Experimental Security Evaluation of the Tillitis TKey Authentication Ecosystem - Design and Implementation of a Testing Environment for Security Evaluation

dc.contributor.authorBredberg, William
dc.contributor.authorGlantz, Maximilian
dc.contributor.authorHakeröd, Erik
dc.contributor.authorJohansson, Elias
dc.contributor.authorLarsson, Hannah
dc.contributor.authorTarkowska, Zuzanna
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerJansson, Patrik
dc.contributor.examinerInayat, Irum
dc.contributor.supervisorHussain, Yasir
dc.date.accessioned2026-08-13T09:03:31Z
dc.date.issued2026
dc.date.submitted
dc.description.abstractThis thesis evaluates the security of the Tillitis TKey authentication ecosystem through simulated attack scenarios and experimental security analysis. Hardware based authentication tokens such as the TKey are an important part of passwordless systems, which aim to replace traditional passwords and improve security. To perform the evaluation, a controlled test environment was developed using virtual machines. Several representative attack scenarios were implemented, including person-in-the-middle, replay, injection, fuzzing, and nonce-reuse attacks. These attacks were used to evaluate security properties such as confidentiality, integrity, and authentication strength, based on observed system behavior and collected log data. The results show that the TKey’s authentication mechanism appears resistant to replay and nonce reuse attacks under the tested conditions, and no direct com promise was achieved through injection or fuzzing. However, the person-in-the middle attack showed that unencrypted communication channels expose authentication metadata and protocol information to interception. The findings highlight that the security of the TKey ecosystem depends not only on the hardware token itself, but also on the security of the surrounding communication and application layers. This thesis contributes a reproducible testing environment and a practical approach for evaluating authentication system security.
dc.identifier.coursecodeDATX11
dc.identifier.urihttps://hdl.handle.net/20.500.12380/312134
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.titleExperimental Security Evaluation of the Tillitis TKey Authentication Ecosystem - Design and Implementation of a Testing Environment for Security Evaluation
dc.type.degreeExamensarbete på kandidatnivåsv
dc.type.degreeBachelor Thesisen
dc.type.uppsokM2

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 26-31B.pdf
Size:
3.09 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Size:
2.35 KB
Format:
Item-specific license agreed upon to submission
Description: