| |
MXI ACCESS IDENTITY |
| |
|
| |
The ACCESS Identity™ product is a suite of modules that delivers strong authentication and digital identity features to security applications. In effect, its goal is to strengthen these applications with the full capabilities of MXI Security Portable Security Devices. |
| |
|
| |
ACCESS Identity allows mission-critical enterprise systems such as single sign-on, remote access, full disk encryption, PKI and device lifecycle management solutions such as ACCESS Enterprise to be fully
secured while allowing for total portability. |
| |
|
| |
 |
| |
|
| |
The table below lists various possible categories of modules in ACCESS Identity that are the perfect companion to third party applications. |
| |
|
| |
| Enterprise SSO (eSSO) |
The ability to manage static user credentials and/or interface with the authentication subsystems of various products, giving users single sign-on capabilities. |
| Remote Access |
The ability to authenticate remote users to an organization’s centralized resources. |
| Full Disk Encryption (FDE) |
The ability to protect a full-disk-encrypted computer with strong authentication prior to loading a computer’s operating system. |
| Public Key Infrastructure (PKI) |
The ability to generally use certificates and keys for encryption, signing, and signature validation. |
| Portable Desktop |
The ability to carry a complete operating system or a virtual machine around with you. |
| |
|
| |
|
|
| |
|
| |
|
| |
|
| |
Password proliferation and resets is a serious administrative issue within enterprise organizations, but in solving it with a Single Sign-On system you may have created two new problems regarding system security and user mobility. |
| |
|
| |
Having a single password being the gateway to all of your systems is a security risk. With MXI Security’s ACCESS Identity solution, MXP-equipped portable security devices can eliminate this problem by providing strong user authentication (two or three-factor) to your enterprise SSO solution. |
| |
|
| |
And with that device in hand, legitimate users can also carry around various SSO credentials - whether one-time-passwords, static credentials, or digital certificates - thus restoring their mobility while retaining the benefits of SSO. |
| |
|
| |
The ability to connect to the corporate network from the outside gives your on-the-move employees much more flexibility, since they can work wherever they happen to have a computer with access to the Internet. At the same time, granting access to the network to outside connections can pose a security risk to your organization. Whether the technology is a VPN, a remote desktop connection, or even access to an SSL-protected web portal, knowing the identity of the remote user is crucial if your corporate resources and information are to be kept safe from unwelcome intruders and imposters. |
| |
|
| |
Using single factor authentication (such as a password) to connect to a remote system over the Internet is an unacceptable risk in today’s digital world, where online threats such as phishing, manin-the-middle attacks, and malicious code are on the rise and increasing at alarming rates. Once an attacker has compromised an employee’s login credentials, your organization’s most valuable and sensitive information assets are dangerously exposed. |
| |
|
| |
MXI Security’s ACCESS Identity software suite offers strong authentication protection for a range of industry-standard products, allowing employees to be given remote access without compromising security. MXP-equipped portable security devices from MXI Security, offer either two-factor or three-factor authentication so you can ensure that only the right people get access to your network from remote locations. |
| |
|
| |
|
| |
|
| |
MXI Security’s solutions for Full Disk Encryption offer you the following major advantages: |
| |
|
| |
Strong User Authentication at Pre-Boot. Even with strong encryption, the strength of the solution is only as good as the strength of user authentication. MXI Security’s devices offer strong passwords optionally coupled with biometric recognition (fingerprint) for increased protection over software only solutions. |
| |
|
| |
Secure Key Storage: If the decryption key is compromised, the secured data is left exposed. When it is stored on an MXI Security device, the user carries it with them – unlike passwordprotected keyfiles on the host computer, which can be stolen by attackers and potentially cracked with offline brute-force attacks.
|
| |
|
| |
Protection of All Data: Most Full Disk Encryption solutions stop at the host computer, leaving information exposed if it is placed on a USB drive for transport to another system. The secure portable storage capabilities of MXI Security’s devices ensure that the data remains safe en route from one place to another. |
| |
|
| |
|
| |
|
| |
A Public Key Infrastructure makes possible a wide range of mission-critical
security applications, including File Encryption, Folder Encryption, Email Encryption, Certificate-based Logins, Digital Signatures, Strong Authentication.
However, organizations face a difficult challenge in deploying a PKI: each user must be able to have their private key available to them anywhere, and it must be kept secret. |
| |
|
| |
Public Key Infrastructure (PKI) |
| |
MXI Security’s solutions for PKI offer hardware-based protection of a user’s private key with strong authentication in an all-in-one portable device. Unlike software-based key protection solutions, our approach ensures that no keys are left on any machine and that all of the cryptographic services are performed within the trusted computing environment of the hardware device. |
| |
|
| |
Further, the device and key can be carried from computer to computer and used without the need to install software, offering true portability while maintaining absolute security. Compliant with industry standards, PKCS #11 and Microsoft CAPI, MXI Security’s solutions for PKI provide wide interoperability with most PKI-enabled applications. |
| |
|
| |
|
| |
|
| |
Need to be fully compliant with data security regulations? Need to maximize the benefits of data protection, portable applications, secure identity and authentication? If so, the deployment of your security devices must be overseen and managed. ACCESS Enterprise™ gives organizations the ability to easily manage and address the following key areas: |
| |
|
| |
User Identities. Your organization should know who carries what device. Furthermore, the identities of these users need to come from the corporate identity store (typically an LDAP directory). The last thing a company needs is yet another identity silo. |
| |
|
| |
Authentication. Policies for authentication, such as password complexity rules, biometric security levels and retry limits, need to be tailored to the needs of each group of users in accordance with their role and operating environment. For example, mobile users may need biometric authentication, while internal users may only need password devices |
| |
|
| |
Digital Credentials. Some portable security devices have the capability to perform digital identity functions, such as generating onetime passwords and public key operations. Having one central point to provision digital credentials such as private keys, token seeds, and static credentials, greatly simplifies the process of enabling these devices for use with your various authentication systems. |
| |
|
| |
Portable Applications. One of the benefits of portable storage is that it can provide greater mobility for applications. Organizations can decide to control the set of applications that are appropriate for different groups of users. For example, mobile workers may need a remote access client on their devices, while internal employees do not need this type of access. |
| |
|
| |
User Rescue. Easy to implement password and biometric recovery options must be available to rescue blocked users, even if they’re away from the corporate network. |
| |
|
| |
Data Recovery. Data recovery options are available to security officers so that they can perform audits on the stored information and, if necessary, without the user being present. |
| |
|
| |
|
| |
|
| |
 |
| |
|
| |
A portable desktop is the ability to access your own personal computing environment from anywhere without being tied to a particular machine. This capability can be achieved in a number of ways – remote desktop connections to server-based computing, carrying portable applications, or carrying an entire operating system around with you. |
| |
|
| |
MXI Security’s portable security devices not only enable complete mobility of portable desktops but give you full security to boot. |
| |
|
| |
Portable applications. Many productivity applications today are now portable, including Internet browsers, email clients, spreadsheets and office tools. |
| |
|
| |
With MXI Security’s portable security devices, these applications can be accessed directly from the device on any machine while the application data is secured within the encrypted hardware. |
| |
|
| |
Portable operating systems. There are a couple of ways to carry a complete operating system around with you. Virtualization solutions provide an abstraction of a machine (a virtual machine) so that a host operating system can run another operating system within a virtual machine. By using a portable security device with a virtualization solution your portable operating system can run on any host machine that has the virtual machine layer installed. |
| |
|
| |
Alternatively, the entire host machine can be rebooted into the operating system that is carried on the device. Regardless of the mode you use (virtual or reboot) MXI Security’s portable security devices offer full protection of the entire portable operating system with hardware encryption of the data and strong user authentication required to access it. |
| |
|
| |
Remote computing. Using your device to carry your remote access client and provide strong authentication to the server or VPN you can be both productive and secure as you access your remote desktop over public networks. |
| |
|