Mutual Authentication, also known as two-way authentication is when two sides of a communications channel verify each other’s identity, instead of only one side verifying the other. Mutual authentication is also known as “two-way authentication” because the process goes in both directions.
In a mutual authentication process, a connection can occur only if the client and the server exchange, verify, and trust each other’s certificates. The certificate exchange occurs by means of the Transport Layer Security (TLS) protocol. The core of this process is to make sure that clients communicate with legitimate servers, and servers cooperate only with clients who attempt access for legitimate purposes.
Mutual authentication is a desired characteristic in verification schemes that transmit sensitive data, in order to ensure data security. Mutual authentication can be accomplished with two types of credentials: usernames and passwords, and public key certificates.
Mutual authentication is often employed in the Internet of Things (IoT). Writing effective security schemes in IoT systems can become challenging, especially when schemes are desired to be lightweight and have low computational costs. Mutual authentication is a crucial security step that can defend against many adversarial attacks, which otherwise can have large consequences if IoT systems (such as e-Healthcare servers) are hacked. In scheme analyses done of past works, a lack of mutual authentication had been considered a weakness in data transmission schemes.
The mutual authentication process involves the following certificates:
- Root CA certificate
Used to identify a certificate authority (CA) that signed a client’s certificate. It is a self-signed certificate that meets the X.509 standard, defining the format of public key certificates. In IoT products, clients upload a root CA certificate or a certificate chain to verify that the certificates that client devices send to edge servers can be trusted.
- Server SSL certificate
Used to identify edge servers to client devices over TLS and to establish a secure connection during the TLS handshake. It is the enhanced TLS certificate that you provide in your property configuration.
- Client SSL certificate
Used to identify client devices to edge servers over TLS. This certificate must meet the X.509 standard, defining the format of public key certificates.
Amsterdam, June 5, 2013 - Gemalto (Euronext NL0000400653 GTO, the world leader in digital security, will supply the Government Printing Works (GPW) of South Africa with Sealys eID cards for their national identity program. GPW will harness Gemalto’s secure embedded software to protect the
MINNEAPOLIS—(August 24, 2018)—Entrust Datacard, a leading provider of trusted identity and secure transaction technology solutions, today announced new, innovative capabilities for the company’s Mobile Smart Credential solution — including Bluetooth functionality which provides automated login and logout support across platforms
FREMONT, Calif., August 23, 2018 — Identiv, Inc. (Nasdaq: INVE) today announced the latest addition to its high-security credential portfolio, uTrust MD Smart Cards. Providing a comprehensive solution for converged physical and logical access control, Identiv’s uTrust MD Smart Card is the
Two-Factor Authentication Market 2018 Global Industry Size, Share, Top Leaders, Historical Analysis, Business Strategy and Industry Segments Poised For Strong Growth In Future 2023
Thursday, August 16th 2018, 8:41 am EDT “Market Research Future” Market Research Future published a research report on “Global Two-Factor Authentication Market Research Report- Forecast 2023” Market Analysis, Scope, Stake, Progress, Trends and Forecast to 2023. Market Scenario: Two Factor
Geneva/New York/Beijing - August 2, 2018 - WISeKey International Holding Ltd ("WISeKey", SIX: WIHN, OTCQX: WIKYY), a leading cybersecurity and IoT company and China Bridge Capital International, a division of China Bridge Capital (CBC) a leading investor in global disruptive