SlideShare a Scribd company logo
All Rights Reserved | FIDO Alliance | Copyright 2018
1
FIDO 2 인증기술 소개
한국전자통신연구원
정보보호연구본부
조상래
All Rights Reserved | FIDO Alliance | Copyright 2018
2
발표내용
1. FIDO 개념
2. FIDO 1.0과 FIDO2 구조
3. FIDO 2 인증장치
4. FIDO 2 활용
All Rights Reserved | FIDO Alliance | Copyright 2018
333333
FIDO 이전
All Rights Reserved | FIDO Alliance | Copyright 2018
444444
FIDO 개념
▶사용자 인증과 원격 인증 프로토콜의 분리
• 사용자 인증수단은 바이오, 토큰, 패턴 등 다양
• 원격 인증은 공개키 기반 단일 방식
☞ 서버 변경 없이 다양한 인증 수단 사용
All Rights Reserved | FIDO Alliance | Copyright 2018
555555
FIDO 1.0 구조
Relying PartyUser Device
Application
App. Server
FIDO Server
FIDO Client
ASM
Authenticator
UAF Protocol
(등록/인증/해지)
All Rights Reserved | FIDO Alliance | Copyright 2018
666666
FIDO 2 필요성
FIDO 2, 왜 필요한가?
▶ FIDO 클라이언트 보급 해소
• FIDO 1.0 클라이언트의 배포주체 모호
• 플랫폼에서 기본 제공해 문제 해결
▶ 웹(Web)에서도 바이오인증 요구
• W3C 표준화로 모든 웹브라우저에 FIDO
기술 적용 목표
▶ UAF와 U2F 통합 필요
• 인증서비스에 대해 모바일과 웹에서
동일한 사용자 경험 제공
▶ 플랫폼 주도권 확보 전략
• 결제 및 온라인 서비스의 첫 번째
관문인 인증 기술을 플랫폼 내 수용
All Rights Reserved | FIDO Alliance | Copyright 2018
User Device
777777
FIDO2 구조
Relying Party
Application
App. Server
FIDO2 Server
OS/Browser
(FIDO Client) 개발자 API /
WebAuthn API
FIDO CTAP
자체 프로토콜
(등록/인증)
인증장치에서 서버로 보내는 메시지
CTAP - Client-To-Authenticator Protocol
All Rights Reserved | FIDO Alliance | Copyright 2018
888888
Web Authentication API
Relying PartyUser Device
Web App
App. Server
FIDO2 Server
Web Browser
자체 프로토콜
(등록/인증)
Built-In
Authenticator
▶ Web Authentication API ?
• 웹앱에서 웹브라우저의 FIDO 기능을 호출하기 위해 사용하는 자바 스크립트 API
• 인증장치를 FIDO 서버에 등록 및 인증하기 위한 기능 제공
• 인증장치가 등록 및 인증에서 사용하는 메시지 포맷 정의
• 다양한 사용 시나리오를 위한 확장 기능 (위치, 바이오 인덱스) 제공
All Rights Reserved | FIDO Alliance | Copyright 2018
999999
FIDO2 Authentication
Ceremony – Registration or Authentication
Authorization Gesture - User Consent
User Presence User Verification
User Touch
Button pressed
Fingerprint
Retina Scan
Face Recognition
All Rights Reserved | FIDO Alliance | Copyright 2018
101010101010
FIDO 인증장치 개념
FIDO Authenticator Framework
Attestation Key
Interface
Authentication
Keys
User Verification
Transaction
Confirmation Display
Platform ▶ 사용자 인증
• 지문, 홍채, PIN, etc.
▶ 키 생성
• 인증 키 생성
▶ 전자서명 생성
• 등록 및 인증
• 거래 확인
All Rights Reserved | FIDO Alliance | Copyright 2018
111111111111
FIDO2 인증장치
Webauthn API
Cross Platform
Authenticator
CTAP
Mobile/PC
Application
Wep Application
Non-Platform
API
(SW Authenticator)
Platform FIDO API
Platform
authenticator
(SW or HW)
CTAP
(USB, NFC, BLE)
Android/iOS
Application
All Rights Reserved | FIDO Alliance | Copyright 2018
121212121212
CTAP Protocol
▶ Client To Authenticator Protocol ?
• 외부 인증장치를 위한 플랫폼 독립적인 범용 API 및 프로토콜 정의
• 플랫폼 연결 방법으로 USB, NFC, Bluetooth 지원
• CTAP은 스마트폰을 인증장치로 이용하여 다른 디바이스에 인증 가능
• O2O 서비스에서 FIDO 인증을 적용할 수 있는 기반 제공
USB Bluetooth
FIDO 기능 지원 디바이스
All Rights Reserved | FIDO Alliance | Copyright 2018
131313131313
FIDO 1.0과 FIDO2 비교
UAF - Universal Authentication Framework
ASM - Authenticator Specific Module
CTAP - Client-To-Authenticator Protocol
All Rights Reserved | FIDO Alliance | Copyright 2018
141414141414
FIDO2 활용
▶스마트폰 -> PC / 브라우저 (FIDO2)
• 모든 플랫폼에 FIDO 서비스 이용 가능
▶서버 인증 -> 주변기기 인증
• IOT환경에 사용자 인증 기술로 활용
▶온라인 -> 오프라인
• O2O 서비스에 다양하게 활용
All Rights Reserved | FIDO Alliance | Copyright 2018
151515151515
맺으며…
▶플랫폼에 FIDO 기능 장착
• 운영체제 -> Windows & Android
• 웹브라우저 -> W3C 표준화로 Edge, Chrome, Firefox
▶다양한 인증장치의 증가
• 플랫폼 기반의 빌트인 인증장치 제공
• USB, Bluetooth, NFC 기반의 외부 인증장치 사용 가능
▶FIDO와 연계한 다양한 인증서비스 가능
• 무자각 인증기술
• 바이오 키 생성 기술
• 블록체인 기술
All Rights Reserved | FIDO Alliance | Copyright 2018
161616161616
조상래 (sangrae@etri.re.kr)
감사합니다

