movie download indiana jones and the last crusade lesbian vampire killers movie download movie download the godfather: part ii scream movie download casino royale ocean's twelve movie download interview with the vampire: the vampire chronicles movie download the savages movie download crank 2: high voltage good will hunting eternal sunshine of the spotless mind movie download the truman show planet of the apes movie download it's a wonderful life shakespeare in love movie download movie download leaving las vegas dog days of summer the incredibles the usual suspects movie download movie download almost famous the dark knight movie download bride wars movie download the last samurai movie download artificial intelligence: ai movie download the wild bunch napoleon dynamite movie download troy movie download movie download back to the future part ii there will be blood movie download movie download atonement movie download harry potter and the goblet of fire the talented mr. ripley ace ventura: pet detective jr. movie download movie download man on wire big fish movie download sleuth natural born killers movie download 2001: a space odyssey austin powers: the spy who shagged me movie download the final inquiry the visitor movie download movie download pulp fiction movie download baraka x-men origins: wolverine movie download movie download star wars: episode iv - a new hope star trek movie download winnie the pooh un-valentine's day the untouchables the aviator movie download gladiator movie download in bruges finding nemo in cold blood movie download the bridge on the river kwai movie download monsters inc. spider-man 3 obsessed movie download enchanted movie download terminator 3: rise of the machines movie download apocalypse now independence day star trek: first contact he's just not that into you the international movie download movie download the uninvited movie download rain man movie download psycho confessions of a shopaholic the curious case of benjamin button movie download futurama: bender's big score red is the color of movie download to kill a mockingbird my friends tigger & pooh's friendly tails movie download the phantom of the opera movie download movie download no country for old men collateral movie download die hard movie download carlito's way movie download mean girls hot fuzz chop shop movie download movie download five minutes of heaven christmas in south park movie download sicko changeling ben-hur: a tale of the christ fahrenheit 9/11 paul blart: mall cop if i didn't care robin hood: prince of thieves the terminator movie download star wars: episode i - the phantom menace movie download movie download a beautiful mind movie download the ghosts of girlfriends past toy story 2 there's something about mary hulk movie download movie download 12 angry men bridget jones's diary batman forever movie download se7en movie download sleepy hollow movie download movie download american pie the blair witch project movie download anchorman: the legend of ron burgundy movie download bruce almighty movie download borat movie download rambo movie download the leon (professional) movie download chicago race to witch mountain the hunt for gollum movie download adventureland movie download million dollar baby jackie brown movie download singin' in the rain pirates of the caribbean: at world's end the chronicles of narnia: the lion witch and the wardrobe movie download movie download the wrestler american beauty movie download the apartment movie download the elephant man movie download iron man shrek movie download forrest gump the chimes at midnight new in town aka chilled in miami cool hand luke notorious 3:10 to yuma the diving bell and the butterfly movie download movie download last chance harvey x-men making waves lucky number slevin movie download the grudge 3 twelve monkeys movie download tales of the black freighter dead poets society movie download movie download dragonball: evolution lara croft: tomb raider serenity x-men: the last stand movie download 007 goldeneye erin brockovich journal of a contract killer movie download movie download children of men romeo + juliet life of brian movie download once upon a time in america hotel rwanda movie download raiders of the lost ark movie download blade runner (final cut) soldier's girl movie download chasing amy movie download movie download lawrence of arabia fargo movie download the great escape movie download the departed stand by me traffic movie movie download movie download underworld: rise of the lycans sweeney todd: the demon barber of fleet street the planets movie download waterworld back to the future movie download movie download the third man scary movie movie download movie download rear window the silence of the lambs before the devil knows you're dead office space movie download movie download transformers armageddon movie download harry potter and the order of the phoenix love actually movie download dogma movie download paths of glory movie download vanilla sky movie download mystic river movie download drag me to hell donnie darko dr. strangelove or: how i learned to stop worrying and love the bomb movie download star wars: episode iii - revenge of the sith movie download the shining movie download movie download cruel intentions juno i am legend movie download gone in sixty seconds how the grinch stole christmas! austin powers: international man of mystery movie download land of the lost movie download the matrix reloaded the big lebowski movie download the lord of the rings: the fellowship of the ring x2 movie download movie download harry potter and the chamber of secrets movie download american psycho indiana jones and the kingdom of the crystal skull movie download beauty and the beast movie download the lord of the rings: the two towers once upon a time in the west movie download movie download l.a. confidential movie download desperado movie download saw movie download moulin rouge! the nines movie download fired up before sunset movie download the godfather: part iii the incredible hulk futurama: into the wild green yonder gandhi movie download angels & demons gone with the wind movie download dead like me a bug's life star wars: episode vi - return of the jedi movie download spider-man 2 movie download movie download the matrix kill bill: vol. 1 goodfellas pirates of the caribbean: the curse of the black pearl movie download movie download the christmas toy the 10th kingdom the skeptic movie download the english patient movie download o brother where art thou? movie download trainspotting movie download harry potter and the sorcerer's stone edward scissorhands movie download dances with wolves movie download city of god movie download the passion of the christ movie download requiem for a dream movie download the telling gran torino movie download life is beautiful mission: impossible ii movie download blade runner movie download a clockwork orange movie download green street hooligans 2 movie download star wars: episode ii - attack of the clones the matrix revolutions the last king of scotland garden state movie download dead set movie download men in black movie download home alone closer movie movie download movie download van helsing movie download groundhog day harry potter and the prisoner of azkaban monsters vs. aliens movie download silent hill movie download one flew over the cuckoo's nest casablanca movie download movie download 21 grams toy story movie download taxi driver movie download unforgiven movie the fast and the furious movie download the godfather 300 spartans movie download the bourne ultimatum movie download movie download saving private ryan bootmen glory ed wood movie download jeff dunham: arguing with myself movie download the shawshank redemption jurassic park movie download aladdin the butterfly effect the snowman shelter heat letters from iwo jima movie download movie download memento hancock black hawk down sin city movie download the sting the hangover movie download i'm not there movie download the insider control movie download the fugitive the princess bride movie download fear and loathing in las vegas movie download superbad the prestige movie download movie download jaws knowing on the waterfront war of the worlds movie download mulholland dr. the rock movie download movie download citizen kane die another day gangs of new york minority report south park: bigger longer & uncut movie download street fighter: the legend of chun-li as good as it gets movie download finding neverland movie download the island movie download charlie's angels the pianist little miss sunshine the darjeeling limited movie download aliens movie download terminator 2: judgment day movie download vertigo live free or die hard kung fu panda movie download underworld movie download schindler's list lost in translation the bourne identity the sixth sense movie download ice age movie download alien movie download from dusk till dawn movie download movie download platoon movie download blood diamond signs movie movie download knocked up the pursuit of happyness movie download die hard 2 the nightmare before christmas movie download spider-man movie download apocalypto movie download being john malkovich amadeus american gangster terminator salvation movie download ferris bueller's day off movie download movie download titanic the simpsons movie the conversation movie download madea goes to jail movie download the devil's advocate movie download some like it hot movie download unbreakable movie download cloverfield pearl harbor boy a pink panther 2 movie download reservoir dogs brokeback mountain movie download indiana jones and the temple of doom robot chicken: star wars movie download i robot movie download 17 again movie download the 40 year old virgin movie download pirates of the caribbean: dead man's chest road to perdition movie download saw ii movie download superman returns movie download braveheart movie download echelon conspiracy state of play movie download movie download frost/nixon the lord of the rings: the return of the king movie download movie download ratatouille speed movie movie download penelope the da vinci code movie download v for vendetta movie download howl's moving castle lock stock and two smoking barrels movie download movie download snatch. movie download the notebook hannah montana: the movie movie download full metal jacket heima movie download star wars: episode v - the empire strikes back movie download catch me if you can the african queen fast & furious 4 movie download night at the museum 2: battle of the smithsonian watchmen ocean's eleven movie download fight club notting hill movie download munich movie download the green mile movie download wall-e movie download gone baby gone rocky movie download movie download the others 12 rounds movie download stardust batman begins movie download hotel for dogs movie download kill bill: vol. 2 the elite squad coraline movie download movie download shrek 2 raging bull slumdog millionaire movie download the mummy movie download the hurt locker movie download movie download american history x movie download the fifth element the man from earth

Posts Tagged Security

A Radical New Approach to (MUTUAL) Authentication

[This thought paper is from Rel-ID Technologies Inc. - a Uniken venture]

Authors Sanjay Deshpande, Dr. Pat Shankar, Eashwar Ganapathy

Abstract In this article, we present a fundamentally new identity framework – RELATIVE IDENTITY - which addresses and eliminates many of the core problems faced by the current identity technologies. We postulate that authentication necessarily has to be mutual and that the only valid way to perform mutual authentication is to make fundamental changes to the identity representation framework.

This can be accomplished by –

  1. Changing from end-point entity labeling (like in the case of login/password, biometric, digital certificates, 2-Way SSL and a combination of these) – to labeling the relationship between the end-point entities (which inherently covers the two end-points in its definition)
  2. Making the authentication protocol truly mutual – and thereby eliminating the susceptibility to man-in-the-middle attacks and phishing

Identity and identification are central to any interaction, both in real and virtual (digital) systems. Especially where the interaction entails access to or manipulation of protected resource(s).

We firmly believe that any identity framework has to address the problem of establishing a mutually-authenticated secure connection BEFORE initiating any data transaction using that connection.
Introduction Identity and Authentication form the central building block of any information security solution/framework. Establishing identity using an authentication protocol is the starting point for any secure transaction. In order to be able to establish identity (be it man or machine), the entity must be characterized by a unique set of symbols (as per the adopted identity representation framework). During the process of actually identifying / authenticating the entity, the same characteristics of  the entity are observed and matched against those that were captured earlier and associated with the entity.

The act of establishing identity is identification. Identity Systems must possess the capability represent, provide, maintain and establish identity. The identity representation framework must ensure that it is extremely difficult to compromise the individual identities it is used to represent. In this article we cover the following points:

  1. Definition of RELative IDentity – the representation
  2. Fundamental properties of identity (representation)
  3. Proof that all authentication must necessarily be mutual ( that 1-way authentication basically flawed)
  4. Fundamental properties of authentication / identification (the process of)
  5. How is Relative Identity different from other identity schemes

The basic flaws and limitations in current identity technologies for websites prevalent in the World Wide Web SSL/Digital Certificates (when used for AUTHENTICATION) become apparent in the context of the axiomatic frame of reference defined in the following sections.

Definition of Relative Identity The relative identity of an entity is

  1. Distributed among the relationship of this entity with other entities. Each such valid relationship –
    • constitutes a unit “Relative  Identity” – an important and inseparable constituent of the identities of each of the entities sharing a valid relationship
    • contributes in the definition of the relative identity of each entity
    • exists only in the context of two (or more) entities who share a relationship
  2. Is the union/collection of all such “Relative Identities”
  3. Is dynamic since new relationships may be established, while old relationships may be discarded, over time
  4. Is associated with a set of labels/attributes/characteristics – immutable and mutable
    • immutable - such as biometrics, which cannot be changed at will
    • mutable - such as SSN which are awarded for a    life time,  log  in passwords, bank account numbers which are changed quite often

In practical implementations of identity based transactions, one is concerned only with the specific (relevant) relative identity and associated attributes, and hence the rest of the identity representation is not susceptible to identity theft.

As is evident from the above definition, the concept of identity in the prevalent conventional identity systems that deal with only labels/attributes/characteristics – “What you have”, “What you know” and “What you are”, totally ignore the most relevant concept of “Who you know” – which is how humans establish trusted relationships.

Fundamental Properties of Relative Identity

The unit relative-identity data -

  1. must be unique (no two relative-identities should have the same identity data)
  2. must be tamper-proof (difficult to reconstruct and reproduce)
  3. must be secret - wholly / partially (should not be communicated in full form during authentication; should be known only to the related entities)
  4. must be used simultaneously and uniquely, to identity all entities involved in the authentication transaction

Most of the prevalent conventional identity systems satisfy properties 1, 2 and 3 above. For example -

  • Login/Password would satisfy 1, 2 (partially) and 3 (partially)
  • Digital Certificates would satisfy 1, 2 and 3 (partially)

What is Mutual Authentication/Identification? Why does one need it?

As yourself the following questions -

  • what is the meaning of authentication if it is not mutual?
  • why would I allow someone to authenticate me, if I can’t authenticate him/her?
  • would I produce my passport to identify myself to someone who does not (even seemingly) possess the requisite authority?
  • Even so, don’t I run the risk of being duped into producing my passport to a person who only looks authentically like he/she has the requisite authority?

The basic flaw in identification over the internet is that an end-user assumes that the website challenging him/her for his/her credentials is indeed the authentic site – so long as interaction with the user-agent application (the web-browser) while accessing the website, is identical to previous such interactions. That is to say – so long as the website looks the same, behaves the same, and does not trigger a negative message  from installed security products (due to more recent efforts in the anti-phishing features of these products).

All things considered, are you sure you can trust such a website that asks for your login credentials?

Conclusion: Authentication, to be of any practical use, MUST BE MUTUAL

Fundamental properties of authentication / identification

The process for identification / authentication

  1. must be tightly integrated with a given/underlying identity representation
  2. must necessarily have a priori access to the identity data that is to be identified / authenticated
  3. must necessarily authenticate all identifying/authenticating parties (entities) – preferably simultaneously

These are simple (minimal) properties that any identity/authentication system must possess. Some of them are straightforward while some may not be seem obvious.

Let us now visit some of the prevalent identification/authentication processes in light of the above properties -

  • Login/Password – satisfies 1 and 2 above
  • Digital Certifications/SSL – does not satisfy 2 and 3, and hence, should NOT be used for authentication
  • Hardware/Software Tokens (and OTPs) – satisfy 1 and 2 but do not satisfy 3

Please note that even the use of multi-factors satisfy only properties 1 and 2 and not the property 3

Let us look at the third property above for authentication protocols that essentially says that - the process MUST be mutual and simultaneous. The term mutual has earlier been defined in the context of client-server architecture as “client must authenticate the  server and  the server must authenticate the client”. Such a definition classifies any “1-way” authentication method executed twice as a valid 2-WAY or mutual authentication process. The fundamental flaws in existing mutual and 1-Way authentication systems are precisely due to the violation of properties (2) and (3) above.
Mutual authentication cannot and should not be implemented using two 1-WAY authentication schemes – e.g. 2-Way SSL, or a combination of login/password and shared secrets/site-key. Any such scheme will be vulnerable to the same attacks that the 1-WAY equivalent is vulnerable to. For example, 2-WAY SSL is susceptible to MITM (man-in-the-middle) in exactly the same way that 1-WAY SSL is - for the same reasons.

How is Relative Identity different from other identity schemes?

Conventionally, identity is associated with the end-point entities (client or server) and authentication involved authenticating the end-points. Authenticating this information for both end-points in sequence is NOT  secure mutual authentication – it is a concatenation of 2 instances of 1-WAY authentication.

The REL-ID (relative identity) approach to authentication is to identify and authenticate the ‘link/relationship’ between the end-point entities – not the individual end-points. That is to say – IDENTITY must necessarily be associated with the ‘link’ representing the relationship between the end-points. This is the only representation, and authentication thereof, that can legitimately be termed as MUTUAL – as the end-points are an integral part of the definition of any such representation.

Authenticating such a ‘link’ would necessarily be mutual – would ensure that all end-points are authenticated simultaneously, and makes the identity of every end-point relative to the other end-point(s) axiomatically.

Conventional Identity System

Conventional Identity System

Relative-Identity System

Relative-Identity System

We believe that, in order to (a) represent the above information correctly at the end-points and (b) arrive at the correct protocols for identification/authentication, one must develop the necessary mathematical frameworks and algorithms. However, before starting to derive them, one must accept and acknowledge the fundamental paradigm shift in the desired properties of such representations and algorithms.

The set of identity representations and identification/authentication algorithms constituting the REL-ID© Security Suite is one such implementation of the identity paradigm described here. Assuming that authentication must necessarily be mutual and simultaneous to be of any value, authentication schemes such as tokens, digital-certificates/SSL, login/password… cannot be compared with REL-ID – since they offer only 1-WAY authentication, at best. Furthermore, methods/products that claim to provide mutual authentication, but in reality implement two 1-WAY authentications (like SITE-KEY – flash-persistent object; Shared Secrets…), will  remain vulnerable to man-in-the-middle attacks due to the inherent vulnerability in the conventional end-point identity representation scheme.

There are no known contemporary technologies/products that are built using mutual authentication protocols, which have the properties mentioned in this article, and which are available commercially.

, ,

No Comments

Website Identity - the root cause for Internet Fraud

,

No Comments

PKI (HSPD-12) for controlling access to your web applications

, , , ,

1 Comment