SlideShare a Scribd company logo
1 of 22
Download to read offline
FIDO CERTIFICATION PROGRAM
Brett McDowell, Executive Director, FIDO Alliance
Hidehito Gomi, Senior Chief Researcher, Yahoo Japan!
Research, Yahoo Japan Corporation
Deployments are enabled by
FIDO Certified™ Products
available today
2
• Ensure interoperability between FIDO officially
recognized implementations
Certification Goals
• Enable implementations to be identified
as officially FIDO certified
• Promote the adoption of the FIDO ecosystem
4
ü Available	to	anyone
ü Ensures	interoperability
ü Promotes	the	FIDO	ecosystem
Steps	to	certification:
1. Conformance	Self-Validation
2. Interoperability	 Testing
3. Certification	 Request
4. Trademark	 License	 (optional)
fidoalliance.org/certification
Getting Ready
• Standards: UAF and U2F
• UAF & U2F 1.0 implementations certified and
in market now
• Strongly encourage servers to support
both UAF & U2F
• Prep note to UAF Authenticators
• Get a Vendor ID
• Register your metadata
• Only required for UAF Authenticators!
Self-Conformance
• Goal: test implementations using online tools to ensure
conformance with specifications
• Both positive and negative testing
• Check corner-cases that might occur only rarely in the real world
• Self-Conformance Validation Process
• Request access to test tools
• Review online help
• Run tests – as many as you would like
• Perform official test and submit results
• Next step: interop interoperability testing
• Pro tip:
• UTHS – code development required
• UTHS - Requires registration with gmail account: create one for your
team
• UAF – partners required for generating messages
Interoperability Testing
• Goals: implementations work together, no problems in the
“real world”
• Separate events for UAF and U2F, same format
• Interop Logistics
• Registration open ~4-6 weeks ahead of time
• Registration closes 14 days ahead of event
• Must pass self-conformance validation first
• In-person attendance preferred, remote attendance if necessary
Interop Criteria
• What happens at interoperability event
• Test with every other implementer at the event
(interoperability)
• Perform normal, real-world actions: register,
authenticate, etc.
• How to pass
• Show that each action with every other
implementer works
• Should issues arise: adjust and retest
• After passing interop: Certification registration
• Pro-tip:
• Pre-testing is the key to success – don’t wait for the interop to start testing
• Pre-testing opt-in available during registration and begins 14 days ahead
of event
Testing Matrix
Example) UAF Interop Event on Apr. 30th, 2015
Server Client Authenticator
Yahoo Japan ETRI NTT DOCOMO
(Fujitsu)
Yahoo Japan Nok Nok Labs QualComm
Yahoo Japan Egistec NTT DOCOMO
(Sharp)
Yahoo Japan Samsung Egistec
Yahoo Japan Samsung SDS Crucialtec
Yahoo Japan Raonsecure Nok Nok Labs
… … …
Real experiences:
• Performed testing with other
participants who I met for the
first time at the event.
• difficult to form a combination
(with client and authenticator)
smoothly.
• Co-worked together with
participants to solve some
problems we met.
Certification
• Requires passing the test tool
and attending an interop
• Certificate will be granted
ASAP, pending
documentation verification;
plan on 10 business days to
be conservative
• All certifications will be public
(on FIDO website) unless
confidentiality is requested
Test is a good opportunity
Tips from real experiences:
1. Self-checking is very important. Validating your
implementation on schema/protocol level is needed
before in-person testing.
2. Interoperability testing is effective to demonstrate the
conformance of your implementation to the specs.
3. Your certification is appealing all over the world.
Derivatives
• Same implementation, different product
• Reasonable caveats apply: bug fixes, etc.
• Designed to lower cost and effort in FIDO
certification
• Hundreds of SKUs; not hundreds of interops
• Lower registration fee for derivatives (next slide)
• Self-Validation and Interop not required
• Uses “derivative test plan” instead
• Must reference original certificate
Certification Fees
• Certification:
• Member: $5,000
• Non-Member: $6,500
• Per certification
• Derivatives:
• Member: $500
• Non-Member: $750
• Per Derivative
• Vendor ID : $3,000 (one-time)
• Credited towards first
certification if used in first 12
months
• Interop: Free!
• Test Tools: Free!
CERTIFICATION FEES OTHER FEES
Certification Mark Usage
• Authenticators / Clients
• Execute Trademark Licensing Agreement (TMLA)
• Relying parties
• “Clickless” license for logo usage
• Enables millions of logo users without the logistical overhead
• One logo, two badges:
What to with your FIDO logos
• Put FIDO logos on your website
• Write a press release
• Put FIDO in your apps
• Put FIDO on your product briefs
• Put FIDO in your tradeshow booth
CERTIFICATION STATISTICS
17
By The Numbers:
Number of Companies
11
40
FIDO
Ready
FIDOCertified
By The Numbers:
Number of Implementations
5
25
10
49
FIDO
Read
y
FIDO
Certified
FIDOCertified
FIDO
Ready
By The Numbers:
Implementation Types
0
5
10
15
20
25
30
35
Client
Authenticator
Server
Call To Action
• Get certified now!
• Get started with specifications at:
https://fidoalliance.org/specifications/download/
• Register for Test Tool access:
http://fidoalliance.org/test-tool-access-request/
• Next interops:
• UAF, December9-10, NTT DOCOMO to host at: DOCOMO Innovations,
Inc., 3240 Hillview Ave, Palo Alto, CA 94304
• U2F, December8, Google to host at: 1300 Crittenden Ln, Mountain
View, CA 94043
• Thank you to our generous interop hosts!
• Registration open now: https://fidoalliance.org/interop-registration/
• Contact us for help and answers:
info@fidoalliance.org
FAQ
• Do I need a Vendor ID?
• Only if you are a UAF Authenticator
• U2F implementers and UAF Servers / Clients do not require a Vendor ID
• Where do I find the form for…?
• https://fidoalliance.org/certification/
• What is the cost for…?
• Test Tools: free (non-memberaccess: $3,000)
• Interop Events: free
• Certification: $5,000 member, $6,500 non-member
• Derivative Certification: $500 member, $750 non-member
• TrademarkLicense Agreement: free
• Where do I start?
• Registerfor test tool access here:
https://fidoalliance.org/test-tool-access-request/

More Related Content

What's hot

What's hot (20)

NTT DOCOMO Deployment Case Study: Your Security, More Simple
NTT DOCOMO Deployment Case Study: Your Security, More SimpleNTT DOCOMO Deployment Case Study: Your Security, More Simple
NTT DOCOMO Deployment Case Study: Your Security, More Simple
 
FIDO2 & Microsoft
FIDO2 & MicrosoftFIDO2 & Microsoft
FIDO2 & Microsoft
 
Introducing FIDO Device Onboard (FDO)
Introducing  FIDO Device Onboard (FDO)Introducing  FIDO Device Onboard (FDO)
Introducing FIDO Device Onboard (FDO)
 
Google Case Sudy: Becoming Unphishable: Towards Simpler, Stronger Authenticaton
Google Case Sudy: Becoming Unphishable: Towards Simpler, Stronger AuthenticatonGoogle Case Sudy: Becoming Unphishable: Towards Simpler, Stronger Authenticaton
Google Case Sudy: Becoming Unphishable: Towards Simpler, Stronger Authenticaton
 
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
FIDO Authentication in Korea: Early Adoption & Rapid InnovationFIDO Authentication in Korea: Early Adoption & Rapid Innovation
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
 
FIDO Authentication & Blockchain
FIDO Authentication & BlockchainFIDO Authentication & Blockchain
FIDO Authentication & Blockchain
 
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -NadalinNew FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
 
Fido China Working Group (FCWG)
Fido China Working Group (FCWG)Fido China Working Group (FCWG)
Fido China Working Group (FCWG)
 
U2F Tutorial - Authentication Tokens for Enterprise and Consumers
U2F Tutorial - Authentication Tokens for Enterprise and ConsumersU2F Tutorial - Authentication Tokens for Enterprise and Consumers
U2F Tutorial - Authentication Tokens for Enterprise and Consumers
 
FIDO Certified Program: Status & Futures
FIDO Certified Program: Status & FuturesFIDO Certified Program: Status & Futures
FIDO Certified Program: Status & Futures
 
The State of FIDO
The State of FIDOThe State of FIDO
The State of FIDO
 
FIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical Overview
 
Market Study on Mobile Authentication
Market Study on Mobile AuthenticationMarket Study on Mobile Authentication
Market Study on Mobile Authentication
 
FIDO Certification
FIDO CertificationFIDO Certification
FIDO Certification
 
NTT DOCOMO Deployment Case Study: Your Security, More Simple.
NTT DOCOMO Deployment Case Study: Your Security, More Simple.NTT DOCOMO Deployment Case Study: Your Security, More Simple.
NTT DOCOMO Deployment Case Study: Your Security, More Simple.
 
FIDO Specifications Overview: UAF & U2F
FIDO Specifications Overview: UAF & U2FFIDO Specifications Overview: UAF & U2F
FIDO Specifications Overview: UAF & U2F
 
A First Step to a World without Passwords
A First Step to a World without PasswordsA First Step to a World without Passwords
A First Step to a World without Passwords
 
FIDO in Government
FIDO in GovernmentFIDO in Government
FIDO in Government
 
FIDO, Federation & Facebook Social Login
FIDO, Federation & Facebook Social LoginFIDO, Federation & Facebook Social Login
FIDO, Federation & Facebook Social Login
 
2018 12-07 tokyo-seminar Brett McDowell
2018 12-07 tokyo-seminar Brett McDowell2018 12-07 tokyo-seminar Brett McDowell
2018 12-07 tokyo-seminar Brett McDowell
 

Similar to Fido Certification Program Process

Similar to Fido Certification Program Process (20)

FIDO Certification Program Updates
FIDO Certification Program UpdatesFIDO Certification Program Updates
FIDO Certification Program Updates
 
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
OpenID Foundation Workshop at EIC 2018 - OpenID Certification UpdateOpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
 
Testistanbul 2016 - Keynote: "Why Automated Verification Matters" by Kristian...
Testistanbul 2016 - Keynote: "Why Automated Verification Matters" by Kristian...Testistanbul 2016 - Keynote: "Why Automated Verification Matters" by Kristian...
Testistanbul 2016 - Keynote: "Why Automated Verification Matters" by Kristian...
 
OpenID Certification Program Update - 2017-10-16
OpenID Certification Program Update - 2017-10-16OpenID Certification Program Update - 2017-10-16
OpenID Certification Program Update - 2017-10-16
 
Inflectra Partner Program 2022
Inflectra Partner Program 2022Inflectra Partner Program 2022
Inflectra Partner Program 2022
 
OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018OpenID Foundation Certification Program Update - October 22, 2018
OpenID Foundation Certification Program Update - October 22, 2018
 
OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02
 
OIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification UpdateOIDF Workshop 4/29/2019 -- OpenID Certification Update
OIDF Workshop 4/29/2019 -- OpenID Certification Update
 
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
 
ITAM US 2017 Audit Defense Plugging the Leaks
ITAM US 2017 Audit Defense Plugging the Leaks ITAM US 2017 Audit Defense Plugging the Leaks
ITAM US 2017 Audit Defense Plugging the Leaks
 
Experiment Your Way to Product Success: How User Acceptance Testing Can Save ...
Experiment Your Way to Product Success: How User Acceptance Testing Can Save ...Experiment Your Way to Product Success: How User Acceptance Testing Can Save ...
Experiment Your Way to Product Success: How User Acceptance Testing Can Save ...
 
Case Procountor: Zephyr test tool deployment
Case Procountor: Zephyr test tool deploymentCase Procountor: Zephyr test tool deployment
Case Procountor: Zephyr test tool deployment
 
presentation.pptx
presentation.pptxpresentation.pptx
presentation.pptx
 
TechTalk: Getting to Know Perfecto
TechTalk: Getting to Know PerfectoTechTalk: Getting to Know Perfecto
TechTalk: Getting to Know Perfecto
 
TechTalk: Get to Know Perfecto
TechTalk: Get to Know Perfecto TechTalk: Get to Know Perfecto
TechTalk: Get to Know Perfecto
 
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
 
Agile Testing – embedding testing into agile software development lifecycle
Agile Testing – embedding testing into agile software development lifecycle Agile Testing – embedding testing into agile software development lifecycle
Agile Testing – embedding testing into agile software development lifecycle
 
So You Think You Can Write a Test Case - XBOSoft Webinar
So You Think You Can Write a Test Case - XBOSoft WebinarSo You Think You Can Write a Test Case - XBOSoft Webinar
So You Think You Can Write a Test Case - XBOSoft Webinar
 
Keeping Your Continuous Test Automation Continuously Valuable
Keeping Your Continuous Test Automation Continuously ValuableKeeping Your Continuous Test Automation Continuously Valuable
Keeping Your Continuous Test Automation Continuously Valuable
 
Not Your Grandfather's Requirements-Based Testing Webinar – Robin Goldsmith, ...
Not Your Grandfather's Requirements-Based Testing Webinar – Robin Goldsmith, ...Not Your Grandfather's Requirements-Based Testing Webinar – Robin Goldsmith, ...
Not Your Grandfather's Requirements-Based Testing Webinar – Robin Goldsmith, ...
 

More from FIDO Alliance

Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comConsumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
FIDO Alliance
 

More from FIDO Alliance (20)

FIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptxFIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptx
 
IBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptxIBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptx
 
OTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptxOTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptx
 
FIDO Workshop-Demo Breakdown.pptx
FIDO Workshop-Demo Breakdown.pptxFIDO Workshop-Demo Breakdown.pptx
FIDO Workshop-Demo Breakdown.pptx
 
CISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptxCISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptx
 
FIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for All
 
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDOFIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDO
 
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comConsumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
 
新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向
 
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
 
Introduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS ServicesIntroduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS Services
 
富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案
 
テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察
 
「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ
 
YubiOnが目指す未来
YubiOnが目指す未来YubiOnが目指す未来
YubiOnが目指す未来
 
FIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみたFIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみた
 
中小企業によるFIDO導入事例
中小企業によるFIDO導入事例中小企業によるFIDO導入事例
中小企業によるFIDO導入事例
 
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセスVPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
 
CloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワークCloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワーク
 
数々の実績:迅速なFIDO認証の展開をサポート
数々の実績:迅速なFIDO認証の展開をサポート数々の実績:迅速なFIDO認証の展開をサポート
数々の実績:迅速なFIDO認証の展開をサポート
 

Recently uploaded

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 

Recently uploaded (20)

08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 

Fido Certification Program Process

  • 1. FIDO CERTIFICATION PROGRAM Brett McDowell, Executive Director, FIDO Alliance Hidehito Gomi, Senior Chief Researcher, Yahoo Japan! Research, Yahoo Japan Corporation
  • 2. Deployments are enabled by FIDO Certified™ Products available today 2
  • 3. • Ensure interoperability between FIDO officially recognized implementations Certification Goals • Enable implementations to be identified as officially FIDO certified • Promote the adoption of the FIDO ecosystem
  • 4. 4 ü Available to anyone ü Ensures interoperability ü Promotes the FIDO ecosystem Steps to certification: 1. Conformance Self-Validation 2. Interoperability Testing 3. Certification Request 4. Trademark License (optional) fidoalliance.org/certification
  • 5. Getting Ready • Standards: UAF and U2F • UAF & U2F 1.0 implementations certified and in market now • Strongly encourage servers to support both UAF & U2F • Prep note to UAF Authenticators • Get a Vendor ID • Register your metadata • Only required for UAF Authenticators!
  • 6. Self-Conformance • Goal: test implementations using online tools to ensure conformance with specifications • Both positive and negative testing • Check corner-cases that might occur only rarely in the real world • Self-Conformance Validation Process • Request access to test tools • Review online help • Run tests – as many as you would like • Perform official test and submit results • Next step: interop interoperability testing • Pro tip: • UTHS – code development required • UTHS - Requires registration with gmail account: create one for your team • UAF – partners required for generating messages
  • 7. Interoperability Testing • Goals: implementations work together, no problems in the “real world” • Separate events for UAF and U2F, same format • Interop Logistics • Registration open ~4-6 weeks ahead of time • Registration closes 14 days ahead of event • Must pass self-conformance validation first • In-person attendance preferred, remote attendance if necessary
  • 8. Interop Criteria • What happens at interoperability event • Test with every other implementer at the event (interoperability) • Perform normal, real-world actions: register, authenticate, etc. • How to pass • Show that each action with every other implementer works • Should issues arise: adjust and retest • After passing interop: Certification registration • Pro-tip: • Pre-testing is the key to success – don’t wait for the interop to start testing • Pre-testing opt-in available during registration and begins 14 days ahead of event
  • 9. Testing Matrix Example) UAF Interop Event on Apr. 30th, 2015 Server Client Authenticator Yahoo Japan ETRI NTT DOCOMO (Fujitsu) Yahoo Japan Nok Nok Labs QualComm Yahoo Japan Egistec NTT DOCOMO (Sharp) Yahoo Japan Samsung Egistec Yahoo Japan Samsung SDS Crucialtec Yahoo Japan Raonsecure Nok Nok Labs … … … Real experiences: • Performed testing with other participants who I met for the first time at the event. • difficult to form a combination (with client and authenticator) smoothly. • Co-worked together with participants to solve some problems we met.
  • 10. Certification • Requires passing the test tool and attending an interop • Certificate will be granted ASAP, pending documentation verification; plan on 10 business days to be conservative • All certifications will be public (on FIDO website) unless confidentiality is requested
  • 11. Test is a good opportunity Tips from real experiences: 1. Self-checking is very important. Validating your implementation on schema/protocol level is needed before in-person testing. 2. Interoperability testing is effective to demonstrate the conformance of your implementation to the specs. 3. Your certification is appealing all over the world.
  • 12. Derivatives • Same implementation, different product • Reasonable caveats apply: bug fixes, etc. • Designed to lower cost and effort in FIDO certification • Hundreds of SKUs; not hundreds of interops • Lower registration fee for derivatives (next slide) • Self-Validation and Interop not required • Uses “derivative test plan” instead • Must reference original certificate
  • 13. Certification Fees • Certification: • Member: $5,000 • Non-Member: $6,500 • Per certification • Derivatives: • Member: $500 • Non-Member: $750 • Per Derivative • Vendor ID : $3,000 (one-time) • Credited towards first certification if used in first 12 months • Interop: Free! • Test Tools: Free! CERTIFICATION FEES OTHER FEES
  • 14. Certification Mark Usage • Authenticators / Clients • Execute Trademark Licensing Agreement (TMLA) • Relying parties • “Clickless” license for logo usage • Enables millions of logo users without the logistical overhead • One logo, two badges:
  • 15. What to with your FIDO logos • Put FIDO logos on your website • Write a press release • Put FIDO in your apps • Put FIDO on your product briefs • Put FIDO in your tradeshow booth
  • 17. 17
  • 18. By The Numbers: Number of Companies 11 40 FIDO Ready FIDOCertified
  • 19. By The Numbers: Number of Implementations 5 25 10 49 FIDO Read y FIDO Certified FIDOCertified FIDO Ready
  • 20. By The Numbers: Implementation Types 0 5 10 15 20 25 30 35 Client Authenticator Server
  • 21. Call To Action • Get certified now! • Get started with specifications at: https://fidoalliance.org/specifications/download/ • Register for Test Tool access: http://fidoalliance.org/test-tool-access-request/ • Next interops: • UAF, December9-10, NTT DOCOMO to host at: DOCOMO Innovations, Inc., 3240 Hillview Ave, Palo Alto, CA 94304 • U2F, December8, Google to host at: 1300 Crittenden Ln, Mountain View, CA 94043 • Thank you to our generous interop hosts! • Registration open now: https://fidoalliance.org/interop-registration/ • Contact us for help and answers: info@fidoalliance.org
  • 22. FAQ • Do I need a Vendor ID? • Only if you are a UAF Authenticator • U2F implementers and UAF Servers / Clients do not require a Vendor ID • Where do I find the form for…? • https://fidoalliance.org/certification/ • What is the cost for…? • Test Tools: free (non-memberaccess: $3,000) • Interop Events: free • Certification: $5,000 member, $6,500 non-member • Derivative Certification: $500 member, $750 non-member • TrademarkLicense Agreement: free • Where do I start? • Registerfor test tool access here: https://fidoalliance.org/test-tool-access-request/