Sunteți pe pagina 1din 20

Two Factor Authentication

Gemalto PROTIVA Performance, Trust and Security

June 2007

Two-Factor AuthenticationWhat Is it?


Gemalto integrates:
Something you knowYour username and password Something you haveA smart cardbased security device
Generates a one-time password (OTP) Stores a digital identity such as a digital certificate

Know

Have

Gemalto offers simplicity and scalability:


You can adapt Protiva smart cardbased devices easily to meet your organizations infrastructure and security needs.

Are

Two-Factor AuthenticationWhat Is it?


Passwords vulnerable to shoulder surfing,
sticky notes, keyboard logging, IT staff insiders

Two-factor means you


need the card or token to login, access systems, sign documents

Smart cards invulnerable


because security is done in the cards computer, no secrets pass through networks in the clear

Data Breaches Affecting All Sizes of Businesses


A subcontractor, Nationwide Retirement Solutions: Up to 38,443 City of Chicago employees (lost PC) PortTix, Merrill Auditorium's ticketing office in Portland, Maine: 2,000 credit card accounts (Web hack) Madrona Medical Group: 6,000 identities stolen (Web attack by former employee) Belhaven College, Miss.: 300 employees (stolen laptop) AAAAA Rent-A-Space: 13,000 identities with credit cards (Web site security oversight)

93 million identity records reported lost or stolen since ChoicePoint in Feb. 2005
Source: Privacy Rights Clearinghouse

Some Market Drivers


Environmental Drivers
Regulatory compliance: SOX: Enterprise HIPAA or PIPEDA: Healthcare FFIEC: Finance Identify fraud & Phishing are threatening Internet commerce and usage Explosion of remote access devices

Industry moves towards strong authentication


2 factor authentication & smart cards will be widely deployed Microsoft pressing security with new products (CLM - http://www.microsoft.com/technet/clm) Microsoft embedding Gemalto technology in Windows Citrix embedding Gemalto technology in their suite (http://www.citrixready.com/v4/page6.html)

SSO projects are driving strong authentication

The industry needs to build a Trust Ecosystem Bill Gates

Identity Management Business Challenges


Passwords :
the most costly and insecure component of identity management and data security too many passwords to remember and burdened by password policy and frequent password changes End users forget their passwords! End users bypass security measures by
selecting weak passwords re-using the same password for all applications writing passwords down in an insecure location

End users are not satisfied with existing 2 factor authentication methods because of:
Time based solution with no control over One Time Passwords generation Life time of token is set Expensive proprietary solution One device = one application. No room for flexibility

Gemaltos fulfilling your needs: How?


Core Technology: Microprocessor Smart Cards

A Smart Card is a market


established Secure and flexible fully functional computer with 100s of features: - Strong encryption - Ease of customization - Growing space - Multi usage - Multi form factors
Card Tokens Financial card

Corporate card

SIM card

Gemalto: serving you better


$2.2 billion 2005 revenue 2.7 billion in market capitalization 11,000 employees, 65 nationalities at your service 21 production sites, 32 personalization centers, 9 R&D centers and 120 sales and marketing offices R&D spent $146 million in 2005; 1500 R&D engineers to fulfill your needs

Some of Gemaltos Smart Card Users?

Over 1 Billion Gemalto Smart Cards shipped in the world

Why?
High value information Password resets
Insider threats

Customer concern Brand impact

Telecommuting

SarBox, GLB, HIPAA, HSPD 12, BASEL II

$15 millionamount FTC fined ChoicePoint


Source: Computerworld, 1-26-06

Who needs it: Identifying Opportunities


Customer base who:
Needs identity access management
Supports a mobile workforce and/or online customers Uses strong authentication already but needs a futureproof investment Is upgrading or expanding server architecture and wants to reduce costs per employee Must meet regulatory compliance

What we provide: Your Digital Security Solution


One time Password (OTP):
Smart Card based token or card format Secure authentication for Web access or VPN OTP Dynamically generated by end user on a touch of a button when needed Easy to customize Based on Open Source Protocol - Oath

Public Key Infrastructure (PKI):


Smart Card based token or card format Secure authentication through identity certificates Used for Login Used for VPN access Used for Signature and Encryption of documents

http://www.gemalto.com

http://www.protiva.gemalto.com/

Physical Access:
Secure access with Card form factor to buildings http://www.netsolutions.gemalto.com/

Technology:
Java and .NET Smart Cards Tokens with no set life time (change battery) Cards Card readers Included software with true anti-phishing capability

Protiva: 300 and 500 Series

300 Series: Unconnected

500 Series: Connected

The Key to Your Kingdom:


CITRIX: Strong authentication Citrix ready solutions

Citrix Secure Solution Download

The Key to Your Kingdom:


I-Gel & CITRIX: Strong authentication I-Gel & Citrix ready solutions

Healthcare Solution Download

Microsoft - Replacing Passwords:


Microsoft: Strong authentication Native in Microsoft

Logon

Remote Access

Secure E-mail

Microsoft partner Gemalto "has done a super job on this," said Gates. "We will be using their smart cards internally - each employee will use those to get in and out of the buildings as we used to connect to our machines. We're requiring them. We will completely replace passwords." Bill Gates, keynote address IT Forum, Copenhagen 2004

Computer Lock

Microsoft Solution Download

Adobe Digital Signature:


Adobe: Strong authentication through signature and encryption

Selling Protiva: Competitive Landscape


Multiple device options Future-proof investment with .NET Smart card with multiple applications True antiphishing, key loggers, trojan capabilities PKI, encryption on the same Device, ready today Security of smart card Ease of synchronization TCO (over 5 years)

Gemalto
Secure Computing

$175
$475 $333 $156 $170
Not available

RSA Vasco Aladdin Authenex

Gemalto & RSA Different Positioning


Gemalto
Smart Cards experts Broad form factors Not a stranded asset PKI Capable No additional server hardware No expiration date Does not get out of sync .NET Technology Converged badge Open standards architecture (OATH) Secure manufacturing processes Citrix Ready Preferred Microsoft vendor One pricing for your solution

RSA
Incumbent, helped define the market Well known, name brand Well entrenched at many end users Time Based Proprietary technology

Thank you!

S-ar putea să vă placă și