Welcome!

Containers Expo Blog Authors: Pat Romanski, Liz McMillan, Elizabeth White, Jyoti Bansal, Yeshim Deniz

Blog Feed Post

Authentication - An Update

Ian Kilpatrick, chairman Wick Hill Group, looks at the current state of authentication and examines the solutions on offer from two companies in Gartner's Magic Quadrant.

123456. Amazingly, surveys show that this is the most popular password for authentication. And simple passwords are still the most used authentication method. However, popularity, in this case, just doesn't equate with success.

Security breaches are becoming a daily occurrence and high profile companies such as Yahoo, Target and Tesco are just some of the famous names amongst the victims of password theft.

Recently, on a Netherlands server, researchers discovered compromised credentials for more than 93,000 websites, including 318,000 Facebook accounts, 70,000 Gmail, Google+ and YouTube accounts, 60,000 Yahoo accounts, 22,000 Twitter accounts and 8,000 LinkedIn accounts.

However, instances like these represent just a fraction of the organisations suffering from password theft. The majority do not publicise the fact, as there is no requirement to notify anyone, nor have they been publicly 'outed.'

So we have a long established way of doing things, that is proven on a daily basis to be inadequate and insecure, yet the majority of companies still use it. How long will this state of affairs last? Will we see another decade of consistent, repetitive authentication failures?

Probably not, because the Darwin principle applies. Those affected by password theft will either come up to the mark, and improve their authentication, or decline and go out of business.

Moreover, strong authentication is on a high growth curve, driven by the multiple waves of change rolling across organisations, both small and large.

Recent developments in computing have led to increasingly fractured and distributed networks, which are harder to protect.

These developments include the growth of mobile computing, remote access, tablets, smartphones and BYOD, together with the increasing popularity of wireless, the cloud, virtualisation and social networking. Alongside this, there has been a rapid growth of data, meaning there is even more to protect than ever before.

Authentication is the most basic step towards protecting networks and while passwords still have a role, that role is increasingly as part of a multi-factor authentication process.

Other forces driving the move towards strong authentication include the increasing pressures on companies to achieve security compliance, with the consequences of failure including hefty ICO fines and possible reputational damage.

Greater press coverage of computer security failures, such as the insecurity of mobiles devices and smartphones, has also had an effect, creating more visibility of the problems.

Authentication types - benefits and disadvantages
Getting the right kind of authentication needs careful thought. A key question is "Is the authentication method something that staff can use relatively easily?" Get something too complicated and you could have problems.

Another key issue is using the right level of authentication. Do you need different levels for different staff, for different applications, for different departments? Is your authentication method flexible enough to cope with that? Broadly speaking, users are looking for authentication methods that provide the best combination of ease-of-use, security, and, of course, cost. Currently, the main options are:

  • weak single-factor authentication (passwords)
  • strong complex passwords, usually with a minimum of characters, including special characters, and recommended to be regularly changed
  • strong two-factor authentication (passwords + something else, such as a token)
  • strong three-factor authentication (passwords + something else, such as a soft token + a mobile phone).

Weak single factor authentication (passwords)
This is the use of single static passwords, still the most common form of authentication and used by most organisations. However, companies are increasingly aware that even if they continue with passwords for part of their workforce, there are employee types such as power workers, knowledge workers, mobile workers and remote workers, where proof of identity is important.

Any password system not collecting and storing passwords in a secure (encrypted) format is fundamentally vulnerable.

Encrypted passwords
While encrypted passwords are more secure than simple passwords, and superficially secure, they are actually at risk of attack by various methods, such as brute force attacks, dictionary attacks and rainbow tables.

Strong complex passwords
That's what many of us use to access our secure online areas and are used in companies to overcome the disadvantages of weak passwords. They need to be not only strong, and typically including special characters or numbers, but also different for different applications, and changed regularly.

Strong complex passwords, when encrypted, are significantly less vulnerable to rainbow tables and similar methods. They are however vulnerable, as many users employ the same passwords for social and online sites as for their business.

Strong authentication
Strong authentication involves one of a range of elements such as hardware tokens, soft tokens, fingerprint recognition, swipe cards and phone as a token, or phone as a recipient of a soft token. Most strong authentication deployments are used together with passwords (two-factor authentication).

Strong two-factor authentication
Strong two factor authentication is a much more secure means of authenticating users onto networks, as it requires two separate security elements.

It comprises something you know (a password) and something you have, e.g. a token, which generates a one-time password (OTP) or a fingerprint. Software and hardware tokens are currently the most popular two-factor solutions, due to their low cost, ease- of-deployment, ease-of-management and the standard of security they provide.

According to Gartner*, hardware tokens still have the largest installed base of any method (70%). In the last few years, however, there has been a move towards the deployment of other types of tokens, including mobile phones, and hardware USBs, such as SafeStick or Ironkey.

