Completed projects: Authentication system

Projects: Authentication System

2021 – 2024 - Secure management of federated identities: enhancing and extending the SPIFFE architecture.

  • Coordinator: Marcos Antonio Simplicio Junior
  • Description: The term Identity Management (IdM) refers to a set of policies, tools, and mechanisms used to manage the lifecycle of digital identities associated with participants in a system, which includes not only individuals but also possibly software or hardware components. Because IdM systems facilitate the creation, verification, and revocation of identities, as well as their corresponding attributes, they are commonly employed in federated environments. In this type of scenario, an IdM system promotes the portability of digital identities, which are dynamically distributed across different domains. This project focuses on the Secure Production Identity Framework for Everyone (SPIFFE), a federated IdM solution consisting of a set of open-source standards for secure identification of software systems in dynamic and heterogeneous environments. The objective is to identify opportunities for improving SPIFFE/SPIRE from different perspectives, especially security, performance, and functionality. Areas of interest include: scenarios involving SPIFFE credential delegation, exploring the concept of Transitive Identity when integrating SPIFFE with external identification and authentication solutions such as OAuth; and the incorporation of attestations into SPIFFE credentials as they are issued or updated.

2013 – 2016 - Secure key derivation from passwords.

  • Coordinator: Marcos Antonio Simplicio Junior
  • Description: User authentication is essential for protecting information in modern systems, which is usually done through passwords. Given the low entropy of passwords that can be memorized by humans, this approach has the drawback of allowing brute-force attacks, in which the attacker tests various possible character combinations until finding the correct password. To avoid this type of attack, algorithms known as key derivation functions (KDFs) have been developed, such as PBKDF2, bcrypt, and more recently, scrypt. In this context, the objective of this research project is to design a KDF that is more secure than the solutions currently existing, including those mentioned above. (CNPq Universal Project, Category A -- Process 473916/2013-4).

2002 – 2003 – SUA.

  • Coordinator: Tereza Cristina Melo de Brito Carvalho
  • Description: Research Project - Single Authentication System (SUA) Duration: 2 years; Funding: Banco Itaú; Value: R$ 50,000.00 The Single Authentication System was developed by the LARC team for a large Brazilian financial institution in 1998. Users of this company used different services, each with different passwords. With the implementation of the system, a single password is used to access all services. With the unification of the database, it was possible to establish mechanisms to follow the institution's security policy. In addition to the unification of the User Registration Database, a management system for it was developed. The management system allows the system administrator to register, edit, and delete users in the different services, as well as allowing the user to change their password.

2000 – 2000 - Single Authentication System Project – LDAP.

  • Coordinator: Tereza Cristina Melo de Brito Carvalho
  • Description: Evolution of the previously developed system, using LDAP.

1999 – 2000 - Digital Authentication System.

  • Coordinator: Wilson Vicente Ruggiero
  • Description: Specification of the Digital Authentication System developed for the São Paulo State Treasury Department.

1999 – 1999 – SADD.

  • Coordinator: Wilson Vicente Ruggiero
  • Description: Research Project: Digital Authentication - DETRAN SP - SADD Duration: 1 year; Funding: Treasury Department; Value: R$ 150,000.00 To guarantee the veracity of payments made to SEFAZ-SP (São Paulo State Finance Department), LARC specified and proposed a viable Digital Authentication protocol to be implemented through systems currently available at Brazilian bank teller windows. These systems use 40-column printers and could not require many characters to represent the digital signature, as this would take too long to print or type and consequently validate. The data relevant to the payment made is digitally signed, making it difficult to falsify bank documents. The system was implemented in March 2000, allowing for an increase in state revenue. The mechanism adds two lines to bank payment receipts with the digital signature. Every transaction at DETRAN-SP (São Paulo State Traffic Department) that includes manual intervention to finalize a payment requires a digital signature. The system verifies the signature and, if correct, confirms the payment, continuing the transaction. Once you have the authenticated document, you can verify its authenticity solely based on the information printed on the document itself.