Authentication
Trust in identity is the basis of electronic relationships between clients and professionals, citizens and governments, and employees and organizations.
Conventional authentication mechanisms based on passwords are vulnerable to multiple phishing attacks that can result in identity theft. Therefore, adopting strategies that can support different and stronger authentication mechanisms is a critical competitive need.
Safelayer authentication offering allows implementing authentication mechanisms with the highest Level of Assurance (LoA), allowing the central management of multiple PKI domains and federation. Other authentication mechanisms such as strong password-based, as well as one-time passwords (OTP) can be added.
Maximum Trust for Exchanging Critical Information
Several regulations from different sectors and regions, including the NIST Special Publication 800-63-1, recommend adapting the security level of the authentication mechanism to the value of the electronic assets and business channels.
Digital certificates, for instance, allow implementing authentication mechanisms with the highest Level of Assurance (LoA) while also facilitating the interoperability and mutual recognition at both the corporate level and between the governments of different countries when the exchange of critical information must be protected.
Safelayer's authentication solution supports the management of trust through the use of policies. Notably, the policy management system of the Safelayer solution can classify the certificates (e.g., distinguish between qualified and non-qualified certificates) and other authentication mechanisms according to their security so that their use can be adapted to the different business channels.
Its focus on SOA (Service-Oriented Architectures) and Web Services, abstract applications of the process of evaluating the LoA and incorporating new security functions that are centrally managed:
- The impact of the implementation of the security logic is minimized and the integration and maintenance costs are reduced.
- As part of the Safelayer's TrustedX platform, it can be scaled to other security services such as electronic signatures and data encryption.