OTP Bank
OTP Bank
infrastructures using
Open Source sofware
Filte
(welcome)
Who am I
More on:
http://www.scss.tcd.ie/Giuseppe.Paterno/
http://www.gpaterno.com/
http://www.linkedin.com/in/gpaterno
Global IT scenario
Lowering TCO
"The economic crisis is going to be a catalyst for
open source, much like the technology crash of
2001 catapulted Linux front and center"
Laurie Wurster, a Gartner analyst.
http://www.openauthentication.org/
Created a common algorithm for one time password
tokens (HOTP)
What is HOTP
http://www.rfc-editor.org/
HOTP: Internals
The algorithm is:
HOTP(K,C) = Truncate(HMAC-SHA-1(K,C))
K
Truncate()
Anathomy of HOTP
HOTP implementations
The software
OTPD server
Supported tokens:
HOTP
CRYPTOCard
FreeRADIUS
Plug-in based
The soft-token
Easy to manage
Lower costs
VPN systems
Wireless LANs
Routers/network equipments
Captive portals
Enteprise scenario
Demo scenario
Authentication server:
OTP Server
FreeRADIUS Server
Client UNIX
Client Unix
Interactive log-in
Interactive log-in
OTP/Radius Server
Authentication
Request
(RADIUS)
Log-on
request
Web Application
OTP/Radius Server
Redirect to
CAS' Single
Sign-on Portal
Authentication
Request
(RADIUS)
Web Access
Demo now!
Thank you!!
Giuseppe Gippa Patern
Visiting Researcher
Trinity College Dublin
[email protected]
http://www.scss.tcd.ie/Giuseppe.Paterno/
http://www.gpaterno.com/