Welcome to TechNet Blogs Sign in | Join | Help

Enterprise IT Identity & Access Management

A Buyer's & Integrator's Guide - WebLog Version 1.0

Syndication

News

Hi, I've moved into an Information Security Research & Strategy role from an IAM Architecture role. So this blog site is retired. I may launch a security blog in the future. Thank you all for visiting!
Authentication Strategy

Authentication is the procedure through which a user or a device or a service (or application) provides sufficient credentials to satisfy access requirements to another service, application, or system.

User Authentication Strategy:

·         Prepare and plan for Strong User Authentication

·      Educate line of business application owners to use standard OS and directory protocol authentication and avoid application custom authentication.

·         Use PKI product for digital certificate service and RMS product for license servic

·         Keep Password logon as temporary authentication method for problematic road warriors

·         Use Kerberos V5 as authentication protocol

·         Use Smartcard/PIN two factor authentication, and evaluate USB Tokens, Wireless Smart Card, Biometrics, TPM authentication

 

Application/Service Authentication Strategy:

·         Use Managed Password (strong password and changed by application itself), Hash, or Software Token for system account

·         Evaluate TPM as long term solution for application/service authentication

 

Device Authentication Strategy:

·         Use EAP-TLS machine cert in conjunction with user smart card cert for wireless LAN access

·         Use Windows Vista (with Network Access Protection feature at server side) for wireless Corpnet LAN connection

·         Use Windows Mobile 2005 (with software cert authentication) for wireless phone device email synchronization

·         Evaluate TPM as long term solution for device authentication

Published Tuesday, June 06, 2006 8:00 AM by Yale Li

Filed under:

Comments

No Comments

Anonymous comments are disabled
Page view tracker