250 likes | 344 Views
Authentication on Mobile Devices for Business Application. Fabian Zoller & Martina Müller. Reason Why. Image source : [http :// goo.gl / VYMFN5]. Bring Your Own Device. Image source : [ M.Müller ]. Bring Your Own Device. Image source : [ M.Müller ]. Authentication Methods.
E N D
Authentication on Mobile Devices for Business Application Fabian Zoller & Martina Müller
ReasonWhy • Image source: [http://goo.gl/VYMFN5]
Bring YourOwn Device • Image source: [M.Müller]
Bring YourOwn Device • Image source: [M.Müller]
AuthenticationMethods Biometric • Image source: [http://goo.gl/zyjhAl]
AuthenticationMethods Biometric Location www.blog.mobileroudie.com • Image source: [http://goo.gl/yPRdEO]
AuthenticationMethods Biometric Location Knowledge • Image source: [http://goo.gl/Pzd5Pn] www.thebayentrepreneu.com
AuthenticationMethods Biometric Location Knowledge Possession • Image source: [http://goo.gl/6QE7fw] www.flickr.com/photos/code_material
Showrooms 2. 1. 4. 3. Image sources: [F. Zoller] [http://goo.gl/VqFSQ] [http://goqr.me] [http://goo.gl/bVT8l] [http://goo.gl/Vv2E] [http://goo.gl/wj8Hw]
System Components Untrusted Site Trusted Site (Company) Request Resource Web- / App Server & Agent Response Resource / Deny Client Device Yes / No / Data (Response Decision [Data]) Authentic? (Request Decision [Data]) Directory Server MakeDecision / Prepare Data Image sources: [http://goo.gl/gXoeT] [http://goo.gl/Vv2E]
MobileDesk • Authentication Flow • Select Certificate • ValidateCertificate • EnterGraphical Password • ValidateGraphical Password • Store Token in Directory • Start Web Applicationwith Token Image sources: [F. Zoller]
MobileKey • Authentication Flow • Touch Device with Identity Chip • Validate Identity Chip • EnterCredentials • ValidateCredentials • Store Token in Directory • Start Web Applicationwith Token Image sources: [F. Zoller]
TwoChannel • Authentication Flow • Enter Username • Generate QR-Code • Scan QR-Code • Enter Password • ValidateCredentials • Start Web Application On Mobile Device Image sources: [F. Zoller]
LocationBased • Authentication Flow • Active WLAN • Validate Access Point • Enter PIN • Generate OTP • Enter OTP and PIN • Validate OTP and PIN • Start Web Application On Mobile Device Image sources: [F. Zoller]
Usability Testing - Interrogations • Is there a significant difference between the arithmetic average authentication time? • iPhone + QR-Code (30 sec) • Android+ Mobile Key (37 sec) • Android/iPhone+ Location Based (39 sec)
Usability Testing - Interrogations • Is there a significant difference between the authentication time within the showrooms? • Mobile Key (37 sec) • Location Based (39 sec) • QR-Code (40 sec)
Usability Testing - Interrogations Is there a significant difference between the different operating systems focussing on the success quotient?