More Related Content

What's hot

2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について
2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について
2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について
FIDO Alliance
 
FIDO2 & Microsoft
FIDO2 & MicrosoftFIDO2 & Microsoft
FIDO2 & Microsoft
FIDO Alliance
 
IBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptxIBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptx
FIDO Alliance
 
FIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for All
FIDO Alliance
 
Basic BGP Configuration
Basic BGP ConfigurationBasic BGP Configuration
Basic BGP Configuration
NetProtocol Xpert
 
FIDO2 Specifications Overview
FIDO2 Specifications OverviewFIDO2 Specifications Overview
FIDO2 Specifications Overview
FIDO Alliance
 
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
Amazon Web Services
 
Web Authentication API
Web Authentication APIWeb Authentication API
Web Authentication API
FIDO Alliance
 
Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装
Haniyama Wataru
 
공인인증서 크래킹 - Inc0gnito 2015
공인인증서 크래킹 - Inc0gnito 2015공인인증서 크래킹 - Inc0gnito 2015
공인인증서 크래킹 - Inc0gnito 2015
Hajin Jang
 
OpenID Connect: An Overview
OpenID Connect: An OverviewOpenID Connect: An Overview
OpenID Connect: An Overview
Pat Patterson
 
FIDO Specifications Overview: UAF & U2F
FIDO Specifications Overview: UAF & U2FFIDO Specifications Overview: UAF & U2F
FIDO Specifications Overview: UAF & U2F
FIDO Alliance
 
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~Tatsuo Kudo
 
U2F/FIDO2 implementation of YubiKey
U2F/FIDO2 implementation of YubiKeyU2F/FIDO2 implementation of YubiKey
U2F/FIDO2 implementation of YubiKey
Haniyama Wataru
 
韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020
韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020
韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020
OpenID Foundation Japan
 
Developer Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for AndroidDeveloper Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for Android
FIDO Alliance
 
Introduction to OpenID Connect
Introduction to OpenID Connect Introduction to OpenID Connect
Introduction to OpenID Connect
Nat Sakimura
 
Securing a Web App with Security Keys
Securing a Web App with Security KeysSecuring a Web App with Security Keys
Securing a Web App with Security Keys
FIDO Alliance
 
Integrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation ProtocolsIntegrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation Protocols
FIDO Alliance
 
Beyond Passwords: FIDO and the Future of User Authentication
Beyond Passwords: FIDO and the Future of User AuthenticationBeyond Passwords: FIDO and the Future of User Authentication
Beyond Passwords: FIDO and the Future of User Authentication
FIDO Alliance
 

