SlideShare a Scribd company logo
All Rights Reserved | FIDO Alliance | Copyright 20171
NEOWAVE + TRUSTELEM
PROTECTING IDAAS*
(WEB/CLOUD SSO*)
WITH FIDO U2F
* IDAAS: IDENTITY AS A SERVICE
SSO: SINGLE SIGN ON
All Rights Reserved | FIDO Alliance | Copyright 20172
Deployment Case Study: Trustelem & Neowave
Protecting IDAAS with FIDO U2F
Gregory Haรฏk, CEO, Trustelem
Frederic Martin, Security Architect, NEOWAVE
All Rights Reserved | FIDO Alliance | Copyright 20173
FIDO U2F TO PROTECT IDENTITY AS A SERVICE
All Rights Reserved | FIDO Alliance | Copyright 20174
NEOWAVE: SMART CARD BASED SECURITY
PRODUCTS
NEOWAVE mission is to address these issues through strong authentication, encryption and digital
signatures based on secure smart card based products.
Identity theft (phishing), fraud, data theft and cyber attacks are on the rise
All Rights Reserved | FIDO Alliance | Copyright 20175
EASY PHISHING ATTACKS AGAINST
SMS CODES
User Real website
username
password
SMS
username
password
SMS
Send SMS3
1
4 5
2
Fake website
or MITM attack
All Rights Reserved | FIDO Alliance | Copyright 20176
EASY PHISHING ATTACKS AGAINST
OTP / TOTP
username
password
OTP
username
password
OTP
OTP generator2
1
3 5
4
User Real websiteFake website
or MITM attack
All Rights Reserved | FIDO Alliance | Copyright 20177
EASY PHISHING ATTACKS AGAINST
SCANNED QR CODE VALIDATION
User Real websiteFake website
or MITM attack
Give access
Read QR Code
2
3
1
Validate (wrong) access4
5
All Rights Reserved | FIDO Alliance | Copyright 20178
FIDO U2F: SIMPLE / SECURE SOLUTION
AGAINST PHISHING ATTACKS
2 โ€“ Data to be signed
(challenge, hashed url, etc.)
4 โ€“ Signed Data
3 โ€“ Digital Signature
(built-in smart card)
6 โ€“ Signature
Verification
1 โ€“ Data to be signed
(challenge, hashed url, etc.)
5 โ€“ Signed Data
SSL Token Binding
MITM protection
All Rights Reserved | FIDO Alliance | Copyright 20179
FIDO U2F USB SECURITY KEY
PLUG KEYDO
SECURITY KEY IN
ENTER USERNAME
& PASSWORD
THATโ€™S IT
All Rights Reserved | FIDO Alliance | Copyright 201710
FIDO U2F NFC CARD
APPROACH
BADGEO NFC CARD
THATโ€™S IT
ENTER USERNAME
& PASSWORD
All Rights Reserved | FIDO Alliance | Copyright 201711
TRUSTELEM: IDENTITY AS A SERVICE
Company
Corporate applications
Trustelem enables your IT users to go from
one application to another, without the need to
re-authenticate.
Trustelem manages digital identities of your
IT users (IDaaS - Identity-as-a-Service Cloud
Single Sign-On, SSO).
All Rights Reserved | FIDO Alliance | Copyright 201712
FIDO U2F ADVANTAGES FOR WEB SSO LOGON
โ€ข No driver installation requirement
โ€ข Web browser built-in support
โ€ข Multi-platform / multi-channel protocol
โ€ข High security level (built-in smart card)
โ€ข Ultimate solution against identity theft
All Rights Reserved | FIDO Alliance | Copyright 201713
SIMPLE /SECURE WEB SSO LOGON
Password then
FIDO U2F
All Rights Reserved | FIDO Alliance | Copyright 201714
ALL-IN-ONE USER DASHBOARDS ACCESS
PROTECTION
Now you donโ€™t have to
wait for Microsoft to
integrate FIDO U2F
authentication :)
All Rights Reserved | FIDO Alliance | Copyright 201715
APPLICATIONS ACCESS
e.g. facebook workplace
All Rights Reserved | FIDO Alliance | Copyright 201716
ADMIN CONSOLE
Setup directories, users,
apps, permissionsโ€ฆ
Logs, deployment audit
All Rights Reserved | FIDO Alliance | Copyright 201717
MORE FIDO U2F ADVANTAGES
โ€ข FIDO U2F devices are anonymous (no user
information, just anonymous keys, association
is done on the server side)
โ€ข FIDO U2F devices can be filtered, web
services can be locked only for our own
customized devices (attestation certificate)
All Rights Reserved | FIDO Alliance | Copyright 201718
CONCLUSION
โ€ข FIDO U2F strongly recommended
for Web SSO users and/or administrators
โ€ข Secure but easy to use and deploy

More Related Content

PPTX
Introduction to FIDO: A New Model for Authentication
PDF
NTT DOCOMO Deployment Case Study
PDF
Introduction to the FIDO Alliance
PDF
FIDO Authentication in Europe the Momentum and Opportunities
PDF
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
PPTX
FIDO & GSMA Mobile Connect
PDF
The Value of FIDO Alliance Membership
PDF
FIDO and the Future of User Authentication
Introduction to FIDO: A New Model for Authentication
NTT DOCOMO Deployment Case Study
Introduction to the FIDO Alliance
FIDO Authentication in Europe the Momentum and Opportunities
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
FIDO & GSMA Mobile Connect
The Value of FIDO Alliance Membership
FIDO and the Future of User Authentication

What's hot (20)

PPTX
Google Case Sudy: Becoming Unphishable: Towards Simpler, Stronger Authenticaton
PPTX
FIDO Masterclass
PDF
Microsoft's Path to Passwordless - FIDO Authentication for Windows & Azure Ac...
PDF
Introduction to FIDO Authentication
PDF
Deployment Case Study: Login.gov & FIDO2
PPTX
Google Case Study: Becoming Unphishable
PDF
Integrating FIDO & Federation Protocols
PDF
FIDO Authentication and GSMA Mobile Connect
PDF
Google Case Study: Strong Authentication for Employees and Consumers
PPTX
Fido Technical Overview
PDF
Google Case Sudy: Becoming Unphishable: Towards Simpler, Stronger Authenticaton
PDF
Authentication and ID Proofing in Education
PPTX
FIDO and Mobile Connect
PDF
FIDO Alliance Vision and Status
PPTX
Fido China Working Group (FCWG)
PPTX
FIDO Specifications Overview
PPTX
FIDO Authentication: Unphishable MFA for All
PPTX
Introduction to the FIDO Alliance: Vision & Status
PDF
Modern Authentication for a Connected World
PPTX
FIDO - The Value of Membership
Google Case Sudy: Becoming Unphishable: Towards Simpler, Stronger Authenticaton
FIDO Masterclass
Microsoft's Path to Passwordless - FIDO Authentication for Windows & Azure Ac...
Introduction to FIDO Authentication
Deployment Case Study: Login.gov & FIDO2
Google Case Study: Becoming Unphishable
Integrating FIDO & Federation Protocols
FIDO Authentication and GSMA Mobile Connect
Google Case Study: Strong Authentication for Employees and Consumers
Fido Technical Overview
Google Case Sudy: Becoming Unphishable: Towards Simpler, Stronger Authenticaton
Authentication and ID Proofing in Education
FIDO and Mobile Connect
FIDO Alliance Vision and Status
Fido China Working Group (FCWG)
FIDO Specifications Overview
FIDO Authentication: Unphishable MFA for All
Introduction to the FIDO Alliance: Vision & Status
Modern Authentication for a Connected World
FIDO - The Value of Membership
Ad

Viewers also liked (11)

PPTX
Introduction to FIDO Alliance
PDF
FIDO Authentication for Multifactor Payments
PDF
NIST 800-63 Guidance & FIDO Authentication
PDF
FIDO Authentication & Blockchain
PDF
FIDO Certified Program: Status & Futures
PDF
FIDO Authentication Opportunities in Healthcare
PDF
Strong Authentication and US Federal Digital Services
PDF
FIDO Technical Specifications Overview
PPTX
Getting to Know the FIDO Specifications - Technical Tutorial
PDF
Javelin Research 2017 State of Authentication Report
PDF
FIDO, Federation & Facebook Social Login
Introduction to FIDO Alliance
FIDO Authentication for Multifactor Payments
NIST 800-63 Guidance & FIDO Authentication
FIDO Authentication & Blockchain
FIDO Certified Program: Status & Futures
FIDO Authentication Opportunities in Healthcare
Strong Authentication and US Federal Digital Services
FIDO Technical Specifications Overview
Getting to Know the FIDO Specifications - Technical Tutorial
Javelin Research 2017 State of Authentication Report
FIDO, Federation & Facebook Social Login
Ad

Similar to Protecting IDAAS with FIDO Authentication (20)

PDF
Introduction to the FIDO Alliance
PDF
The Future of Authentication for IoT
PDF
โ€œYour Security, More Simple.โ€ by utilizing FIDO Authentication
PDF
Tokyo Seminar: FIDO Alliance Vision and Status
PDF
FIDO Authentication Technical Overview
PDF
FIDO Authentication Technical Overview
PPTX
The State of Passkeys with FIDO Alliance.pptx
PDF
Beyond Passwords: FIDO and the Future of User Authentication
PDF
Beyond Passwords: FIDO & the Future of Consumer Authentication
PPTX
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
PPTX
Introduction to FIDO Alliance: Vision and Status -Tokyo Seminar -Brett McDowell
PPTX
FIDO Munich Seminar Introduction to FIDO.pptx
PDF
Technical Principles of FIDO Authentication
PDF
Technical Principles of FIDO Authentication
PPTX
FIDO Munich Seminar: FIDO Tech Principles.pptx
PPTX
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
PDF
Using FIDO Authenticator for IoT Devices
PPTX
Intro to Passkeys and the State of Passwordless.pptx
PDF
Introduction to FIDO Biometric Authentication
PDF
Eliminating Passwords with Biometrics for Identity Access Management Webinar
Introduction to the FIDO Alliance
The Future of Authentication for IoT
โ€œYour Security, More Simple.โ€ by utilizing FIDO Authentication
Tokyo Seminar: FIDO Alliance Vision and Status
FIDO Authentication Technical Overview
FIDO Authentication Technical Overview
The State of Passkeys with FIDO Alliance.pptx
Beyond Passwords: FIDO and the Future of User Authentication
Beyond Passwords: FIDO & the Future of Consumer Authentication
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
Introduction to FIDO Alliance: Vision and Status -Tokyo Seminar -Brett McDowell
FIDO Munich Seminar Introduction to FIDO.pptx
Technical Principles of FIDO Authentication
Technical Principles of FIDO Authentication
FIDO Munich Seminar: FIDO Tech Principles.pptx
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
Using FIDO Authenticator for IoT Devices
Intro to Passkeys and the State of Passwordless.pptx
Introduction to FIDO Biometric Authentication
Eliminating Passwords with Biometrics for Identity Access Management Webinar

More from FIDO Alliance (20)

PPTX
Securing Account Lifecycles in the Age of Deepfakes.pptx
PPTX
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
PPTX
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
PPTX
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
PPTX
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
PPTX
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
PPTX
FIDO Alliance Seminar State of Passkeys.pptx
PPTX
FIDO Munich Seminar: Securing Smart Car.pptx
PPTX
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
PPTX
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
PPTX
FIDO Munich Seminar Workforce Authentication Case Study.pptx
PPTX
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
PPTX
FIDO Munich Seminar FIDO Automotive Apps.pptx
PPTX
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
PPTX
UX Webinar Series: Aligning Authentication Experiences with Business Goals
PDF
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
PDF
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
PDF
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
PDF
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
PDF
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
Securing Account Lifecycles in the Age of Deepfakes.pptx
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Munich Seminar: Securing Smart Car.pptx
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
FIDO Munich Seminar Workforce Authentication Case Study.pptx
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
FIDO Munich Seminar FIDO Automotive Apps.pptx
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
UX Webinar Series: Aligning Authentication Experiences with Business Goals
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf

Recently uploaded (20)

PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
ย 
PPTX
Digital Literacy And Online Safety on internet
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PDF
Sims 4 Historia para lo sims 4 para jugar
PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
DOCX
Unit-3 cyber security network security of internet system
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PPTX
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PDF
WebRTC in SignalWire - troubleshooting media negotiation
PDF
๐Ÿ’ฐ ๐”๐Š๐“๐ˆ ๐Š๐„๐Œ๐„๐๐€๐๐†๐€๐ ๐Š๐ˆ๐๐„๐‘๐Ÿ’๐ƒ ๐‡๐€๐‘๐ˆ ๐ˆ๐๐ˆ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ“ ๐Ÿ’ฐ
ย 
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PDF
Cloud-Scale Log Monitoring _ Datadog.pdf
PPTX
Slides PPTX World Game (s) Eco Economic Epochs.pptx
PPTX
artificial intelligence overview of it and more
PDF
The Internet -By the Numbers, Sri Lanka Edition
ย 
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
ย 
PDF
Unit-1 introduction to cyber security discuss about how to secure a system
PDF
Testing WebRTC applications at scale.pdf
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
ย 
Digital Literacy And Online Safety on internet
The New Creative Director: How AI Tools for Social Media Content Creation Are...
Sims 4 Historia para lo sims 4 para jugar
PptxGenJS_Demo_Chart_20250317130215833.pptx
Introuction about ICD -10 and ICD-11 PPT.pptx
Unit-3 cyber security network security of internet system
SASE Traffic Flow - ZTNA Connector-1.pdf
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
Module 1 - Cyber Law and Ethics 101.pptx
WebRTC in SignalWire - troubleshooting media negotiation
๐Ÿ’ฐ ๐”๐Š๐“๐ˆ ๐Š๐„๐Œ๐„๐๐€๐๐†๐€๐ ๐Š๐ˆ๐๐„๐‘๐Ÿ’๐ƒ ๐‡๐€๐‘๐ˆ ๐ˆ๐๐ˆ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ“ ๐Ÿ’ฐ
ย 
Design_with_Watersergyerge45hrbgre4top (1).ppt
Cloud-Scale Log Monitoring _ Datadog.pdf
Slides PPTX World Game (s) Eco Economic Epochs.pptx
artificial intelligence overview of it and more
The Internet -By the Numbers, Sri Lanka Edition
ย 
RPKI Status Update, presented by Makito Lay at IDNOG 10
ย 
Unit-1 introduction to cyber security discuss about how to secure a system
Testing WebRTC applications at scale.pdf

Protecting IDAAS with FIDO Authentication

  • 1. All Rights Reserved | FIDO Alliance | Copyright 20171 NEOWAVE + TRUSTELEM PROTECTING IDAAS* (WEB/CLOUD SSO*) WITH FIDO U2F * IDAAS: IDENTITY AS A SERVICE SSO: SINGLE SIGN ON
  • 2. All Rights Reserved | FIDO Alliance | Copyright 20172 Deployment Case Study: Trustelem & Neowave Protecting IDAAS with FIDO U2F Gregory Haรฏk, CEO, Trustelem Frederic Martin, Security Architect, NEOWAVE
  • 3. All Rights Reserved | FIDO Alliance | Copyright 20173 FIDO U2F TO PROTECT IDENTITY AS A SERVICE
  • 4. All Rights Reserved | FIDO Alliance | Copyright 20174 NEOWAVE: SMART CARD BASED SECURITY PRODUCTS NEOWAVE mission is to address these issues through strong authentication, encryption and digital signatures based on secure smart card based products. Identity theft (phishing), fraud, data theft and cyber attacks are on the rise
  • 5. All Rights Reserved | FIDO Alliance | Copyright 20175 EASY PHISHING ATTACKS AGAINST SMS CODES User Real website username password SMS username password SMS Send SMS3 1 4 5 2 Fake website or MITM attack
  • 6. All Rights Reserved | FIDO Alliance | Copyright 20176 EASY PHISHING ATTACKS AGAINST OTP / TOTP username password OTP username password OTP OTP generator2 1 3 5 4 User Real websiteFake website or MITM attack
  • 7. All Rights Reserved | FIDO Alliance | Copyright 20177 EASY PHISHING ATTACKS AGAINST SCANNED QR CODE VALIDATION User Real websiteFake website or MITM attack Give access Read QR Code 2 3 1 Validate (wrong) access4 5
  • 8. All Rights Reserved | FIDO Alliance | Copyright 20178 FIDO U2F: SIMPLE / SECURE SOLUTION AGAINST PHISHING ATTACKS 2 โ€“ Data to be signed (challenge, hashed url, etc.) 4 โ€“ Signed Data 3 โ€“ Digital Signature (built-in smart card) 6 โ€“ Signature Verification 1 โ€“ Data to be signed (challenge, hashed url, etc.) 5 โ€“ Signed Data SSL Token Binding MITM protection
  • 9. All Rights Reserved | FIDO Alliance | Copyright 20179 FIDO U2F USB SECURITY KEY PLUG KEYDO SECURITY KEY IN ENTER USERNAME & PASSWORD THATโ€™S IT
  • 10. All Rights Reserved | FIDO Alliance | Copyright 201710 FIDO U2F NFC CARD APPROACH BADGEO NFC CARD THATโ€™S IT ENTER USERNAME & PASSWORD
  • 11. All Rights Reserved | FIDO Alliance | Copyright 201711 TRUSTELEM: IDENTITY AS A SERVICE Company Corporate applications Trustelem enables your IT users to go from one application to another, without the need to re-authenticate. Trustelem manages digital identities of your IT users (IDaaS - Identity-as-a-Service Cloud Single Sign-On, SSO).
  • 12. All Rights Reserved | FIDO Alliance | Copyright 201712 FIDO U2F ADVANTAGES FOR WEB SSO LOGON โ€ข No driver installation requirement โ€ข Web browser built-in support โ€ข Multi-platform / multi-channel protocol โ€ข High security level (built-in smart card) โ€ข Ultimate solution against identity theft
  • 13. All Rights Reserved | FIDO Alliance | Copyright 201713 SIMPLE /SECURE WEB SSO LOGON Password then FIDO U2F
  • 14. All Rights Reserved | FIDO Alliance | Copyright 201714 ALL-IN-ONE USER DASHBOARDS ACCESS PROTECTION Now you donโ€™t have to wait for Microsoft to integrate FIDO U2F authentication :)
  • 15. All Rights Reserved | FIDO Alliance | Copyright 201715 APPLICATIONS ACCESS e.g. facebook workplace
  • 16. All Rights Reserved | FIDO Alliance | Copyright 201716 ADMIN CONSOLE Setup directories, users, apps, permissionsโ€ฆ Logs, deployment audit
  • 17. All Rights Reserved | FIDO Alliance | Copyright 201717 MORE FIDO U2F ADVANTAGES โ€ข FIDO U2F devices are anonymous (no user information, just anonymous keys, association is done on the server side) โ€ข FIDO U2F devices can be filtered, web services can be locked only for our own customized devices (attestation certificate)
  • 18. All Rights Reserved | FIDO Alliance | Copyright 201718 CONCLUSION โ€ข FIDO U2F strongly recommended for Web SSO users and/or administrators โ€ข Secure but easy to use and deploy