SyferLock, One Time Passwords, and Multi-Factor Authentication
SyferLock Technology Corporation Releases MySyferLock™, an OpenID & Cloud Access Security Solution, Delivering the Most Secure Knowledge Based Authentication System Featuring Device-less, Zero Footprint One Time Passwords for OpenID Users
SyferLock's MySyferLock™ system is an OpenID technology where the user still remembers and leverages their existing static password, but when the OpenID user registers using MySyferLock™, the user creates a transparent multi-token authentication scheme that has the user input and transmit their password as a true one time password through MySyferLock's™ patented security grid user interface.
Key to MySyferLock™ users is that they now have the option for more secure cloud access - universal access - using device-less, zero footprint one time passwords to login to their favorite OpenID enabled web sites and portals versus using an easily compromised static password.
The security, ease, self-service, flexibility and adaptability of MySyferLock™ is unparalleled in the authentication market, and what is available to OpenID users. There now is a more secure gateway to the cloud!
SyferLock! The only Enhanced Authentication Technology that Addresses and Fixes BOTH Passwords and Personal Identification Numbers (PINs)
SyferLock's unparalleled flexibility offers users the ability to take either passwords or PINs and make them one time passwords/PINs without the need of any additional hardware, tokens or client-side software. SyferLock's patented methodology can be customized and fine tuned allowing superior security and cost savings for their users.
PASSWORDS
GridAdvanced™ delivers enhanced authentication and security for those users (and use cases) where ONLY a password can be used, and access needs to be from any machine anywhere:
PINs
Grid2Form™ with GridPIN™ allows a user's password to be bolstered with an additional form of authentication – a secure one time PIN generated from a user's existing static PIN:
CLICK TO PLAY DEMO
CLICK TO PLAY DEMO
Both GridAdvanced™ and Grid2Form/GridPIN™ deliver award winning benefits for both their customers and users:
Allows you to use existing passwords
Makes all passwords device-less one time password
Always on security – from any machine, anywhere
Complete self service escalating security features to combat key-logging, sniffing, phishing, even continuous screen capture
Self-service 2 factor authentication capabilities
Self-service customized UI and languages
Detailed account monitoring and analysis
SyferLock Technology Corporation Bolsters Its Existing Security Offerings with
Superior 2 Factor Authentication via GridSoftToken™
SyferLock's GridSoftToken™ is a software-based token technology that allows a user to lock their account access to a specific machine or device. GridSoftToken™ is easily installed and self-serviced through SyferLock's Security Center, and once installed delivers organizations superior security through true 2 factor authentication, as well as the added security of one time password/PIN generation added to the existing username and the existing password. GridSoftToken™ delivers true 2 factor authentication, and helps achieve critical security requirements and compliance mandates from such regulations as PCI, FFIEC, SOX, GLB and others.
Where SyferLock and its unique patented technology and methodology are superior, is that the additional critical security benefit of greater “user” authentication is delivered (in addition to device-level authentication) by the use of GridSoftToken™. Where other tokens generate and display the access code, password or PIN in the clear (Figure 2. below), SyferLock's GridSoftToken™ displays a security User Interface that further requires a multi-token, knowledge-based authentication scheme for secure login (Figure 1 below). Lost devices and attempts for unauthorized computer use are further protected by this unique aspect of GridSoftToken™ helping organizations address these security threats as well.
SyferLock Announces the Integration of its GridGuard™ Device-less One Time
Password Enhanced Authentication Technology into Cisco's SSL VPN
SyferLock is pleased to announce that users of Cisco SSL VPNs can now secure remote access with SyferLock's GridGuard™ enhanced authentication solution. GridGuard's 3.0 version allows a very secure, flexible, self-service, low cost alternative for one time password generation versus the deployment of costly and cumbersome hardware solutions. Award winning critical security benefits delivered by GridGuard™:
Allows you to use existing passwords
Makes all passwords device-less one time password
Always on security – from any machine, anywhere
Complete self service escalating security features to combat key-logging, sniffing, phishing, even continuous screen capture
SyferLock now offers deployments and their users the ability to self-service 2FA through its AutoToken™ technology.
GridKey™ is a 2FA feature that allows the user the option to bolster their authentication with an additional layer of
security - by sending a one time password (OTP) to either an email account or phone via SMS text message.
Competitively unique to SyferLock is that the GridKey™ will only be generated and delivered AFTER the user applies
and completes a deviceless “multi-token” OTP authentication process at their initial login - creating unparalleled
secure access. The SyferLock system leverages the user's existing password and it is securely entered as an OTP through
SyferLock's patented methodology and security grid UI.
SyferLock Announces New Integration with SAML
GridGuard™ and SAML Integration.... Own Your Own Identity!
SyferLock's GridGuard Servers integration with SAML now provides Internet
Single-Sign On (SSO) through a federated identity management system.
Organizations are faced with securing a growing number of access points,
including internal and external Software as a Service (SaaS) applications.
The challenge is to provide the highest level of security while keeping
costs in perspective. With the GridGuard solution, employees will only
need to remember one password instead of multiple passwords for each of
their applications, and their credentials will be protected by the enhanced
security of the GridGuard technology. The GridGuard server is installed
in your company's network and processes all logins into any supported
application(s) – SalesForce.com, CentralDesktop, Google Apps and more.
The user's ID and password are
never
passed to the SaaS application nor
outside your network. Therefore, the employees own their identity!
Contact SyferLock today
for more information or to deploy the solution as part of your
organization's security initiatives.
Utilizing SyferLock’s Approach to Achieve Greater Password Security
and Enhanced Authentication
SyferLock Technology's Grid Data Security solution is the simplest, most secure deviceless one-time password system offered to computer users today. Users can log in from any computer anywhere, and are still afforded the security and protection of one-time passwords. Security is achieved without tokens, cell phones, print materials, or other devices.
SyferLock's patented approach and methodology offers increasing levels of security through the use of Decoy Digits™ and additional manipulation of the system (GridAdvanced™). So even when an attacker can capture ALL of the information during a login attempt, it is still unlikely that he will be able to obtain the user's credentials. Contact SyferLock for an expanded online demonstration that covers these features.
Click the animation above for an introduction to the Grid Data Security solution (GridAdvanced™) and a variation of just one of the many security grid user interfaces that can be created and selected through MyGrid™.
SyferLock Technology Corporation has released a family of patented products that
offers a paradigm shifting approach to passwords and access to computers,
networks and the Internet.
Historically, reusable passwords are the weakest authentication method, but
remain the most commonly used type of authentication on enterprise networks
as well as on the Internet. One Time Passwords (OTPs) are impervious to attacks
perpetrated on reusable password systems.
SyferLock Technology Corporation has engineered a secure, authentication system providing device-less, One Time Passwords allowing Users to have a simpler, more secure way to access information.
Utilizing SyferLock’s Approach to Cross and Cover the Authentication Spectrum
- Weak and vulnerable against the most prevalent and easily executed attacks
- Attempts to make them “limited time passwords” i.e. expire every 30,60,90 days add no real strength to the threat matrix, but add a real Total Cost of Ownership (TCO) burden to users and organizations
- Passwords are the most pervasive form of authentication for the majority of users
- Increased strength from One Time Password generation and “having something”
- Physicality and the very nature of the “something you have” unfortunately create real limitations
- Heavy Burden on Total Cost of Ownership (TCO)
- Limited deployment – due to budget constraints and/or mandated/ suggested deployment - e.g. SOX, to only users deemed absolutely necessary to have greater security
- No secure, un-intrusive “plan B” for lost, stolen or broken devices
It is this large part of the authentication spectrum that SyferLock’s unique approach and methodology addresses. SyferLock delivers proven, effective security through One Time Passwords or PINs, while allowing IT security a viable alternative for greater information access control.
- Utilizes a user’s existing password and organization’s database store
- Absolute ZERO footprint and device-less in nature
- Lower TCO and lightweight aspects, allow for complete user coverage
- Bolsters and works in conjunction with other factors and security measures
- SyferLock’s OTP system eliminates or mitigates the following attacks:
The implementation of the Grid Data Security system, and its use of GridPasses™ and GridCodes™, allows organizations to reduce or eliminate the threats and risks currently plaguing users of reusable passwords. These critical security benefits are delivered with absolutely NO additional user hardware or software. ANYWHERE, ANY MACHINE, MORE SECURELY™.
GridOne™ Reduces or Eliminates the Following Threats
Key-Logging
Automated Attacks
Sniffing
Replay
Brute force
Interception
Shoulder surfing
Dictionary
Stored Browser Passwords
In addition to this threat and risk mitigation, SyferLock’s One Time Password Approach helps address U.S. and international authentication regulations and guidelines such as PCI DDS, FFIEC, SOX, GLB, HIPAA, FISMA, PIPEDA, 21 CFR Part 11, Annex 11, BASEL II, European and Japanese Data Protection Directives.
The power and process of simple substitution. At log-in, substitute the real password with randomly changing numbers! A substitution cipher with the strength of one-to-many.
MySyferLock™ allows users the ability to login to their OpenID enabled accounts with higher security, device-less, zero footprint One Time Passwords utilizing one of the, if not the most secure knowledge based authentication systems currently available.
SyferLock Technology Corporation has received Federal Information Processing Standards
(FIPS) 140-2 algorithm validation as part of the Cryptographic Algorithm Validation Program (CAVP)
The SyferLock Technology Corporation mission: "Deliver better ways to secure data, networks and identities™. "
Patented Technology
SyferLock Technology Corporation’s authentication system is patented under
patent nos. 7,143,440 &
7,725,712
with the United States Patent and Trademark Office
(additional patents and foreign patents pending)
Customer Portal Protection™
Alternative lightweight, One Time Password, Web-Based Authentication Solution.