Strong Authentication Protocol using PIV Card with Mobile Devices

Nowadays weak single-factor authentication mechanisms like passwords or passphrases are commonly used. Static passwords are easy to use, just remember them in mind. However it has many security weaknesses and even strong passwords are not strong enough. For example, strong secrets are difficult to r...

Full description

Bibliographic Details
Main Author: Kunning, Mao
Format: Others
Language:English
Published: KTH, Skolan för informations- och kommunikationsteknik (ICT) 2013
Subjects:
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-128418
id ndltd-UPSALLA1-oai-DiVA.org-kth-128418
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-kth-1284182013-09-12T04:30:04ZStrong Authentication Protocol using PIV Card with Mobile DevicesengKunning, MaoKTH, Skolan för informations- och kommunikationsteknik (ICT)2013Mobile Applications SecurityStrong AuthenticationSmart CardNowadays weak single-factor authentication mechanisms like passwords or passphrases are commonly used. Static passwords are easy to use, just remember them in mind. However it has many security weaknesses and even strong passwords are not strong enough. For example, strong secrets are difficult to remember, and people tend to share authentication credentials across systems, which reduce the overall security tremendously. Thus, for security sensitive environment we need strong multi-factors authentication. Smart card based certificate strong authentication solution can be used as a replacement for standard password-based schemes. And also a large existing base of deployed smart cards used to provide authentication in other areas can be reused to reduce costs significantly. This master thesis presents a study of how to implement certificate-based strong authentication on mobile devices using PIV smart card. It proposes a strong authentication protocol based on FIPS 201 Personal Identity verification standard, and FIPS 196 entity strong authentication protocol scheme, and describes the implementation of a mobile security application developed on iOS system using a smart card reader. Our solution can provide high level of security services for mobile applications, and can easily protect their confidentiality, integrity and authenticity. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-128418Trita-ICT-EX ; 2013:120application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
topic Mobile Applications Security
Strong Authentication
Smart Card
spellingShingle Mobile Applications Security
Strong Authentication
Smart Card
Kunning, Mao
Strong Authentication Protocol using PIV Card with Mobile Devices
description Nowadays weak single-factor authentication mechanisms like passwords or passphrases are commonly used. Static passwords are easy to use, just remember them in mind. However it has many security weaknesses and even strong passwords are not strong enough. For example, strong secrets are difficult to remember, and people tend to share authentication credentials across systems, which reduce the overall security tremendously. Thus, for security sensitive environment we need strong multi-factors authentication. Smart card based certificate strong authentication solution can be used as a replacement for standard password-based schemes. And also a large existing base of deployed smart cards used to provide authentication in other areas can be reused to reduce costs significantly. This master thesis presents a study of how to implement certificate-based strong authentication on mobile devices using PIV smart card. It proposes a strong authentication protocol based on FIPS 201 Personal Identity verification standard, and FIPS 196 entity strong authentication protocol scheme, and describes the implementation of a mobile security application developed on iOS system using a smart card reader. Our solution can provide high level of security services for mobile applications, and can easily protect their confidentiality, integrity and authenticity.
author Kunning, Mao
author_facet Kunning, Mao
author_sort Kunning, Mao
title Strong Authentication Protocol using PIV Card with Mobile Devices
title_short Strong Authentication Protocol using PIV Card with Mobile Devices
title_full Strong Authentication Protocol using PIV Card with Mobile Devices
title_fullStr Strong Authentication Protocol using PIV Card with Mobile Devices
title_full_unstemmed Strong Authentication Protocol using PIV Card with Mobile Devices
title_sort strong authentication protocol using piv card with mobile devices
publisher KTH, Skolan för informations- och kommunikationsteknik (ICT)
publishDate 2013
url http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-128418
work_keys_str_mv AT kunningmao strongauthenticationprotocolusingpivcardwithmobiledevices
_version_ 1716597185220444160