The rapid fall in the price of tokens means they are now available from only a few pounds per user per year. That is less than the cost of ONE password-related helpdesk call, so tokens can represent a major cost-saving, as well as an improvement in security.

Strong three factor authentication
This is far superior and involves something you know (e.g. password), something you have (e.g. authentication token) and something you are (e.g. fingerprint, retinal scan, facial recognition). While biometric authentication is obviously more costly and complicated to use, it is appropriate for high security applications/departments such as pharmaceutical R&D, finance, etc.

Trends
Contextual authentication
Contextual authentication is growing, but not yet mainstream. It uses contextual information (such as users' behaviour patterns) to decide whether a user is genuine. It can improve on the use of a password, without the need for traditional two factor strong authentication.

Mobile devices can play a significant role in contextual authentication. They can capture relevant contextual information such as tapping rhythm, voice recognition, facial contours, and iris details.

A strategic view
A growing trend amongst enterprises is to take a more strategic view of authentication. Companies are acknowledging they may need different levels of authentication for different scenarios, different users and different applications. They are looking for one flexible authentication method which can facilitate these different levels. Currently, however, most enterprises and SMEs still tend to use a single authentication method.

The Cloud
The popularity of the cloud should be noted, with researchers predicting that by year-end 2016, about 30% of enterprises will choose cloud-based services as their delivery option for new or refreshed user authentication implementations - up from about 10% today.

Mobile devices
Smartphones and mobile devices are playing a growing part in the authentication scenario. They are already widely used as authentication tokens; they function as fairly powerful computers and are an endpoint in themselves, so need protecting; and they can be used for biometric and contextual authentication.

Two authentication market leaders
Two of the leaders in Gartner's Magic Quadrant for User Authentication* are VASCO and SafeNet.

VASCO
VASCO is a well-known name in authentication and has one of the widest ranges of authentication methods currently available. The company is very strong in the financial sector, government, enterprises and e-commerce, with solutions for companies from SMEs up to the largest enterprises.

Gartner* says VASCO has a "very strong position in this market" and calls the company "a very strong innovator."

Authentication platforms include IDENTIKEY (server software), IDENTIKEY Virtual Appliance, IDENTIKEY Appliance (a hardware appliance), IDENTIKEY Federation Server (a higher end server appliance), DIGIPASS as a Service (private cloud service), and MYDIGIPASS.COM (public cloud service).

IDENTIKEY Server
This is an authentication software suite for organisations of all sizes, with centralised user management, web-based administration, multi-platform support and enhanced reporting features. It verifies authentication requests and centrally administers user authentication policies.

IDENTIKEY Appliance
This is a standalone authentication appliance that secures remote access to corporate networks and web-based applications. It can be used in an unlimited number of applications across a variety of fields, such as online applications, banking applications, enterprise security and remote access.

SMEs
One solution for small businesses from VASCO is DIGIPASS Pack for Remote Authentication. This is an out-of-the-box solution which combines all necessary hardware and software to provide a high level of security to organisations with limited resources and budgets.

Authentication tokens
VASCO offers a very wide range of authentication tokens, with the brand name DIGIPASS, including DIGIPASS Software, DIGIPASS Hardware and DIGIPASS Readers

Go to http://www.wickhill.com/products/vendors/detail/27/Vasco for further information and case studies.

SAFENET
Gartner* says that SafeNet "demonstrated a very sound market understanding, as well as very strong product strategy and innovation." Gartner also says "SafeNet has a strong position in this market…"

SafeNet itself says it has a vision to make two-factor authentication universally available and that it provides inexpensive, easy-to-use, innovative solutions to a large range of clients, worldwide. Clients are in business, government and non-profit organisations.

SafeNet solutions include:
SafeNet Authentication Service
An SaaS (software-as-a service) based authentication platform. This solution comes in four types: a cloud-based service for enterprises, a cloud service for service providers, an onsite solution for enterprises, and an onsite solution for service providers.

It has been designed, says SafeNet, to make two-factor authentication easy to implement and manage. Features include a comprehensive degree of automation to drastically reduce the cost of management, administration, tokens that do not expire and a comprehensive self-service portal that allows users to carry out many functions that would traditionally only have been resolved by the help desk.

SafeNet authentication tokens
SafeNet supports a very broad range of authentication methods and form factors including: OTP hardware and software tokens, OOB, hybrid tokens and phone tokens for all mobile platforms. SafeNet's authentication platform supports a wide variety of 3rd party tokens, such as those from RSA.

Go to http://www.wickhill.com/products/vendors/detail/16/SafeNet for further info and case studies.

ENDS

* Gartner Magic Quadrant for User Authentication, December 2013. Analyst Ant Allan.

Source: RealWire

Read the original blog entry...

More Stories By RealWire News Distribution

RealWire is a global news release distribution service specialising in the online media. The RealWire approach focuses on delivering relevant content to the receivers of our client's news releases. As we know that it is only through delivering relevance, that influence can ever be achieved.

@ThingsExpo Stories
DevOps at Cloud Expo – being held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real r...
SYS-CON Events announced today that Systena America will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Systena Group has been in business for various software development and verification in Japan, US, ASEAN, and China by utilizing the knowledge we gained from all types of device development for various industries including smartphones (Android/iOS), wireless communication, security technology and IoT serv...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend @CloudExpo | @ThingsExpo, June 6-8, 2017, at the Javits Center in New York City, NY and October 31 - November 2, 2017, Santa Clara Convention Center, CA. Learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
SYS-CON Events announced today that Super Micro Computer, Inc., a global leader in compute, storage and networking technologies, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Supermicro (NASDAQ: SMCI), the leading innovator in high-performance, high-efficiency server technology, is a premier provider of advanced server Building Block Solutions® for Data Center, Cloud Computing, Enterprise IT, Hadoop/...
In his keynote at @ThingsExpo, Chris Matthieu, Director of IoT Engineering at Citrix and co-founder and CTO of Octoblu, focused on building an IoT platform and company. He provided a behind-the-scenes look at Octoblu’s platform, business, and pivots along the way (including the Citrix acquisition of Octoblu).
SYS-CON Events announced today that CollabNet, a global leader in enterprise software development, release automation and DevOps solutions, will be a Bronze Sponsor of SYS-CON's 20th International Cloud Expo®, taking place from June 6-8, 2017, at the Javits Center in New York City, NY. CollabNet offers a broad range of solutions with the mission of helping modern organizations deliver quality software at speed. The company’s latest innovation, the DevOps Lifecycle Manager (DLM), supports Value S...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, whic...
SYS-CON Events announced today that Peak 10, Inc., a national IT infrastructure and cloud services provider, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Peak 10 provides reliable, tailored data center and network services, cloud and managed services. Its solutions are designed to scale and adapt to customers’ changing business needs, enabling them to lower costs, improve performance and focus intern...
The 21st International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Digital Transformation, Machine Learning and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding busin...
SYS-CON Events announced today that Enzu will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Enzu’s mission is to be the leading provider of enterprise cloud solutions worldwide. Enzu enables online businesses to use its IT infrastructure to their competitive ad...
Everywhere we turn in our industry we can find strong opinions about the direction, type and nature of cloud’s impact on computing and business. Another word that is used in every context in our industry is “hybrid.” In his session at 20th Cloud Expo, Alvaro Gonzalez, Director of Technical, Partner and Field Marketing at Peak 10, will use a combination of a few conceptual props and some research recently commissioned by Peak 10 to offer a real-world consideration of how the various categories of...
In his opening keynote at 20th Cloud Expo, Michael Maximilien, Research Scientist, Architect, and Engineer at IBM, will motivate why realizing the full potential of the cloud and social data requires artificial intelligence. By mixing Cloud Foundry and the rich set of Watson services, IBM's Bluemix is the best cloud operating system for enterprises today, providing rapid development and deployment of applications that can take advantage of the rich catalog of Watson services to help drive insigh...
SYS-CON Events announced today that SoftLayer, an IBM Company, has been named “Gold Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. SoftLayer, an IBM Company, provides cloud infrastructure as a service from a growing number of data centers and network points of presence around the world. SoftLayer’s customers range from Web startups to global enterprises.
Multiple data types are pouring into IoT deployments. Data is coming in small packages as well as enormous files and data streams of many sizes. Widespread use of mobile devices adds to the total. In this power panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists will look at the tools and environments that are being put to use in IoT deployments, as well as the team skills a modern enterprise IT shop needs to keep things running, get a handle on all this data, and deli...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend @CloudExpo | @ThingsExpo, June 6-8, 2017, at the Javits Center in New York City, NY and October 31 - November 2, 2017, Santa Clara Convention Center, CA. Learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
Five years ago development was seen as a dead-end career, now it’s anything but – with an explosion in mobile and IoT initiatives increasing the demand for skilled engineers. But apart from having a ready supply of great coders, what constitutes true ‘DevOps Royalty’? It’ll be the ability to craft resilient architectures, supportability, security everywhere across the software lifecycle. In his keynote at @DevOpsSummit at 20th Cloud Expo, Jeffrey Scheaffer, GM and SVP, Continuous Delivery Busine...
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm.
SYS-CON Events announced today that EARP Integration will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. EARP Integration is a passionate software house. Since its inception in 2009 the company successfully delivers smart solutions for cities and factories that start their digital transformation. EARP provides bespoke solutions like, for example, advanced enterprise portals, business intelligence systems an...
SYS-CON Events announced today that WineSOFT will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Based in Seoul and Irvine, WineSOFT is an innovative software house focusing on internet infrastructure solutions. The venture started as a bootstrap start-up in 2010 by focusing on making the internet faster and more powerful. WineSOFT’s knowledge is based on the expertise of TCP/IP, VPN, SSL, peer-to-peer, mob...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @CloudExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.