Ng
Fook Seng said that for business organizations, strong authentication solutions
could be available through the integration of personalized smart cards,
enterprise identity management systems, and digital certificate services based
on Public Key Infrastructure (PKI). These solutions can be implemented in phases
within an existing infrastructure – an organization can start with strong
authentication based on one-time passwords (OTP) for remote network access,
for instance.
From there it could migrate to PKI services and federated identity systems using
the same infrastructure and end-user devices.
The utilization of smart card-based devices can bind digital identity information to individuals and provide a second factor of authentication in a convenient form factor that can be used anywhere. These devices are used by presenting a personal identification number (PIN), known only by the end-user at the point of service access. Powered by a secure cryptographic processor, they can generate one-time passwords and store identity credentials, data, applications, certificates and public and private keys.
PKI solutions incorporate public and private keys and their certificates with software, encryption technologies, processes and services to enable secure communications and business transactions. Applications include pre-boot authentication, secure network and workstation logon, email encryption, secure data coverage and digital signatures
| << Back to: Dilemma of Choices | Next: Importance of authentication >> |