290 likes | 618 Views
Tokenless Two-Factor Authentication for Juniper SSL VPN Appliances. Vesa Tiihonen, Director Tectia Corporation. September 27 th 2011. Contents. Tectia MobileID Introduction Mobile Authentication – Use Cases and Benefits Key Differentiators of Tectia MobileID Juniper Technology Alliance
E N D
Tokenless Two-Factor Authentication for Juniper SSL VPN Appliances Vesa Tiihonen, Director Tectia Corporation September 27th 2011
Contents • Tectia MobileID Introduction • Mobile Authentication – Use Cases and Benefits • Key Differentiators of Tectia MobileID • Juniper Technology Alliance • SSL VPN Login Use Cases • Tectia MobileID integration with Juniper SSL VPN • Summary
Best tokenless 2FA solution available • Tectia MobileID : a next-generation tokenless authentication solution • Multi-factor appliance designed specifically for on-demand and out-of-band authentication, • Based on high quality SMS One-Time-Password (OTP) as strong authentication technology, • Supports also other OTP delivery methods, such aspassword lists, email OTP, and any OATH compliant hardware and software tokens. • Fully customizable • Operator Grade SMS Messaging Connections Out-Of-The-Box
SMS authentication use cases When to consider tokenless login • When you have geographically dispersed groups of users • When you have a mobile / remote workforce • When you provide an extranet • When you have ad-hoc login requirements • When you do not want to invest in and manage hardware • When you can’t wait weeks for a new token to be delivered
Benefits of using Tectia MobileID • No seed data to be compromised • No security devices to be stolen or lost • 24/7 service deactivation provided by operators, not only by your company helpdesk • One-Time Password unpredictable and 100% random, unlike with tokens • Ability to detect fraudulent activity, e.g. Man-in-the-Middle (MitM/MitB) attacks • Improved user login experience • Less administration • Fewer helpdesk calls
Benefits of using Tectia MobileID Fraud prevention and password management with SMS OTP • Pro-actively lock end user accounts after N failed login attempts • Notification of locked account via SMS • Permit account re-activation via SMS • GeoIP match on Mobile device location • Permit forgotten password/PIN reset via SMS, eliminating the need for helpdesk services Lock my account
Unmatched scalability and reliability • Scales to millions of concurrent users • Operator grade SMS delivery world-wide with SLA-guaranteed throughputtimes • Certified to work with • In live productionsince 2003 • Modular architecture that provides service provider-grade scalability,customization and control of networkconditions and business logic
Unmatched TCO and ROI • Flexible pricing models with ability to pay based on active use • Low TCO solution • Practically ZERO administration;new users activated instantly • Tokenless solution – no logistics overhead No extra or hidden costs!
Tectia MobileID – Fast deployment and activation Add/remove traditional token user vs. MobileID:
Tectia MobileID – Superior end-user experience • No end-user training needed • Usage 100% intuitive • No changes to existing login process • Works on any phone, andanywhere in the world So easy it makes your customers smile – guaranteed!
Tectia MobileID – multi-use authentication platform Tectia MobileID can solve ANY ad-hoc multi-factor authentication problem: • 2-factor authentication for SSL VPN access (RADIUS) • 2-factor authentication for Web Services and portals (SOAP) • Solving Man-in-the-Browser / Man-in-the-Middle threats withOut-Of-Band authentication • Multi-domain (LDAP) support • MS Outlook Web Access • Instant Messaging OTP • Any custom ad-hoc on-demand multi-factor authentication use case • 2-factor SMS OTP for MS Windows logins • Supports ALL OTP techniques: email, lists, OATH tokens, Voice, etc. • Cloud-based SMS OTP available Out-Of-The-Box • OTP and business logic for online banking transaction verification
Tectia MobileIDmRules framework Custom business logic for Authentication, Authorization and Access (AAA) • New authentication methods can be added and the existing ones extended • Authentication methods can be chained, triggered, scheduled, etc. • Network packets (i.e. RADIUS) can be re-written, routed, scheduled, etc. Sample custom access rule
Juniper Technology Alliance • Juniper SSL VPN with Tectia MobileID:Full turnkey2FA solutionwithoutthe challenges of firstgenerationtwo-factorauthentication! • Protect against unauthorized access to your critical business information • Reduce your IT administrative workload and hard costs, • Easily scale with tokenless, one time use passcodes delivered via SMS, • Be up an running in hours, not weeks or months! +
Direct integration to existing corporate infrastructure Juniper Technology Alliance 958482 Operator grade global 3G network Third party Gatewayor Integrated Tectia Messaging service One-time password Hello Jane, Your SMS password is 949372 AD/ LDAP Internet Firewall SSL VPN Remote user 15
Authenticating using SMS One-Time Password Scenario 1 – SSL VPN login
Authenticating using SMS One-Time Password On-demand SMS password for two-factor authentication
Authenticating using SMS One-Time Password And you’re logged in!
Authenticating using SMS One-Time Password Scenario 2 – Login with pre-distributed SMS
Authenticating using SMS One-Time Password And you’re logged in!
Technical integration with Juniper SSL VPN Adding a new RADIUS Server to VPN appliance
Technical integration with Juniper SSL VPN Adding a new RADIUS Client to MobileID appliance
Technical integration with Juniper SSL VPN Connecting Tectia MobileID to AD / LDAP
Technical integration with Juniper SSL VPN MobileID is LIVE – Start using it!
Tectia MobileID Web Admin Interface Administer the Virtual Appliance
Viewing Tectia MobileID Logs in Real-Time Viewing Tectia MobileID Logs in Real-Time
Try Tectia MobileID Live Today! • Live VPN demonstration for anybody, anywhere, free-of-charge: • Juniper SSL VPN login: • Register here: http://mobileiddemo.ssh.com/pub/index.php?plugin=register&app=juniper • Login and demo here: http://mobileiddemo.ssh.com/pub/index.php?plugin=testing&app=juniper
Summary Tectia MobileID Competitive Solutions • Operator grade messaging capabilities • Integrated HA messaging • Allows ad-hoc use • Highly scalable • Framework for customized login methods • Certified for Juniper SSL VPN • Typically no operator messaging support • No High Availability (HA), requires purchasing and configuring 3rd party messaging service or product • Accounts must be registered and provisioned to work • Typically for SME use only • Typically only few pre-defined methods available
Thank You! Your People. Your Secrets. Protected.