Using Smart Cards and Token Devices for Authentication

Up to this point, we have been focusing on passwords, which are considered part of the first authentication method: something you know. The second factor of authentication is something you have. For this method, the user must have something in their possession to successfully authenticate. Two common examples are smart cards and token devices.

A smart card is a credit-card sized card that has a certificate embedded in it. It also has electrical contacts that allow data from the card to be read when the card is inserted into a smart-card reader. Figure 3-9 shows a smart card and a smart-card reader.

It’s common for smart cards to also include information about the user, such as a picture ...

Get Microsoft® Windows® Security: Essentials now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.