Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


June 1997

Token-Based Security Add-Ons


RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

So How Do You Use a Token?
An ACE logon is similar to a standard NT logon. Users press Ctrl+Alt+Del to bring up the NT security box, and enter a logon name and a password. The ACE/Client presents a second window, as Screen 1 shows, to prompt for a passcode, which is the user's PIN plus token code.

Authentication occurs when the ACE/Server recognizes the passcode. The authentication server knows the SecurID hash algorithm and has a database record of the secret key (the numeric seed) each token uses. When the server receives the authentication request, it validates the user's PIN from the server database and then independently computes the code for that user's SecurID token for the current 60-second window of time. The server then matches the resulting passcode against the passcode the user entered.

The ACE/Server system is time based (each passcode is valid for only 60-seconds), and each SecurID token has an internal timestamp. If 60 seconds is too large a window, you can implement 30-second passcodes instead.

Time synchronization is critical to prevent the ACE/Server system from calculating the wrong passcode. To allow for imprecision in the token's measure of the current time, the authentication server tracks, records, and adjusts for any historic time drift in each token's clock-chip. The server calculates a passcode not only for that current time but also for the 60-second time slot that preceded it, and the next time slot in sequence.

End-User Responsibilities
For a token-based authentication system to operate effectively, end users must know that the system is not a panacea. The ACE/Server system assumes the users will protect their PIN. After someone has the user's PIN and physical token, that person can masquerade as the legitimate user and gain system access.

Why Trust the System?
Security Dynamics does not reveal or publish details about the secret keys that the company programs into each token. That secrecy makes some security people a little nervous about potential flaws within the ACE architecture. The only public information provided about the secret keys is that each secret key programmed into a SecurID token is random and unique (no two tokens have the same secret key) and that each is significantly longer than the 56-bit key used in the Data Encryption Standard (DES). This approach implies that a brute force attack against the ACE/Server architecture is possible but such an attack would be extremely expensive and time consuming.

Security Is the Answer
Sharing information across networks and over the Internet can put sensitive and confidential information in a precarious position. A token-based two-factor authentication system can help keep your network secure.

DSS NT Logon
AssureNet Pathways (formerly Digital Pathways)
415-964-0707
Web: http://www.digpath.com
Email: sales@anpi.com
Price: $99
SafeWord Authentication Server & DES Gold Card
Secure Computing
510-827-5707 or 800-333-4416
Web: http://www.safeword.com
Price: Contact Secure Computing for pricing
ACE/Server, ACE/Client, and SecurID token Security Dynamics
800-732-8743
Web: http://www.securid.com
Price: Contact Security Dynamics for pricing

End of Article

   Previous  1  [2]  Next  


Reader Comments
I DON'T GET IT! HOW DOES THE TOKEN BASED SECURITY SYSTEM WORK?
STEP BY STEP (BASIC)

gurdeep November 06, 2003


Mega AS Consulting Ltd developed a new technology product, the CAT - Cellular Authentication Token to provide a commodity product that every business will be able to afford in order to protect its users Server access. This is a Two Factor Authentication generator of One Time Passwords using the popular Cellulars.

The CAT is a stand-alone product that does not use SMS or any type of communications. With no special hardware overhead and no hidden costs this product is the most cost effective product in the security market today.

With benefits like:

Low cost
Ease of use
Multiple OTP accounts management
No hidden costs
No communication or SMS required
Security standards - TFA
Using the cellular and not an additional propriety hardware

This product is the replacement of the old tokens technology used today for securing users access to servers.

With this new technology a new service is now possible – the eAuthentication service where companies who are no willing to purchase the Authentication server package can get the authentication done as a service at Mega AS Consulting Ltd.’s CAT Authentication Server for a monthly charge.

More information at: www.megaas.co.nz


arnnei,arnneisp July 11, 2004 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Deep Dive into Windows Server 2008 R2 presented by John Savill

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement