Experimental Security Evaluation of the Tillitis TKey Authentication Ecosystem - Design and Implementation of a Testing Environment for Security Evaluation
| dc.contributor.author | Bredberg, William | |
| dc.contributor.author | Glantz, Maximilian | |
| dc.contributor.author | Hakeröd, Erik | |
| dc.contributor.author | Johansson, Elias | |
| dc.contributor.author | Larsson, Hannah | |
| dc.contributor.author | Tarkowska, Zuzanna | |
| dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
| dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
| dc.contributor.examiner | Jansson, Patrik | |
| dc.contributor.examiner | Inayat, Irum | |
| dc.contributor.supervisor | Hussain, Yasir | |
| dc.date.accessioned | 2026-08-13T09:03:31Z | |
| dc.date.issued | 2026 | |
| dc.date.submitted | ||
| dc.description.abstract | This thesis evaluates the security of the Tillitis TKey authentication ecosystem through simulated attack scenarios and experimental security analysis. Hardware based authentication tokens such as the TKey are an important part of passwordless systems, which aim to replace traditional passwords and improve security. To perform the evaluation, a controlled test environment was developed using virtual machines. Several representative attack scenarios were implemented, including person-in-the-middle, replay, injection, fuzzing, and nonce-reuse attacks. These attacks were used to evaluate security properties such as confidentiality, integrity, and authentication strength, based on observed system behavior and collected log data. The results show that the TKey’s authentication mechanism appears resistant to replay and nonce reuse attacks under the tested conditions, and no direct com promise was achieved through injection or fuzzing. However, the person-in-the middle attack showed that unencrypted communication channels expose authentication metadata and protocol information to interception. The findings highlight that the security of the TKey ecosystem depends not only on the hardware token itself, but also on the security of the surrounding communication and application layers. This thesis contributes a reproducible testing environment and a practical approach for evaluating authentication system security. | |
| dc.identifier.coursecode | DATX11 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12380/312134 | |
| dc.language.iso | eng | |
| dc.setspec.uppsok | Technology | |
| dc.title | Experimental Security Evaluation of the Tillitis TKey Authentication Ecosystem - Design and Implementation of a Testing Environment for Security Evaluation | |
| dc.type.degree | Examensarbete på kandidatnivå | sv |
| dc.type.degree | Bachelor Thesis | en |
| dc.type.uppsok | M2 |
