Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > What should an enterprise look for in a password token and a vendor?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What should an enterprise look for in a password token and a vendor?

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 05 September 2008
Our company is looking into using password tokens. What should we look for in a product, and in a vendor?

>
One-time password (OTP) tokens are known as two-factor authentication. They're meant to augment existing user IDs and passwords with an extra layer of authentication. The idea is that if a password is compromised, the OTP device would still have to be broken as well to gain system access.

OTP tokens are usually small pocket-size fobs with a small screen that displays a number. The number changes every 30 or 60 seconds, depending on how the token is configured. The user then enters his or her user ID and PIN number, plus the number displayed on the token in the password field for access to the system.

The choice of a password token should be based on the company's needs. Why do you need tokens, and who will be using them? Are they for employees to access internal systems, or for customers to access externally facing systems, like websites? Are they for compliance with regulations or for beefing up existing authentication to systems hosting high-risk data?

Those questions aside, the choice of password tokens should be based on how well they mesh with existing network and authentication architecture and their ease-of-use and acceptance by employees. Other considerations are maintenance, support and scalability -- how easy are they to support and will they grow as authentication needs expand?

First, OTP tokens should be compatible with existing authentication infrastructure. They should be managed from a central location so users can be provisioned or deleted as required, at will. Authentication credentials from the device should be able to be stored easily in the current directory service, whether Active Directory or LDAP.

Second, the device should be easy for employees or customers to use. If it's difficult, or employees aren't given proper training, they'll figure out ways around the device, which defeats its purpose. Also, as with user IDs and passwords, tokens should never be shared.

Lastly, tokens should be easy for system administrators to install, deploy and maintain. A token-based system should be scalable to handle additional users as a network grows, and the devices should be configurable because the length of the number, or the time it's displayed on the screen, may need to be shorter or longer, based on the business and security requirements. Tokens also need to be purchased, stored and distributed, adding to the cost of maintenance and overhead.

There are a lot of vendors in this space, including EMC Corp.'s RSA division, Aladdin Knowledge Systems Inc., Entrust Inc., VASCO Data Security International, ActivIdentity Inc., and VeriSign Inc. They offer a range of token types from small key chain fobs to mini-calculators.

More information:


BROWSE BY TAG
Identity Management and Access Control,   Security Token and Smart Card Technology,   Enterprise Identity and Access Management,   User Authentication Services,   Two-Factor and Multifactor Authentication Strategies,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Identity Management and Access Control
Is Identity Management as a Service (IDaaS) a good idea?
How to log in to multiple servers with federated single sign-on (SSO)
How to confirm the receipt of an email with security protocols
Learn about enterprise strategy for server virtualization single sign-on
Employee information security awareness training for new IAM systems
Can you combine RFID tag technology with GPS to track stolen goods?
Is there a free enterprise-caliber password-management tool?
Cryptosystem attacks that do not involve obtaining the decryption key
Can any firm or organization get a digital signature certificate?
Should the CTO have domain administrator access?

Security Token and Smart Card Technology
First Data, RSA push tokenization for payment processing
How to log in to multiple servers with federated single sign-on (SSO)
Best Authentication Products
Are 'strong authentication' methods strong enough for compliance?
Risk management must include physical-logical security convergence
RSA researcher Ari Juels: RFID tags may be easily hacked
Portable security storage device could replace OTP devices
Can you combine RFID tag technology with GPS to track stolen goods?
Security token and smart card authentication
Embedded smart card chips are open to hack attacks

Two-Factor and Multifactor Authentication Strategies
Two-factor authentication, vigilance foil password theft
Security on a budget: How to make the most of authentication tools
Best Authentication Products
Best Identity and Access Management Products
Are 'strong authentication' methods strong enough for compliance?
PCI compliance requirement 7: Restrict access
PCI compliance requirement 9: Physical access
Best practices: How to implement and maintain enterprise user roles
Changing times for identity management
RSA researcher Ari Juels: RFID tags may be easily hacked

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication server  (SearchSecurity.com)
Chameleon Card  (SearchSecurity.com)
key chain  (SearchSecurity.com)
key fob  (SearchSecurity.com)
key string  (SearchSecurity.com)
national identity card  (SearchSecurity.com)
security token  (SearchSecurity.com)
smart card  (SearchSecurity.com)
tokenization  (SearchSecurity.com)
two-factor authentication  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts