|
Softlock Secure Web Access Solution provides a hardware based Authentication
method over the web. Most web sites and web applications depend on user name and
passwords authentication, which is not a secure way for authentication. Softlock
Secure Web Access provides extra security with Two and Three Factors
Authentication based on Softlock Smart Token.
- Something you know: PIN or Password
- Something you have: Softlock Smart Token hardware device
- Something you are: Softlock Smart Token hardware device with Fingerprint
(Biometric)
Softlock Secure Web Access can be accomplished in different methods that can
meet vendors’ needs.
Secure Web Access using SSL certificates
In this method, Softlock Smart Token is integrated with Secure Web
Authentication using SSL certificate installed on web server, and signed
certificates installed on Smart token. This method establishes a secure web
authentication for users owning Smart Token with signed certificates and
establishes a Secure Internet Connection with web browser and web site.

Secure Web Access using User Account
In this method, Softlock Smart Token will hold the User Account required for
login (i.e. user name and password). The user account will be stored on the
Smart Token and used in the login process without the involvement of the user.
This method is useful in replacing the regular login method with automated
method, keeping the user account secure against malwares and key loggers. This
method can be combined with Secure Web Access using SSL Certificates to
establish a complete secure internet connection with user account login.
The following figure illustrates the Softlock Admin Tool (User Account) which
imports User Account on Smart Token.

The following figure illustrates the Secure Authentication operation based on
user account. The user owning a valid Smart Token will be able to login to the
web site without entering User Name and Password. Configuring the web site and
Smart token with SSL and signed certificates for establishing a secure internet
connection will lead to a complete secure web access, resistant to key loggers,
malwares and packet sniffers. Combining SSL certificate authentication with user
account authentication is optional, yet it provides the highest security
available.

Secure Web Access using SDK
Softlock Smart Token is shipped with complete SDK in different interfaces.
Establishing Secure Web Access using Smart Token SDK is easy and provides the
flexibility for the vendor to construct a customized web access methodology
which meets his needs. SDK can provide much functionality which is compatible
with international standards (PKCS#11 and CSP) along with customized Softlock
SDK APIs. The following are a set of functions any vendor can establish using
the SDK solution:
- Symmetric Encryption/Decryption
- Asymmetric Encryption/Decryption (RSA)
- Signing/Verifying
- Read/Write
|