Experimental Security Evaluation of the Tillitis TKey Authentication Ecosystem - Design and Implementation of a Testing Environment for Security Evaluation

Hämtar...
Bild (thumbnail)

Publicerad

Typ

Examensarbete på kandidatnivå
Bachelor Thesis

Program

Modellbyggare

Tidskriftstitel

ISSN

Volymtitel

Utgivare

Sammanfattning

This thesis evaluates the security of the Tillitis TKey authentication ecosystem through simulated attack scenarios and experimental security analysis. Hardware based authentication tokens such as the TKey are an important part of passwordless systems, which aim to replace traditional passwords and improve security. To perform the evaluation, a controlled test environment was developed using virtual machines. Several representative attack scenarios were implemented, including person-in-the-middle, replay, injection, fuzzing, and nonce-reuse attacks. These attacks were used to evaluate security properties such as confidentiality, integrity, and authentication strength, based on observed system behavior and collected log data. The results show that the TKey’s authentication mechanism appears resistant to replay and nonce reuse attacks under the tested conditions, and no direct com promise was achieved through injection or fuzzing. However, the person-in-the middle attack showed that unencrypted communication channels expose authentication metadata and protocol information to interception. The findings highlight that the security of the TKey ecosystem depends not only on the hardware token itself, but also on the security of the surrounding communication and application layers. This thesis contributes a reproducible testing environment and a practical approach for evaluating authentication system security.

Beskrivning

Ämne/nyckelord

Citation

Arkitekt (konstruktör)

Geografisk plats

Byggnad (typ)

Byggår

Modelltyp

Skala

Teknik / material

Index

Endorsement

Review

Supplemented By

Referenced By