FIDO: LE FUTUR DE
L’AUTHENTIFICATION ?
23 Mars 2017
SAFRAN IDENTITY AND SECURITY RESTRICTED
SAFRAN IDENTITY AND SECURITY
Safran Identity and Security / 15-07-2016 / Direction2
R&D
Investment equal to nearly
7%
of revenue
Workforce
8,700+
EMPLOYEES
in 57
COUNTRIES
€1.9 BILLION
of revenue
#1
worldwide in biometric
IDENTITY
SOLUTIONS
(fingerprint, iris and face)
Systems deployed in
MORE THAN
100 COUNTRIES
A GLOBAL LEADER
IN IDENTITY
AND SECURITY
SAFRAN IDENTITY AND SECURITY RESTRICTED
Intro
Safran Identity & Security / 23 Mars 20173
1. FIDO en bref
2. Les cas d’usages FIDO UAF, U2F, 2.0
SAFRAN IDENTITY AND SECURITY RESTRICTED
Safran Identity & Security / 23 Mars 20174
FIDO EN BREF
1
SAFRAN IDENTITY AND SECURITY RESTRICTED
The FIDO Alliance is an open industry
association of over 250 organizations
with a focused mission:
authentication standards
5
All Rights Reserved | FIDO Alliance | Copyright 2017.
SAFRAN IDENTITY AND SECURITY RESTRICTED
FIDO Alliance Mission
Develop
Specifications
Operate
Adoption Programs
Pursue Formal
Standardization
1 2 3
define an open, scalable, interoperable set of
mechanisms that supplant reliance on passwords
to authenticate users of online services
All Rights Reserved | FIDO Alliance | Copyright 2017.
SAFRAN IDENTITY AND SECURITY RESTRICTED
Board Members
7
All Rights Reserved | FIDO Alliance | Copyright 2017.
SAFRAN IDENTITY AND SECURITY RESTRICTED
HOW “Shared Secrets” WORK
ONLINE
The user authenticates themselves online
by presenting a human-readable “shared
secret”
All Rights Reserved | FIDO Alliance | Copyright 2017.
SAFRAN IDENTITY AND SECURITY RESTRICTED
HOW FIDO WORKS
AUTHENTICATOR
LOCAL ONLINE
The user authenticates
“locally” to their device (by
various means)
The device authenticates the
user online using public key
cryptography
All Rights Reserved | FIDO Alliance | Copyright 2017.
SAFRAN IDENTITY AND SECURITY RESTRICTED
No 3rd Party in the Protocol
No Secrets on the Server Side
Biometric Data (if used) Never Leaves Device
No (*new*) Link-ability Between Services
No (*new*) Link-ability Between Accounts
All Rights Reserved | FIDO Alliance | Copyright 2017.
SAFRAN IDENTITY AND SECURITY RESTRICTED
Certification Growth
 An open competitive market
 Ensures interoperability
 Sign of mature FIDO ecosystem
250+
FIDO® Certified
products available
today
230
74
32
62
74
108
162
216
253
304
Apr-15 Jul-15 Sep-15 Dec-15 Mar-16 May-16 Aug-16 Jan-17
TOTAL
11
All Rights Reserved | FIDO Alliance | Copyright 2017.
SAFRAN IDENTITY AND SECURITY RESTRICTED
Safran Identity & Security / 23 Mars 201712
LES CAS D’USAGE
FIDO UAF
FIDO U2F
FIDO 2.0
2
SAFRAN IDENTITY AND SECURITY RESTRICTED
UAF (Universal Authentication Framework)
• Specifications
• V1.0 : Final
• V1.1 : implementation draft
U2F (Universal Second Factor)
• Specifications
• V1.0 : Final
• V1.1 : implementation draft
FIDO 2.0 (ex UFS)
• Technical improvement
• CTAP : interfaces with Authenticator
• WebAuthn : Browser API defined by W3C
• Specifications
• Draft
FIDO Specifications
13
SAFRAN IDENTITY AND SECURITY RESTRICTED
ATTENTION : FIDO = AUTHENTIFICATION (et non identité)
14
=
(site.com)
jdoe ->
Phase 1: l’enregistrement Phase 2: l’authentification
01001…
10110…
SAFRAN IDENTITY AND SECURITY RESTRICTED
A Fido Server is the backend service that cryptographically authenticate an application
user through a FIDO authenticator.
Main features
• Compliance with FIDO protocol (U2F/UAF/Fido 2.0)
• Authenticator policy management
• API with the user Agent (Registration)
FIDO Server
Safran Identity & Security / 23 Mars 201715
SAFRAN IDENTITY AND SECURITY RESTRICTED
FIDO Standard : Compatibility Aspects
U2F
FIDO “Gold”
Server
FIDO2
FIDO2
FIDO2
UAF
U2F
Interoperability
still to finalize
Roaming Authenticator
through CTAP
bound
authenticator
WebAuthn/U2F
U2F JS API
UAF JS API
UAF
WebAuthn/CTAP
Safran Identity & Security / 23 Mars 201716
SAFRAN IDENTITY AND SECURITY RESTRICTED
Fido 2.0 (WebAuthn + CTAP)
Safran Identity & Security / 23 Mars 201719
IDP
User Device
Browser
Roaming
Authenticators
with transport
channels and
CTAP payload
Relying Party
WebApplication
FIDO
Server
HTTPS
Registration,
Authentication &
Transaction
Confirmation
FIDO
Alliance
Metadata
Service
BLE USB NFC
Mobile Apps
OS
Bound
authenticators
SAFRAN IDENTITY AND SECURITY RESTRICTED
• Technical:
• UAF: decreasing to almost stalled activity, trying to bring keystore as level 2 authenticators and bridging to WebAuthn
• U2F: most of the work bridging to WebAuthn
• CTAP: stalled waiting for a final status on WebAuthn
• Related: WebAuthn very active development effort on Chrome, Edge and Mozilla
• Working Groups
• SRWG: Move initial levels 1=>4 to 2=>5 with an initial level for compliance and high level security overview (include
software and TouchID authenticators)
• CWG: Continue the biometric certification without PAD, rely upon TEE certification levels for 2+ levels
• P3WG: Influence US NIST, EU for identity and banking standards
Status update
Safran Identity & Security / 23 Mars 201720
SAFRAN IDENTITY AND SECURITY RESTRICTED
Safran Identity & Security / 23 Mars 201721

More Related Content

PPTX
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
PDF
FIDO Technical Specifications Overview
PDF
Web Authentication API
PDF
FIDO Authentication & Blockchain
PDF
Implementation Case Study by eWBM
PDF
FIDO U2F & UAF Tutorial
PDF
FIDO Specifications Overview: UAF & U2F
PDF
NIST 800-63 Guidance & FIDO Authentication
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
FIDO Technical Specifications Overview
Web Authentication API
FIDO Authentication & Blockchain
Implementation Case Study by eWBM
FIDO U2F & UAF Tutorial
FIDO Specifications Overview: UAF & U2F
NIST 800-63 Guidance & FIDO Authentication

What's hot (20)

PPTX
Getting to Know the FIDO Specifications - Technical Tutorial
PPTX
Technical Considerations for Deploying FIDO Authentication
PPTX
FIDO and Strong Authentication in US Federal Government
PDF
Integrating FIDO Authentication & Federation Protocols
PDF
FIDO UAF Specifications: Overview & Tutorial
PDF
FIDO2 & Microsoft
PDF
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
PPTX
FIDOAlliance
PPTX
UAF Tutorial: Passwordless, Biometric Authentication for Native Apps
PDF
FIDO in Government
PPTX
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
PPTX
FIDO Specifications Overview
PDF
CIS14: An Overview of FIDO's Universal Factor (UAF) Specifications
PDF
FIDO Specifications Tutorial
PDF
FIDO UAF 1.0 Specs: Overview and Insights
PPTX
U2F/FIDO2 implementation of YubiKey
PDF
Google & FIDO Authentication
PPTX
FIDO Certification
PPTX
Introduction to FIDO Alliance: Vision and Status -Tokyo Seminar -Brett McDowell
PDF
FIDO alliance #idcon vol.18
Getting to Know the FIDO Specifications - Technical Tutorial
Technical Considerations for Deploying FIDO Authentication
FIDO and Strong Authentication in US Federal Government
Integrating FIDO Authentication & Federation Protocols
FIDO UAF Specifications: Overview & Tutorial
FIDO2 & Microsoft
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDOAlliance
UAF Tutorial: Passwordless, Biometric Authentication for Native Apps
FIDO in Government
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
FIDO Specifications Overview
CIS14: An Overview of FIDO's Universal Factor (UAF) Specifications
FIDO Specifications Tutorial
FIDO UAF 1.0 Specs: Overview and Insights
U2F/FIDO2 implementation of YubiKey
Google & FIDO Authentication
FIDO Certification
Introduction to FIDO Alliance: Vision and Status -Tokyo Seminar -Brett McDowell
FIDO alliance #idcon vol.18
Ad

Viewers also liked (13)

PDF
OAuth and REST web services
PPT
Importancia de las economias asiaticas y relaciones con el peru
PPTX
Archivio139
PDF
FIDO, Strong Authentication and elD in Germany
PDF
Dragões alados (dragon flyz) teoria de tudo
ODT
Bus 475 capstone final exam new 2016 part 1
ODT
Bus 475 capstone final examination part 2 new 2016
ODT
Bus 475 final exam new 2016 phoenix
ODT
Mkt 421 final exam 2016
DOCX
PDF
Hacking Health Halifax 2017 Pitching
DOC
PDF
保持積極的思想 - Keep your thoughts positive
OAuth and REST web services
Importancia de las economias asiaticas y relaciones con el peru
Archivio139
FIDO, Strong Authentication and elD in Germany
Dragões alados (dragon flyz) teoria de tudo
Bus 475 capstone final exam new 2016 part 1
Bus 475 capstone final examination part 2 new 2016
Bus 475 final exam new 2016 phoenix
Mkt 421 final exam 2016
Hacking Health Halifax 2017 Pitching
保持積極的思想 - Keep your thoughts positive
Ad

Similar to Identity Tech Talks #3 FIDO futur of authentication (20)

PPTX
Introduction to FIDO: A New Model for Authentication
PDF
Introduction to the FIDO Alliance
PPTX
Introduction to the FIDO Alliance: Vision and Status
PPTX
FIDO - The Value of Membership
PDF
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
PDF
Introduction to FIDO Authentication
PDF
Tokyo Seminar: FIDO Alliance Vision and Status
PPTX
Introduction to the FIDO Alliance: Vision & Status
PPTX
Introduction to FIDO Alliance
PDF
Fido uaf-overview-v1.1-rd-20161005
PDF
Beyond Passwords: FIDO & the Future of Consumer Authentication
PDF
Introduction to FIDO Alliance
PPTX
FIDO Alliance Vision and Updates
PDF
2018 12-07 tokyo-seminar Brett McDowell
PDF
FIDO Alliance Vision and Status
PDF
Introduction to the FIDO Alliance
PDF
FIDO Authentication Technical Overview
PDF
FIDO Authentication Technical Overview
PDF
Technical Principles of FIDO Authentication
PDF
Technical Principles of FIDO Authentication
Introduction to FIDO: A New Model for Authentication
Introduction to the FIDO Alliance
Introduction to the FIDO Alliance: Vision and Status
FIDO - The Value of Membership
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
Introduction to FIDO Authentication
Tokyo Seminar: FIDO Alliance Vision and Status
Introduction to the FIDO Alliance: Vision & Status
Introduction to FIDO Alliance
Fido uaf-overview-v1.1-rd-20161005
Beyond Passwords: FIDO & the Future of Consumer Authentication
Introduction to FIDO Alliance
FIDO Alliance Vision and Updates
2018 12-07 tokyo-seminar Brett McDowell
FIDO Alliance Vision and Status
Introduction to the FIDO Alliance
FIDO Authentication Technical Overview
FIDO Authentication Technical Overview
Technical Principles of FIDO Authentication
Technical Principles of FIDO Authentication

More from Leonard Moustacchis (20)

PDF
Identity verification and AI
PDF
De la bonne utilisation de OAuth2
PDF
WebAuthn & FIDO2
PDF
Facebook data breach and OAuth2
PDF
Identity techtalk orange
PPTX
Intelligent authentication Identity tech talks
PDF
Blockchain et ses cas d'usages - Identity Tech Talk#10
PDF
iProov et Biométrie Identity Tech Talk #10
PDF
Microservice et identité
PDF
Évènement 01 Business - GDPR, confiance et confidentialité des données, défi ...
PDF
201707 dsp2 standards, sécurité, quels impacts - wavestone
PDF
Identité et Automobile
PDF
Meetup devops
PDF
Quels sont les enjeux de la réglementation GDPR
PDF
Présentation de UMA (User Managed Access)
PDF
Mon Raspberry PI a une identité !
PDF
Comment ça marche: OpenID Connect fournisseur d’identité universel de Google ...
PDF
Pas d'IoT sans Identité!
PDF
Valorisez votre écosystème d'identités
PDF
L’identité numérique : un atout incontournable pour construire une relation c...
Identity verification and AI
De la bonne utilisation de OAuth2
WebAuthn & FIDO2
Facebook data breach and OAuth2
Identity techtalk orange
Intelligent authentication Identity tech talks
Blockchain et ses cas d'usages - Identity Tech Talk#10
iProov et Biométrie Identity Tech Talk #10
Microservice et identité
Évènement 01 Business - GDPR, confiance et confidentialité des données, défi ...
201707 dsp2 standards, sécurité, quels impacts - wavestone
Identité et Automobile
Meetup devops
Quels sont les enjeux de la réglementation GDPR
Présentation de UMA (User Managed Access)
Mon Raspberry PI a une identité !
Comment ça marche: OpenID Connect fournisseur d’identité universel de Google ...
Pas d'IoT sans Identité!
Valorisez votre écosystème d'identités
L’identité numérique : un atout incontournable pour construire une relation c...

Recently uploaded (20)

PPTX
Database Information System - Management Information System
PDF
Exploring The Internet Of Things(IOT).ppt
PPTX
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
PDF
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
PPTX
Introduction to cybersecurity and digital nettiquette
PDF
Understand the Gitlab_presentation_task.pdf
PDF
Alethe Consulting Corporate Profile and Solution Aproach
PPTX
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
PDF
Containerization lab dddddddddddddddmanual.pdf
PPTX
TITLE DEFENSE entitle the impact of social media on education
PPTX
t_and_OpenAI_Combined_two_pressentations
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PPT
12 Things That Make People Trust a Website Instantly
DOCX
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
PPTX
IPCNA VIRTUAL CLASSES INTERMEDIATE 6 PROJECT.pptx
PDF
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf
PDF
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
PPTX
Reading as a good Form of Recreation
PPTX
The-Importance-of-School-Sanitation.pptx
PDF
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
Database Information System - Management Information System
Exploring The Internet Of Things(IOT).ppt
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
Introduction to cybersecurity and digital nettiquette
Understand the Gitlab_presentation_task.pdf
Alethe Consulting Corporate Profile and Solution Aproach
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
Containerization lab dddddddddddddddmanual.pdf
TITLE DEFENSE entitle the impact of social media on education
t_and_OpenAI_Combined_two_pressentations
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
12 Things That Make People Trust a Website Instantly
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
IPCNA VIRTUAL CLASSES INTERMEDIATE 6 PROJECT.pptx
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
Reading as a good Form of Recreation
The-Importance-of-School-Sanitation.pptx
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf

Identity Tech Talks #3 FIDO futur of authentication

  • 1. FIDO: LE FUTUR DE L’AUTHENTIFICATION ? 23 Mars 2017
  • 2. SAFRAN IDENTITY AND SECURITY RESTRICTED SAFRAN IDENTITY AND SECURITY Safran Identity and Security / 15-07-2016 / Direction2 R&D Investment equal to nearly 7% of revenue Workforce 8,700+ EMPLOYEES in 57 COUNTRIES €1.9 BILLION of revenue #1 worldwide in biometric IDENTITY SOLUTIONS (fingerprint, iris and face) Systems deployed in MORE THAN 100 COUNTRIES A GLOBAL LEADER IN IDENTITY AND SECURITY
  • 3. SAFRAN IDENTITY AND SECURITY RESTRICTED Intro Safran Identity & Security / 23 Mars 20173 1. FIDO en bref 2. Les cas d’usages FIDO UAF, U2F, 2.0
  • 4. SAFRAN IDENTITY AND SECURITY RESTRICTED Safran Identity & Security / 23 Mars 20174 FIDO EN BREF 1
  • 5. SAFRAN IDENTITY AND SECURITY RESTRICTED The FIDO Alliance is an open industry association of over 250 organizations with a focused mission: authentication standards 5 All Rights Reserved | FIDO Alliance | Copyright 2017.
  • 6. SAFRAN IDENTITY AND SECURITY RESTRICTED FIDO Alliance Mission Develop Specifications Operate Adoption Programs Pursue Formal Standardization 1 2 3 define an open, scalable, interoperable set of mechanisms that supplant reliance on passwords to authenticate users of online services All Rights Reserved | FIDO Alliance | Copyright 2017.
  • 7. SAFRAN IDENTITY AND SECURITY RESTRICTED Board Members 7 All Rights Reserved | FIDO Alliance | Copyright 2017.
  • 8. SAFRAN IDENTITY AND SECURITY RESTRICTED HOW “Shared Secrets” WORK ONLINE The user authenticates themselves online by presenting a human-readable “shared secret” All Rights Reserved | FIDO Alliance | Copyright 2017.
  • 9. SAFRAN IDENTITY AND SECURITY RESTRICTED HOW FIDO WORKS AUTHENTICATOR LOCAL ONLINE The user authenticates “locally” to their device (by various means) The device authenticates the user online using public key cryptography All Rights Reserved | FIDO Alliance | Copyright 2017.
  • 10. SAFRAN IDENTITY AND SECURITY RESTRICTED No 3rd Party in the Protocol No Secrets on the Server Side Biometric Data (if used) Never Leaves Device No (*new*) Link-ability Between Services No (*new*) Link-ability Between Accounts All Rights Reserved | FIDO Alliance | Copyright 2017.
  • 11. SAFRAN IDENTITY AND SECURITY RESTRICTED Certification Growth  An open competitive market  Ensures interoperability  Sign of mature FIDO ecosystem 250+ FIDO® Certified products available today 230 74 32 62 74 108 162 216 253 304 Apr-15 Jul-15 Sep-15 Dec-15 Mar-16 May-16 Aug-16 Jan-17 TOTAL 11 All Rights Reserved | FIDO Alliance | Copyright 2017.
  • 12. SAFRAN IDENTITY AND SECURITY RESTRICTED Safran Identity & Security / 23 Mars 201712 LES CAS D’USAGE FIDO UAF FIDO U2F FIDO 2.0 2
  • 13. SAFRAN IDENTITY AND SECURITY RESTRICTED UAF (Universal Authentication Framework) • Specifications • V1.0 : Final • V1.1 : implementation draft U2F (Universal Second Factor) • Specifications • V1.0 : Final • V1.1 : implementation draft FIDO 2.0 (ex UFS) • Technical improvement • CTAP : interfaces with Authenticator • WebAuthn : Browser API defined by W3C • Specifications • Draft FIDO Specifications 13
  • 14. SAFRAN IDENTITY AND SECURITY RESTRICTED ATTENTION : FIDO = AUTHENTIFICATION (et non identité) 14 = (site.com) jdoe -> Phase 1: l’enregistrement Phase 2: l’authentification 01001… 10110…
  • 15. SAFRAN IDENTITY AND SECURITY RESTRICTED A Fido Server is the backend service that cryptographically authenticate an application user through a FIDO authenticator. Main features • Compliance with FIDO protocol (U2F/UAF/Fido 2.0) • Authenticator policy management • API with the user Agent (Registration) FIDO Server Safran Identity & Security / 23 Mars 201715
  • 16. SAFRAN IDENTITY AND SECURITY RESTRICTED FIDO Standard : Compatibility Aspects U2F FIDO “Gold” Server FIDO2 FIDO2 FIDO2 UAF U2F Interoperability still to finalize Roaming Authenticator through CTAP bound authenticator WebAuthn/U2F U2F JS API UAF JS API UAF WebAuthn/CTAP Safran Identity & Security / 23 Mars 201716
  • 17. SAFRAN IDENTITY AND SECURITY RESTRICTED Fido 2.0 (WebAuthn + CTAP) Safran Identity & Security / 23 Mars 201719 IDP User Device Browser Roaming Authenticators with transport channels and CTAP payload Relying Party WebApplication FIDO Server HTTPS Registration, Authentication & Transaction Confirmation FIDO Alliance Metadata Service BLE USB NFC Mobile Apps OS Bound authenticators
  • 18. SAFRAN IDENTITY AND SECURITY RESTRICTED • Technical: • UAF: decreasing to almost stalled activity, trying to bring keystore as level 2 authenticators and bridging to WebAuthn • U2F: most of the work bridging to WebAuthn • CTAP: stalled waiting for a final status on WebAuthn • Related: WebAuthn very active development effort on Chrome, Edge and Mozilla • Working Groups • SRWG: Move initial levels 1=>4 to 2=>5 with an initial level for compliance and high level security overview (include software and TouchID authenticators) • CWG: Continue the biometric certification without PAD, rely upon TEE certification levels for 2+ levels • P3WG: Influence US NIST, EU for identity and banking standards Status update Safran Identity & Security / 23 Mars 201720
  • 19. SAFRAN IDENTITY AND SECURITY RESTRICTED Safran Identity & Security / 23 Mars 201721