Revisiting Multi-Factor Authentication Token Cybersecurity: A TLS Identity Module Use Case

Pascal Urien

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Multi-factor authentication (MFA) procedures are widely used by digital systems. There are usually performed by hardware tokens comprising a microcontroller and an USB interface. The security level is increased by computing cryptographic procedures in secure elements such as smartcards. Authenticity of MFA token is a critical topic since hardware or software components may be cloned or modified, for example through supply chain. Due to industrial competition cyber security aspects of MFA token are not generally in the public domain, and therefore somewhat relies on security by obscurity (SbO). In this paper we present an original MFA token built with open hardware (Arduino) and javacard, which realizes a TLS pre-shared-key identity module (TLS-IM). The microcontroller is authenticated by SRAM dynamic PUF features, its software is checked by attestation procedure based on the bijective MAC time stamped algorithm. The javacard application is authenticated by PKI means, and manages a TLS-PSK channel for remote administration.

Original languageEnglish
Title of host publication2024 International Conference on Computing, Networking and Communications, ICNC 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages33-38
Number of pages6
ISBN (Electronic)9798350370997
DOIs
Publication statusPublished - 1 Jan 2024
Externally publishedYes
Event2024 International Conference on Computing, Networking and Communications, ICNC 2024 - Big Island, United States
Duration: 19 Feb 202422 Feb 2024

Publication series

Name2024 International Conference on Computing, Networking and Communications, ICNC 2024

Conference

Conference2024 International Conference on Computing, Networking and Communications, ICNC 2024
Country/TerritoryUnited States
CityBig Island
Period19/02/2422/02/24

Keywords

  • IoSE
  • Secure Element
  • Security
  • TLS

Fingerprint

Dive into the research topics of 'Revisiting Multi-Factor Authentication Token Cybersecurity: A TLS Identity Module Use Case'. Together they form a unique fingerprint.

Cite this