Hitoshi Kokumai

3年前 · 1 分の読書時間 · 0 ·

ブログ作成
>
ブログ Hitoshi
>
Digital Identity - ‘Physical Tokens’ vs ‘Onetime Password Messaging’

Digital Identity - ‘Physical Tokens’ vs ‘Onetime Password Messaging’

2 Channel Expanded Password System

Question: Which proposition do you think is better as the second factor of 2-factor authentications?

Answer: All depend on where you see the better balance between security and convenience for each use case.

We could see a merit of physical tokens or hardware keys as against OTP messaging that is relatively more vulnerable in the online environment, but we could also see its demerit ; When we have dozens of accounts to protect, would we have to carry around a big bunch of hardware keys which could physically catch a quick eye of bad guys or would we have to re-use one or a few hardware keys across many accounts, physically creating a single point of failure?

In order to overcome this conflict, we came up with our own proposition of 2-channel/2-factor authentication for achieving an optimal balance between security and convenience at a higher level, which was implemented for a corporate network 6 years ago and is still running.

Click the link for more

https://www.linkedin.com/pulse/advanced-persistent-threats-digital-identity-hitoshi-kokumai/


Excerpt:  Our proposition of 2-channel authentication could help. 

 With our 2-channel scheme, the onetime code can be recovered and sent to the server only by the legitimate user who retains the secret credential in their brain.

 Further details are provided in this slide “2-Channel Authentication with No Physical Tokens and No SMS” for the specifics.

 It is also referred to as a powerful phishing deterrent in “Targeted/Spear Phishing and Expanded Password System”

 By the way, this 2-channel scheme is not just a concept, but was actually implemented in the real world for corporate use. 


コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

I got interested in this article -on the password problem · “Tech Q&A” · https://www.unionleader.c ...

2年前 · 2 分の読書時間

Bad guys, who have a quantum computer at hand, would still have to break the part of user authentica ...

2年前 · 2 分の読書時間

Some friends directed my attention to this news report - · “Biometric auth bypassed using fingerpri ...

この職種に興味がある方はこちら

  • 共栄ドラッグストア

    レジ販売スタッフ

    次の場所にあります: Whatjobs JP C2 - 2日前


    共栄ドラッグストア Osaka, 日本

    **共栄ドラッグストア** · **【レジ販売スタッフ】大人気の梅田エリアでのお仕事。話題のコスメや日用品をオトクな社員割引で買えます。** · (応募可能期間 :2024/02/16 ~ 2030/12/31) · **・給与** · アルバイト:時給1,100円 · **・職種** · レジ販売スタッフ · **・勤務地** · 大阪府大阪市北区芝田1-1-3 阪急三番街 南館 B1F · **・こだわり条件** · 交通費支給 · 学生・フリーター歓迎 · 未経験者歓迎 · 週3日以内 · ‐‐‐‐‐‐‐‐‐‐ · 勤務地は阪急三番街なので、出勤前 ...

  • Siemens K.K. - Industry Software

    Customer Success Manager

    次の場所にあります: Talent JP C2 - 4日前


    Siemens K.K. - Industry Software Tokyo, 日本 Permanent

    Siemens Digital Industries Software is a leading provider of solutions for the design, simulation, and manufacture of products across many different industries. Formula 1 cars, skyscrapers, ships, space exploration vehicles, and many of the objects we see in our daily lives are b ...

  • ヒューマンリソシア株式会社

    赤十字血液センターで採血補助

    次の場所にあります: Whatjobs JP C2 - 2日前


    ヒューマンリソシア株式会社 Tokyo, 日本

    **【未経験OK☆秋葉原駅スグ1分♪】赤十字血液センターで採血補助**: · **職種:**看護助手、その他助手 · **時給:**1,500円 · **勤務予定地:**東京都千代田区 · **最寄駅:** · JR山手線秋葉原駅 / 徒歩1分 · 東京メトロ日比谷線秋葉原駅 / 徒歩1分 · 都営地下鉄新宿線小川町(東京)駅 / 徒歩10分 · **時間:**08時30分~17時00分 / 月火水木金土日祝 / 土曜出勤:就業先カレンダーによる · **期間:**長期 · **特徴:**未経験OK / 制服有り / 駅近 / 急募 / 禁煙 / ワード ...