Non-intrusive authentication
Daniele Alberto Galliano, Antonio Lioy, Fabio Maino · 1997
Available security solutions often are not widely used because the associated secure applications are awkward to use or they lack functionality when compared to standard insecure tools. To avoid this dicothomy, we developed a non-intrusive (or external) clientserver authentication framework which requires no modification to both the clients and the servers. In this way, full featured clients can be used to the satisfaction of the user community, and off-the-shelf servers can be used with augmented security to the happiness of the system administrators. Our approach relies on software agents which use private keys and a challengeresponse protocol to authenticate TCP/IP connection setup. The paper discusses the general framework as well as a sample implementation. Attacks and countermeasures are also outlined. The approach explicitly doesn’t address data privacy during transmission, as we would rather see it placed at application level.