What's hot (20)

2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について
2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について
2019 FIDO Tokyo Seminar - FIDO認定と国内で初めて開催したFIDO相互接続性試験について
 
FIDO2 & Microsoft
FIDO2 & MicrosoftFIDO2 & Microsoft
FIDO2 & Microsoft
 
IBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptxIBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptx
 
FIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for All
 
Basic BGP Configuration
Basic BGP ConfigurationBasic BGP Configuration
Basic BGP Configuration
 
FIDO2 Specifications Overview
FIDO2 Specifications OverviewFIDO2 Specifications Overview
FIDO2 Specifications Overview
 
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
 
Web Authentication API
Web Authentication APIWeb Authentication API
Web Authentication API
 
Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装
 
공인인증서 크래킹 - Inc0gnito 2015
공인인증서 크래킹 - Inc0gnito 2015공인인증서 크래킹 - Inc0gnito 2015
공인인증서 크래킹 - Inc0gnito 2015
 
OpenID Connect: An Overview
OpenID Connect: An OverviewOpenID Connect: An Overview
OpenID Connect: An Overview
 
FIDO Specifications Overview: UAF & U2F
FIDO Specifications Overview: UAF & U2FFIDO Specifications Overview: UAF & U2F
FIDO Specifications Overview: UAF & U2F
 
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
 
U2F/FIDO2 implementation of YubiKey
U2F/FIDO2 implementation of YubiKeyU2F/FIDO2 implementation of YubiKey
U2F/FIDO2 implementation of YubiKey
 
韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020
韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020
韓国における FIDO/ eKYC /DID の現状と今後の取り組み - OpenID Summit 2020
 
Developer Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for AndroidDeveloper Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for Android
 
Introduction to OpenID Connect
Introduction to OpenID Connect Introduction to OpenID Connect
Introduction to OpenID Connect
 
Securing a Web App with Security Keys
Securing a Web App with Security KeysSecuring a Web App with Security Keys
Securing a Web App with Security Keys
 
Integrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation ProtocolsIntegrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation Protocols
 
Beyond Passwords: FIDO and the Future of User Authentication
Beyond Passwords: FIDO and the Future of User AuthenticationBeyond Passwords: FIDO and the Future of User Authentication
Beyond Passwords: FIDO and the Future of User Authentication
 

Similar to Introduction to FIDO2 (Korean Language)

Raonsecure FIDO Ecosystem Deployment Case Study
Raonsecure FIDO Ecosystem Deployment Case StudyRaonsecure FIDO Ecosystem Deployment Case Study
Raonsecure FIDO Ecosystem Deployment Case Study
FIDO Alliance
 
Crucialtec FIDO Deployments and Future Possibilities
Crucialtec FIDO Deployments and Future PossibilitiesCrucialtec FIDO Deployments and Future Possibilities
Crucialtec FIDO Deployments and Future Possibilities
FIDO Alliance
 
Establishment of FIDO Korea Working Group
Establishment of  FIDO Korea Working GroupEstablishment of  FIDO Korea Working Group
Establishment of FIDO Korea Working Group
FIDO Alliance
 
XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용
XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용
XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용
XpressEngine
 
FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)
FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)
FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)
FIDO Alliance
 
Encrypted media extention
Encrypted media extentionEncrypted media extention
Encrypted media extentionTaehyun Kim
 
Hyperconnect pycon 2019
Hyperconnect pycon 2019Hyperconnect pycon 2019
Hyperconnect pycon 2019
Jun Young Lee
 
드론 관제 기술동향
드론 관제 기술동향 드론 관제 기술동향
드론 관제 기술동향
SeungWook Choi
 
FIDO Ecosystem with Integration of Blockchain (Korean)
FIDO Ecosystem with Integration of Blockchain (Korean)FIDO Ecosystem with Integration of Blockchain (Korean)
FIDO Ecosystem with Integration of Blockchain (Korean)
FIDO Alliance
 
AI-IoT 연동을 위한 KT GiGA Genie Home Skills
AI-IoT 연동을 위한 KT GiGA Genie Home SkillsAI-IoT 연동을 위한 KT GiGA Genie Home Skills
AI-IoT 연동을 위한 KT GiGA Genie Home Skills
ksdc2019
 
[한국핀테크포럼] 회원사소개: 인터페이
[한국핀테크포럼] 회원사소개: 인터페이[한국핀테크포럼] 회원사소개: 인터페이
[한국핀테크포럼] 회원사소개: 인터페이
Hyeseon Yoon
 
Rfid asset managesystem
Rfid asset managesystemRfid asset managesystem
Rfid asset managesystem
YoungKyu Choi
 
RFID Asset Manage System
RFID Asset Manage SystemRFID Asset Manage System
RFID Asset Manage System
YoungKyu Choi
 
[Nsb] kisa 세미나자료 2016_11_17
[Nsb] kisa 세미나자료 2016_11_17[Nsb] kisa 세미나자료 2016_11_17
[Nsb] kisa 세미나자료 2016_11_17
Wonil Seo
 
Oracle autonomous blockchain cloud service
Oracle autonomous blockchain cloud serviceOracle autonomous blockchain cloud service
Oracle autonomous blockchain cloud service
Mee Nam Lee
 
2015 n tels iot product lineup_2015
2015 n tels iot product lineup_20152015 n tels iot product lineup_2015
2015 n tels iot product lineup_2015
SangHoon Lee
 
2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx
2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx
2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx
RinandarMuslimin
 
Sotis 소개
Sotis 소개Sotis 소개
Sotis 소개
종명 류
 
[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기
[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기
[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기
Chris Ryu
 
[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사
[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사
[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사
JEONG HAN Eom
 

Similar to Introduction to FIDO2 (Korean Language) (20)

Raonsecure FIDO Ecosystem Deployment Case Study
Raonsecure FIDO Ecosystem Deployment Case StudyRaonsecure FIDO Ecosystem Deployment Case Study
Raonsecure FIDO Ecosystem Deployment Case Study
 
Crucialtec FIDO Deployments and Future Possibilities
Crucialtec FIDO Deployments and Future PossibilitiesCrucialtec FIDO Deployments and Future Possibilities
Crucialtec FIDO Deployments and Future Possibilities
 
Establishment of FIDO Korea Working Group
Establishment of  FIDO Korea Working GroupEstablishment of  FIDO Korea Working Group
Establishment of FIDO Korea Working Group
 
XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용
XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용
XECon2015 :: [3-3] 김찬희 & 전창완- 네이버 아이디 로그인 소개 및 Laravel 적용
 
FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)
FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)
FIDO2 Overview & RaonSecure Integration Case Study (Korean Language)
 
Encrypted media extention
Encrypted media extentionEncrypted media extention
Encrypted media extention
 
Hyperconnect pycon 2019
Hyperconnect pycon 2019Hyperconnect pycon 2019
Hyperconnect pycon 2019
 
드론 관제 기술동향
드론 관제 기술동향 드론 관제 기술동향
드론 관제 기술동향
 
FIDO Ecosystem with Integration of Blockchain (Korean)
FIDO Ecosystem with Integration of Blockchain (Korean)FIDO Ecosystem with Integration of Blockchain (Korean)
FIDO Ecosystem with Integration of Blockchain (Korean)
 
AI-IoT 연동을 위한 KT GiGA Genie Home Skills
AI-IoT 연동을 위한 KT GiGA Genie Home SkillsAI-IoT 연동을 위한 KT GiGA Genie Home Skills
AI-IoT 연동을 위한 KT GiGA Genie Home Skills
 
[한국핀테크포럼] 회원사소개: 인터페이
[한국핀테크포럼] 회원사소개: 인터페이[한국핀테크포럼] 회원사소개: 인터페이
[한국핀테크포럼] 회원사소개: 인터페이
 
Rfid asset managesystem
Rfid asset managesystemRfid asset managesystem
Rfid asset managesystem
 
RFID Asset Manage System
RFID Asset Manage SystemRFID Asset Manage System
RFID Asset Manage System
 
[Nsb] kisa 세미나자료 2016_11_17
[Nsb] kisa 세미나자료 2016_11_17[Nsb] kisa 세미나자료 2016_11_17
[Nsb] kisa 세미나자료 2016_11_17
 
Oracle autonomous blockchain cloud service
Oracle autonomous blockchain cloud serviceOracle autonomous blockchain cloud service
Oracle autonomous blockchain cloud service
 
2015 n tels iot product lineup_2015
2015 n tels iot product lineup_20152015 n tels iot product lineup_2015
2015 n tels iot product lineup_2015
 
