Blog

Low Cost Multi-factor Authentication!

The recent publication of the analysis of Multi-factor Authentication Products found in US NIST 2017 Digital Identity Guidelines makes very interesting reading!

CASQUE SNR fulfils the description of “Multi-factor Cryptographic Hardware Device able to address Assurance Requirements at Level 3” – the highest level.

CASQUE SNR doesn’t need any other supporting methods as Section 4.5 Summary of Requirements in the above document explains.

The overall cost of Ownership for Organisations wanting the highest assurance is therefore smaller with CASQUE SNR than those methods such SMS and OTP that need reinforcement from multiple other authentication methods.

Corporate Vision Magazine has announced the winners of the 2017 Technology Innovator Awards.

We have won another award –

“Best Identity Assurance Authentication Technology: CASQUE SNR”

Corporate Vision Magazine has announced the winners of the 2017 Technology Innovator Awards.

Now celebrating its third year, the Technology Innovator Awards return in 2017 to showcase the talented individuals, teams and firms that form the backbone of this dynamic industry.

We aim to raise the profile of those who’s innovative thinking and commitment to technology make the industry what it is today.

Laura Hunter, Awards Co-ordinator, commented: “Technology is vital to everyday life, therefore it has been a real pleasure to be able to showcase those dedicated to making innovations happen. I would like to congratulate my winners and wish them the best of luck going forward.”  

Corporate Vision Magazine 2017 Technology Awards

Many MFAs need Support!

The recent document – NIST Special Publication 800-63B, Digital Identity Guidelines, Authentication and Lifecycle Management dated June 2017 makes interesting reading – it places out of band (SMS messages) in the lowest category of Authentication Assurance Levels with OTP only slightly better.

CASQUE SNR easily fulfils the criteria of a “Multi-factor Hardware Crypto Device” as defined in NIST 800-63B and so is able to be employed for applications demanding the highest assurance level without requiring multiple other methods.  It is the only Multi-factor Authentication product certified by UK’s NCSC as suitable for secret.

If you would like a detailed exposition of the weakness of existing MFA techniques just use the contact form.

Another Biometric Authentication falls over

Biometric Authentication isn’t the bee’s knees or its irises or its sound.
Biometrics is deprecated as a means of Authentication in NIST Digital Identity Guidelines, not only because of some amusing cases:
BBC fools HSBC voice recognition security system;
Lyrebird claims it can recreate any voice using just one minute of sample audio;
Researcher shows malware can make headphones into microphones and record voice:
but because it fails the rule of high assurance systems- “must always be able to recover from compromises” (despite the great advances in organ transplant surgery).

Identity Assurance in Canada

Distributed Management Systems is delighted to welcome BTI Global Innovation as our Distributor for CASQUE SNR Products in Canada.

BTI Global Innovation Inc. is a full service international business development and consulting services company, serving government, International Investment Promotion organizations, Economic Development Agencies, Research Institutions and industry clients in the ICT, advanced engineering, aerospace, defence,  security and cyber security sectors in North America and Internationally.

The contact is Bernadette Terry

New Goldmine in Cloud Identity

The growth of Cloud Computing has created a new goldmine and this paper describes the opportunity and shows how it can be exploited.

There is a significant increased risk of Insider Attack simply because utilising a Managed Service Provider (MSP) widens the potential attack population and as human motives of greed, revenge and ideology persist, there is more likelihood that these inspire malevolent acts (intelligence gathering, sabotage, ransom) by Insiders and their collaborators.

The overlap of MSP credentials that can access their Clients Systems make penetration of the MSP a fruitful target allowing a rich vein of data plunder from the Clients. The recent published report “Operation Cloud Hopper”  by PWC and BAE Systems describe the mechanisms of such an attack.

Having a Multi-factor Authentication (MFA) Technology that can resist country sponsored hacks and deny Insider attacks is of course the answer, but most existing techniques do not pass scrutiny on close inspection.  If you think Password only credentials are adequate or believe Biometrics provide access with non-repudiation or think SMS validation is secure, or if you feel that popular authentication products that rely on fixed secrets are safe from Insider attacks; we can definitely improve your scrutiny thresholds.

We suggest that an additional necessary attribute for an Identity Provider is that the Client should “own” it. This prevents locked-in syndrome to the main MSP and also allows other Cloud Providers to be accessed with a consistent level of Identity Assurance. Such independent Identity Provider provision is possible using the Open Id Connect Protocol.

Now the good news- we can let you mine this new goldmine by using our radical, innovative challenge-response methodology, CASQUE SNR, which provides Key Generation and Key Distribution without dependence on a fixed secret and so is immune from Insider attacks.

CASQUE SNR is proven – in use by UK Ministry of Defence, recent version certified at source code level by UK’s National Cyber Security Centre as suitable for Secret. CASQUE SNR is protected – US patent granted with all of its 19 claims in 2016, three further inventions remain as private knowhow, no dependence on any third party IP. CASQUE SNR is definable – In US NIST 2016 publication “Digital Identity Guidelines”, it fulfils the criteria of a “Multi-factor Cryptographic Hardware device able to address Assurance Requirements at Level 3” which is the highest level.

Adding CASQUE SNR to your offerings brings a powerful differentiator as well as a lucrative revenue stream.

Contact us to discover how we can help with a low cost entry to this important opportunity.

 

NCSC completes latest CASQUE SNR Certification

NCSC completes latest CASQUE SNR Certification

CASQUES SNR v2.2 has just completed CAPS certification by NCSC and is suitable for Secret as part of a layered approach.

Uniquely, CASQUE SNR protects from Insider Attacks.

New Token manifestations include two optical Tokens, secure Sims and contactless Smartcards.

Evaluation system that works out-of-the box available now!