Authentication and SignOn at RSA SF by Leticia Smith
March 2016 – One of the dominant topics at the RSA Conference in San Francisco for the Enterprise environment was authentication and signon for users with authorization. While there were a large number of companies addressing externally generated threats to the data centers and cloud services, a number of companies were focusing on challenges of authenticating authorized users.
Challenges include keeping authorized users only accessing data they are supposed to, making sure that the person signing into the system is the correct person and making sure that person is not duplicated electronically, and that there are no people listening in on the data and connections. The show featured over 80 companies in this space on the expo floor such as SecureAuth, AuthLite, Inside Secure, Keypasco, Rambus Cryptogrphy Research, and ThreatMetrix .
While passwords and password control is the dominant technology for authentication, other methods are coming into the workplace. A key point for the authentication technology, is it should not be invasive to or interfere with the work product being created by the employees being authenticated. It is needs to have a low degree of false positives, and should not require a learning curve to operate or administrate.
SecureAuth Authentication System
One of the new technologies is an updated biometric tracking from SecureAuth. They have system that generates a typing style and pattern to be associated with the password. In this structure, the characters of the password are only part of the authentication. The pressure, speed, pauses, timing of the entry is the other part of the authentication. The system then supports standard enterprise authentication management – what should be accessible, at what time, with what permissions, etc.
Rambus was showing a number of solutions including their protection against Simple Power Analysis (SPA) and Differential Power Analysis (DPA). Their solutions include techniques for protecting devices against DPA and related side-channel attacks as well as tools for monitoring the effectiveness of the counter measures.
Companies such as HP, Dell and IBM were showing integration of authentication in their public and private facing data centers and cloud solutions. The solution being shown dealt with the management of the solution and the enterprise level reporting that occurs with its use.


