sms passcode esitysv.4.0

14
SMS PASSCODE® World leading technology in two factor authentication using your mobile phone

Upload: samuli-kallio

Post on 07-Apr-2018

230 views

Category:

Documents


0 download

TRANSCRIPT

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 1/14

SMS PASSCODE®World leading technology in

two factor authenticationusing your mobile phone

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 2/14

SMS Passcode - what we do

+We ensure that users are who they say they are beforethey are granted system access !

Anders Andersen [email protected] +45 5152 9996

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 3/14

Recognized technology leader in new generationtwo-factor authentication via SMS

Citrix Ready Solution of the Year Finalist, May 2010 

One of only 6 finalists in the world

”Product Excellence Award in Two- and multifactor authentication ”, March 2010  

Winner of the Info Security Product Guides Customer Trust Global Excellence Awared

Red Herring Global 100, January 2010 100 most interesting privately held IT companies Globally

Secure Computing Magazine Global Top 5 Innovator in Security, October 2009 

Selected a Top 5 technology by expert panel at the SC World Conference

Tech Tour 25 , August 2009 The Top 25 most promising technology company in Northern Europe

Red Herring EMEA 100, May 2009 

100 most interesting privately held IT companies Globally,

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 4/14

What now?

Challenge- and

Session specific

User name/

Password/

Token

User name/

Password

Personalized

User name

Why two-factor authentication?

Threat level

Time

Just a plain

Connection

60’ies  70’ies  80’ies  90’ies  00’s 

Trash binresearch

Key-logger

Phishing

Phishing/PharmingReal-time

Over Dic.Attacks

Anders Andersen [email protected] +45 5152 9996

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 5/14

The road to the best solution?- More than just user-name and a password 

User ID / ’Strong’ password 

Biometrics Iris-scan

Hardware tokens Grid cards

Mobile softtokens Desktop tokens

Certificates Hybrids

Real-time, challenge & session-based via SMS PASSCODE

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 6/14

SMS PASSCODE® two-factor authentication

PASSCODE 

 

PASSCODE 

Traditional approach SMS Passcode

Username + password, session locking

Challenge: SMS with passcode

Passcode entered

Correct passcode entered from correct PC?

Yes No

Systems access Access denied

1D448AE

1D448AE

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 7/14

SMSPASSCODE®

is atwo-factor

authenticationsystem

Citrix WebInterface

Protection

RADIUSProtection

IISWeb SiteProtection

ISAPI

WindowsLogon

Protection

GINA

Citrix AccessGateway AE

4.5

CitrixiPhone/iPadreciever 2.0

WindowsLogon

Credential Provider 

ISA/TMG

Web Site

Protection

SMS PASSCODE®

AUTHENTICATION CLIENTS 

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 8/14

Industry leading client support 

SMSPASSCODE®two-factor

authenticationEngine

Fault-tolerant and scalable Platform 

Transmitters (one or groups)

User Credentials 

Radius

Web

Sites

Windows

Logon

Citrix Web

interface

Citrix

Access

GatewayAE

Citrix

iPhone

Receiver

Radius, VPN and SSL VPNs: Checkpoint, Cisco, Citrix Access Gateway, NetScaler, Juniper, F5 and other challenge/response supported VPN and SSL VPN systems 

Outlook Web Access 2003/07/ 10 Sharepoint & other portals via UAG Microsoft IIS sites (using Integrated Windows Authentication)RD Web Access with single sign-on 

ISA /

TMG

Gina: Windows XP & Server 2003 VMware View & Virtual Desktops Credentials Provider:  

Windows Vista, Windows 7 and Server 2008 VMware View & Virtual Desktops 

Citrix Web Interface 4.x, 5.x, 6.x 

Citrix Access Gateway Advanced Edition 

ISA/TMG protected Web Sites ISA/TMG VPN access 

Citrix iPhone Receiver 2.1 and later 

GUI Configuration tool

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 9/14

The SMS PASSCODE® solution

INTERNET

SMS PASSCODE® SERVER 

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 10/14

The SMS Passcode solution

INTERNET

Prioritized

Failover

Failover + Load Balancing

Failover

+

Load

Balancing

Anders Andersen [email protected] +45 5152 9996

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 11/14

The SMS PASSCODE solution

Modem groups

• Group modemsaccording to differentneeds (e.g. per country,per GSM service

provider, …) 

Secondary mobilenumbers

• Allocate an additionalmobile number to

selected users(GSM receiver failover)

Load Balancing

Policies

• Create advanced rulesfor detailed loadbalancing on subsetsof modems

• Prefix load balancing

• GSM Service providerload balancing

• GSM receiver failover

• Static passcodes

Advanced Load Balancing

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 12/14

• Flexible reliability for enterprise and hosting

providers –  Advanced load balancing and fail-over policy on many 

attributes

 – Support multiple Active Directories

The SMS Passcode solution 

SMSPASSCOD

Edatabase

AD1 AD1

Customdirectories

Transformation to meet

SMS PASSCODE format

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 13/14

Why SMS PASSCODE ?

The User

• No token hassle

• Cellphone always athand

• Easy, intuitive logonprocedure

• No scratch cardsetc. to worry about

Overall security

• Phishing impossible:• Passcode locked to

the specific session

• Passcode onlygenerated if the user isfound in AD

• Time constrained

• Flash sms –erasedfrom phone

automatically

• Users can block

cellphones 24/7

• Brute force andDoS attack detection

The IT administrator• No token distribution

• No lost or broken tokens

to replace

• Easy administration via AD• Multiple ADs• Multi-domain

• SMS PC installed in a matter

of hours

• Cellphones do not expire – (tokens do)

• Easily scalable - modular

8/4/2019 Sms Passcode Esitysv.4.0

http://slidepdf.com/reader/full/sms-passcode-esitysv40 14/14

The SMS Passcode solution

Anders Andersen asa@smspasscode com 45 5152 9996

• Licensing model

•  Starter Pack (SMS modem + modem license + 5 users)

• Additional users (CALs)

• 1, 2, or 3 years Software Assurance