<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3016247286097812909</id><updated>2011-11-27T16:29:57.825-08:00</updated><category term='Mobile Signing'/><category term='Mobile Phone Software Tokens'/><category term='Tablet Security'/><category term='verification'/><category term='Roaming PKI'/><category term='2FA OTP for Web based Email'/><category term='Security as Service'/><category term='Software Certification'/><category term='SquirrelMail Integration'/><category term='Out of Band Authentication'/><category term='Authentication Platform'/><category term='Digital Signature from mobile phone'/><category term='Replace USB token'/><category term='Social Networking  Threats'/><category term='OOBA'/><category term='Security'/><category term='Protection against RSA SecurID Compromise'/><category term='WebSign'/><category term='NFC Security'/><category term='End To End Encryption'/><category term='Multi Factor-Multi Layered Authentication'/><category term='Digital Signing from Phone'/><category term='Mobile PKI'/><category term='Mobile Token'/><category term='Video Security'/><category term='VSIGN'/><category term='Token Trends'/><category term='Non Repudiation'/><category term='transaction authorization'/><category term='2010 IT Security Predictions'/><category term='FIPS compliant Digital Signatures'/><category term='Mobile Sign Wireless PKI'/><category term='Monetization of Authentication Service'/><category term='Digital Certificate Lifecycle'/><category term='Identity Consolidation'/><category term='biometrics'/><category term='MSIGN'/><category term='Facebook mail'/><category term='Cloud Security'/><title type='text'>EzIdentity, Next Generation Authentication Platform</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>15</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-449381029655830704</id><published>2011-04-27T19:11:00.000-07:00</published><updated>2011-04-27T19:18:20.455-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Protection against RSA SecurID Compromise'/><title type='text'>Time to move away from RSA SecurID</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-6Zb2XneVQFg/TbjN4jlDaDI/AAAAAAAAA-4/BS0CYUtpdjc/s1600/RSA1.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 196px; height: 200px;" src="http://4.bp.blogspot.com/-6Zb2XneVQFg/TbjN4jlDaDI/AAAAAAAAA-4/BS0CYUtpdjc/s200/RSA1.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5600452508142233650" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;"One survey indicates 44 percent of businesses are reevaluating their use of security tokens, with another 15 percent speeding up already planned evaluations of alternatives. In banking and financial services specifically, as many as 81 percent of respondents indicated that security concerns surrounding tokens have caused their organization to evaluate the use of out-of-band authentication, with 82% indicating their organization is likely to use phone-based authentication."&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;extracted from - http://www.banktech.com/risk-management/229402308&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;h1&gt;&lt;span style="'font-family:"&gt;&lt;span style="font-size:100%;"&gt;RSA Advanced Persistent Threat (APT)&lt;/span&gt;&lt;/span&gt;&lt;/h1&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;On March 17, 2011, &lt;/span&gt;&lt;a href="http://www.rsa.com/node.aspx?id=3872" target="_blank"&gt;&lt;span style="text-decoration:none;text-underline:nonecolor:#303030;"&gt;&lt;span style="font-size:100%;"&gt;RSA announced&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;sup&gt;&lt;span style="font-size:100%;"&gt;[1]&lt;/span&gt;&lt;/sup&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;span style="'font-size:"&gt;&lt;span style="font-size:100%;"&gt;that a cyberattack on its systems was successful and resulted in the compromise and disclosure of information "specifically related to RSA's SecurID two-factor authentication products". While the full extent of the breach remains publicly undisclosed, RSA states that "this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack."&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;In a filing with the Securities and Exchange Commission (SEC)&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;sup&gt;&lt;span style="font-size:100%;"&gt;[2]&lt;/span&gt;&lt;/sup&gt;&lt;span style="font-size:100%;"&gt;, EMC officially disclosed the breach to investors and regulators. EMC indicated it "does not believe that the matter described in the letter and note will have a material impact on its financial results." The filing was accompanied by a copy of their initial announcement, as well as a &lt;/span&gt;&lt;a href="http://www.sec.gov/Archives/edgar/data/790070/000119312511070159/dex992.htm" target="_blank"&gt;&lt;span style="text-decoration:none;text-underline: nonecolor:#303030;"&gt;&lt;span style="font-size:100%;"&gt;SecurCare Online Note&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;sup&gt;&lt;span style="font-size:100%;"&gt;[3]&lt;/span&gt;&lt;/sup&gt;&lt;span style="font-size:100%;"&gt;, which was made available to their customers. This SecurCare note provides little additional detail, but advises actions that customers should take to protect their infrastructure. These actions fall into the category of best practices, and do not address new risks to infrastructure supporting a SecurID deployment.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;h2&gt;&lt;span style="'font-family:"&gt;&lt;span style="font-size:100%;"&gt;Background on SecurID operation&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;As shown in Figure 1, the SecurID system can be implemented with either a physical hardware token (typically a key-fob or wallet sized card), or a software based token (with implementations for desktop and mobile devices). In either case, the authentication system relies on these tokens to produce a time-synchronized one-time password (OTP) that is unique to a given token and only valid for a brief time.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;v:shapetype id="_x0000_t75" coord spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f" style="font-size:21600,21600;"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;v:formulas&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;span style="font-size:100%;"&gt;   &lt;/span&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;/v:formulas&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;o:lock ext="edit" aspectratio="t"&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" alt="Figure 1. SecurID system implementations." style="width:204pt;height:220.5pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;v:imagedata src="file:///C:\Users\Vikram\AppData\Local\Temp\msohtmlclip1\01\clip_image001.jpg" href="http://www.secureworks.com/research/threats/rsacompromise/image001.jpg"&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/v:shape&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;This function is performed through the use of a proprietary algorithm that uses the current time and an embedded device-specific 128-bit seed to produce a rotating code known as a 'tokencode'. A user authenticates by combining this tokencode with a PIN (Personal Identification Number) to produce a one-time password that is submitted to the server. PINs are not required in all implementations. PINs are created by the user on the first attempted use of a token after deployment or re-assignment. For this reason, PINs may not always be required.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;v:shape id="_x0000_i1026" type="#_x0000_t75" alt="Figure 2. SecurID authentication process." style="width:213.75pt;  height:213.75pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;v:imagedata src="file:///C:\Users\Vikram\AppData\Local\Temp\msohtmlclip1\01\clip_image003.jpg" href="http://www.secureworks.com/research/threats/rsacompromise/image002.jpg"&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/v:shape&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Figure 2. SecurID authentication process&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;A back-end server (known as ACE/Server) holds these same seeds and algorithm, and can thus perform the same calculation to verify a password was generated from the current tokencode. This process is intended to verify that the client possesses a token, but more accurately indicates that they have knowledge of the appropriate seed and RSA's algorithm. The huge number of possible seeds and constantly changing nature of the tokencodes effectively thwart password guessing and interception attacks. It's generally accepted in cryptography that "If the cryptographic algorithm must remain secret in order for the system to be secure, then the system is less secure."&lt;/span&gt;&lt;sup&gt;&lt;span style="font-size:100%;"&gt;[6] &lt;/span&gt;&lt;/sup&gt;&lt;span style="font-size:100%;"&gt;This axiom is commonly known as &lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Kerckhoffs%27s_Principle" target="_blank"&gt;&lt;span style="text-decoration:none;text-underline:nonecolor:#303030;"&gt;&lt;span style="font-size:100%;"&gt;Kerckhoffs's Principle&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;. &lt;/span&gt;&lt;sup&gt;&lt;span style="font-size:100%;"&gt;[7]&lt;/span&gt;&lt;/sup&gt;&lt;span style="font-size:100%;"&gt; The RSA SecurID algorithm is proprietary, but is known to many RSA partners. Efforts have also been made to reverse engineer the algorithm and perform an analysis of the underlying security. &lt;/span&gt;&lt;sup&gt;&lt;span style="font-size:100%;"&gt;[4] [5]&lt;/span&gt;&lt;/sup&gt;&lt;span style="font-size:100%;"&gt; while not fully public, exposure of the algorithm is unlikely to affect overall system integrity.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;However, seed secrecy is critical. An exposure of the seed to a third party may allow duplication of tokencodes, and by extension allow the guessing of PINs and one-time passwords.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;h2&gt;&lt;span style="'font-family:"&gt;&lt;span style="font-size:100%;"&gt;Impact of the Breach on RSA customers&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;Due to RSA's public nondisclosure of specific details regarding the nature of the compromise, the impact of this breach on their customers remains largely unknown. However, based on this information and knowledge of SecurID's operation, it's possible to establish theories as to what information may have been compromised. These theories in turn help to formulate response plans.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;The compromised information may have related to one or more of the following factors, each of which would potentially impact the integrity of the SecurID system to varying degrees:&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; margin-left:36.0pt;text-align:justify;text-indent:-18.0pt;line-height:16.8pt; mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font-size:100%;"&gt;§&lt;/span&gt;&lt;span style="'font:7.0pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Records of seeds used in hardware or software tokens manufactured to date&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; margin-left:36.0pt;text-align:justify;text-indent:-18.0pt;line-height:16.8pt; mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font-size:100%;"&gt;§&lt;/span&gt;&lt;span style="'font:7.0pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Relationship of those seeds to specific token serial numbers&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; margin-left:36.0pt;text-align:justify;text-indent:-18.0pt;line-height:16.8pt; mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font-size:100%;"&gt;§&lt;/span&gt;&lt;span style="'font:7.0pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Relationship of seeds or token serial numbers to specific clients&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; margin-left:36.0pt;text-align:justify;text-indent:-18.0pt;line-height:16.8pt; mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font-size:100%;"&gt;§&lt;/span&gt;&lt;span style="'font:7.0pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Information regarding RSA's SecurID algorithm that could expose mathematical and cryptographic weaknesses&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; margin-left:36.0pt;text-align:justify;text-indent:-18.0pt;line-height:16.8pt; mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font-size:100%;"&gt;§&lt;/span&gt;&lt;span style="'font:7.0pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Information regarding specific implementations of the algorithm that may reveal implementation weaknesses in specific products&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; margin-left:36.0pt;text-align:justify;text-indent:-18.0pt;line-height:16.8pt; mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font-size:100%;"&gt;§&lt;/span&gt;&lt;span style="'font:7.0pt"&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Source code or other information regarding ACE server that may reveal vulnerabilities&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;Until further information is available, the prudent course of action is to assume the worst: that SecurID seeds have been exposed, their assignment to specific RSA customers is known, and the source code of ACE server and other products has been compromised and may reveal weaknesses.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;h1&gt;&lt;span style="'font-family:"&gt;&lt;span style="font-size:100%;"&gt;EZMCOM Solution&lt;/span&gt;&lt;/span&gt;&lt;/h1&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;In light of the RSA breach, EZMCOM’s superior software-based authentication form factors provides a better alternative to SecurID tokens at a reduced cost of ownership and 100% customer coverage with ease of use. We have already begun working with organizations that are looking to quickly move off of the RSA platform due to security concerns resulting from the breach. EZMCOM is uniquely positioned to enable rapid implementation and deployment. For banks, EZMCOM’s EzIdentity™ authentication platform can be used to roll out multi-layer, multi-factor strong authentication in just weeks. For enterprise, healthcare, and government organizations, EZMCOM offers off-the-shelf support for a wide range of applications and automated enrolment tools to expedite deployment to their employees. EZMCOM also offers stronger protection from new attacks such as Man-In-The-Middle (MITM), Man-In-The-Browser (MITB), a better user experience, and a lower TCO.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;h2&gt;&lt;span style="'font-family:"&gt;&lt;span style="font-size:100%;"&gt;Security Primer of EZMCOM authentication clients&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;The fundamental approach of seed generation in EZMCOM’s authentication software form factors is dynamic and run-time based. This implies that the seeds are not pre-programmed and are not available at any point of time with participating administrators of Customer (e.g. Banks, Enterprises) or EZMCOM employees. &lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto; text-align:justify;line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;During the time of EZMCOM Token activation, its user receives via out-of-band channel a randomness (RND-1) generated by the EZMCOM server system. Another random component (RND-2) is generated on the EZMCOM Token side and along with RND-1 as a function of cryptographically strong PBKDF2 algorithm creates the Token seed in run-time. A registration code generated from EZMCOM Token client is then submitted to the server system. This allows the server system to have the RND-2 component for constructing the Token seed.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;h1&gt;&lt;span style="'font-family:"&gt;&lt;span style="font-size:100%;"&gt;References&lt;/span&gt;&lt;/span&gt;&lt;/h1&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p style="line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;[1] - &lt;/span&gt;&lt;a href="http://www.rsa.com/node.aspx?id=3872"&gt;&lt;span style="font-size:100%;"&gt;Open Letter to RSA Customers&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p style="line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;[2] - &lt;/span&gt;&lt;a href="http://www.sec.gov/Archives/edgar/data/790070/000119312511070159/d8k.htm"&gt;&lt;span style="font-size:100%;"&gt;Form 8-K filing, RSA&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p style="line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;[3] - &lt;/span&gt;&lt;a href="http://www.sec.gov/Archives/edgar/data/790070/000119312511070159/dex992.htm"&gt;&lt;span style="font-size:100%;"&gt;RSA SecurCare Online Note&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p style="line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;[4] - &lt;/span&gt;&lt;a href="http://www.linuxsecurity.com/resource_files/cryptography/initial_securid_analysis.pdf"&gt;&lt;span style="font-size:100%;"&gt;Initial Cryptanalysis of the RSA SecurID Algorithm&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p style="line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;[5] - &lt;/span&gt;&lt;a href="http://docs.google.com/viewer?a=v&amp;amp;q=cache:Eybx6frQlDoJ:citeseerx.ist.psu.edu/viewdoc/download%3Fdoi%3D10.1.1.64.6120%26rep%3Drep1%26type%3Dpdf+rsa+securid+algorithm&amp;amp;hl=en&amp;amp;gl=us&amp;amp;pid=bl&amp;amp;srcid=ADGEESgy8FnnBnM-J58cFkE5b2OB5d8poWbn9GcbpBCrdtrbXwbqQR1yuU_0ZKbSbM"&gt;&lt;span style="font-size:100%;"&gt;Cryptanalysis of the Alleged SecurID Hash Function (extended version)&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p style="line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;[6] - &lt;/span&gt;&lt;a href="http://www.schneier.com/crypto-gram-0205.html"&gt;&lt;span style="font-size:100%;"&gt;Secrecy, Security, and Obscurity&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:100%;"&gt;  &lt;/span&gt;&lt;p style="line-height:16.8pt"&gt;&lt;span style="font-size:100%;"&gt;[7] - &lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Kerckhoffs%27s_Principle"&gt;&lt;span style="font-size:100%;"&gt;Kerckhoffs's Principle&lt;/span&gt;&lt;/a&gt;&lt;span style="'font-family:;font-size:9.0pt;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="mso-bidi-line-height:115%;font-size:10.0pt;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-449381029655830704?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/449381029655830704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2011/04/time-to-move-away-from-rsa-securid.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/449381029655830704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/449381029655830704'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2011/04/time-to-move-away-from-rsa-securid.html' title='Time to move away from RSA SecurID'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-6Zb2XneVQFg/TbjN4jlDaDI/AAAAAAAAA-4/BS0CYUtpdjc/s72-c/RSA1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-128841414032442386</id><published>2011-01-04T23:14:00.001-08:00</published><updated>2011-01-04T23:24:15.180-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook mail'/><category scheme='http://www.blogger.com/atom/ns#' term='NFC Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Cloud Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Video Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Tablet Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Identity Consolidation'/><title type='text'>2011 IT Security Predictions</title><content type='html'>&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;Coming from 2010, there is still many solutions and issues that will get more attention, check out my earlier post "Recap on 2010 IT security Predictions". This is more in continuation of earlier post. However it brings out &lt;/span&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;the needed &lt;/span&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;security for the new things that have happened &lt;/span&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;13. Google Mail vs. Facebook Email / Messaging service and Security? [New]&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Google is going to get hit badly as every facebook user (which very likely is gmail user) will be moving away from gmail to facebook messaging. I personally feel it is not good for the user. It is always good to have certain things separate – social profile and email should be kept separate. Facebook will also follow advertisement revenue from you. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;14. Identity Consolidation [New]&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Too many password and too many credit cards, all need to be come together to have one id and one card. Google checkout, Paypal and now Facebook Credits all are coming in so still the security is short of it. Even if Google is promoting 2FA but hackers are cracking 2FA. Strong Security for Identity Consolidation is needed. OpenID is good but it is not there as one Globe ID. Consolidation is the key and it also leads to one point failure scenario. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;15. Video Protection [New]&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;2011 will see exponential rise in video. Skype, iphone 4, ipad 2 (likely with video call feature), Wimax, android based tabs – all this will lead to more videos (calls or contents). Video call security is never considered till now but it will come into life as your videos will be going through many hops and compromise can happen at any level. Video protection needs some good products to come into market. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;15. Tablet World but Is Open good? [New]&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Android based tabs will flood the market. It is a open platform which makes it prone for malware, spyware, virus etc. Enterprises will have a nightmare managing them as people will have data everywhere. Tabs are going to become more popular so data protection, email protection, message protection, anti theft all these need to be considered for enterprise usage.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;/span&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;16. NFC is here but where is the security ?[New]&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Google Android announced new phone model coming out with NFC support. There are few SIM manufacturers (like Taisys) which have got NFC enabled SIM offered for PrePaid Transactions. It is certainly the future but there is a inherent technologuy risk - anyone can manipulate data. All I need to do have a trans-receiver sit in like Starbucks. Without you even knowing your NFC card will be charged. This is a serious threat to this technology and products. Be sure of what you use NFC for?&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;17. Cloud is coming - Private Or Public ?[New]&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Cloud is the next buzz word and it is great for large enterprises and SME as no need to invest on infra, desktop, applications. Every thing will be a service. Companies like Arcot, Tricipher have been bought over by CA and VMware. This clearly shows the Cloud Infra companies are certainly looking for strong identity protection. Private Or Public should not matter if the security is well taken care off. One of the issues will always be increase in the bandwidth usage and it might become a bottom neck as Cloud, Software as a service become more popular. Said that, many promising technologies are coming to address to the offer more bandwidth.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;It will be another exciting year. Look forward to 2011.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;regards,&lt;br /&gt;vikram&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-128841414032442386?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/128841414032442386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2011/01/2011-it-security-predictions.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/128841414032442386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/128841414032442386'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2011/01/2011-it-security-predictions.html' title='2011 IT Security Predictions'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-2050717082888146119</id><published>2011-01-04T21:49:00.001-08:00</published><updated>2011-01-04T21:52:24.592-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WebSign'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Signing from Phone'/><category scheme='http://www.blogger.com/atom/ns#' term='Roaming PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Sign Wireless PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='OOBA'/><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Phone Software Tokens'/><category scheme='http://www.blogger.com/atom/ns#' term='transaction authorization'/><category scheme='http://www.blogger.com/atom/ns#' term='2010 IT Security Predictions'/><category scheme='http://www.blogger.com/atom/ns#' term='Non Repudiation'/><title type='text'>Recap on 2010 IT Security Predictions</title><content type='html'>&lt;div class="moz-text-html" lang="x-western"&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;Last year I made following predictions for 2010. Even thought 2010 was tough year for many and most of the CIO and CISO were looking for cutting cost still security did get a good boost.  It is warming up what will come in 2011 and 2012 will be much bigger for security. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;1. Virus / Malware will hit Mobile&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Virus / Malware for mobile devices and smartphones will escalate as more apps are provided that facilitate users ability to do more things related to e-commerce, travel and financial apps. Given that many end users feel less vulnerable on their mobile devices it could be a steep learning curve to convince them they need to take similar protections as they would on their PCs. Guys making the malware will promote these virus and malwares software for your phones as free downloads of ringtones, games, utility apps. These apps will be say as spyware applications for PCs. With GPS enabled phones, it will be dangerous to get infected with these viruses.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Yes. Many new viruses did come in but the impact is still that great mostly because the compromise and loss are still unknown and they are not mass scale. With PC anti virus maturity, most of the phone vendors have implemented good process to screen the applications (screening and code signing etc). It is not much of threat until user installed the FAKE application. With user education, later can still be resolved.]