNECTED

19

Page 20: 2014 IoT Forum_ Fido Alliance

THANKS!

Email: [email protected] https://www.youtube.com/watch?v=ffLERYgteJQ

Sponsored By