Download as a PDF

Transcript
Contents
Contents
1 Introduction
1.1
4
Motivation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
4
1.1.1
Hardware tokens . . . . . . . . . . . . . . . . . . . . . . . . .
6
1.1.2
Advantages and disadvantages of ordinary storage media . . .
7
1.2
A quick introduction to PAM . . . . . . . . . . . . . . . . . . . . . .
8
1.3
A quick introduction to cryptographic hashes
1.4
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
2 Security aspects
. . . . . . . . . . . . . 10
13
2.1
One time password engine . . . . . . . . . . . . . . . . . . . . . . . . 13
2.2
Authentication information
2.3
USB device verification . . . . . . . . . . . . . . . . . . . . . . . . . . 15
2.4
Conceptional groundwork for Rescue Devices . . . . . . . . . . . . . . 16
. . . . . . . . . . . . . . . . . . . . . . . 14
2.4.1
Untracable data hiding and single-user restrictiveness . . . . . 16
2.4.2
Alternative initialization vectorization and rescue PINs . . . . 17
2.5
Implementation-dependent security topics: C vs. managed vs. interpreted languages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
2.6
Two-factor authentication (PIN-based verification) . . . . . . . . . . 19
2.7
Weaknesses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
3 Implementation
3.1
3.2
22
Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
3.1.1
Library linkage and compiler settings . . . . . . . . . . . . . . 22
3.1.2
Favoring UDEV in behalf of DevFS . . . . . . . . . . . . . . . 23
Design and architecture
. . . . . . . . . . . . . . . . . . . . . . . . . 24
3.2.1
Modularization . . . . . . . . . . . . . . . . . . . . . . . . . . 24
3.2.2
libpamauth.so . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Seite 2