Find White Papers
Home
About Us
List Your Papers
    
> Arcot > Strong Authentication Technical Whitepaper

Strong Authentication Technical Whitepaper

White Paper Published By: Arcot

In the past, authentication solutions were either easy to use and inexpensive, but insecure (such as username/password) or very secure but expensive or difficult to implement (such as OTP tokens and smart cards). Arcot offers a third option: WebFort, a software-only, two-factor authentication solution. It delivers the right balance of cost, convenience, and strength.



Tags : 
arcotid, pki, multi-factor authentication, strong authentication, cryptographic camouflage, webfort x.509 certificate, public key infrastructure, authentication

Arcot
Published:  Jun 04, 2008
Type:  White Paper
Length:  13 pages


W H I T E P A P E R
®ArcotID
Technical Whitepaper
August 2007®ArcotIDTechnical Whitepaper
W H I T E P A P E R
"Since the invention of Organizations that wish to use strong authentication have a variety of methods frompublic key cryptography which to choose. These methods range from simple username/password mecha-twenty-five years ago, peo- nisms that exist in every operating system to hardware-based one-time passwordple have been struggling to secure the private key (OTP) tokens, biometric, smart card and PKI systems. However, all of these solu-without the assistance tions confirm an old security adage: "inexpensive, easy, and secure - choose two".of hardware. Arcot's In the past, authentication solutions were either easy to use and inexpensive, butinnovative Cryptographic insecure (such as username/password) or very secure but expensive or difficult toCamouflage has solved this implement (such as OTP tokens and smart cards). Arcot offers a third option:problem. Finally there is a ®WebFort , a 100% software, two-factor authentication solution. WebFort deliverscost-effective and conven-ient means to strongly the right balance of cost, convenience, and strength.authenticate users and ®Introducing the ArcotIDtransactions over the At the heart of WebFort is the ArcotID. The ArcotID is An Introduction to Public Key InfrastructuresInternet without the need the only "Software Smart Card" on the market today. It Public Key Infrastructure (PKI) exists to providefor cumbersome hardware." combines the protection for digital IDs like a hardware secure online authentication services. Prior to publicMartin HellmanProfessor Emeritus, smart card with the lower cost and simplicity of a soft- key cryptography, the principle of a "shared secret"Stanford University ware solution. The ArcotID provides strong, two factor formed the basis of authentication. This time-honoredauthentication. It is a 100% software solution that system of passwords, pass phrases, and secret hand-allows organizations to replaces simple shakes required both parties to arrange to share ausername/password or OTP tokens with the strength piece of information. The critical problem was (andof PKI, without changing the user experience. continues to be) how to share a particular piece ofinformation between parties when there is a potentiallyThe ArcotID features an easy-to-use and familiar user- unlimited number of participants. The number of2name/password user interface. It integrates quickly shared secrets grows at the rate of the square (N ) ofwith existing infrastructures with support for standards the number of participants.such as RADIUS-based OTP, SAML, MS CSP andPKCS#11. Unlike traditional software key containers, A better system is a central authority, trusted by allthe ArcotID resists brute-force attacks using patented parties, that is responsible for authenticating every"Cryptographic Camouflage"1 technology to hide the party. This central authority provides all parties withprivate key from would-be attackers. credentials that anyone can verify, based on the char-acteristics of the credential itself. A good example ofIn addition to strong authentication, the ArcotID this is a passport issued by the government. The gov-enables PKI applications such as electronic document ernment requires specific forms of proof of identitysigning, secure email, and secure ecommerce. As before issuing a passport and includes tamper-evidenta 100% software solution, the ArcotID enables organi- technology in the passport itself to reduce the proba-zations to leverage the advantages of Public Key bility of forgery. Once issued, the passport is a self-Infrastructures without the expense and management contained authentication credential.issues inherent with hardware-based secure key stor-age. Public-Key Cryptography1. "Software Smart Cards via Cryptographic Camouflage", D.N. The basis for PKI is Public Key Cryptography, alsoHoover and B. N. Kausik, Proceedings of the 1999 IEEE known as "asymmetric key" cryptography. PublicSymposium on Security and Privacy, IEEE Computer Society.Patent 6,170,058
1ArcotIDWhitepaper
Key cryptography is a form of encryption where two math- Currently, the primary use of digital certificates is forematically related "keys" (seemingly random strings of authentication. The significant advantages of certificate-numbers) can be used to encrypt (scramble) and decrypt based authentication over othe... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search