Specializations › Information security › Authentication of users

In the majority of cases, users use simple passwords to access the PC (network workstation or mobile computer), information resources (databases and file servers), and different application systems. This presents a serious and easily realized threat of unauthorized access to these resources by unauthorized users (both internal and external ones). The causes of this are as follows:

  • user passwords, as a rule, are simple and with low resistance to cracking (secure passwords are hard to memorize), so, using special tools, the task of guessing the majority of user passwords is feasible in reasonable time
  • using one password for the entire set of resources creates a threat of cracking, especially during remote access and transmission of passwords over unprotected transmission channels (a malicious user can intercept or crack a user’s password on one information resource and then, with a high probability, gain unauthorized access to the remaining resources in the name of this user)
  • to reduce the probability of unauthorized access, users have to create and store a unique password for each information resource, but this involves memorizing several passwords and presents an inconvenience because the user has to enter several different passwords to access different resources (logon to a network, access to databases and special applications, etc.)

To address security problems occurring with simple passwords, more reliable tools of user authentication are needed. Such tools implement severe (reliable) authentication systems based on special attributes. They are much more reliable than simple passwords, and cannot be cracked or modified.

Instead of using simple passwords, users can use more complex sequences of symbols (generated by special systems and written on convenient carriers), bifactor authentication systems, open key certificates or one-time passwords changed in time, making it technically impossible to crack them.

Using mobile physically protected storages (electronic USB-keys, smart cards and others) for storing authentication information also significantly increases security because the users need not memorize and enter a big number of passwords to access different resources.

Partners:

 

Aladdin 

 

RSA 

 

 

You can contact our specialists online and get the consultation