Firewall Wizards mailing list archives

Re: Token based OTP: SafeWord or SecurID?


From: Rick Smith <rick_smith () securecomputing com>
Date: Mon, 25 Sep 2000 16:53:12 -0500

At 02:21 PM 9/25/00, daN. wrote:

Out of curiosity does anyone know if there are Smart-Card security cards out there the work on public Key cryptography? (Computer passes you a random token, card signs it and passes it back? System verifies it by checking against public key) ...

All the smart card vendors I've talked to are working with public key cryptography.

To my knowledge, however, none of them are pushing a challenge-response protocol like you outlined, which is probably similar to the old FIPS JJJ protocol. AFAIK, nobody has fielded a successful product based on that. We did something for the government a few years back that prototyped the concept, but it never took off commercially.

The big action I hear about in PK authentication seems to involve SSL client authentication in browsers or IKE authentication for VPNs.

Rick.
smith () securecomputing com         roseville, minnesota


_______________________________________________
Firewall-wizards mailing list
Firewall-wizards () nfr net
http://www.nfr.net/mailman/listinfo/firewall-wizards


Current thread: