Transcript
Page 1: Quality Tokenless Authentication using SMS

QUALITY TOKENLESS AUTHENTICATION USING

SMS A webinar by

SecurEnvoy and CM TelecomMay 7th 2014

Page 2: Quality Tokenless Authentication using SMS

THE ADDED VALUE OF TOKENLESS

AUTHENTICATIONby

Phil UnderwoodSecurEnvoy

Page 3: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

Quality Tokenless® Authentication using SecurEnvoy and CM-SMS

Page 4: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

How Many Passwords ?

Page 5: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

• “Social engineering”• Finding written password

– Post-It Notes• Guessing password / pin

– Dog/Child’s name/ Birthday• Shoulder surfing

• Keystroke logging– Can be resolved with mouse based entry

• Screen scraping (with Keystroke logging)

• Brute force password crackers– L0phtcrack, Cain & Abel

Problems with passwords

Page 6: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

Two Factor Authentication?

We use it every day

ATM - Chip and PIN

Two Factor is?

Something you own - ATM cardSomething you know

PIN, Secret, Password

Page 7: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

Token Two Factor Types

• Hardware Tokens– Require distribution, synchronising

• Smart Cards– Require distribution, certificate management

• USB Sticks– Require distribution, certificate management

Page 8: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

What the Analysts say

• User eXperience • Several vendors highlighted the increasing

emphasis on UX across all use cases, with such epigrams as "UX is key" and "UX is king.”

"Abusing your employees with poor IT usability is no longer acceptable in today's marketplace.”

– Source Gartner “Magic Quadrant for User Authentication” December 2013

Page 9: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

Tokenless Two factor• Phone as the Authenticator

– 6.9 billion GSM connections(source https://gsmaintelligence.com)

• Tokenless®, via SMS – What about SMS delays– What if I'm in a building with no signal– I’m using my phone to connect to the internet

• Tokenless®, via Voice or eMail

• Tokenless®, via Software– Many different phone interfaces– Massive QA issues– Major support issues– Limited supported phone types– Software deployment problems

Page 10: Quality Tokenless Authentication using SMS

© 2014 SecurEnvoy

WEB/VPN

User Experience?

Page 11: Quality Tokenless Authentication using SMS

SENDING QUALITY SMS MESSAGES

byCas SchalkxCM Telecom

Page 12: Quality Tokenless Authentication using SMS

CONTACT DETAILS

Cas Schalkx

email: [email protected]: @cmtelecom

Page 13: Quality Tokenless Authentication using SMS

GOOD SERVICE DEPENDS ON GOOD SMS

What is a good SMS?– An SMS that is delivered at your phone

in less than 10 seconds.

Why is that difficult….?

Page 14: Quality Tokenless Authentication using SMS

YOUR MESSAGE TRAVELS THROUGH A CHAIN

YouSecurEnvoy

SMS GW

Operator

??

But no SMS Gateway is connected to all

operators around the world

Page 15: Quality Tokenless Authentication using SMS

AND THAT CHAIN MIGHT BE LONG…

YouSecurEnvoy

SMS GW

Operator

Partner

So they use partners to connect to operators.

Page 16: Quality Tokenless Authentication using SMS

… OR EVEN LONGER

YouSecurEnvoy

SMS GW

Operator

Partner

But that partner might use a partner as well.

Partner

Page 17: Quality Tokenless Authentication using SMS

TWO PARAMETERS TO MEASURE QUALITY

YouSecurEnvoy

SMS GW

Operator

Partner Partner

Delivery time (DT) in seconds

Delivery rate (DR) in percentage %

• Reasons for high Delivery Time• Long processing time in the chain• CM can process up to 2000 messages per

second

• Reasons for low Delivery Rate: • Bad phone numbers• Failure somewhere in the chain

Page 18: Quality Tokenless Authentication using SMS

CM IS 24/7 OPTIMIZING ROUTES

YouSecurEnvoy

CMOperator

Partner

Partner

Partner

CM’s Network Operation Center

Based upon DR and DT data we constantly find the best partners to deliver the message to the operator.

We can guarantee 90%> delivery within 10 seconds.

Free Retry service

Page 19: Quality Tokenless Authentication using SMS

WHY CM

We are building the worlds best platform for mobile messaging and payments. Daily proven by

2.7 million messages on 5 continents and in 180 countries.

Direct connections

Approval to work with governments

and banks

High capacity and fast delivery time

Private redundant data center

Around for 15 yearsCommercial SMS available 1993

Open 24/7

Page 20: Quality Tokenless Authentication using SMS

HONORABLE MENTION

Don’t just take our word for it…

Page 21: Quality Tokenless Authentication using SMS

START NOW!

• Try tokenless authentication– Go to www.securenvoy.com and select the 30 day

free trial– During the trial you get free test messages via CM

Telecom

• Improve your SMS delivery– Go to securenvoy.cmtelecom.com and create an

account to start sending using the Global Gateway Priority.

• If you are Dutch; download the whitepaper– www.cm.nl/sectorexpertise/beveiliging– If you speak English, contact me for a translation

([email protected]).

Page 22: Quality Tokenless Authentication using SMS

THANK YOU

PHIL UNDERWOOD – [email protected]

Global Head of Pre Sales

CAS SCHALKX– [email protected]

Product Marketeer

@cmtelecom

cmtelecomtv

+CMTelecomBVBreda

cm-telecom


Top Related