Strong Authentication for Remote Access with Smart Cards or USB Tokens
Remote Access is one of the most vulnerable entry points to IT resources, as it is open to attacks originating outside of the organization’s physical perimeter. For organizations concerned with rising security threats and weakness of password authentication, ActivIdentity offers strong authentication for a wide variety of remote applications.
Features and Benefits
- Strong security – Two-factor authentication establishes the identity of the user through possession of a smart card or USB token, and knowledge of the PIN code (like an ATM). With ActivClient® the users’ authentication credentials (PKI keys and certificates, static passwords, or one time passwords) are stored securely within the device.
- Ease of use – End-Users simply insert their smart card (or USB token) and type their PIN code to enable strong authentication.
- Accountability for compliance – With two-factor authentication, organizations have strong proof of identity in order to protect access to information systems and link online activity to users, an essential element to addressing regulatory compliance.
- Portability for digital certificates – Smart cards are the ideal way to store certificates and private keys. Instead of leaving keys behind on a workstation, users can safely carry their credentials, reducing exposure to theft and making it easy to log in from multiple workstations.
- Extensible – A smart card can be used for multiple applications such as physical and logical identification, data security and digital signatures and file/disk encryption. When combined with ActivIdentity SecureLogin® SSO, the smart card or USB token also enables Single Sign On for improved security and user productivity.
Certifications
- ActivClient PIV API module – FIPS 201 certified by NIST
- ActivClient supports FIPS 140 certified smart cards and applets
- ActivKey drivers – WHQL certified
Standards compliance
- GlobalPlatform / OpenPlatform
- Java Card™
- PKCS#11
- Microsoft® CAPI / Crypto API
- ISO 7816 o PC/SC
- PIV / FIPS 201
- CAC (Common Access Card)
- GSC-IS 2.1
Supported VPN / Dial-up products
- Check Point Connectra™
- Check Point Firewall-1 / VPN-1
- Cisco® Systems VPN solutions o Citrix Access Gateway™
- Juniper® Networks VPN solutions
- Microsoft ISA Server
- Microsoft L2TP/IPSec VPN client
- Microsoft Remote Access Server (RAS)
- Nortel Networks™ Contivity
- Any VPN supporting RADIUS / TACACS+
- Any VPN supporting PKCS#11 / CAPI
ActivIdentity products used in this solution
Supported web products
- Apache
- Microsoft Internet Information Services
- Microsoft Outlook® Web Access
- Sun Java™ System Web Server
- Any web site supporting SSL client authentication
- Any web server capable of RADIUS reques
Supported remote applications
- Citrix Presentation Server™ (and Web Interface)
- Microsoft Terminal Services
- Sun™ Secure Global Desktop and Sun Ray