PKI & OTP

Ng Fook Seng said that for business organizations, strong authentication solutions could be available through the integration of personalized smart cards, enterprise identity management systems, and digital certificate services based on Public Key Infrastructure (PKI). These solutions can be implemented in phases within an existing infrastructure – an organization can start with strong authentication based on one-time passwords (OTP) for remote network access, for instance. From there it could migrate to PKI services and federated identity systems using the same infrastructure and end-user devices.

The utilization of smart card-based devices can bind digital identity information to individuals and provide a second factor of authentication in a convenient form factor that can be used anywhere. These devices are used by presenting a personal identification number (PIN), known only by the end-user at the point of service access. Powered by a secure cryptographic processor, they can generate one-time passwords and store identity credentials, data, applications, certificates and public and private keys.

PKI solutions incorporate public and private keys and their certificates with software, encryption technologies, processes and services to enable secure communications and business transactions. Applications include pre-boot authentication, secure network and workstation logon, email encryption, secure data coverage and digital signatures

<< Back to: Dilemma of Choices   Next: Importance of authentication >>

 

 

 

See also...

OTP Technology

More info...

ProtivaTM Tokens & Readers using One-time-pasword

Personal Portable security devices (PPSD)

Unconnected OTP tokens & readers

Connected USB tokens

PKI Technology

More info...