Presentation is loading. Please wait.

Presentation is loading. Please wait.

1 Passwords are Dead! Entrust IdentityGuard™ Chris Voice VP Identity Management.

Similar presentations


Presentation on theme: "1 Passwords are Dead! Entrust IdentityGuard™ Chris Voice VP Identity Management."— Presentation transcript:

1 1 Passwords are Dead! Entrust IdentityGuard™ Chris Voice Chris.voice@entrust.com VP Identity Management

2 Copyright Entrust, Inc. 2004 2 Entrust Confidential - Subject to Terms of MNDA Entrust We are Security Specialists èIndustry pioneer & leader with 90 patents èIntegration and support for leading technology vendors èPartnerships with leading Integrators èBest in class service and technical support èStrong balance sheet with over $100M in cash and no debt

3 Copyright Entrust, Inc. 2004 3 Entrust Confidential - Subject to Terms of MNDA Identity Theft Identity-Theft is the fastest growing crime in America… 10 MILLION victims in 2003 US Federal Trade Commission Losses from Identity theft cost $5 billion in 2003 (US Federal Trade Commission)

4 Copyright Entrust, Inc. 2004 4 Entrust Confidential - Subject to Terms of MNDA Phishing Losses from “phishing” cost financial institutions $1.2 billion in 2003 (Gartner)

5 Copyright Entrust, Inc. 2004 5 Entrust Confidential - Subject to Terms of MNDA What do your customers think? èMarket research is based on online survey findings collected by Greenfield Online between August 16 and 20, 2004 èRepresentative sample of 10,000 respondents was taken from Greenfield Online's panel of 3+ million consumers è2,000 completed surveys made up the results from consumers in the United States, Canada, Germany and the U.K èThe confidence interval of data collected is + or – 2.2%. èWhile the data collection was conducted on behalf of Entrust Inc, at no time were the survey respondents aware of Entrust participation

6 Copyright Entrust, Inc. 2004 6 Entrust Confidential - Subject to Terms of MNDA Participation in E-Commerce & On-line Banking Take-Away èSomething is preventing on-line users from participating in more sensitive / higher value transactions on-line. Do you participate in e-commerce? (on-line shopping, on-line banking, on-line travel booking, on- line bill payment, etc…) Do you bank on-line?

7 Copyright Entrust, Inc. 2004 7 Entrust Confidential - Subject to Terms of MNDA User Concern around Identity Theft Take-Away èMost users have specific concerns about on- line identity theft of users concerned about the security of on-line banking, including the possibility of your identity being stolen and someone else accessing your accounts?

8 Copyright Entrust, Inc. 2004 8 Entrust Confidential - Subject to Terms of MNDA User Reaction to Improved Security Take-Away èOn-line identity security is a barrier to up- take of on-line banking èThere is a business payback from increasing security of users who do not currently bank on-line would be willing to do so if the security of on-line banking was improved to significantly reduce the chances of your identity being stolen and account information accessed.

9 Copyright Entrust, Inc. 2004 9 Entrust Confidential - Subject to Terms of MNDA User Reaction to Improved Security Take-Away èOn-line identity security is a barrier to up- take of additional on-line banking services èThere is a business payback from increasing security of users would be likely to use additional, higher value, banking services online if the security of on-line banking was improved to significantly reduce the chances of your identity being stolen.

10 Copyright Entrust, Inc. 2004 10 Entrust Confidential - Subject to Terms of MNDA Influence on User Buying Behavior Take-Away èCustomer buying behavior is being impacted by security concerns èDifferentiation based on security can be a competitive advantage of users would be likely to be influenced in selecting a bank by the protection of your identity in on-line banking. of users would be very likely to switch banks to get better protection from identity theft.

11 Copyright Entrust, Inc. 2004 11 Entrust Confidential - Subject to Terms of MNDA User Mobility What this means: èAddressing on-line identity security requires solutions that work across multiple channels Which methods do you use or would you like to use to access your banking on-line? chose more than one…

12 Copyright Entrust, Inc. 2004 12 Entrust Confidential - Subject to Terms of MNDA “I skate to where the puck will be…”

13 Copyright Entrust, Inc. 2004 13 Entrust Confidential - Subject to Terms of MNDA What is required? “When you get to the core issue of most identity theft attacks, it really falls back to needing stronger authentication ” (John Pescatore, Gartner) Prevents an attack from being successful No reliance on user education Can be deployed now

14 Copyright Entrust, Inc. 2004 14 Entrust Confidential - Subject to Terms of MNDA User Acceptance of Strong Authentication Take-Away èCustomers are ready to accept an impact to user experience to deliver increased security èA small number would not, thus any solution must be able to operated optionally of users would be willing to use a second factor of authentication if it significantly increased your security of users would be likely to leave their bank, if it required this method for log-in.

15 Copyright Entrust, Inc. 2004 15 Entrust Confidential - Subject to Terms of MNDA Strong Authentication Challenge Usability & Cost Security

16 Copyright Entrust, Inc. 2004 16 Entrust Confidential - Subject to Terms of MNDA Authentication Approaches Purchase & Deployment Investment Authentication Strength Passwords ? IdentityGuard èStrong second factor security èInexpensive to produce and deploy èEasy to use and support Tokens PKI Smartcards

17 Copyright Entrust, Inc. 2004 17 Entrust Confidential - Subject to Terms of MNDA èRandom authentication card issued to each user èRandom characters in grid with row/column headers èSeparate plastic card or on existing card Entrust IdentityGuard Concept – Think “Bingo” Stand-Alone CardCard Add-On

18 Copyright Entrust, Inc. 2004 18 Entrust Confidential - Subject to Terms of MNDA èAt each log-in, user presented with randomly generated coordinate request –Different for each log-in –In conjunction with existing method (ex. User name / Password) èUser looks up coordinates and enters response Authentication Process 92 AnyUser ******

19 Copyright Entrust, Inc. 2004 19 Entrust Confidential - Subject to Terms of MNDA Benefits èSecure –High entropy –Resistance to brute force –Resistance to phishing èEasy to Manage –Flexible/inexpensive to produce & distribute –Long-lasting card to minimize issuance costs –Real-life recovery to maximize “up-time”

20 Copyright Entrust, Inc. 2004 20 Entrust Confidential - Subject to Terms of MNDA Benefits cont’d èEasy to Use –Intuitive method –Convenient form-factor –Extensible to other channels èCost –Fraction of cost of traditional hardware authentication devices Call Center / Interactive Voice Response Mobile Devices

21 Copyright Entrust, Inc. 2004 21 Entrust Confidential - Subject to Terms of MNDA Easily Fits into Current Environment End User IdentityGuard Existing Password Sign-on Application 1. Login page with randomly generated IdentityGuard challenge 2. User enters user name, password and IdentityGuard response 3. User name and password authenticated with existing infrastructure 4. User name and IdentityGuard challenge & response sent to server 5. IdentityGuard server returns authentication confirmation 6. User Authenticated Linux-based High scalability & availability

22 Copyright Entrust, Inc. 2004 22 Entrust Confidential - Subject to Terms of MNDA Summary of Benefits èStrong Security èEasy to Manage èEasy to Use èExtensible èLow Cost

23 Copyright Entrust, Inc. 2004 23 Entrust Confidential - Subject to Terms of MNDA Questions? Presenter Name chris.voice@entrust.com For more information on Countering Identity Theft: http://www.entrust.com/identityguard/index.htm chris.voice@entrust.comhttp://www.entrust.com/identityguard/index.htm


Download ppt "1 Passwords are Dead! Entrust IdentityGuard™ Chris Voice VP Identity Management."

Similar presentations


Ads by Google