Black Hat Physical Device Security: Exploiting Hardware and Software

Authenticating with Credentials

The first time cryptography will be used within a device most often will be to determine the identity of a user. This process is called authentication. The information used to establish the identity is known as the credentials. A driver's license and passport are common forms of physical authentication. In our daily lives, a username and password are the most common forms of credentials.

From the perspective of the device that receives the credentials, the method of input determines the relationship of the data to the entity that sent the credentials. This means that a fingerprint scanner makes an image and performs calculations based on what is pressed against the screen where it scans. The validity of a correct image is based on a comparison of the input data processed to the stored correct data. While some devices could detect that something not quite a fingerprint is being received, those determinations are merely rough calculations based on what a generic fingerprint should look like. These processes are not necessarily accurate, but for the general use of any device, the processes make it good enough to sell. Arbitrary data matching, using video- and audio-based technology, will always have trouble asserting that when the credentials are correct, they are coming from the right source. All these devices have input based on the physical world. The device doesn't know the difference between real and wrong input methods, only that the data is either wrong or right.

Some fingerprint...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Biometrics Software
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.