&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;2. Security as a Service&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;Security Tokens which have become Software driven in lieu of hardware will go subscription based from license procurement model. This will be enabled by the selling Security as a Service. This will be true for managed and hosted services where regulation compliance is a need and customer wishes to have 3rd party Security provider. The overall security as a service will cover better vulnerability management/reduction, application &lt;/span&gt;&lt;span lang="EN-MY" style="COLOR: rgb(146,208,80);font-family:'Arial','sans-serif';" &gt;level&lt;/span&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt; firewall, strong authentication, robust encryption and closer attention to legal jurisdictions.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Yes. This has also come into main stream. Google has released support for 2FA for their Google Apps. Along with that, everything that is moving to cloud which needs to have strong authentication and strong privacy control. 2011 will be much bigger year for Security as a service. Still strong authentication solutions are not giving the best suited simple, easy, effortless user experience. This is the GAP that need to be filled up. 2011 will be interesting year to see Saas to mature and enterprises using Cloud Services will certain go for Strong authentication based login.]  &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;3. End To End Encryption&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;With the mobile workers and work from home mindset, remote access will become more crucial and at the same time, there will be a lot of data at the user side getting generated and will be under threat (of getting stolen or theft). Along with this, why should you trust the network - Wired or Wireless networks? End to end protection is going to get a big boost in 2010 to protect the data. For instance, insurance agents are doing business from their laptop and there is no protection of the end-customers private information on the system. Application to Application, end to end protection will be the basic need for all the e-business work flows above and beyond SSL certificate.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Partly yes. Application based end to end encryption is certainly a need but an alternate solution – Out Of Band Authentication   - is giving a better and stronger security solution as compared to end to end encryption. E2E is a good technical solution but backend system integration has been the show stopper for it whereas OOB is simpler to implement. Still OOB will not be able to protect from internal breach. End To End Encryption  Or confidential data masking must be put in place. Companies like safe.net are betting on end to end encryption with their HSM based solution, it will good to see how well it does?]&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;4. Tested and Certified Software Will Have the Edge&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;Currently a lot of software and hardware products do not have security checklist as a must to pass. Now more push towards Certification and Compliance will come into action and making it a standard. BASIL, PCI-DSS, HIPAA are there but it will go to many other sectors. Procurement actions will require more robust testing of software and firmware to insure significant reduction of many of the vulnerabilities that we are dealing with today. Certification should become faster and cheaper for this too happen.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;/span&gt; &lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Partly Yes. There has been increase in security awareness and adoption was increased. PCI-DSS and HIPPA certainly come out stronger in 2010. Basil 3 should also made good impact in coming years. Security Awareness and Security not be taken as afterthought are needed more as fraudsters are getting smart in tricking gullible users. Still a lot more emphasis needs to go in Security, Privacy education and ceritification. ]&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;5. Multi-factor Authentication becomes more popular&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Event though Granter states that 2FA is not enough (which all the security gurus have been screaming for decade) still 2010 will be the year for wider adaption of two-factor authentication for the end users. With federation of the many various types of two factor authentication that are around today we will finally see strong authentication become the rule NOT the exception. However, it will not be limited to 2FA(what you know? and what you have?) , but it will become multi factor (where you are? what you see? and what you are?) questions also will become the identity authentication criteria to allow the authentication and access. It will certainly be driven by software (not hardware) to make it widely.&lt;/span&gt;&lt;span lang="EN-MY" style="COLOR: rgb(146,208,80);font-family:'Arial','sans-serif';" &gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Yes. Many companies and sectors are adopting multi factor authentication. Many new companies providing Multi factor authentication have coming alive. OATH had 10-12 members last year but now they have 30plus members that are taking public standard for OTP ahead in the market. Mobile phone based software application form of token is going to be a very popular token for coming years.  Unfortunately hackers have become smarter to break One time password based authentication. OOB authentication Or PKI based end to end encryption will be needed. Web SSO (with SSL-VPN or without  SSL-VPN) will also come into strong focus as each enterprise uses many applications that they wish to webify and take it to market.  OTP, Web SSO, Federated Identity, Unified Single ID will be becoming more common words we will hear in 2011. All of this will be needed for cloud infra also. ]&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;6. Voice biometric for Password Reset and Getting new services activated&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;Password management is one of the biggest expensive support activity. Filling form, faxing them and waiting for weeks to get your PIN will change through Voice biometric. Forgot the PIN, call the support helpline, authentication your self and get the new PIN. Same will apply to new services where you will need Activation Code or PIN delivered from out of band with authentication.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization: Yes &amp;amp; No. This never got into action in 2010. Few banks did roll it out and companies like PerSay did get market attention for a short time. The clients for voice biometric for looking at authentication for phone banking or customer support. It never really did well or will pick up in 2011 mainly due to two reason – First: Voice biometric is cracked (there are ways this technology can be broken – I will not cover that in this post but it is doable.) and Second reason is : business model is per Call, the billing is exponential as the more users and more transactions will come into play. It is good as there is no software or hardware involved to be issued to the end-user but cost-security does not favour this form of security.]&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;7. Social Networking Threats on rise&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;As more and more businesses turn to social networking sites to extend their customer reach and build brand awareness, sensitive data becomes even more available and vulnerable. This past year, the KoobFace worm spread like wildfire through several social networks including Facebook, MySpace, Friendster and Twitter. In October, a massive bot-based attack, Bredolab, affected three-quarters of a million Facebook users by sending fake password reset messages. No solution will come in 2010.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY" style="COLOR: rgb(146,208,80);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;&lt;/span&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – No. I am just amazed to see people are just not worried about their privacy and security. There have been so many applications (for facebook, hi5, orkut that simply steal the users personal details. You click on Allow and your complete life is out in somebody’s hand. 2011 will be the same and people will still do the same thing. More Threats and Attacks will happen on / using Social Networking. It is like smoking where we know it is not good but we will still do it.]&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;8. Digital Signatures will go Mobile&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;Today we have two options to do Signing (to enforce Non Repudiation) - Software Signing (through your internet browser secure storage of Certificates) OR Hardware Signing (where Smart Card OR USB Key stores your Certificate). Both are good but restrictive in nature. What you carry with you once is a Phone. Your Keypair will be carried inside your Phone and you will use that for signing and verifying your transactions, documents and emails. It will be cost effective and not restricted in nature as compared to today's options.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Yes. Infact I am proud to share: we, EZMCOM, are one of the first movers for complete out with Mobile PKI as a Service that will be enabled for all the banks and financial institutes in country in ASEAN. It gives higher risk appetite, legal binding, simple-effortless user experience (unlike hardware PKI token) and global roaming. In fact the model is “pay per use” making it very competitive in terms of pricing too. 2011 will be big year for this as it will go global. ]&lt;span style="COLOR: rgb(102,102,102)"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;9. Email Protection with DLP (Data Leakage Protection)&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Email is the most widely used communication tool for businesses today. Email Signing to hold its legal value is become a need of the businesses. Also making your communication confidential will also become crucial. Solutions like PGP for desktop email encryption and signing are present but they will not fly any more. It will be enterprise level or ISP level email protection. Currently we have anti spam, anti virus for our email but not sufficient when it comes to internal breaches and legal conflict. Email Signing as well as DLP will come strongly in 2010-11.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Not Really. Email Archival and DLP did get good attention and it was very much needed in 2010. Still Email signing / encryption is not coming into main stream yet. Why? Gmail does not want it as they cannot show advertisements. Blackberry offer it but you need to pay premium. Why will anyone give email security. I will be happy if free email encryption (SMIME) gets offered esp by gmail, it will be great service to all.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;On the other hand for DLP, Only enterprise market are looking at DLP solutions. DLP is more to do with processes + people than technology. Simple way to bypass is to carry a camera (which all phones have now) and click the pictures of the documents from your screen. Controlling people in the world on web is not possible there are many simple or sophisticated ways to bypass security and steal the data. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;What is needed in 2011 is collaboration tools like yammer and close network + application monitoring tools. We need to have happy employees that work closely so they do not steal. If somehow there is a PC compromised by external hacker(s) then application / network monitoring will be the right solution. In addition, if you have really private and confidential files and data then go for PKI Certificate based Encryption Tools (there are many good ones in the market now. 2011 might have this but i am blur on this one.] &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;10. Identity Management and Authentication and SSO will consolidate&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;Consolidation of the PIN, Token, Certificate along with web based SAML enabled single sign-on is going to give efficient, best TCO, least support mainly for private and public sectors. National ID cards will become crucial to enable many e-service, m-services and real services using one consolidated platform for Identity Management and Authentication. Federated Identity will become more popular in 2010.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;&lt;/span&gt; &lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Not Really. 2011 might be the year for it after the long recession.]&lt;span style="COLOR: rgb(102,102,102)"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;11. Rise of Scareware&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;While free anti-virus products are great to decrease the growing amount of malware threats out there, users need to be cautious about rogue anti-malware products -- otherwise known as "scareware" -- that organized crime rings will use to take advantage of end-users and disable their computers. Scareware reared its ugly head this year through fake advertisements (malvertising) for antivirus on&lt;i&gt;The New York Times&lt;/i&gt; website.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN-BOTTOM: 0pt; LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Yes. 2010 has seen many malware and scareware esp. As SMSes, emails and browser plugins. There is no stopping in 2011, it will continue and now a better and biggest enabler is Social Networking sites where more scarewares will be coming in. There is always a NEWS – good or bad / real or fake. Wikileaks is also whistleblower for good of the world. 2011 will many more surprises solets wait for it.]&lt;span style="COLOR: rgb(102,102,102)"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;12. No Privacy &lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-MY" style="COLOR: rgb(102,102,102);font-family:'Arial','sans-serif';" &gt;&lt;br /&gt;Google, Facebook, twitter etc willensure you have no privacy alot. Your emails, blog, wall-to-wall comments, tweets will be used for social intelligence. Your location will be given away through your Nokia, Iphone, Blackberry. Please be aware of No Privacy World.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;[Realization – Yes. 2010 started No Privacy and 2011 will be more No Privacy year. Every one will know where you are, what you are doing, whom are you with, what you are hearing, what you are texting / tweeting / facebooking . Your Pc and your phone are the spy on you. This is a double edged sword that is good (when it comes to shoping / getting deals / location based service – it is great) but it is bad (when every one in facebook / google will know what you are hearing / doing ?).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="LINE-HEIGHT: normal"&gt;&lt;span lang="EN-MY"  style="font-family:'Arial','sans-serif';"&gt;Decide you self are you private person or public person? ] &lt;span style="COLOR: rgb(102,102,102)"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;pre class="moz-signature" cols="72"&gt;&lt;span style="font-family:Georgia;"&gt;It will be great to hear out your comments. Do contact me at vikram @ ezmcom . com &lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-2050717082888146119?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/2050717082888146119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2011/01/recap-on-2010-it-security-predictions.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/2050717082888146119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/2050717082888146119'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2011/01/recap-on-2010-it-security-predictions.html' title='Recap on 2010 IT Security Predictions'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-8508927718487361578</id><published>2010-09-17T02:25:00.001-07:00</published><updated>2010-09-20T19:41:22.937-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WebSign'/><category scheme='http://www.blogger.com/atom/ns#' term='VSIGN'/><category scheme='http://www.blogger.com/atom/ns#' term='Out of Band Authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='verification'/><category scheme='http://www.blogger.com/atom/ns#' term='MSIGN'/><category scheme='http://www.blogger.com/atom/ns#' term='Mobile PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='OOBA'/><category scheme='http://www.blogger.com/atom/ns#' term='transaction authorization'/><category scheme='http://www.blogger.com/atom/ns#' term='Non Repudiation'/><title type='text'>True Out of band Authentication with PKI</title><content type='html'>&lt;div style="width:425px" id="__ss_5246035"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/vikramsareen/true-out-of-band-authentication" title="True Out Of Band Authentication"&gt;True Out Of Band Authentication&lt;/a&gt;&lt;/strong&gt;&lt;object id="__sse5246035" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=ezidentity-oob-options-100920213344-phpapp01&amp;stripped_title=true-out-of-band-authentication&amp;userName=vikramsareen" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed name="__sse5246035" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=ezidentity-oob-options-100920213344-phpapp01&amp;stripped_title=true-out-of-band-authentication&amp;userName=vikramsareen" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;In today’s dynamic environment, fraudsters are continuously developing increasingly sophisticated ways to attack and circumvent security measures and the number of ‘Man-in-the-middle’, Trojans and other malicious software ("Malware") attacks are increasing steadily. Amid increasing attacks and an urgent need to protect customers online, BFSI institutions, B2C segment are turning to ‘Out-Of-Band Authentication’ where user’s identity is verified using a channel other than the one being used to facilitate the transaction.&lt;br /&gt;&lt;br /&gt;We, at EZMCOM Inc, have announced the availability of their ‘Out-of-band Authentication’ solution with world’s first OOB with Non Repudiation. EZMCOM’s next generation EzIdentity Platform gives regulation guidelines compliant Multi Factor “Out of Band” authentication to protect from Man-in-the-Middle, Trojan attacks and give non repudiation using true PKI.&lt;br /&gt;Unlike traditional ‘OOB’ methods, which limit the transaction to the user’s mobile phone, EZMCOM’s solution offers OOB through Web, through mobile app as well as voice call. Following shows the value of each -&lt;br /&gt;· WebSIGN OOB converts Laptop /PC into virtual authentication tunnel between Server and Client. It uses our patented technology and has no software installation requirements.&lt;br /&gt;· MSIGN OOB converts your smart phone into two way two factor, end to end encrypted and signed channel for authentication and digital signature. MSIGN is user friendly and convenient as it works on all Java, Blackberry, iPhone, Android OS based phones.&lt;br /&gt;· VSIGN OOB is the voice based OOB authentication which uses “What you know - PIN” and “What you are – voice signature” for authentication. It is a reliable two way authentication form and needs no additional installation.&lt;br /&gt;&lt;br /&gt;According to Our Product market survey, out-of-band transaction verification via a MSIGN and WEB SIGN are better value for money along with their ability to defeat man-in-the-browser attacks such as the Zeus Trojan. Above and beyond, Web Sign and MSIGN offer truly non repudiation especially for high value transactions based businesses (like corporate and trading). MSIGN and WEBSIGN both do digital signing using RSA 1024bit key pair issued by the Recognized Certificate Authority.&lt;br /&gt;&lt;br /&gt;Our true Out-of-band Authentication is being widely acknowledged especially by banks &amp;amp; financial institutions. Two key reasons are – First: our offering is Mobile Operator &amp;amp; SMS independent. Second: Ability to have true legally binding non repudiation which no other solution in the world offers.&lt;br /&gt;&lt;br /&gt;Banks and Certificate Authorities are embracing true OOB solution as they have the universal reach like SMS and have no/ minimal impact over customer behaviour. Verifying users details through phone (over SMS) is just not enough these days, due to the increasing call-jacking associated with online identity theft. EZMCOM offers not just 1, but 3 strong channels for authentication, making their platform the ‘Multi-factor, out of band authentication’ platform in the true sense.&lt;br /&gt;&lt;br /&gt;For free evaluation and to learn more on our OOB, please contact us at &lt;a href="mailto:sales@ezmcom.com"&gt;sales@ezmcom.com&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-8508927718487361578?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/8508927718487361578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2010/09/true-out-of-band-authentication-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/8508927718487361578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/8508927718487361578'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2010/09/true-out-of-band-authentication-with.html' title='True Out of band Authentication with PKI'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-312371765922165667</id><published>2010-04-22T04:45:00.001-07:00</published><updated>2010-04-22T04:45:52.471-07:00</updated><title type='text'>Ezidentity solution for Bank Negara Compliance</title><content type='html'>Check out this SlideShare Presentation: &lt;div style="width:425px" id="__ss_3815622"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/guestecf51c5/ezidentity-solution-for-bank-negara-compliance" title="Ezidentity solution for Bank Negara Compliance"&gt;Ezidentity solution for Bank Negara Compliance&lt;/a&gt;&lt;/strong&gt;&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=banknegarae-bankingguidelineinterpretation-100422062411-phpapp02&amp;stripped_title=ezidentity-solution-for-bank-negara-compliance" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=banknegarae-bankingguidelineinterpretation-100422062411-phpapp02&amp;stripped_title=ezidentity-solution-for-bank-negara-compliance" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="padding:5px 0 12px"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/guestecf51c5"&gt;guestecf51c5&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-312371765922165667?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/312371765922165667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2010/04/ezidentity-solution-for-bank-negara.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/312371765922165667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/312371765922165667'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2010/04/ezidentity-solution-for-bank-negara.html' title='Ezidentity solution for Bank Negara Compliance'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-4269872677991284391</id><published>2010-03-25T07:11:00.000-07:00</published><updated>2010-03-25T07:18:46.747-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Digital Signing from Phone'/><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Sign Wireless PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='Mobile PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='Replace USB token'/><title type='text'>Prefect Substitute: Mobile Token for PKI USB Token</title><content type='html'>&lt;p&gt;Newly released MSign Technology that converts Mobile Sign into Secure Keystore for you to carry Digital Certificate and also allows you to sign your documents as well as transactions from your phone. We have compiled a list of keyfeatures that make your Blackberry Or Nokia phone a prefect replacement to conventional old time PKI USB token - &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Msign gives anytime, anywhere mobile signing where user gives approval &amp;amp; signs transactions on their phone. &lt;/li&gt;&lt;li&gt;No dependency on PC / Laptop. No driver installation needed. &lt;/li&gt;&lt;li&gt;No Hardware token involved. No logistics. No Inventory Management. No Damage and replacement. &lt;/li&gt;&lt;li&gt;User can use multiple PCs as mobile sign application is on the phone is independent. &lt;/li&gt;&lt;li&gt;No need to share Token / PIN with others. Gives best protection with best experience with least user education. &lt;/li&gt;&lt;li&gt;Holds legally binding, Non Repudiation as Certificates are issued by Certificate Authority. It can work with multiple CAs from other countries too. &lt;/li&gt;&lt;li&gt;Cuts down on communication time and cost by auto alert and instant signing (accept and reject) option.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Mobile token makes a good candidate for replacing USB hardware token. &lt;/p&gt;&lt;p&gt;We are offering free trial for banks, government departments, enterprises as well as partners. Please feel free to contact us. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-4269872677991284391?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/4269872677991284391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2010/03/prefect-substitute-mobile-token-for-pki.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/4269872677991284391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/4269872677991284391'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2010/03/prefect-substitute-mobile-token-for-pki.html' title='Prefect Substitute: Mobile Token for PKI USB Token'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-3788163488093950742</id><published>2010-03-25T07:04:00.000-07:00</published><updated>2010-03-25T07:09:59.796-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Token'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Signature from mobile phone'/><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Sign Wireless PKI'/><title type='text'>Mobile Sign Technology Added to EzIdentity Platform as MSign</title><content type='html'>&lt;span style="font-family:arial;font-size:85%;"&gt;EZMCOM's Mobile Sign technology lets &lt;strong&gt;mobile phone users securely authenticate themselves, digitally sign documents &amp;amp; data and confirm legally binding transactions&lt;/strong&gt; by entering a self-chosen PIN. The Mobile Sign offering uses &lt;strong&gt;two-channel, two-factor authentication based on Public Key Infrastructure (PKI)&lt;/strong&gt;, combining an over-the-air platform with a java software client on the phone. The software is used to secure online banking, mobile payments, e-commerce, governmental services and identity and access rights management for enterprise applications. EZMCOM's Mobile Sign digital signature is independent of Mobile Operators. And Bank / Enterprise deploys Mobile Sign Connector that interfaces with their Application(s) like Online Corporate Banking, Retail Banking. Mobile Sign Connector is pre-configured with Mobile Sign Gateway (deployed as a service with CA). Gateway provides Mobile Sign Client provisioning, Activation, Certificate Issuance and Usage. Gateway along with Connector uses digital signed SMS and Data between customer and bank making sure complete channel is protected and no Man-in-the-Middle attack compromises the transaction.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;&lt;strong&gt;Mobile Sign Technology empowers&lt;/strong&gt; - Bank with cost effective and simplified approach for conducting legal transactions. First, Bank does not need to issue PKI tokens &amp;amp; smart cards for carrying their certificates, with Mobile Sign technology, any smart phone becomes secure certificate store. Second, User is not bound to computer for approving transactions or signing documents, with Mobile Sign user can be anywhere till conduct banking and sign transactions &amp;amp; documents from their phone.  Bank will be enabled with complete mobile wireless PKI certificate management and digital signatures. Today's consumers always have with them is their mobile phone, and they clearly express their desire to use it more and more for convenience in their daily life. Enabling people to conveniently sign legally-valid transactions is opening up a whole range of new applications for the mobile, at the service of citizens. This is enabled with EZMCOM's Mobile Sign Technology.&lt;br /&gt;&lt;br /&gt;To know more, contact us.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-3788163488093950742?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/3788163488093950742/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2010/03/mobile-sign-technology-added-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/3788163488093950742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/3788163488093950742'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2010/03/mobile-sign-technology-added-to.html' title='Mobile Sign Technology Added to EzIdentity Platform as MSign'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-1536084121472675490</id><published>2009-12-21T18:55:00.000-08:00</published><updated>2009-12-21T19:02:43.697-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Software Certification'/><category scheme='http://www.blogger.com/atom/ns#' term='biometrics'/><category scheme='http://www.blogger.com/atom/ns#' term='Social Networking  Threats'/><category scheme='http://www.blogger.com/atom/ns#' term='Security as Service'/><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Signing'/><category scheme='http://www.blogger.com/atom/ns#' term='2010 IT Security Predictions'/><category scheme='http://www.blogger.com/atom/ns#' term='Multi Factor-Multi Layered Authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='End To End Encryption'/><title type='text'>2010 IT Security Predictions</title><content type='html'>&lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;Wish you a happy holidays and happy new year. We have compiled a list of 12 predictions that we, as security company foresee in coming year of 2010. Please do leave your comments or email us if you are looking for the solution. &lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;1. Virus / Malware will hit Mobile&lt;/b&gt;&lt;br /&gt;Virus / Malware for mobile devices and smartphones will escalate as more apps are provided that facilitate users ability to do more things related to e-commerce, travel and financial apps. Given that many end users feel less vulnerable on their mobile devices it could be a steep learning curve to convince them they need to take similar protections as they would on their PCs. Guys making the malware will promote these virus and malwares software for your phones as free downloads of ringtones, games, utility apps. These apps will be say as spyware applications for PCs. With GPS enabled phones, it will be dangerous to get infected with these viruses.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;2. Security as a Service&lt;br /&gt;&lt;/b&gt;Security Tokens which have become Software driven in lieu of hardware will go subscription based from license procurement model. This will be enabled by the selling Security as a Service.  This will be true for managed and hosted services where regulation compliance is a need and customer wishes to have 3rd party Security provider. The overall security as a service will cover better vulnerability management/reduction, application level firewall, strong authentication, robust encryption and closer attention to legal jurisdictions.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;3. End To End Encryption&lt;br /&gt;&lt;/b&gt;With the mobile workers and work from home mindset, remote access will become more crucial and at the same time, there will be a lot of data at the user side getting generated and will be under threat (of getting stolen or theft). Along with this, why should you trust the network - Wired or Wireless networks? End to end protection is going to get a big boost in 2010 to protect the data. For instance, insurance agents are doing business from their laptop and there is no protection of the end-customers private information on the system. Application to Application, end to end protection will be the basic need for all the  e-business work flows above and beyond SSL certificate.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;span style="font-size:85%;"&gt;&lt;b style="font-family: arial;"&gt;4. Tested and Certified Software Will Have the Edge&lt;br /&gt;&lt;/b&gt;&lt;span style="font-family:arial;"&gt;Currently a lot of software and hardware products do not have security checklist as a must to pass. Now more push towards Certification and Compliance will come into action and making it a standard. BASIL, PCI-DSS, HIPAA are there but it will go to many other sectors. Procurement actions will require more robust testing of software and firmware to insure significant reduction of many of the vulnerabilities that we are dealing with today. Certification should become faster and cheaper for this too happen.  &lt;/span&gt;&lt;/span&gt;&lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;5. Multi-factor Authentication becomes more popular&lt;/b&gt;&lt;br /&gt;Event though Granter states that 2FA is not enough (which all the security gurus have been screaming for decade) still 2010 will be the year for wider adaption of two-factor authentication for the end users. With federation of the many various types of two factor authentication that are around today we will finally see strong authentication become the rule NOT the exception. However, it will not be limited to 2FA(what you know? and what you have?) , but it will become multi factor (where you are? what you see? and what you are?) questions also will become the identity authentication criteria to allow the authentication and access. It will certainly be driven by software (not hardware) to make it widely.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;6. Voice biometric for Password Reset and Getting new services activated&lt;br /&gt;&lt;/b&gt;Password management is one of the biggest expensive support activity. Filling form, faxing them and waiting for weeks to get your PIN will change through Voice biometric. Forgot the PIN, call the support helpline, authentication your self and get the new PIN. Same will apply to new services where you will need Activation Code or PIN delivered from out of band with authentication.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;span style="font-size:85%;"&gt;&lt;b style="font-family: arial;"&gt;7. Social Networking Threats &lt;/b&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:arial;font-size:85%;"  &gt;on rise&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;As more and more businesses turn to social networking sites to extend their customer reach and build brand awareness, sensitive data becomes even more available and vulnerable. This past year, the KoobFace worm spread like wildfire through several social networks including Facebook, MySpace, Friendster and Twitter. In October, a massive bot-based attack, Bredolab, affected three-quarters of a million Facebook users by sending fake password reset messages. No solution will come in 2010.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;8. Digital Signatures will go Mobile&lt;br /&gt;&lt;/b&gt;Today we have two options to do Signing (to enforce Non Repudiation) - Software Signing (through your internet browser secure storage of Certificates) OR Hardware Signing (where Smart Card OR USB Key stores your Certificate). Both are good but restrictive in nature. What you carry with you once is a Phone. Your Keypair will be carried inside your Phone and you will use that for signing and verifying your transactions, documents and emails. It will be cost effective and not restricted in nature as compared to today's options.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;9. Email Protection with DLP (Data Leakage Protection)&lt;/b&gt;&lt;br /&gt;Email is the most  widely used communication tool for businesses today. Email Signing to hold its legal value is become a need of the businesses. Also making your communication confidential will also become crucial. Solutions like PGP for desktop email encryption and signing are present but they will not fly any more. It will be enterprise level or ISP level email protection. Currently we have anti spam, anti virus for our email but not sufficient when it comes to internal breaches and legal conflict. Email Signing as well as DLP will come strongly in 2010-11.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;span style="font-size:85%;"&gt;&lt;b style="font-family: arial;"&gt;10. Identity Management and Authentication and SSO will consolidate&lt;br /&gt;&lt;/b&gt;&lt;span style="font-family:arial;"&gt;Consolidation of the PIN, Token, Certificate along with web based SAML enabled single sign-on is going to give efficient, best TCO, least support mainly for private and public sectors. National ID cards will become crucial to enable many e-service, m-services and real services using one consolidated platform for Identity Management and Authentication. Federated Identity will become more popular in 2010.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;11. Rise of Scareware&lt;/b&gt;&lt;br /&gt;While free anti-virus products are great to decrease the growing amount of malware threats out there, users need to be cautious about rogue anti-malware products -- otherwise known as "scareware" -- that organized crime rings will use to take advantage of end-users and disable their computers. Scareware reared its ugly head this year through fake advertisements (malvertising) for antivirus on &lt;i&gt;The New York Times&lt;/i&gt; website.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;12. No Privacy &lt;/b&gt;&lt;br /&gt;Google, Facebook, twitter etc willensure you have no privacy alot. Your emails, blog, wall-to-wall comments, tweets will be used for social intelligence. Your location will be given away through your Nokia, Iphone, Blackberry. Please be aware of No Privacy World. &lt;/span&gt;&lt;/p&gt;&lt;pre  class="moz-signature" cols="72" style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-1536084121472675490?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/1536084121472675490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/12/2010-it-security-predictions.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/1536084121472675490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/1536084121472675490'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/12/2010-it-security-predictions.html' title='2010 IT Security Predictions'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-5298561473479918144</id><published>2009-09-21T09:13:00.000-07:00</published><updated>2009-09-21T09:50:48.108-07:00</updated><title type='text'>Time based OTP are not enough!!!</title><content type='html'>Yesterday, &lt;span class="postdate"&gt;20 September 2009 another case got reported (&lt;a href="http://zikkir.com/scitech/3958"&gt;click &lt;/a&gt;for linked article) where RSA SecureID time based One Time Password Token, provided to customer (&lt;/span&gt;&lt;span&gt;&lt;span&gt;account manager at Ferma - a construction firm), Mountain View, CA. But there was  trojan &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;on the computer initiated 27 &lt;/span&gt;&lt;/span&gt;&lt;span class="IL_SPAN"&gt;&lt;input name="IL_MARKER" type="hidden"&gt;transactions&lt;/span&gt; to various bank accounts, siphoning off $447,000 in a matter of minutes.&lt;br /&gt;&lt;br /&gt;These RSA SecureID token were generating OTP based on 30s intervals still the trojan got to bypass it. OTP did what it wass suppose to do but the attack was beyond the protection level provided by the RSA token. In simply words - It was unable to protect in this form of Script in the Middle OR Trojan Attack where the transaction is intercepted and changed. Token is no protection to this form of attacks.&lt;br /&gt;&lt;br /&gt;What all is missing -&lt;br /&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;The transaction did not have any integrity enforced. The transaction did not have "sign what you see" authentication layer.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;There is no end to end encryption to protection the OTP or transaction details.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;There was no risk based engine monitoring the change in behavior of users pattern. There was no alert or threshold check to tell the user that there is money getting drained out.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span&gt;To address to above, authentication platform have to provide -&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;what you know?  - userid and password&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;what you have?  -  Time Password (strong will be Challenge based OTP)&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;sign what you see? -  Transaction Signing using Token Or Out of band&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;what is user's behavior? - Risk Based Authentication &lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;with whom I am communicating?  - End to End Encryption make sure only right parties can communicate.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;To give a complete authentication platform that will compliment  "what you know? - userid and password" comes from EZMCOM in form of EzIdentity platform -&lt;br /&gt;&lt;ul&gt;&lt;li&gt;1. &lt;a href="http://www.ezmcom.com/ezmcom/products_eztoken.jsp"&gt;EzToken &lt;/a&gt;- what you know? &lt;/li&gt;&lt;li&gt;2. &lt;a href="http://www.ezmcom.com/ezmcom/products_ezsign.jsp"&gt;EzSign &lt;/a&gt;- sign what you see? &lt;/li&gt;&lt;li&gt;3. &lt;a href="http://www.ezmcom.com/ezmcom/products_ezcert.jsp"&gt;EzCert &lt;/a&gt;- sign what you see with non repudaition enforcement (digital signature)&lt;/li&gt;&lt;li&gt;3. EzWatch - Risk based authentication (coming soon)&lt;/li&gt;&lt;li&gt;4. &lt;a href="http://www.ezmcom.com/ezmcom/products_ezcrypto.jsp"&gt;E2EE &lt;/a&gt;- End to End Encryption &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;We suggest to look more closely to your authentication requirement for your application(s).&lt;br /&gt;&lt;br /&gt;We can help you out by our free authentication gap analysis for your application(s). Please get in touch with us -&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.ezmcom.com/ezmcom/request_call.jsp"&gt;Click here&lt;/a&gt; to Request a call&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Drop me an email - vikram @ ezmcom dot com / skype out @ vikramsareen. &lt;/li&gt;&lt;/ul&gt;Have a great day.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-5298561473479918144?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/5298561473479918144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/09/time-based-otp-are-not-enough.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/5298561473479918144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/5298561473479918144'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/09/time-based-otp-are-not-enough.html' title='Time based OTP are not enough!!!'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-1801216050967473026</id><published>2009-09-11T00:05:00.000-07:00</published><updated>2009-09-11T00:59:41.592-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2FA OTP for Web based Email'/><category scheme='http://www.blogger.com/atom/ns#' term='SquirrelMail Integration'/><title type='text'>2FA OTP for Web based Email (SquirrelMail Integration)</title><content type='html'>&lt;div style="text-align: left;"&gt;One of the most used business tool is Email and web based email access is used by 90% enterprises globally. There are popular email solution available in market like Microsoft Outllook Web Access, Lotus, Free ones Gmail, Yahoo,  Open source - SquirrelMail, SendMail etc.&lt;br /&gt;&lt;br /&gt;Most of the  confidential and restricted information and documents like proposals, quotations, agreements, invoices, partners / clients and potential customers details etc  exchanged through these email.&lt;br /&gt;&lt;br /&gt;Corporate cyber warfare is becoming more common where hackers are offering their services to companies to spy on you and also steal your confidential and private information. The easiest place to attack is your Email.&lt;br /&gt;&lt;br /&gt;Most of the email solution, commercial or open source do not come with strong protection. It comes with only basic authentication where you provide userid and password to log into the web based email system.&lt;br /&gt;&lt;br /&gt;This is where EZMCOM comes in and helps you to strengthen your email with strong identity protection by providing One time password protection to your email Id.&lt;br /&gt;&lt;br /&gt;Using our &lt;a href="http://www.ezmcom.com/ezmcom/products_eztoken.jsp"&gt;EzToken&lt;/a&gt; (software and hardware tokens) you can add strong authentication to your email solution. We are taking the example of the SquirrelMail where we will show how easy it is to add Second Factor Authentication for this open source web based email solution.&lt;br /&gt;&lt;br /&gt;There are 3 easy, quick steps to follow -&lt;br /&gt;&lt;u&gt;&lt;b&gt;STEP-1:&lt;/b&gt;&lt;/u&gt; Modify the UI "$SQWEBMAIL_HOME/&lt;b&gt;src/login.php&lt;/b&gt;" to ask for a 2nd factor (OTP) input&lt;br /&gt;Example:&lt;br /&gt; &lt;!-- EZMCOM START: ADDED INPUT FIELD FOR OTP.  --&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/SqoDW1jxmJI/AAAAAAAAA7s/U4cQQ52YuDk/s1600-h/OTP-Add.JPG"&gt;&lt;img style="cursor: pointer; width: 257px; height: 59px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/SqoDW1jxmJI/AAAAAAAAA7s/U4cQQ52YuDk/s200/OTP-Add.JPG" alt="" id="BLOGGER_PHOTO_ID_5380116395716614290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;STEP-2:&lt;/b&gt;&lt;/u&gt; Add the following lines of code at an appropriate place in the file "$SQWEBMAIL_HOME/&lt;b&gt;src/redirect.php&lt;/b&gt;"&lt;br /&gt;/* Verify that username and OTP are correct. */&lt;br /&gt;$otp = trim($otp); /* $otp variable receives the input value from the above modified login page */&lt;br /&gt;$success = "0";&lt;br /&gt;$otp_verification = verifyOTP($login_username,$otp);&lt;br /&gt;if($otp_verification != $success) {&lt;br /&gt; $msg = 'One-Time Password verification failed: ';&lt;br /&gt; logout_error( _($msg . $otp_verification) );&lt;br /&gt; exit;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;STEP-3:&lt;/b&gt;&lt;/u&gt; Add the following function in the file "$SQWEBMAIL_HOME/&lt;b&gt;functions/auth.php&lt;/b&gt;"&lt;br /&gt;/**&lt;br /&gt;* Verify OTP&lt;br /&gt;* This function performs One-Time Password authentication&lt;br /&gt;*&lt;br /&gt;* @param string $username and $otp&lt;br /&gt;* @return authentication result '0' for success, or failure return code&lt;br /&gt;*/&lt;br /&gt;function verifyOTP($username, $otp) {&lt;br /&gt; /* initialize the below orgid to the EzIdentity group ID&lt;br /&gt;    displayed in provisioning portal. Default (1st group Id) is 3 */&lt;br /&gt; $orgid = '3';&lt;br /&gt; /* initialize the below URL to point to EzIdentity Authentication&lt;br /&gt;    server. Edit IP address, Port. Default value of http port: 9880 */&lt;br /&gt; /* Note: Requires HTTP integration API plug-in to be installed in EzIdentity */&lt;br /&gt; /* Note: Requires appropriate firewall access controls for access  */&lt;br /&gt; $url = '&lt;a class="moz-txt-link-freetext" href="http://115.133.157.109:9880/auth/ezidentity/verifyallotp.jsp"&gt;http://IP:PORT/auth/ezidentity/verifyallotp.jsp&lt;/a&gt;';&lt;br /&gt;&lt;br /&gt; $data = array ('strUserId' =&gt; $username, 'iOrgId' =&gt; $orgid, 'strOtp' =&gt; $otp);&lt;br /&gt; $data = http_build_query($data);&lt;br /&gt; $optional_headers = '';&lt;br /&gt; $result = do_post_request($url, $data);&lt;br /&gt; return $result;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;Once you do the above mentioned 3 steps, you are enabled with Strong protection for your SquirrelMail.&lt;br /&gt;&lt;br /&gt;Following are the user experience for the new strong authentication of SquirrelMail -&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sqn_8A0da3I/AAAAAAAAA7U/RJKoyEotcdw/s1600-h/01-webmail-login.jpg"&gt;&lt;img style="cursor: pointer; width: 253px; height: 126px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sqn_8A0da3I/AAAAAAAAA7U/RJKoyEotcdw/s200/01-webmail-login.jpg" alt="" id="BLOGGER_PHOTO_ID_5380112636348033906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Screen 1: Login asking for OTP along with userid and password&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sqn_8a5dNsI/AAAAAAAAA7c/a-OuYd3Xf6M/s1600-h/02-webmail-OTP-success-2.jpg"&gt;&lt;img style="cursor: pointer; width: 232px; height: 111px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sqn_8a5dNsI/AAAAAAAAA7c/a-OuYd3Xf6M/s200/02-webmail-OTP-success-2.jpg" alt="" id="BLOGGER_PHOTO_ID_5380112643348313794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Screen 2: Password and OTP validated to get successful login&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-9xE9-FdEVY/Sqn_89TVAHI/AAAAAAAAA7k/MTdc5_asirY/s1600-h/03-webmail-OTP-fail.jpg"&gt;&lt;img style="cursor: pointer; width: 277px; height: 104px;" src="http://4.bp.blogspot.com/_-9xE9-FdEVY/Sqn_89TVAHI/AAAAAAAAA7k/MTdc5_asirY/s200/03-webmail-OTP-fail.jpg" alt="" id="BLOGGER_PHOTO_ID_5380112652583633010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Screen 2: Invalid  OTP OR try to reuse the OTP again - Login failure&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Similar to SquirrelMail, all the other popular email solutions can be configured to offer strong protection. In the back end you will have EzIdentity platform to manage the token and users and from your email solution, you will do the authentication.&lt;br /&gt;&lt;br /&gt;With &lt;a href="http://www.ezmcom.com/ezmcom/products_ezapp.jsp"&gt;EzIdentity&lt;/a&gt; platform along with &lt;a href="http://www.ezmcom.com/ezmcom/products_eztoken.jsp"&gt;EzToken&lt;/a&gt; Software tokens, the total cost of ownership for rolling out strong authentication for your enterprise email solution is as low as USD 2 per user per month.&lt;br /&gt;&lt;br /&gt;For details on the &lt;a href="http://www.ezmcom.com/ezmcom/products_ezapp.jsp"&gt;EzIdentity&lt;/a&gt; solution and for free trial, please &lt;a href="http://www.ezmcom.com/ezmcom/request_call.jsp"&gt;contact us&lt;/a&gt;. We will be glad to assist you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-1801216050967473026?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/1801216050967473026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/09/2fa-otp-for-web-based-email.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/1801216050967473026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/1801216050967473026'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/09/2fa-otp-for-web-based-email.html' title='2FA OTP for Web based Email (SquirrelMail Integration)'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-9xE9-FdEVY/SqoDW1jxmJI/AAAAAAAAA7s/U4cQQ52YuDk/s72-c/OTP-Add.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-3232484269377074904</id><published>2009-08-02T22:54:00.000-07:00</published><updated>2009-08-02T23:45:05.297-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Phone Software Tokens'/><title type='text'>Mobile Phone Software Tokens - Why and What?</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-9xE9-FdEVY/SnaGzh1kHDI/AAAAAAAAA6U/WDJSf_r0iDo/s1600-h/EzToken-Supported-Phones.png"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 104px;" src="http://3.bp.blogspot.com/_-9xE9-FdEVY/SnaGzh1kHDI/AAAAAAAAA6U/WDJSf_r0iDo/s200/EzToken-Supported-Phones.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5365624225873009714" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;span class="Apple-style-span"  style="font-family:Arial;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;span class="Apple-style-span"   style="font-family:Arial;font-size:130%;"&gt;&lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;span style="color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Software tokens are future of the One Time Password tokens. The hardware tokens are difficult specially for retail / consumer commerce and internet banking. Software tokens are much simpler to manage and provision and they are able to offer following value proposition - &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Strong two-factor authentication to protected services&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Application available for all popular phone models.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Application available for download through the Apple App Store&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;One-tap token provisioning for the end user&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Support for Login and Transaction signing.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Support for Roaming PKI using Transaction OTP.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Support for Software Development Kit (SDK) for application developers to integrate into their work flows and platforms. Also enables end to end encryption too using Pend Patent OTP based encryption algorithm.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;              &lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;span style="color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;EZMCOM EzToken support more than 800+ phone models including – &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-top:0in;margin-right:0in;margin-bottom:12.0pt; margin-left:2.25pt;line-height:normal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;iPhone&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Blackberry&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Windows Mobile&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Smart phone / Java Enabled Phones&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;span style="color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Mobile phone provide convenient and cost-effective two-factor authentication to enterprise applications and resources. EzIdentity Authentication Platform, the software that powers &lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial; line-height: 16px; "&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;EZMCOM Identity Protection Platform / Authentication System&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: normal; "&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; – are available for free of cost evaluation and purchase worldwide.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;span style="color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;EZMCOM offers enterprises a wide range of user authentication options to help positively identify users before they interact with mission-critical data and applications through:&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;VPNs &amp;amp; WLANs&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Email&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Intranets &amp;amp; extranets&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Web servers&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Online publishing servers&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Remote Access through Citrix and SSL-VPN etc gateways&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Any Web Based System&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Any RADIUS Protocol Supported network resources&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;                &lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;span style="color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;The use of software tokens decreases total cost of ownership for organizations as they don’t require any physical shipping, can be revoked and automatically redeployed if the phone is lost, eliminating the need for replacement tokens. Additionally, having the software authenticator on a business critical device like the iPhone and Blackberry reduces the number of lost or forgotten tokens, decreasing the number of costly technical support calls.&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12.0pt;line-height:normal"&gt;&lt;span style="color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Free download of iPhone OTP Token: EZMCOM EzToken Software Token App for iPhone is available at no charge from the App Store on iPhone and iPod touch or at &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.itunes.com/appstore/" target="_blank"&gt;&lt;span style=" text-decoration:none;text-underline:nonecolor:blue;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;www.itunes.com/appstore/&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;. The required token seed is available for purchase worldwide from EZMCOM and partners. The EzToken Software Token for Mobile Devices is designed for enterprise users whose organizations have the EzIdentity system implemented.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="  ;font-size:10.5pt;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;   &lt;/span&gt;&lt;span style="  ;font-size:10.5pt;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt; &lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-3232484269377074904?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/3232484269377074904/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/08/mobile-phone-software-tokens-why-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/3232484269377074904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/3232484269377074904'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/08/mobile-phone-software-tokens-why-and.html' title='Mobile Phone Software Tokens - Why and What?'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-9xE9-FdEVY/SnaGzh1kHDI/AAAAAAAAA6U/WDJSf_r0iDo/s72-c/EzToken-Supported-Phones.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-4239140012108122934</id><published>2009-07-02T21:14:00.001-07:00</published><updated>2009-07-03T03:41:21.822-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Token Trends'/><title type='text'>Token Trends: What people search on google?</title><content type='html'>&lt;span style="font-size:100%;"&gt;While working on our EZMCOM website (getting launched soon), we were analyzing what are people searching for when it comes to authentication and security. We did few search comparison using &lt;a href="http://www.google.com/insights/search"&gt;google.com/insights&lt;/a&gt;&lt;/span&gt; and results were surprisingly pleasant for us.&lt;br /&gt;&lt;br /&gt;We would like to share our interpretation on Authentication Token Trends with you. We searched the trend for following tokens from 2007 to till date -&lt;br /&gt;&lt;ul&gt;&lt;li&gt;hardware token&lt;br /&gt;&lt;/li&gt;&lt;li&gt;software token&lt;br /&gt;&lt;/li&gt;&lt;li&gt;usb token + pki token&lt;/li&gt;&lt;li&gt;sms token&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-9xE9-FdEVY/Sk3WWj1xmaI/AAAAAAAAA5c/SQDo_1Dysn8/s1600-h/search.png"&gt;&lt;img style="cursor: pointer; width: 307px; height: 94px;" src="http://3.bp.blogspot.com/_-9xE9-FdEVY/Sk3WWj1xmaI/AAAAAAAAA5c/SQDo_1Dysn8/s320/search.png" alt="" id="BLOGGER_PHOTO_ID_5354171215079643554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;(click to enlarge)&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;There were surprising results which came into light. People have been searching more on the PKI and USB Token than hardware token, this makes usb token as most ideal token for enterprises to use for authentication.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sk3a1O69WHI/AAAAAAAAA5k/rk4YL-TSBpI/s1600-h/total-average.png"&gt;&lt;img style="cursor: pointer; width: 260px; height: 103px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sk3a1O69WHI/AAAAAAAAA5k/rk4YL-TSBpI/s320/total-average.png" alt="" id="BLOGGER_PHOTO_ID_5354176140086696050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt; average search over 2.6 years&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Second in race is  software token followed with hardware token. It is always that hardware token is much better when it comes to security as it is hamper proof. However, the search results reflect complete possible of it where people are searching more on software token than hardware token.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-9xE9-FdEVY/Sk3b8gWSb-I/AAAAAAAAA5s/wFYFHZdxSUE/s1600-h/interest-over-time.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 93px;" src="http://4.bp.blogspot.com/_-9xE9-FdEVY/Sk3b8gWSb-I/AAAAAAAAA5s/wFYFHZdxSUE/s320/interest-over-time.png" alt="" id="BLOGGER_PHOTO_ID_5354177364535439330" border="0" /&gt;&lt;/a&gt;Search Volume over 2.6 years (click to enlarge)&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: left;"&gt;One of the interesting observation is also the region from where the searches are carried out. We realized that mostly the search comes from two regions - North America, Europe and India.  The key reason would be:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;America and Europe are  ahead from others when it comes to regulations and compliance&lt;br /&gt;&lt;/li&gt;&lt;li&gt;India is R&amp;amp;D office for many security firms that must be doing the search of security products.&lt;/li&gt;&lt;/ul&gt;Please find the following results to share more on the details of the regions for each form of token as follows (click to enlarge the image) -&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sk3dqPWmVKI/AAAAAAAAA6M/TYEbvRRQi3Y/s1600-h/software-token-interest.png"&gt;&lt;img style="cursor: pointer; width: 200px; height: 74px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sk3dqPWmVKI/AAAAAAAAA6M/TYEbvRRQi3Y/s200/software-token-interest.png" alt="" id="BLOGGER_PHOTO_ID_5354179249758950562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;software token&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sk3dp9UaKAI/AAAAAAAAA58/Dxkmh-lp1Fw/s1600-h/pki-token-interest.png"&gt;&lt;img style="cursor: pointer; width: 200px; height: 74px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sk3dp9UaKAI/AAAAAAAAA58/Dxkmh-lp1Fw/s200/pki-token-interest.png" alt="" id="BLOGGER_PHOTO_ID_5354179244917925890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;usb token&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sk3dppCsyuI/AAAAAAAAA50/VK_QBwTZEeU/s1600-h/hardware-token-interest.png"&gt;&lt;img style="cursor: pointer; width: 200px; height: 78px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sk3dppCsyuI/AAAAAAAAA50/VK_QBwTZEeU/s200/hardware-token-interest.png" alt="" id="BLOGGER_PHOTO_ID_5354179239474940642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;hardware token&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sk3dp82LBLI/AAAAAAAAA6E/wXOfJ6RqyAY/s1600-h/sms-token-interest.png"&gt;&lt;img style="cursor: pointer; width: 200px; height: 72px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sk3dp82LBLI/AAAAAAAAA6E/wXOfJ6RqyAY/s200/sms-token-interest.png" alt="" id="BLOGGER_PHOTO_ID_5354179244791104690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;sms token&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;Why are we sharing the above with you?&lt;/span&gt;&lt;br /&gt;Even though EzIdentity platform is offering all the 4 types of tokens and many more but there is a change in the direction of the choice of token that people seek.&lt;br /&gt;&lt;br /&gt;The confidence from usb pki token is highest as it is a secure hardware device that carries your strong Private-Public Key pair. Making it impossible for any hacker to get into.&lt;br /&gt;&lt;br /&gt;Following to this, software - why - becuase it is free of logistics + invenotry costs, reusable, real-time, easy to install and carry.&lt;br /&gt;&lt;br /&gt;SMS and hardware do have good points in their favor but pki and software token make a better combination to roll out for your enterprise or commerce portal or government work flow.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Next Steps&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Check out the insight results yourself - &lt;a href="http://www.google.com/insights/search/#q=hardware%20token%2Csoftware%20token%2Cusb%20token%20%2B%20pki%20token%2CSMS%20token&amp;amp;date=1%2F2007%2031m&amp;amp;cmpt=q"&gt;Click Here&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Visit us at &lt;a href="http://www.ezmcom.com/"&gt;www.ezmcom.com&lt;/a&gt; for more information&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-4239140012108122934?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/4239140012108122934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/07/token-trends-what-people-search-on.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/4239140012108122934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/4239140012108122934'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/07/token-trends-what-people-search-on.html' title='Token Trends: What people search on google?'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-9xE9-FdEVY/Sk3WWj1xmaI/AAAAAAAAA5c/SQDo_1Dysn8/s72-c/search.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-6323509448324917947</id><published>2009-06-22T07:37:00.001-07:00</published><updated>2009-06-22T08:33:33.573-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Roaming PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='FIPS compliant Digital Signatures'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Certificate Lifecycle'/><category scheme='http://www.blogger.com/atom/ns#' term='Non Repudiation'/><title type='text'>EzCert: EzIdentity Offering for PKI (Roaming and Conventional Approaches)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sj-hMNMjdOI/AAAAAAAAAyY/PF5v1EsNchU/s1600-h/pki-options.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 266px; height: 120px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/Sj-hMNMjdOI/AAAAAAAAAyY/PF5v1EsNchU/s200/pki-options.JPG" alt="" id="BLOGGER_PHOTO_ID_5350172113412256994" border="0" /&gt;&lt;/a&gt;EzIdentity offers an unique platform that brings One Time Password Tokens as well as Digital Certificate (PKI) under one platform. It is the only platform that offers Public Key Infrastructure in two forms -&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Roaming PKI (new way of doing things)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Conventional PKI (the proven approach)&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-9xE9-FdEVY/Sj-gPd6EQLI/AAAAAAAAAyQ/DofcvxDPFvM/s1600-h/EzCert.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 190px; height: 200px;" src="http://3.bp.blogspot.com/_-9xE9-FdEVY/Sj-gPd6EQLI/AAAAAAAAAyQ/DofcvxDPFvM/s200/EzCert.JPG" alt="" id="BLOGGER_PHOTO_ID_5350171069926097074" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Our third layer that enforces non repudiation is called EzCert. This layer can be used with/without OTP authentication too if conventional PKI is needed. It brings regulation compliance in de facto and most cost effective manner.&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;Following part of this post covers how EzIdentity platform offers PKI options. The market need is demanding roaming PKI where the user does not need to carry Digital Certificate with him, he uses strong authentication to establish authenticity *(and servers performs crypto operations on behalf of user).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;EzIdentity interfacing with any Certificate Authority like Verisign, Thwate (or any national CA) is straight forward. There can be dedicated or non-dedicated connection to the CA infrastructure. EzIdentity interfaces over Secure HTTP Or Secure Web Services with the CA for the following operations to manage the lifecycle of the certificates.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sj-hkGaUfSI/AAAAAAAAAyg/R-SmVBk2944/s1600-h/CA-interfacing.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 143px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sj-hkGaUfSI/AAAAAAAAAyg/R-SmVBk2944/s320/CA-interfacing.JPG" alt="" id="BLOGGER_PHOTO_ID_5350172523907808546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;There are two options for enterprise or bank to go ahead with PKI. Roaming or Conventional. Lets look at them both respectively in terms of the work flow.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. Roaming PKI Approach - &lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_-9xE9-FdEVY/Sj-iJBeB97I/AAAAAAAAAyo/0B7ToTsw7hY/s1600-h/roaming-pki.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 490px; height: 128px;" src="http://3.bp.blogspot.com/_-9xE9-FdEVY/Sj-iJBeB97I/AAAAAAAAAyo/0B7ToTsw7hY/s320/roaming-pki.JPG" alt="" id="BLOGGER_PHOTO_ID_5350173158236354482" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;the work flow will be -&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Step 1: The customer PFX is secured archived with EzIdentity and is issued a Security 2FA Token (hardware Or Software). Calling Application does not have any access to Token Secrets Or PFX.&lt;/li&gt;&lt;li&gt;Step 2: User logs into Application with Strong 2FA Authentication. Customer goes to transaction flow and wishes to sign the transaction.&lt;/li&gt;&lt;li&gt;Step 3: Application will ask for Strong Authentication again at transaction confirmation. If customer has Challenge Response Token then user can create MAC on his token otherwise normal OTP.&lt;/li&gt;&lt;li&gt;Step 4: Application will call EzIdentity to sign on behalf of user the “To be Signed Data” and Signature OTP. If OTP validation is successful then EzIdentity will sign transaction using user’s PFX.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;2. Conventional PKI Approach -&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sj-i7ZaDpOI/AAAAAAAAAyw/KGF1-BWpI3Q/s1600-h/conventional-pki.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 489px; height: 139px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/Sj-i7ZaDpOI/AAAAAAAAAyw/KGF1-BWpI3Q/s320/conventional-pki.JPG" alt="" id="BLOGGER_PHOTO_ID_5350174023655597282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;the work flow will be -&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Step 1: The customer carries his PFX on the token or flash drive. The PIN is already sent via SMS and person remembers or store it.&lt;/li&gt;&lt;li&gt;Step 2: User logs into Application with PKI based authentication. Customer goes to transaction (TX) flow and wishes to sign the transaction. &lt;/li&gt;&lt;li&gt;Step 3: Application will promote user to select Certificate from Token Or Flash Drive, Enter the PIN and perform digital signing. The signed data and PKCS signature is posted. &lt;/li&gt;&lt;li&gt;Step 4: Application will call EzIdentity with signed data and PCS signature to validate the certificate and verify the signature. If both are success then EzIdentity returns success to application.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;EzIdentity gives an extremely cost effective solution when it comes to unified platform for OTP as well as Digital Signatures. This is the uniqueness that benefits to the enterprises in terms of platform management, support, training and roll-out.&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Next Steps&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="mailto:vikram@ezmcom.com?subject=Request%20A%20Call"&gt;Click here&lt;/a&gt; to Request a call&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Email me at vikram@ezmcom.com&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Visit us at &lt;a href="http://www.ezmcom.com/"&gt;www.ezmcom.com&lt;/a&gt; for more information&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-6323509448324917947?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/6323509448324917947/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/06/ezcert-ezidentity-offering-for-pki.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/6323509448324917947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/6323509448324917947'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/06/ezcert-ezidentity-offering-for-pki.html' title='EzCert: EzIdentity Offering for PKI (Roaming and Conventional Approaches)'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-9xE9-FdEVY/Sj-hMNMjdOI/AAAAAAAAAyY/PF5v1EsNchU/s72-c/pki-options.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-2517628881296677424</id><published>2009-06-12T09:40:00.000-07:00</published><updated>2009-06-12T17:46:02.738-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Monetization of Authentication Service'/><title type='text'>Making Money from Tokens</title><content type='html'>&lt;span style="font-size:100%;"&gt;Security is looked as sunken investment where security solution is a cost that is part of the operation cost for running the business or service. Now it is changing esp. for the retail and corporate online commerce and banking.&lt;br /&gt;&lt;br /&gt;BFSI industries are looking at authentication and making the needed investments due to following three reasons -&lt;br /&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Regulation across the globe is demanding all the banking and trading companies to implement Second factor Authentication.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Online interface is a must. you want to keep your customer, they demand online option and for free.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;SMS is not reliable and costly affair when the volume and velocity of the users and their transactions grows exponentially. You cannot give SMS as only option.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-size:100%;"&gt;Esp. Banks in Asia have started looking into offering choice to the customer. Starting in Singapore, India, Malaysia all the countries are looking at offering variety of tokens to their customers but interesting they are charging for these tokens.&lt;br /&gt;&lt;br /&gt;Please have a look at the following two examples of Asian banks - &lt;a href="http://www.ocbc.com/"&gt;OCBC &lt;/a&gt;from Singapore and &lt;a href="http://www.axisbank.com/"&gt;AXIS Bank&lt;/a&gt; from India.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.ocbc.com/"&gt;OCBC Bank&lt;/a&gt; &lt;/span&gt;&lt;span style="font-size:100%;"&gt;- they have launched 3 different form of tokens - SMS based , Mobile Phone based (mobile banking along with OTP generator) and Hardware token.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/SjKLfVUj8KI/AAAAAAAAAxc/Mq6G30UuQ-4/s1600-h/ocbc-1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 384px; height: 218px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/SjKLfVUj8KI/AAAAAAAAAxc/Mq6G30UuQ-4/s320/ocbc-1.JPG" alt="" id="BLOGGER_PHOTO_ID_5346489078057791650" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;choice of tokens&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/SjKL3NNUn7I/AAAAAAAAAxk/egdHy6UfLh0/s1600-h/ocbc-2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 382px; height: 197px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/SjKL3NNUn7I/AAAAAAAAAxk/egdHy6UfLh0/s320/ocbc-2.JPG" alt="" id="BLOGGER_PHOTO_ID_5346489488196804530" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Mobile Token is Strongly Recommended&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.axisbank.com/"&gt;AXIS Bank&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; - they have launched again 3 different forms of tokens - SMS based, Web Token (OTP generated for your browser - not an exe installer but java applet approach) and Hardware Token.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_-9xE9-FdEVY/SjKNsiYiSgI/AAAAAAAAAxs/RaztLb6edkQ/s1600-h/axis-bank-1.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 359px; height: 362px;" src="http://1.bp.blogspot.com/_-9xE9-FdEVY/SjKNsiYiSgI/AAAAAAAAAxs/RaztLb6edkQ/s320/axis-bank-1.JPG" alt="" id="BLOGGER_PHOTO_ID_5346491503925676546" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Netsecure - added authentication for&lt;br /&gt;retail and corporate banking&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/SjKOFr1HwUI/AAAAAAAAAyE/4_oUGXWe8MM/s1600-h/axis-bank-4.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 382px; height: 179px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/SjKOFr1HwUI/AAAAAAAAAyE/4_oUGXWe8MM/s320/axis-bank-4.JPG" alt="" id="BLOGGER_PHOTO_ID_5346491935958221122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;hardware token for INR 800 per token&lt;br /&gt;and replacement for INR 500&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_-9xE9-FdEVY/SjKOA0ZeugI/AAAAAAAAAx8/e_a30npZFMg/s1600-h/axis-bank-3.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 413px; height: 224px;" src="http://2.bp.blogspot.com/_-9xE9-FdEVY/SjKOA0ZeugI/AAAAAAAAAx8/e_a30npZFMg/s320/axis-bank-3.JPG" alt="" id="BLOGGER_PHOTO_ID_5346491852358859266" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Web token for INR 150 pa&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-9xE9-FdEVY/SjKN79Pcq8I/AAAAAAAAAx0/vUZbDF6LH8M/s1600-h/axis-bank-2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 448px; height: 174px;" src="http://4.bp.blogspot.com/_-9xE9-FdEVY/SjKN79Pcq8I/AAAAAAAAAx0/vUZbDF6LH8M/s320/axis-bank-2.JPG" alt="" id="BLOGGER_PHOTO_ID_5346491768833354690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;SMS Token for INR 150 pa&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;Above shows how banks are moving into generating revenue from a value added service to their internet banking.  With this approach, monetizing the authentication token, there are changing the mind set on creating security as a sunken cost.&lt;br /&gt;&lt;br /&gt;It is good for the customer too as they get to chose their token and also bank is able to offer not cheap security solution.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Steps&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="mailto:vikram@ezmcom.com?subject=Request%20A%20Call"&gt;Click here&lt;/a&gt; to Request a call&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Email me at vikram@ezmcom.com&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Visit us at &lt;a href="http://www.ezmcom.com/"&gt;www.ezmcom.com&lt;/a&gt; for more information&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-2517628881296677424?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/2517628881296677424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/06/making-money-from-tokens.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/2517628881296677424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/2517628881296677424'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/06/making-money-from-tokens.html' title='Making Money from Tokens'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-9xE9-FdEVY/SjKLfVUj8KI/AAAAAAAAAxc/Mq6G30UuQ-4/s72-c/ocbc-1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3016247286097812909.post-8024466193194013128</id><published>2009-06-12T09:24:00.000-07:00</published><updated>2009-06-12T09:39:16.392-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Authentication Platform'/><title type='text'>Welcome note</title><content type='html'>We welcome you to our new blog primarily focused on EzIdentity authentication platform. We will share a lot on the&lt;br /&gt;&lt;ul&gt;&lt;li&gt;salient features&lt;br /&gt;&lt;/li&gt;&lt;li&gt;use cases - value and business proposition&lt;br /&gt;&lt;/li&gt;&lt;li&gt;"behind screen" technologies&lt;br /&gt;&lt;/li&gt;&lt;li&gt;upcoming features&lt;/li&gt;&lt;li&gt;case studies&lt;br /&gt;&lt;/li&gt;&lt;li&gt;comparison with other technologies and platforms&lt;/li&gt;&lt;li&gt;achieving regulations and compliance&lt;/li&gt;&lt;li&gt;total cost of ownership and return on investment&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;We look forward to your feedback, comments, suggestions for us to make EzIdentity platform best suited for market need esp. yours.&lt;br /&gt;&lt;br /&gt;Thanks for your support.&lt;br /&gt;&lt;br /&gt;Yours truly,&lt;br /&gt;vikram sareen,&lt;br /&gt;Co-Founder,  EZMCOM Inc.&lt;br /&gt;www.ezmcom.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3016247286097812909-8024466193194013128?l=ezidentity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ezidentity.blogspot.com/feeds/8024466193194013128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ezidentity.blogspot.com/2009/06/welcome-to-ezidentity-blog-by-ezmcom.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/8024466193194013128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3016247286097812909/posts/default/8024466193194013128'/><link rel='alternate' type='text/html' href='http://ezidentity.blogspot.com/2009/06/welcome-to-ezidentity-blog-by-ezmcom.html' title='Welcome note'/><author><name>Vikram Sareen</name><uri>http://www.blogger.com/profile/12307718926176750129</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_-9xE9-FdEVY/SQGRgZig9ZI/AAAAAAAAACk/eKCafV4IcAM/S220/P1030594.JPG'/></author><thr:total>0</thr:total></entry></feed>
