Experimental Security Evaluation of the Tillitis TKey Authentication Ecosystem - Design and Implementation of a Testing Environment for Security Evaluation
Hämtar...
Ladda ner
Publicerad
Typ
Examensarbete på kandidatnivå
Bachelor Thesis
Bachelor Thesis
Program
Modellbyggare
Tidskriftstitel
ISSN
Volymtitel
Utgivare
Sammanfattning
This thesis evaluates the security of the Tillitis TKey authentication ecosystem
through simulated attack scenarios and experimental security analysis. Hardware
based authentication tokens such as the TKey are an important part of passwordless
systems, which aim to replace traditional passwords and improve security.
To perform the evaluation, a controlled test environment was developed using
virtual machines. Several representative attack scenarios were implemented, including person-in-the-middle, replay, injection, fuzzing, and nonce-reuse attacks. These
attacks were used to evaluate security properties such as confidentiality, integrity,
and authentication strength, based on observed system behavior and collected log
data.
The results show that the TKey’s authentication mechanism appears resistant
to replay and nonce reuse attacks under the tested conditions, and no direct com
promise was achieved through injection or fuzzing. However, the person-in-the
middle attack showed that unencrypted communication channels expose authentication metadata and protocol information to interception.
The findings highlight that the security of the TKey ecosystem depends not
only on the hardware token itself, but also on the security of the surrounding communication and application layers. This thesis contributes a reproducible testing
environment and a practical approach for evaluating authentication system security.
