In modern networks and systems, due to the increase of security breaches using device compromise, it is inevitable to identify the device before connecting to the organization’s networks. Existing approaches such as physically unclonable functions (PUF) that use the devices’ digital fingerprint for authentication, require hardware-level implementation. Hence, it is difficult to implement in a generic environment such as an organizational network that may need to provide access to the devices including Bring Your Own Devices (BYOD). This paper proposes a certificate-based device authentication system for an enterprise network. The proposed system can authenticate both the organizational devices and BYOD by automatically issuing the certificate. It reduces the overhead related to certificate management such as issuance, revocation, renewal, etc., and helps to minimize human interventions, therefore increasing overall efficiency. By implementing the proposed approach, an extra layer of security can be provided to the organization’s network.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Certificate-Based Device Authentication System for an Enterprise Network

  • Aleena Terese George,
  • Hrishikesh Rajendra Neve,
  • N. Muraleedharan

摘要

In modern networks and systems, due to the increase of security breaches using device compromise, it is inevitable to identify the device before connecting to the organization’s networks. Existing approaches such as physically unclonable functions (PUF) that use the devices’ digital fingerprint for authentication, require hardware-level implementation. Hence, it is difficult to implement in a generic environment such as an organizational network that may need to provide access to the devices including Bring Your Own Devices (BYOD). This paper proposes a certificate-based device authentication system for an enterprise network. The proposed system can authenticate both the organizational devices and BYOD by automatically issuing the certificate. It reduces the overhead related to certificate management such as issuance, revocation, renewal, etc., and helps to minimize human interventions, therefore increasing overall efficiency. By implementing the proposed approach, an extra layer of security can be provided to the organization’s network.