Welcome | Sign In
ECommerceTimes.com
Security

Microsoft, RSA Team on Windows User Authentication

Print Version
E-Mail Article
Reprints
Microsoft, RSA Team on Windows User Authentication

While the RSA-Microsoft solution cannot do as much as a smart card, which can contain a host of information about a user, including limitations on how he or she can use certain information, it may catch on because of its ease of implementation.


Microsoft (Nasdaq: MSFT) and RSA Security have said they will work together to develop authentication technology, making it easier to secure Windows and keep sensitive corporate information safe. The announcement came at RSA's annual security conference in San Francisco.

Specifically, Microsoft said it will use RSA's SecurID technology to offer an alternative to traditional password-based access control. SecurID uses authentication tokens in addition to a personal identification number (PIN).

The keychain-size tokens generate new, random digital passwords every 60 seconds that only work when the PIN number is also provided by the user.

Two Heads

This so-called two-factor authentication eliminates the need to constantly change user passwords and reduces the risk that unauthorized users will access a network. Unlike other options, however -- such as biometrics or other smart-card solutions -- the RSA option does not require that additional hardware be added to the network.

Art Coviello, RSA's CEO, called the solution a "smart, simple alternative to static passwords" that will help enterprises avoid "expensive and damaging security breaches."

"Customers have told us they want strong, integrated authentication technology," Microsoft security chief Michael Nash said.

Slow Going

The security industry has long tried to encourage enterprises to adopt more vigorous forms of identification and access control. Employees often choose easy-to-remember -- and therefore easy to decipher -- passwords, and passwords used for long periods of time can be stolen by hackers simply by tracking a user's keystrokes.

Despite the shortcomings of traditional passwords, hardware-based solutions such as smart-card readers have been slow to catch on, in part because of their added expense and in part because there is no single standard that would make smart cards universal, Gartner (NYSE: IT) research director Mark Nicolett told the E-Commerce Times.

"Card or token readers are still viewed as too costly and too risky an option by most enterprises," Nicolett said.

While the RSA solution cannot do as much as a smart card, which can contain a host of information about a user, including limitations on how he or she can use certain information, it may catch on because of its ease of implementation. "Anything that doesn't require ripping up the network or adding hardware that may or may not be the standard in five years is going to get a long look," Nicolett added.

Window to the World

Not surprisingly, making Microsoft deployments more secure is a key theme at the RSA confab. IDC analyst Allan Carey said while the improvement over passwords addresses only one of the many types of security concerns surrounding Windows installations, it may signal to Windows customers that Microsoft is serious about making it secure on all fronts.

"Anything Microsoft can be seen doing to make its products safer is going to be a positive in the minds of customers," especially those who may be considering alternatives such as Linux, Carey told the E-Commerce Times.

Also on Tuesday, Sun Microsystems (Nasdaq: JAVA) announced plans to roll out an identity-management solution for Windows and other Microsoft environments.

Sun said its Identity Manager, based on technology it acquired from Waveset Lighthouse, will enable centralized management of user identities across all different applications used in an enterprise.

Gates on Security

Both announcements came just ahead of a much-anticipated keynote speech by Microsoft chairman Bill Gates at the RSA conference. Gates used that keynote to highlight the various fronts on which Microsoft is working on the security problem, citing a laundry list of industry partnerships and technology efforts.

Gates also demonstrated a number of security features that Microsoft is including in its Windows XP service pack, including the built-in firewall and enhancements built into the Internet Explorer browser.


Print Version E-Mail Article Reprints More by Keith Regan


Talkback: Join the Discussion.
Re: Microsoft, RSA Team on Windows User Authentication
arnneisp
Posted 2004-07-18
Most of the security tokens today are old technology, expensive, uneasy to carry and ...

More by Keith Regan

Yahoo Slaps Fresh Coat of Gloss on Microsoft Deal Defense
June 30, 2008
With its shareholders meeting set to take place in less than five weeks, Yahoo has put together a 32-page presentation, emphasizing why the investors should vote to keep the current board in place. The company also reiterated why it chose to partner with Google instead of letting Microsoft buy part of it.
French Court Stings eBay With $63M Judgment Over Knockoff Sales
June 30, 2008
eBay is planning to appeal a ruling by a French court that ordered it to pay $63 million to the luxury goods maker Louis Vuitton Moet Hennessey. The court also barred the online auctioneer from selling four brands of perfume on its Web sites accessible in France.
New Auto Loan Leads Marketplace Shifts Into Drive
June 30, 2008
Reply.com's move into the auto finance market is a logical one the company, as automotive advertising spending is moving online in increasingly greater amounts. The company is partnering with the Detroit Trading Company to create a massive repository of auto finance leads online.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network