FIDO, the password and Live Ensure®
FIDO aims to leverage hardware devices such
as phones and tablets as well as fingerprint readers, webcams, TPM ( Trusted Platform Module) chips and
tokens into an open-standard whereby there will be inter-operability between
different systems but which comply to the standard. A client/server architecture in combination with some
hardware fingerprint starts to approach a much more secure approach than the
exchange of self reported credentials.
The creation of a global repository and
browser based plug-in (a la
certificate authority) is IMO a potential weakness in the model. Who will be the custodian of this
information and who will ensure it is updated. ? The graphic
below provides an overview of the approach.
Some of the key elements of FIDO are
already embodied in the architecture of Live Ensure® (LiveEnsure)
the Cloud based authentication solution that leverages the user’s smart-phones
to provide contextual validation without the use of passwords. Live Ensure® has already created the key elements of what FIDO is setting out to
achieve.
Live Ensure® achieves the following :
·
Passwordless authentication = like FIDO
·
Leveraging existing device (smartphone)
≠ FIDO (requires tokens)
·
Rapid scalability (Cloud
Service) ≈ FIDO (except for token
distribution)
·
Triangulated architecture =
FIDO
Live Ensure® embraces a new approach to authentication and endorses any efforts
in the direction of making the end user experience better. If this can be done while
achieving stronger security so much the better. Live
Ensure® intends to engage with the FIDO Alliance to
make a contribution to this important effort in simplifying and strengthening
end-user log-in security.
Comments
Post a Comment