12.07.2015 Views

CRYPTOCard Strong User Authentication, TEPUM Secura

CRYPTOCard Strong User Authentication, TEPUM Secura

CRYPTOCard Strong User Authentication, TEPUM Secura

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong><strong>Authentication</strong>[ Ayrıntılı bilgi için; info@secura.com.tr ]


Agenda• Securing the Access Points• 2 Factor <strong>Authentication</strong>• <strong>CRYPTOCard</strong> Token Types• SC-1 Smart Card• KT-1 Key Chain• RB-1 Hard Token• ST-1 Soft Token• PT-1 Palm O/S• CRYTOAdmin<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 2


Securing the Access PointsWeb ServerwithCRYPTOWebAgentCitrix ServerwithCRYPTOLogonAgentExchange ServerwithCRYPTOLogonAgentCRYPTOAdminon Funk SBR,MS-IASor CiscoSecure ACS<strong>CRYPTOCard</strong>CRYPTOAdmin<strong>Authentication</strong>Server<strong>CRYPTOCard</strong>CRYPTOAdmin<strong>Authentication</strong>Server Replica<strong>CRYPTOCard</strong><strong>Authentication</strong> PointsRemote <strong>User</strong>with<strong>CRYPTOCard</strong>TokenVPN GatewayRAS/NASLegacy/CostumApplicationwithCRYPTOKitSDKLocal <strong>User</strong>with<strong>CRYPTOCard</strong>TokenMicrosoftWindows ServerwithCRYPTOLogonUnix ServerwithCRYPTOKitPAM<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 3


2 Factor <strong>Authentication</strong>TokenSomething you have+=PINOne-timePassword“18293” Something you know“143-9640” “Bob is Bob”Passwords cannot be re-usedPasswords are unpredictable, non-deduceableNew password every time<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 4


<strong>CRYPTOCard</strong> QUICKLog1. <strong>User</strong> enables token by entering their PIN4. “Authenticated”2. Token Calculates New Password (Response)<strong>User</strong>ID> johnsmithPassword> 143-96403. Password (Response) entered into PC and compared withServer<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 5


Typical End <strong>User</strong> Experience #1CRYPTOAdmin<strong>Authentication</strong> ServerDannxxxxxx“Authenticated”1. <strong>User</strong> inserts Smart Card into Reader3. Select token from the drop-down listPDCBDC2. CRYPTOLogon Dialog Box appears 4. Enter your Token’s PIN<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 6


Typical End <strong>User</strong> Experience #2CTRL+Alt+DelDannCRYPTOAdmin<strong>Authentication</strong> Server143-9640“Authenticated”1. Press Ctrl+Alt+Delete 3. Select <strong>User</strong> Name from drop-down listPDCBDC2. CRYPTOLogon Dialog Box appears 4. Press button on KT-1 to displayResponse<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 7


Token Type: SC-1 Smart Card• Multi-Platform• QUICKLog Mode• Challenge/Response• Digital Signature• Programming• Software• Reprogammable• Multiple Tokens / card• Digital Certificates• Deploy Once Technology<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 8


Token Type: KT-1 Key Chain• Platform Independent• QUICKLog Mode• Programming• Automated (KTI Initializer)• Reprogammable• Deploy Once Technology<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 9


Token Type: RB-1 Hard Token• Platform Independent• QUICKLog Mode• Challenge/Response Mode• Digital Signature Mode• Programming• Manual (step-by-step)• Automated (RBI Initializer)• Reprogrammable• Deploy Once Technology<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 10


Token Type: ST-1 Soft Token• Multi-Platform• QUICKLog Mode• Challenge/Response• Digital Signature• Programming• Software (.tok file)• Reprogammable• Deploy Once Technology• Electronic Distribution<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 11


Token Type: PT-1 Palm O/S• Palm O/S 3.5+• QUICKLog Mode• Challenge/Response Mode• Digital Signature Mode• Programming• Software (.pdb file)• Reprogrammable• Deploy Once Technology• Electronic Distribution<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 12


CRYPTOAdmin Operator InterfaceToolbarToken ListGroup TreeDrag and drop between groupsPreviewPaneGroup users by access rightsCustomize tokens according toyour requirements<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 13


CRYTPOAdmin Supported Applications• VPN Solutions• Cisco VPN 3000 Family• Check Point VPN-1• Nortel Contivity• Netscreen• SSH• RADIUS Compliant VPNs• Firewall Solutions• Cisco PIX• Check Point Firewall-1• Nokia• Watchguard• RADIUS Compliant firewalls• Web Servers/Portals• Microsoft IIS• Apache• Sun One• Cold Fusion• Citrix Nfuse/ICA• ASP, JSP, CFM Pages• Domain Logon• Microsoft Windows NT/2000• Unix (Solaris/Linux)<strong>CRYPTOCard</strong> <strong>Strong</strong> <strong>User</strong> <strong>Authentication</strong>, Page 14


Teşekkür Ederiz.[ Ayrıntılı bilgi için; info@secura.com.tr ]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!