2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx
2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx
2020.07.14 PWJ SunTechI IoT 소개자료 (최종) (2).pptx
 
Sotis 소개
Sotis 소개Sotis 소개
Sotis 소개
 
[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기
[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기
[BRK30137]윈도우 헬로우와 FIDO인증이 적용된 Kubernetes시스템 구현하기
 
[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사
[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사
[Blt] 기술경영을 위한 ip포트폴리오 전략 20160305 유철현 변리사
 

More from FIDO Alliance

FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdfFIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdfFIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: CloudGate.pdf
FIDO Alliance Osaka Seminar: CloudGate.pdfFIDO Alliance Osaka Seminar: CloudGate.pdf
FIDO Alliance Osaka Seminar: CloudGate.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdf
FIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdfFIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdf
FIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: Welcome Slides.pdf
FIDO Alliance Osaka Seminar: Welcome Slides.pdfFIDO Alliance Osaka Seminar: Welcome Slides.pdf
FIDO Alliance Osaka Seminar: Welcome Slides.pdf
FIDO Alliance
 
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FIDO Alliance
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
FIDO Alliance
 
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdfHow Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
FIDO Alliance
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
FIDO Alliance
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
FIDO Alliance
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
FIDO Alliance
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
FIDO Alliance
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
FIDO Alliance
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
FIDO Alliance
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
FIDO Alliance
 

More from FIDO Alliance (20)

FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdfFIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
FIDO Alliance Osaka Seminar: LY-DOCOMO-KDDI-Mercari Panel.pdf
 
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdfFIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
FIDO Alliance Osaka Seminar: NEC & Yubico Panel.pdf
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
FIDO Alliance Osaka Seminar: CloudGate.pdf
FIDO Alliance Osaka Seminar: CloudGate.pdfFIDO Alliance Osaka Seminar: CloudGate.pdf
FIDO Alliance Osaka Seminar: CloudGate.pdf
 
FIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdf
FIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdfFIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdf
FIDO Alliance Osaka Seminar: PlayStation Passkey Deployment Case Study.pdf
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
FIDO Alliance Osaka Seminar: Welcome Slides.pdf
FIDO Alliance Osaka Seminar: Welcome Slides.pdfFIDO Alliance Osaka Seminar: Welcome Slides.pdf
FIDO Alliance Osaka Seminar: Welcome Slides.pdf
 
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
 
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdfHow Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
 

Introduction to FIDO2 (Korean Language)

