Microsoft Passport Windows Hello A multifactor authentication system

  • Slides: 22
Download presentation

Microsoft Passport & Windows Hello A multi-factor authentication system built for you and your

Microsoft Passport & Windows Hello A multi-factor authentication system built for you and your users Achieve higher levels of security while reducing costs Increase user convenience with simple unlock gestures

Integrate Microsoft Passport & Windows Hello X Windows 10 apps Enterprise content Edge-friendly websites

Integrate Microsoft Passport & Windows Hello X Windows 10 apps Enterprise content Edge-friendly websites

Best-in-class security standards should not be kept secret Microsoft has contributed this technology to

Best-in-class security standards should not be kept secret Microsoft has contributed this technology to the Fast Identity Online (FIDO) Alliance

Integrate Microsoft Passport & Windows Hello X Windows Hello Edge-friendly websites

Integrate Microsoft Passport & Windows Hello X Windows Hello Edge-friendly websites

Coming soon: Integrate FIDO Devices X FIDO Devices Edge-friendly websites

Coming soon: Integrate FIDO Devices X FIDO Devices Edge-friendly websites

make. Credential get. Assertion

make. Credential get. Assertion

MSAssertion MSCredential. Type //Used as key identifier MSCredential. Type

MSAssertion MSCredential. Type //Used as key identifier MSCredential. Type

MSAssertion MSTransport. Type Embedded MSTransport. Type // RSASSA-PKCS 1 -v 1_5 //JSON Web. Key

MSAssertion MSTransport. Type Embedded MSTransport. Type // RSASSA-PKCS 1 -v 1_5 //JSON Web. Key //Returns NULL //Always return

MSAccount. Info //ignored //Used as key identifier //ignored

MSAccount. Info //ignored //Used as key identifier //ignored

MSCredential. Parameters //Set to RSASSA-PKCS 1 -v 1_5 //ignored

MSCredential. Parameters //Set to RSASSA-PKCS 1 -v 1_5 //ignored

challenge

challenge

MSCredential. Filter MSCredential. Spec //Acceptable list of credential type MSCredential. Spec //Set to "FIDO_2_0"

MSCredential. Filter MSCredential. Spec //Acceptable list of credential type MSCredential. Spec //Set to "FIDO_2_0"

MSSignature. Parameters

MSSignature. Parameters

MSAssertion MSFIDOSignature //UTF JSON Encoded of //{ // Challenge: <>, // User Prompt: <>,

MSAssertion MSFIDOSignature //UTF JSON Encoded of //{ // Challenge: <>, // User Prompt: <>, //} //set to 10000000 // UTF 8 encoding of signature over // (authnr. Data|| SHA-2 Hash of // client. Data)

http: //aka. ms/fidoblog http: //www. w 3. org/Submission/fido-web-api/ http: //www. w 3. org/Submission/2015/SUBM-fido-signature-format-20151120/ http:

http: //aka. ms/fidoblog http: //www. w 3. org/Submission/fido-web-api/ http: //www. w 3. org/Submission/2015/SUBM-fido-signature-format-20151120/ http: //www. w 3. org/Submission/2015/SUBM-fido-key-attestation-20151120/