|
Key Features
Authentication Services
Multi-factor authentication and mitigation
- Keystroke Dynamics
- Device Tags
- SMS delivered one-time-passwords
- SMTP delivered one-time-passwords
- Challenge-Response Questions
Policy Management Services
Robust, risk-based policy management
- Factor Selection: Select the factors to be utilized on a policy by policy basis
- Workflow Definition: Easily define which observed factors are assessed and which mitigation factors are provided
- Assignment: Associate policies to users and groups based on business and security requirements
- Configurable synchronization with identity stores
- Federation of identity stores, access points, and policies
Workflow Services
Integrated capabilities for managing authentication process
- Enrollment: Guides the user in establishing keystroke dynamics template, challenge-response questions, and device tags
- Verification: Captures and checks multiple factors to verify identity
- Mitigation: Provides user login assistance according to established policy if the primary factor cannot be verified
- Password Reset: Accommodates password reset according to security policies of the organization
Centralized Management and Reporting Tools
Secure, browser-based console
- Server Operations & Peer Status
- User and group enrollment status, login history and access trends
- Help desk tools for troubleshooting
- User and group failed login detail for case management
Role-based access
Peering Services
Integrated support for a multi-peer replication and failover configuration
- Peer-to-peer communication is via secure channel
- Each peer includes a secure data repository mitigating many single points of failure
- Supports an optional centralized repository configuration
- Two-peer system supports up to 72,000 authentications per hour
Flexible and Secure Architecture
Server-based, security-optimized architecture
- Key exchange using 2048-bit asymmetric encryption
- Message encryption using 128 & 256-bit AES
- Encrypted Repository
- SSL channel encryption as optional additional layer and several mechanisms used for preventing replay
|