Strong User Authentication

There's a trend and it doesn't look like stopping. It involves the increase of important information stored on your corporate network combined with the increasing frequency of access to that information from outside your network. Problem!

Do you really know who it is at the other end of the connection? It's a fact that security reliant on static reusable passwords has proven easy for hackers to beat. So what are the alternatives?



There are many different types of authentication methods today. In general, the authentication strength is dependent upon three different factors:
  • Something you know. (eg. passwords)
  • Something you have. (eg. a hardware token, credit card)
  • Something you are. (eg. fingerprints, signature, iridology)

At a minimum, strong authentication must include at least two factors. Passwords alone (one-factor authentication) cannot provide strong user authentication, regardless of their complexity. Nevertheless, strong authentication must be easy to use, inexpensive to own and maintain.

The "things you are" - usually called biometrics - are currently the most expensive and least popular method. As biometric techniques develop, we expect to see usage increase in the future.

The most practical method of enforcing two-factor authentication at present is via the combination of somthing you know (password or PIN) and something you possess (an "authenticator"). Think about what's required to use an ATM. This combination delivers a much more reliable level of user authentication than reusable passwords.

We'd suggest that organisations consider the positive identification of users before they interact with mission-critical data and applications. Typically this occurs through methods such as:

  • VPNs
  • Wireless communications
  • E-mail
  • Intranets
  • Extranets
  • Web servers
  • Other network resources


Related Information:
  • VASCO GO 3...
    Portable, Strong Authentication for Convenience and User Acceptance User acceptance of security tools is a crucial factor in guaranteeing the success of secu...
  • NSW Teachers Credit Union Picks Imprivata for SSO...
    Stronger Endpoint Security, Impressive Simplicity, Better Business Model Teachers Credit Union has selected enterprise security specialist CoreSight for a key ...
  • SMS Strong Authentication...
    SecurAccess from SecurEnvoy - Transforms any phone that can receive text messages into an authentication device SecurAccess allows organisations to provide sta...
  • VASCO Launches Digipass GO5 and GO6...
    Important Strengthening of Digipass "GO" Product Line - Robust and Waterproof Digipass GO5 and GO6 Contribute to VASCO’s "Full Option, All-...
  • VASCO Unveils Business Strategy 2007...
    On January 31, 2007 VASCO Data Security, the world’s number one provider of strong authentication and e-signature products and services, unveiled its busi...
 

Contact Details

Ph: 03 9878 2726
Ph: 02 8011 3337
E: info@coresight.com.au

10/11 Mary St
BLACKBURN VIC 3130

PowerBroker Free Edition

BeyondTrust Tweets

twitter Bird

Quick Login

To download some resources or submit support requests you'll need to register. It's painless, and you'll only need to do this once.



CoreSight Quote

Free Joomla 1.5 Templates by JoomlaShine.com