FIDO2 web passwordless authentication for SSO systems

The passwords are not completely secure anymore as the number of accounts and password-related attacks is increasing. This means that the personal or sensitive information of a user could be leaked, or it could even affect its finances as passwords are the most used authentication method. To solve t...

Full description

Autores:
Hernández León, Andrés Felipe
Tipo de recurso:
Trabajo de grado de pregrado
Fecha de publicación:
2020
Institución:
Universidad de los Andes
Repositorio:
Séneca: repositorio Uniandes
Idioma:
eng
OAI Identifier:
oai:repositorio.uniandes.edu.co:1992/51504
Acceso en línea:
http://hdl.handle.net/1992/51504
Palabra clave:
Autenticidad (Informática)
Sistemas electrónicos de seguridad
Seguridad en computadores
Cifrado de datos (Informática)
FIDO2 (Protocolo)
Ingeniería
Rights
openAccess
License
http://creativecommons.org/licenses/by-nc-nd/4.0/
Description
Summary:The passwords are not completely secure anymore as the number of accounts and password-related attacks is increasing. This means that the personal or sensitive information of a user could be leaked, or it could even affect its finances as passwords are the most used authentication method. To solve this a new environment called passwordless has emerge, promising to take care of all the password related attacks as it eliminates them of the authentication process or uses multiple authentication methods in order to evade trusting fully on passwords. Therefore, this investigation project, researched on passwordless environments and designed and implemented a passwordless infrastructure based on an educational system. Based on this design, a prototype was designed and implemented with the objective of understanding deeply this kind of environment, the reach and functionality that it may have on a real-world environment.