English   Deutsch

Sebastian Rohr: Can authentication be both strong and flexible?

Can authentication be both strong and flexible?
by Sebastian Rohr
sr@kuppingercole.com
The procedures may differ, but the reasons behind them are the same: Companies want to protect themselves from rampant online fraud. And it's not just banks that are starting to deploy so-called "two-tier" or "redundant" security to their customers. The big question, though, remains: Are these systems really safer? Or to put it another way: Are two better than one in the complex world of IT security?

Our gut feeling says yes, but theories sometimes misfire. Take for instance a customer with multiple bank accounts who wants to be able to access all of them while on the road. He may have to lug a load of authentication hardware around wherever he goes. Oh, and don't forget the corresponding reader devices!

On the other side, operators of an online shop or internet service often opt for proprietary solutions, forcing the user to go through the learning process every time he wants to use a new service. There may be safety in confusion, but don't bet on it.

As a rational person, one with an average sense of risk-awareness and an adequately developed understanding of the technology issues, you may sometimes ask yourself whether all this is strictly necessary. After a while, though, we all tend to just give up and submit to life's complexity.

But in fact, there are already alternatives available. Just take highly flexible authentication systems on the market today which generally run under the name "Versatile Authentication Service Platform", or VASP. Most of them allow for simultaneous use of various authentication mechanisms such as user name/password, one-time passwords, certificate-based verification via smartcards, grid cards, challenge-response systems, biometric systems or any combination of the above.

This goes especially for shared applications that perform transaction-based or context-based risk analysis during authentication, something that can be of great benefit to the companies involved. In this case, authentication aims at matching the level of access allowed to the individual transaction or task. True strong authentication is optional in such cases since slightly weaker (and cheaper) methods may suffice. Such systems are usually able to escalate the authentication process by requesting additional bonafides if more sensitive data is needed.

In order to successfully deploy this kind of system, organizations need to model risks and thresholds on experience from previous transactions. If they don't, helpdesks will be inundated with calls from frustrated users and customers complaining about being unable to read email while on vacation or access their corporate data from their home offices. 

A sensible, well thought-out and above all highly flexible authentication strategy should be part of any responsible IT strategy. The tools and tokens are out there for IT departments and system integrators to create strong authentication systems that don't lead to new problems and generally make life miserable for the user. But since there is yet no universal system available, the best method seems to be to opt for end-point centralization using VASP. Choosing the right solution may depend on the number of users, the type of applications involved as well as on available budget, but once in place it can go far towards reducing complexity and increasing security - and that not just in theory, but in actual practice.

Created: 08.03.10, modified: 02.04.10

Information
Newsletter
Kuppinger Cole Identity Management Newsletter
Services
KCP provides strategic consulting services for vendor and user companies covering all areas of identity & access management.
Reports
Use KCP as an independent, objective, and neutral authority on the Market for Identity Management products and solutions
Podcasts
Free audio and video presentations on important IAM-topics
Current surveys
IAM-Studie 2010
PARTICIPATE 
Virtualization Security Trends & Insights
PARTICIPATE 
Blogs
Tim Cole
28.08.2010 11:53
Not Just Any Port in a Storm
READ 
European Identity Conference Blog
27.08.2010 04:45
Google authentication support
READ 
Martin Kuppinger
12.08.2010 11:34
Diving down to the details of access controls
READ 
Sachar Paulus
11.08.2010 10:05
The GRC Marketplace is shaking up: SAP and CA partnering on GRC
READ 
Sebastian Rohr
04.08.2010 20:18
Your token to VISA…
READ 
Felix Gaehtgens
19.02.2010 17:40
Gerry Gebel joins Axiomatics
READ 
Joerg Resch
17.02.2010 11:15
Identity Management is key to Smart Grid Security
READ 
Links
 Kuppinger Cole News

 Kuppinger Cole Podcasts

 Kuppinger Cole on Facebook

 Kuppinger Cole on Twitter

 Visit us at Xing

 IAM-Wiki

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2010 Kuppinger Cole