home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers





  F E A T U R E 
A Token of Our Esteem

September 6, 1999


Hardware Tokens: A Hands-On Look
Token-Based Authentication
We focused on challenge-response tokens and not on smartcard-based devices. Most tokens are credit-card-sized or smaller with internal chipsets programmed to calculate complex algorithms. Some algorithms are proprietary (like SecurID's) while others rely on the standard DES-based codes. Tokens may have a user-input interface--in the form of a keypad--or none at all. Most input is solely to allow PIN entry to "unlock" the card and let the user see the proper pass code. Some cards offer additional authentication schemes or programmability that can be selected through this interface. Some vendors offer other gimmicks, such as a calculator or light-sensitive inputs. None of these additional features change the basic idea behind a token--it is something the user holds, verifying he or she is authorized to have access.

In choosing a token solution, it is important to review the actual hardware that your users will employ. Several key areas to consider are battery life, displays, interfaces, programming, size and durability. All tokens run on batteries; most will run from two to five years before the battery will need to be changed or the token replaced. Output displays typically are LCD-based though the quality and clarity of these screens varies greatly. A token should be easy to read at a glance when next to your keyboard or monitor. Consider if the interfaces on the token are easy to work with, if programming can be accomplished quickly and accurately, and if the size of the device is conducive to easy handling while not being easy to misplace. Finally, consider durability. In an interesting and unplanned test, one of our SecurID key fobs was inadvertently sent through a washing machine (warm wash/cold rinse). In this new level of testing for Network Computing, the key fob survived and continues to function flawlessly.

It's worthwhile to consider some other potential "bad token scenarios" and their ramifications. Although we couldn't stress-test the durability of the vendors' tokens, some (such as Vasco's Digipass 300) seem to be more fragile than others. Then there's always the potential of loss or theft. It will mean downtime for your user and administrative headaches if new tokens need to be issued and the missing token must be disabled or invalidated. Finally, you might just forget to take your token with you.

PAGE: 1 I 2 I 3 I 4 I 5 I 6 I 7 I 8 I 9 | 10 I NEXT PAGE
 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights