A common challenge for enterprises in today’s business world is allowing employees access to their company email accounts from any location while maintaining strong security. Many enterprises have deployed Microsoft Outlook Web Access (OWA) providing a Web-based email system that can be accessed from any machine with just a web browser. The problem is that OWA offers minimal security as it only relies on the single-factor authentication - password - which can be easily compromised.
Adding a strong authentication to an OWA deployment provides enterprises with a secure email system. Unfortunately, most existing strong authentication solutions require additional hardware devices such as smart cards, USB keys or One-Time Password (OTP) hardware tokens, which are expensive to implement, deploy, manage and very inconvenient to the users.
Deepnet Unified Authentication Platform for OWA is a two-factor authentication solution designed specifically for securing outlook web access, without the requirements of new hardware devices. Deepnet Unified Authentication Platform utilizes the devices users already have (computers, mobile phones, PDA etc) or the user’s behavioural biometrics (typing pattern, voiceprint), as the second factor. This eliminates the need to distribute new hardware, making the system cost effective, user friendly and simple to manage.
Key Benefits
Deepnet Unified Authentication Platform for OWA consists of the Deepnet Authentication Server, Token Repository Server and Microsoft Active Directory Server, as illustrated below.
These servers can be installed and operating on separated machines or on a single machine, depending on the scale of the customer’s business applications.
Deepnet Authentication ServerDeepnet Authentication Server is a secure, scalable, cross-platform authentication server that centrally controls access to web applications. Deepnet Authentication Server is designed to be deployable across a wide range of commonly available platforms that supports Java. Therefore, it can run on Windows, Linux, Unix, Sun OS and many mainframes.
Token RepositoryDeepnet Authentication Server uses a SQL database server as its token repository. It can be connected to the customer’s existing SQL server (MS-SQL 2000/2003, Oracle) or mySQL server which is included in its installation package.
Active DirectoryDeepnet Authentication Server supports assignment of tokens to users residing in Active Directory without modification of the directory schema. User data is not imported from the directory into Deepnet Authentication Server. Instead, Deepnet Authentication Server queries the directory during the authentication process to validate the user’s status. Changes made in the directory are automatically and immediately reflected in Deepnet Authentication Server.
Deepnet Unified Authentication Platform supports several authentication methods including mobile phone based one-time password token, device based soft token, virtual smart card and software-only behaviour biometrics.
Mobile 2x2 is a one-time password token application. It is a small J2ME application downloadable to any Java enabled mobile phones, including Windows Mobile, RIM Blackberry, Symbian OS and Palm OS. Mobile 2x2 also supports Windows desktop. Its Desktop Edition runs on Windows 2000/XP and Windows Mobile. Read more...
Mobile Pass is also a one-time password solution. While Mobile 2x2 generates one-time password offline, Mobile Pass delivers one-time password in real time via SMS, email or voice over the phone. Mobile Pass works with any mobile phone. Read more...
Based on the Keystroke Dynamics science, TypeSense accurately identifies users by their “type prints” - the unique patterns they type characters across a keyboard. TypeSense requires no hardware and no software installation. Read more...
VoiceSense is a text and language independent biometric speaker verification system that also requires no hardware and no software installation. Voice can be received from the user’s mobile phone, landline telephone or computer microphone. Read more...
Smart ID is a virtual smart card in a software form factor, providing the same advanced security functionality as physical smart cards, but at only a fraction of the cost. Smart ID is fully compliant with PKI architecture with supports of PKCS #11 and MS-CAPI. Smart ID is available for Windows 2000/XP and Windows Mobile. Read more...
Device Pass is a software-based two-factor authentication solution based on patent-pending device fingerprinting technologies. Device Pass client is available for Windows 2000/XP and Windows Mobile. Read more...
Remote 2x2 is a remote two-factor authentication solution that requires no hardware and no software installation. All the user needs is a standard web browser such as Internet Explorer, Firefox or Safari for Mac OS. Read more...
Smart 2x2 is a smart device token that requires a browser plug-in. Smart 2x2 is natively supported by Deepnet Explorer web browser, and its plug-in software is available for Internet Explorer and Firefox for Windows. Read more...
To download this document in PDF format click here.