Brukerautentisering - kapittel 6 Flashcards

1
Q

different between entity and message authentication?

A

entity authentication - verify the identity of an entity at the end of a session
message authentication : verify the origin of a message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name two cryptographic methods to achieve message authentication

A

MAC and digital signature

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

4 requirement for biometric authentication

A
  1. universality: every person should have the characteristic (universalitet)
  2. distinctiveness: any two persons should have sufficiently different characteristics (særpreg)
  3. permanence: shouldn’t change much over time (permanent)
  4. collectability - characteristic can be measured quantitatively (målbarhet)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

n-factor user-authentication

A

using n independent mechanism for verifying identity
Eks: smart car and pin, fingerprint authentication and password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Passordcracking -hvordan?
1. lagret som hashverdi
2. lagret som salt
3. lagret i klartekst
4. lagret som saltet hashverdi

A
  1. med hashtabell
  2. ingen
  3. uten hashtabell
  4. vanskelig å cracke
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Hva er PAD?

A

oppdage forsøk på forfalskning av biometri (men vanskelig å oppdage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Hva sier FMR av en biometrisk system?

A
  • False match rate -viser hvor mange ikke-genuine brukere blir godtatt
    -eks: FMR = MAS (matching attacker samples)/ TAS(total numer of attacke samples9
    -FAM = 0,05 tilsvarer 5 personer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Hva sier FNMR av en biometrisk system?

A

False non-match rate
Viser hvor mange genuine brukere blir avvist
- FNMR = NMUS (non-matching user samples/TUS (total numer user samples)
Eks: FNMR = 0,07 tilsvarer 7 personer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Hva står EER for?

A

Equal Error Rate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Ideelt biometrisk system er når…

A

FNMR = FMR = EER = 0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Brukes i FIDO-løsninger

A

onlineenheter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

har som regel klokke

A

OTP-brikke

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Brukes i BankID på mobil

A

sekundærkanal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

brukes i BankID

A

OTP-brikke

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

blir autenisert av leser/terminal

A

pass og ID-kort

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Brukes for overføring av autorisasjonskode/mønster til bruker

A

sekundærkanal

17
Q

Three catgories of credentials for user authentication

A
  1. something you know (knowledge) - password, pin
  2. Something you have (ownership - security token
  3. Somthing you are (inherence) - face recognition, iris
    (secondary channel ex. SMS)
18
Q

Principle and purpose of salting

A

password salting is to include a random numer when hashing and it ensures that equal passwords have different hashes and makes cracking more difficult by preventing the use of hash tables

19
Q

eGovernment 3 classes of requirements for assurance level of user authentication

A
  1. authentication method strength
  2. credential management assurance
  3. identity registration assurance
20
Q

Advantage of Biometrics

A

easy to use, can not loose or forget

21
Q

Disadvantage of Biometrics

A

High false negative rate, low performance, threat for personal safety, threat for privacy usability

22
Q

Disadvantage of Biometrics

A

High false negative rate, low performance, threat for personal safety, threat for privacy usability

23
Q

What is the main advantage of passwords/pins generated by an authenticationtoken compared to “normal” ones?

A

they are different for each authentication attempt (one time password)

24
Q

Describe 2 synchronised quthentication tokens

A

clock-based : client and server have synchronized internal clocks, that are used to derive an OTP
Counter-baser: client and server have a counter, which is used to derive an OTP.

25
Q

Hva er FIDO?

A

(Fast Identity Onlin)
er en industriallianse som standardiserer autentisering med online-enheter, og som forvalter sertifisering av FIDO-godkjente enheter

26
Q

Identity registration assurance

A

krav til riktig registrering av bruker
-pre-autentiseirng med legitmasint f.eks fødselsattest, biometri

27
Q

credential management assurance

A

krav til håndtering av autentikatorer
-generering
-mottak
- oppbevaring

28
Q

authentication Method Assurance

A

krav til autentiseringsmetode
- passordlengde og kvalitet
-kryptografisk styrke
-manipuleringsbestandig brikke
-dynamisk
-PKI-basert
-flerfaktor-autentisering