Strong Authentication in details



Similar documents
DIGIPASS Authentication for Windows Logon Product Guide 1.1

IDENTIKEY Server Product Guide

Identikey Server Getting Started Guide 3.1

DIGIPASS Authentication for Sonicwall Aventail SSL VPN

MIGRATION GUIDE. Authentication Server

IDENTIKEY Appliance Administrator Guide

DIGIPASS Authentication for Cisco ASA 5500 Series

Identikey Server Product Guide

IDENTIKEY Server Windows Installation Guide 3.2

DIGIPASS Authentication for Check Point Connectra

DIGIPASS Authentication for Windows Logon Getting Started Guide 1.1

DIGIPASS Authentication for GajShield GS Series

INTEGRATION GUIDE. DIGIPASS Authentication for Salesforce using IDENTIKEY Federation Server

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

DIGIPASS Authentication for Citrix Access Gateway VPN Connections

Secure your business DIGIPASS BY VASCO. The world s leading software company specializing in Internet Security

INTEGRATION GUIDE. DIGIPASS Authentication for F5 FirePass

DIGIPASS Authentication for Microsoft ISA 2006 Single Sign-On for Outlook Web Access

DIGIPASS Authentication for Check Point Security Gateways

INTEGRATION GUIDE. DIGIPASS Authentication for Juniper SSL-VPN

INTEGRATION GUIDE. DIGIPASS Authentication for Google Apps using IDENTIKEY Federation Server

INTEGRATION GUIDE. DIGIPASS Authentication for Cisco ASA 5505

IDENTIKEY Server Administrator Reference 3.1

Identikey Server Windows Installation Guide 3.1

IDENTIKEY Server Windows Installation Guide 3.1

INTEGRATION GUIDE. DIGIPASS Authentication for Citrix NetScaler (with AGEE)

INTEGRATION GUIDE. DIGIPASS Authentication for Office 365 using IDENTIKEY Authentication Server with Basic Web Filter

Identikey Server Administrator Reference 3.1

DIGIPASS Authentication for SonicWALL SSL-VPN

DIGIPASS as a Service. Google Apps Integration

OVERVIEW. DIGIPASS Authentication for Office 365

Identikey Server Performance and Deployment Guide 3.1

DIGIPASS Authentication for Juniper ScreenOS

INTEGRATION GUIDE. General Radius Config

INTEGRATION GUIDE. DIGIPASS Authentication for VMware Horizon Workspace

Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Getting Started

IDENTIKEY Server DIGIPASS BY VASCO. VASCO s next generation authentication server

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

INTEGRATION GUIDE. DIGIPASS Authentication for SimpleSAMLphp using IDENTIKEY Federation Server

Intel Open Day. VASCO and Intel Identity Protection Technology. Richard Zoni Sales Manager Italy VASCO Data Security

INTEGRATION GUIDE. DIGIPASS Authentication for Microsoft Exchange ActiveSync 2007

VASCO Consulting Services

Check Point FDE integration with Digipass Key devices

IDENTIKEY Product Family

DIGIPASS as a Service. Product Guide

Ultra-strong authentication to protect network access and assets

Ultra-strong authentication to protect network access and assets

Ultra-strong authentication to protect network access and assets

Creation date: 09/05/2007 Last Review: 31/01/2008 Revision number: 3

ViSolve Open Source Solutions

Proven. Trusted.

Gründe für Starke Authentifizierung

IDENTIKEY Authentication Server

DIGIPASS CertiID. Getting Started 3.1.0

axsguard Gatekeeper Internet Redundancy How To v1.2

Hyper-V Installation Guide. Version 8.0.0

Apache Server Implementation Guide

Two-Factor Authentication

Intel Identity Protection Technology Enabling improved user-friendly strong authentication in VASCO's latest generation solutions

A Guide to New Features in Propalms OneGate 4.0

RSA SecurID Two-factor Authentication

Digipass for Citrix VM3.0: troubleshooting guide. Creation date: 11/07/2007 Last Review: 30/11/2007 Revision number: 2

PrinterOn Print Management Overview

Secure Web Access Solution

STRONGER AUTHENTICATION for CA SiteMinder

Using Entrust certificates with VPN

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

Internet Redundancy How To. Version 8.0.0

GRAVITYZONE HERE. Deployment Guide VLE Environment

Mobile Admin Security

Check Point FW-1/VPN-1 NG/FP3

Strong Authentication for Secure VPN Access

WHITEPAPER. SECUREAUTH 2-FACTOR AS A SERVICE 2FaaS

RSA Authentication Manager 7.1 Security Best Practices Guide. Version 2

Implementing two-factor authentication: Google s experiences. Cem Paya (cemp@google.com) Information Security Team Google Inc.

DIGIPASS Authentication for Remote Desktop Web Access User Manual 3.4

How To Manage A Plethora Of Identities In A Cloud System (Saas)

Digipass Plug-In for IAS troubleshooting guide. Creation date: 15/03/2007 Last Review: 24/09/2007 Revision number: 3

ADDING STRONGER AUTHENTICATION for VPN Access Control

The Cloud, Mobile and BYOD Security Opportunity with SurePassID

nexus Hybrid Access Gateway

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

ProtectID. for Financial Services

Data Sheet. NCP Secure Enterprise Management. Next Generation Network Access Technology

A dm inistrator Reference

NetIQ Advanced Authentication Framework

DualShield. for. Microsoft TMG. Implementation Guide. (Version 5.2) Copyright 2011 Deepnet Security Limited

RSA Authentication Manager 7.1 Basic Exercises

Swivel Multi-factor Authentication

Configuring IBM Cognos Controller 8 to use Single Sign- On

PRIVACY, SECURITY AND THE VOLLY SERVICE

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

Software Token Security & Provisioning: Innovation Galore!

Transcription:

Strong Authentication in details Kuznetsov Alexander Technical Account Manager

VASCO Core Activities

Overview DIGIPASS DIGIPASS Go Range DIGIPASS E-signature DIGIPASS Reader DIGIPASS for Mobile DIGIPASS Nano Virtual DIGIPASS DIGIPASS for Web DIGIPASS PKI DIGIPASS for Windows 3

Security Level Evolution of Authentication Devices WYSIWYS Keyloggers Virtual keyboards Static Passwords Time-based OTP Phishing Pharming Counter-based OTP Electronic signature MitM Meaningful user prompts MitM with Social Engineering Sophistication Level of Attacks Federal Reserve Briefing 4

Evolution of Authentication platforms Security Cost Ease of Use Flexibility 5

VASCO Software DIGIPASS DIGIPASS Go Range DIGIPASS E-signature DIGIPASS Reader DIGIPASS for Mobile DIGIPASS Nano Virtual DIGIPASS DIGIPASS for Web DIGIPASS PKI DIGIPASS for Windows 6

Market leader: Digipass for Mobile 4.0 Dedicated authentication application in your mobile device Focus: Strong Security! Weak PIN detection, Device Binding, Time+Event Based

DP 4 Mobile: why? Easy to integrate Included web samples Easy to deploy Three provisioning options Easy to use Intuitive graphical user interface Easy to customize Use your own colors and logos for Mobile 8

Supported Mobile Platforms Android OS 2.2 and later ios 4.1 and later BlackBerry OS 5.0 and later MIDP2 compatible devices Windows Mobile / Phone 9

DP 4 Mobile Editions Standard Fully customizable Customer responsible for provisioning process Enterprise Not customizable Only authentication 3DES, Time Based, Decimal 2 VASCO responsible for provisioning process 10

Step 1: Software Package Download Enterprise Server HTTP download + HTTP download + Local Install + HTTP download + Local Install + Local Install 11

Step 2: Activation Modes Offline activation QR code activation Online activation 12

Offline Activation DIGIPASS Serial Number Activation Code (21 Digits) Reactivation Password + Local Password DIGIPASS Serial Number Activation Code Reactivation Password 13

QR Activation 14

Online Activation Identifier + Autorization Code + Nonce 3 4 AAL2GenActivationCodeXErc AAL2GenActivationDataRndKey Encrypted Full Activation Data = (Encrypted with activation password) Static Vector + Serial Number Suffix + Activation Code + Reactivation Counter + Nonce 1 Identifier Authorization Code Activation Password 2 Generate Nonce 5 Activate with activation password 15

Step 3: OTP Post Activation Response 2 1 OTP AAL2VerifyPassword 16

Post Activation Device Binding Response 3 2 Serial Number + Derivation Code AAL2DeriveTokenBlobs 1 Platform Finger Print Can also be done offline 17

Full Picture 18

DP4Mobile Challenge/Response

DP4Mobile - QR Challenge/Response

Customization: Mobile Provisioning 21

Customization: Post Activation 22

Customization: Mobile Settings 23

Customization: Multilanguage One XML file per language \CustomizationTool\input\xml Can also be used for #looks 24

Test your Digipass for Mobile Already now, go get your DIGIPASS at: http://dp4mobile.demo.vasco.com/dp4mobile/

DIGIPASS SDK: Software engine DIGIPASS SDK J2ME (Java, BlackBerry) iphone OS (Objective C) WindowsMobile 5.0+ / Windows Phone Symbian OS (2 nd to 5 th editions) Android Integration partners Clear2pay, Monext, Lemonway mfoundry FundTech Banking applications HSBC GarantiBank Alfa-Bank 26

DIGIPASS: The building blocks A Generated code Secret That changes DIGIPASS Time Event Challenge User Interface Is Protected Encryption Algorithm Storage Parameters Secret Encryption Algorithm Time Human Readable Truncation By VASCO 27

The same concept on a different platform DIGIPASS User Encryption Interface Algorithm Storage Parameters DIGIPASS User Interface User Encryption Interface Algorithm Communication Interface Storage Parameters Storage Platform X Static Vector Secret Core Secret Dynamic Vector Time Shift Time Time DIGIPASS SDK Time Application By VASCO By VASCO 28

Software DIGIPASS: Secure Platform 29

Software DIGIPASS: Platform Scoring Jail broken? Infected? Location? Behavior? 30

Software DIGIPASS: Application Security True Random Key generation Secure Key provisioning Application Signing & Obfuscation Slow Encryption Function Device Binding External Audit 31

Software DIGIPASS: Native Integration 32

DIGIPASS NANO: Secure Component 33

Digipass Nano More Security More Convenience Test your DPNANO sample at SIM Toolkitmenu http://dpnano.demo.vasco.com 34

Intel IPT: Integrated DIGIPASS in your PC Federal Reserve Briefing 35

Intel IPT drivers Hardware security level Regular password logon experience No shipping! Central provisioning Large penetration potential 36

Digipass for Web + Intel IPT DP4Web applet: Activation through VASCO Generate OTP Generate e-signature Supported by all VASCO server solutions 37

VASCO Server Side offering 38

VASCO Identikey Server Single point of Authentication Custom web applications Hardware Software Citrix, OWA, etc. Smart Cards VPN, SSLVPN, Firewall, etc.

Functional architecture Front-End Integration Customer Web Applications Web-based Administration User & DIGIPASS Administration Reporting Command Line TCL Apache Tomcat Webserver IIS Web Applications SEAL SOAP SOAP SEAL Back-End Authentication RADIUS Client RADIUS SEAL RADIUS LDAP via Windows API via Custom API Domain Login PostgreSQL ODBC LDAP/LDAPS AD Active Directory Users & Computers Database Directory

Identikey Server features Authentication and e-signature validation Server Strong authentication validation Transaction data signing e-signature DIGIPASS Family ready (including SMS) Policy based authentication Different policy for each application Automatic creation of users Auto-assigning of the DIGIPASS to the User Easy to Integrate in your front-end application RADIUS protocol (Authentication) SOAP protocol Web-services SAML protocol Federation authentication High-availability and scalability model Load balancing (primary and backup servers) DB availability control service 41

Identikey Server features Centralized Web-based administration interface DIGIPASS & User management Domains & Organizational units Policy management Application management System management Delegated administration > 80 Different administrative priveleges Reporting capabilities 28 standard reports available Custom reports Admin access can be protected by OTP System and performance monitoring capabilities Fully PCI-DSS compliant 42

DIGIPASS Authentication for Windows Logon DAWL features: Offline authentication (up to 30 days) Force OTP Password Randomization PSM Password Synchronization Manager DCR Dynamic Client Registration DNS reverse Lookup Terminal Server authentication `

DAWL Architecture + PSM Windows SEAL Windows LDAP ` SEAL-SSL

What is DIGIPASS as a Service

Supported Types of Authenticators

API vs Web Interface

Availability

MYDIGIPASS.COM 49

MDP: concept Front-end End-user Website 1 2 3 Validation Back-end Validation ok DIGIPASS as a Service 50

MDP: Launch pad & Marketplace 51

MDP: available today 3 types of DIGIPASS Hardware DP GO6 Software Mobile DP Software DP4Web with Intel IPT QR-code autologin 52

DEMO List of valid time-based OTP s Interval between 2 successive time units Additional digits List of valid counter-based OTP s Speeds up verification of an OTP Generated by host Optional Randomly Used for first OTP validation Sent to user Time granularity Standard 32 seconds

Thank You Alex Kuznetsov Technical Account Manager EE-CIS aku@vasco.com

Copyright & Trademarks Copyright 2011 VASCO Data Security. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any means, electronic, mechanical, photocopying, recording, or otherwise, without the prior written permission of VASCO Data Security. Trademarks VASCO, VACMAN, IDENTIKEY, axsguard, DIGIPASS and the logo are registered or unregistered trademarks of VASCO Data Security, Inc. and/or VASCO Data Security International GmbH in the U.S. and other countries Disclaimer of Warranties and Limitations of Liabilities This Report is provided on an 'as is' basis, without any other warranties, or conditions. 55