Retour d'expérience sur la conception d'une solution d'authentification renforcée
Dominique Alglave, Pascal Colombani · HAL (Le Centre pour la Communication Scientifique Directe) · 2015
In IT systems, access is secured by authentication. This application security component is highly vulnerable when used in conjunction with a single sign on (SSO), as it can spread a vulnerability to the entire federated domain.The French Ministry of education has developed a model of an enhanced authentication solution, choosen from a previous study (see [[https://2013.jres.org/archives/34/index.htm|The state of the art on enhanced authentication]]), to validate the concept, its integration, its security level, its user-friendly level, the enrolment and organisational processes...This solution should be less vulnerable to phishing and keyloggers than a simple password protection, without strong authentication constraints and physical media deployment complexity.The Ministry has chosen to develop a self solution using a dynamic grid. This solution does not rely on a physical device, does not require plug-in installation and uses a pattern which is difficult to transmit in case of phishing.The principle is that the user knows a secret pattern in a grid and is challenged with a grid containing random numbers or letters. The overlay of the pattern onto the random grid creates a One Time Password (OTP). The authentication is strengthened with the use of an additional 'pin' code entered before or after the OTP.The model trials connections to radius, SAML V2 and Open Id Connect clients to test uses for various purposes (Web SSO, VPN, user workstation, etc.).