Support
 
  | Products | Services | Partners | Support | News | Company | Purchase | View Cart | May 10, 2005    
 Knowledge Base
 Troubleshooting
 Interactive Support
 Software Download
 Supported Devices
 Support by Partner
 Report a Bug
 Product Registration

 Security Concepts
 Authentication Basics
 PKI

 Documents
Security Concepts

I/O Software understands that advanced information security is not simply a loose conglomerate of different applications and tools. To ensure proper access and logical security, a product must act as a well-balanced authentication management infrastructure and cover at a minimum the following aspects:

  • Authentication - Verification of users' claimed identities by using one or more of the following: secrets (what you know), tokens (what you have) and biometrics (what you are).
  • Authorization - Determination that a user is authorized to carry out a particular action, such as logging on to an application, accessing a database, or decrypting files.
  • Audit - Detailed logging of authentication and authorization actions, with the ability to review and analyze logs to uncover suspicious activities, failures, etc.
  • Administration - System administrators can centrally enroll users and define policies that control authentication and authorization for particular users, user groups, or applications.

When selecting software and technologies, one must also take into account:

  • Integrity - Authentication data (such as biometric templates), device/terminal/workstation communications as well as policy and system settings are secure and protected from tampering and forgery by other applications, hackers, etc.
  • Confidentiality - Secret application data as well as authentication and authorization information is encrypted at all times to protect it from access by unauthorized users, hackers, etc.
  • Non-Repudiation - Tools and logging mechanisms ensure that users cannot claim that an action occurred without their knowledge.
A well designed product will also provide such benefits as:
  • Convenience - Properly implemented security functionality makes a system easier to use, so that users will not attempt to bypass it or be inconvenienced by it.
  • Flexibility - Different applications call for different security measures, so security layers are flexible in order to provide the right amount of protection to the problem being addressed.
  • Modularity - System can be customized to fit a customers needs, using only the components necessary for a particular application, while being easily upgradeable.
  • Centralization - Administrators are able to manage the whole system in a consolidated and integrated manner, from a central or multiple locations.
  • Return on Investment - Organization save time and money by eliminating the 50% or more of help desk calls related to lost, stolen, and forgotten passwords.
Security is also always only as strong as its weakest link. Just as it is flawed to expect a system to be secure when it is protected by password authentication, it is inappropriate to assume system security when there is no coherent and comprehensive security infrastructure.

I/O Software's products represent a true end-to-end solution that cover all aspects of secure authentication; from providing multiple device support and centralized account management tools, to supplying a range of applications and services. Supporting various devices allows developers and integrators to focus their attention on their specific security challenge at hand and selecting the most flexible device for their problem.

I/O Software's SecureTec SDK provides developers and integrators with the perfect tool to do just that. It hands them the flexible tools to leverage I/O Software's comprehensive security platform and gives them immediate access to a multitude of devices, client/server communication, account management, and other related tools. I/O Software offers its end-to-end solution platform to all of its partners, particularly system integrators and developers.

True security in an end-to-end solution is implemented as a comprehensive system. It is a really a process that involves all 'links' within a chain and does not single out or ignore any one element. I/O Software can help clients define that process and related technologies via our consulting group.

Security issues are often generated by patching different pieces into a conglomerate of applications that lack integration and full interoperability. I/O Software's products bridge potential gaps and provide true and integrated security.


Go to Authentication Basics  

Return to Top