|
Low Cost Strong Two-Factor-Authentication
Single Sign-On needs strong authentication. The "sign IA" supports all common types of tokens and smartcards in order to achieve a high security level and to protect the company's intellectual property as well as the client's data. If a token or smartcard solution is already implemented in the landscape, then it can be directly integrated without further programming effort. In a system environment without this authentication hardware (tokens / smartcards) the investment is resulting in high financial expenditures: the cost for each token or smartcard deployed and licence fees for possibly thousands of users. The most cost-effective solution here is the Detack PIN / iTAN Authenticator an Add-On to the "sign IA", developed and maintained by Detack. This IT security solution is based on the common and accepted online banking system, the user receives an indexed tan list, e.g. printed on sealed paper, for each login a new one time valid tan is requested - external attackers will be securely excluded.
The Detack PIN/iTAN Authenticator implements strong two factor authentication without further requirement of cost extensive hardware like tokens or smartcards.
This Add-On to the "sign IA" is not only designed for authentication on numerous applications, it also secures with additional tan requests pre-defined services and transactions. In this case an additional TAN is requested from the user to safeguard against abuse.
On the following live screenshot an example of the compliant logging of the PIN/iTAN Authenticator and various configuration options in the Management Interface is presented:
The Detack PIN/iTAN Authenticator is a stand alone PIN/iTAN authentication and management application. This solution provides user authentication, user management, PIN/iTAN generation and management, user helpdesk and user data printing. As well as the "sign IA" this application can be customized to the client's requirements, starting by the design of the interface and individual TAN lists up to the customization of various functionalities like the compliant logging mechanisms.
|