How adaptive is the CAT?
By Hans-Peter Waldegger Manager Cyber Security, Swisscom B2B
visit https://2023.swisscyberstorm.com/sche... & https://www.swisscyberstorm.com for more information
The following summary was machine generated from the YouTube transcript and then reviewed by human eyes. If you spot any errors, please comment below.
Summary
Presenter: Hans-Peter Waldegger
Title: How adaptive is the CAT?
Category: SCS2023
*Subcategory: Sponsor
Video: • Sponsor Swisscom: How adaptive is the CAT?...
Length: 29:19
Content: Hans-Peter Waldegger discusses the Continuous Adaptive Trust (CAT) system developed at Swisscom B2B, focusing on how it enhances authentication processes for complex B2B environments. The presentation highlights the need for robust authentication mechanisms, the evolution of authentication assurance levels, and the importance of minimizing user inconvenience through adaptive, continuous authentication. Waldegger also addresses challenges related to B2B environments, such as session management and reauthentication.
Keywords:
Continuous Adaptive Trust
Strong Authentication
B2B Security
Authentication Assurance Levels
Session Management
Ideas
The shift from point-in-time authentication to continuous authentication addresses session aging and reduces the need for frequent user reauthentication.
B2B environments have more complex needs than B2C due to multiple concurrent sessions, necessitating advanced session management solutions.
Implementing adaptive authentication involves adjusting authentication requirements based on contextual factors like location and session history, aiming to minimize user disruption.
Effective continuous authentication requires synchronization between session management and identity systems, which can be complex in distributed environments.
Ensuring user trust involves transparent communication about how continuous authentication and location tracking are managed, particularly in B2C contexts.
Quotes
"Access to data and applications need to be protected. How do we do it? Typically, we do it with strong authentication."
"In the B2B area, you have many sessions at the same time, and they all need to be secure and managed."
"If you lose your token, you need to be able to replace it. If you forget your PIN, you need to be able to reset it."
"We try to reduce the number of reauthentications that are required by using continuous authentication methods."
Facts
Swisscom classifies strong authentication into four levels, ranging from basic username and password to advanced cryptographic binding on user devices.
Point-in-time authentication can lead to session risks as the session ages, requiring methods to address session quality deterioration over time.
B2B environments face unique challenges due to multiple concurrent sessions, which complicates the implementation of strong authentication.
Continuous access evaluation protocols, such as OpenID Connect, are used to manage and evaluate authentication states dynamically.
Resources
*OpenID Connect:* Protocol mentioned for continuous access evaluation and sharing authentication information between systems.
*Mobile ID Platform:* Swisscom's central platform for authentication, which includes features like location tracking and fallback methods.
Recommendation
Adopt continuous authentication methods to minimize reauthentication requirements and enhance user experience.
Ensure users are well-informed about how their data and location are used in the authentication process to build trust and comply with privacy regulations.
Develop solutions that address session management complexities in B2B environments, including effective synchronization between authentication systems and session data.