  • 1. All Rights Reserved | FIDO Alliance | Copyright 2018 1 FIDO 2 인증기술 소개 한국전자통신연구원 정보보호연구본부 조상래
  • 2. All Rights Reserved | FIDO Alliance | Copyright 2018 2 발표내용 1. FIDO 개념 2. FIDO 1.0과 FIDO2 구조 3. FIDO 2 인증장치 4. FIDO 2 활용
  • 3. All Rights Reserved | FIDO Alliance | Copyright 2018 333333 FIDO 이전
  • 4. All Rights Reserved | FIDO Alliance | Copyright 2018 444444 FIDO 개념 ▶사용자 인증과 원격 인증 프로토콜의 분리 • 사용자 인증수단은 바이오, 토큰, 패턴 등 다양 • 원격 인증은 공개키 기반 단일 방식 ☞ 서버 변경 없이 다양한 인증 수단 사용
  • 5. All Rights Reserved | FIDO Alliance | Copyright 2018 555555 FIDO 1.0 구조 Relying PartyUser Device Application App. Server FIDO Server FIDO Client ASM Authenticator UAF Protocol (등록/인증/해지)
  • 6. All Rights Reserved | FIDO Alliance | Copyright 2018 666666 FIDO 2 필요성 FIDO 2, 왜 필요한가? ▶ FIDO 클라이언트 보급 해소 • FIDO 1.0 클라이언트의 배포주체 모호 • 플랫폼에서 기본 제공해 문제 해결 ▶ 웹(Web)에서도 바이오인증 요구 • W3C 표준화로 모든 웹브라우저에 FIDO 기술 적용 목표 ▶ UAF와 U2F 통합 필요 • 인증서비스에 대해 모바일과 웹에서 동일한 사용자 경험 제공 ▶ 플랫폼 주도권 확보 전략 • 결제 및 온라인 서비스의 첫 번째 관문인 인증 기술을 플랫폼 내 수용
  • 7. All Rights Reserved | FIDO Alliance | Copyright 2018 User Device 777777 FIDO2 구조 Relying Party Application App. Server FIDO2 Server OS/Browser (FIDO Client) 개발자 API / WebAuthn API FIDO CTAP 자체 프로토콜 (등록/인증) 인증장치에서 서버로 보내는 메시지 CTAP - Client-To-Authenticator Protocol
  • 8. All Rights Reserved | FIDO Alliance | Copyright 2018 888888 Web Authentication API Relying PartyUser Device Web App App. Server FIDO2 Server Web Browser 자체 프로토콜 (등록/인증) Built-In Authenticator ▶ Web Authentication API ? • 웹앱에서 웹브라우저의 FIDO 기능을 호출하기 위해 사용하는 자바 스크립트 API • 인증장치를 FIDO 서버에 등록 및 인증하기 위한 기능 제공 • 인증장치가 등록 및 인증에서 사용하는 메시지 포맷 정의 • 다양한 사용 시나리오를 위한 확장 기능 (위치, 바이오 인덱스) 제공
  • 9. All Rights Reserved | FIDO Alliance | Copyright 2018 999999 FIDO2 Authentication Ceremony – Registration or Authentication Authorization Gesture - User Consent User Presence User Verification User Touch Button pressed Fingerprint Retina Scan Face Recognition
  • 10. All Rights Reserved | FIDO Alliance | Copyright 2018 101010101010 FIDO 인증장치 개념 FIDO Authenticator Framework Attestation Key Interface Authentication Keys User Verification Transaction Confirmation Display Platform ▶ 사용자 인증 • 지문, 홍채, PIN, etc. ▶ 키 생성 • 인증 키 생성 ▶ 전자서명 생성 • 등록 및 인증 • 거래 확인
  • 11. All Rights Reserved | FIDO Alliance | Copyright 2018 111111111111 FIDO2 인증장치 Webauthn API Cross Platform Authenticator CTAP Mobile/PC Application Wep Application Non-Platform API (SW Authenticator) Platform FIDO API Platform authenticator (SW or HW) CTAP (USB, NFC, BLE) Android/iOS Application
  • 12. All Rights Reserved | FIDO Alliance | Copyright 2018 121212121212 CTAP Protocol ▶ Client To Authenticator Protocol ? • 외부 인증장치를 위한 플랫폼 독립적인 범용 API 및 프로토콜 정의 • 플랫폼 연결 방법으로 USB, NFC, Bluetooth 지원 • CTAP은 스마트폰을 인증장치로 이용하여 다른 디바이스에 인증 가능 • O2O 서비스에서 FIDO 인증을 적용할 수 있는 기반 제공 USB Bluetooth FIDO 기능 지원 디바이스
  • 13. All Rights Reserved | FIDO Alliance | Copyright 2018 131313131313 FIDO 1.0과 FIDO2 비교 UAF - Universal Authentication Framework ASM - Authenticator Specific Module CTAP - Client-To-Authenticator Protocol
  • 14. All Rights Reserved | FIDO Alliance | Copyright 2018 141414141414 FIDO2 활용 ▶스마트폰 -> PC / 브라우저 (FIDO2) • 모든 플랫폼에 FIDO 서비스 이용 가능 ▶서버 인증 -> 주변기기 인증 • IOT환경에 사용자 인증 기술로 활용 ▶온라인 -> 오프라인 • O2O 서비스에 다양하게 활용
  • 15. All Rights Reserved | FIDO Alliance | Copyright 2018 151515151515 맺으며… ▶플랫폼에 FIDO 기능 장착 • 운영체제 -> Windows & Android • 웹브라우저 -> W3C 표준화로 Edge, Chrome, Firefox ▶다양한 인증장치의 증가 • 플랫폼 기반의 빌트인 인증장치 제공 • USB, Bluetooth, NFC 기반의 외부 인증장치 사용 가능 ▶FIDO와 연계한 다양한 인증서비스 가능 • 무자각 인증기술 • 바이오 키 생성 기술 • 블록체인 기술
  • 16. All Rights Reserved | FIDO Alliance | Copyright 2018 161616161616 조상래 (sangrae@etri.re.kr) 감사합니다