|
Authentication TokensG/On Authentication TokensGiritech was first to market in 2004 with its innovative G/On USB that in one mobile device provides two-factor authentication and secure software storage for connectivity. The evolution of devices has since accelerated as CPU and memory circuits have reached new levels of integration with more and more functionality on smaller and smaller chips. Giritech is proud to offer the next state-of-the-art innovation within authentication tokens. The G/On solution is based on cryptographically secure smart-card technology implementing a very strong mutual authentication protocol and completely avoiding the counterfeiting issue of copying devices. Furthermore, as opposed to alternative smart-card based solutions, Giritech’s solutions offer the user full device independence because the solution can be accessed and used on devices with limited login rights (no administrative rights required) and without requiring special drivers or other token specific software on the device. The new authentication tokens therefore combine leading edge technology and capabilities with the unique user convenience of G/On. Read more about G/On's Challenge/Response based authentication method here. The advanced smart-card technology is provided by the highly visionary developer of integrated tokens, the German company, Giesecke & Devrient (G&D, www.gi-de.com). G&D is a leading developer of smart-card technologies for credit cards, access cards, and personal identification (PIV) cards. Giritech has worked closely with G&D to ensure that G&D’s new generation of secure authentication, memory and encryption devices supports the functionality of G/On. Although G/On 5’s plug-in architecture will enable the support of multiple different tokens, G/On 5 is developed specifically to support G&D’s series of smart-card based tokens called G&D StarSign© Mobility Token. Currently, G/On 5 supports two G&D tokens and it is the intent of Giritech and G&D to support all of the G&D StarSign Mobility Tokens in the 2010-2011 time frame. G/On Authentication Tokens with smart cardG/On MicroSmart 1GB
Based on Giesecke & Devrient StarSign® Mobile Security Card. This device is a standard microSD flash The flash memory is used for the storage of the G/On client software and associated application clients and data. The G/On microSD supports Windows, Mac, and Linux and can be used in mobile devices such as high speed broadband modems (e.g. USBConnect QUALCOMM 3G or HUAWEI Mobile Connect Modem E180 used by mobile carriers around the world), Laptops, PDAs and other mobile devices with a microSD interface. The G/On MicroSmart operates without any installation of drivers and doesn’t require administrator rights on the device thus reducing costs for implementation, support and help desks. G/On USB
|
Based on Hagiwara UDRW G3 technology. This Windows Only USB device contains flash memory, a separate CD-ROM partition, and a hidden memory zone accessible only to the G/On Server. The device offers automatic launch of the G/On Windows client without any prior
installation or administrator rights, storage of G/On Client software on write protected CD partition and read/write memory for storage of data and application clients. Authentication functionality is based on a private key stored in a hidden memory zone. G/On USB H3 1GB was the standard token device used with earlier generations of G/On.
G/On 5 also supports the previous generation H2 (128 MB) of the Hagiwara USB Tokens. However, G/On 5 does not support the first generation, H1 (64 MB) of the Hagiwara Tokens used for the very first versions of G/On.
This special token makes it possible to use personal laptops or other personal computing devices as G/On authentication factors. The G/On Computer User Token stores its private keys in a registry entry for the specific user account on the computer and uses the MAC address of the enabled network adapters to link the private key to the computer.
This option is particular valuable in these scenarios:
An iPad and an iPhone can to a very large degree be considered a personal device and, hence, it can be used as a personal authentication token. The Mobile Token stores its private key in a secured area on the iPad and iPhone and uses a unique device identification number to link the private key to the iOS device.The Mobile Token is enrolled on the G/On Server and provides two-factor authentication together with userid and password.
Use of the iPad and iPhone as authentication tokens provide a superior and convenient user experience and the IT administrator can quickly deny access for the device in case it is lost or stolen.
In addition to hardware based authentication tokens, G/On 5 also supports software based tokens. G/On SoftToken is a challenge-response based authentication using public key cryptography but without the need for a X.509 based Public Key Infrastructure (PKI). The soft-token is generated by the G/On Server and allows authentication of users from a wide range of hardware devices. Note: Like other soft-token based solutions, the G/On SoftToken is not tied to the hardware device and should normally only be used on trusted hardware devices (computers, USB keys, external storage devices etc.). Please notice: SoftTokens MUST be stored on removable drives and devices.
Based on Giesecke & Devrient StarSign® Mobility Token Classic. This USB device contains flash memory, a separate CD-ROM partition, a flash controller supporting data encryption, and a smart-card and supports Windows, Mac and Linux. Provided the ability of the operating systems, this device offers automatic launch of the G/On client without any prior installation or administrator rights. The G/On USB SafeSmart permits automatic encryption of data stored on the token fully transparent to the user and the smart-card ensures the security of the identities stored on the token. In one single device, the G/On USB SafeSmart offers protection of data in transit as well as at rest.
Based on Giesecke & Devrient StarSign® Mobility Token ID1. This device provides the ultimate secure access solution by combining G/On with existing smart-cards for Personal Identity Verification (PIV) and supports Windows, Mac and Linux. Chip cards in ID1 format can be inserted into the device and be
used as G/On authentication. A second smart-card is included and can be used for authentication of the device in the case the PIV card issuer does not provide software access. The G/On USB MultiSmart functions as a user-friendly, driverless card reader in mini format and includes flash memory, hardware data encryption, CD-ROM partition, and an ARM7 processor. Except for drivers potentially required by the PIV card, the device itself requires no driver installation and does not require administrative rights on the PC.
|
G/On 5 Hardware Authentication Tokens |
MicroSmart & |
USB H4 |
Mobile Token |
Computer |
SoftToken |
|
Availability |
Now |
Now |
Now |
Now |
Now |
|
Supported Operating Systems |
Windows |
Windows Only |
iOS |
Windows only |
Windows |
|
Software Execution from Token |
Yes |
Yes |
Software installed on device |
Software installed on computer |
Yes |
|
Zero Footprint |
Yes |
Yes |
n/a |
n/a |
Yes |
|
Driverless Operation – uses existing mass storage driver |
Yes |
Yes |
n/a |
n/a |
Yes |
|
Works for NON-admin users |
Yes |
Yes |
n/a |
Yes |
Yes |
|
Authentication Method |
Challenge-Response Protocol and Private Key on Smart Card |
Challenge-Response Protocol on Computer and Private Key in hidden memory |
Challenge-Response Protocol on Computer and Private Key in protected storage |
Challenge-Response Protocol on Computer and Private Key in User Registry |
Challenge-Response Protocol on Computer and Private Key on Removable Storage |
|
CD ROM partition for read only storage of G/On Client |
No |
Yes |
n/a |
n/a |
No |
|
Flash Memory |
1GB |
1GB less size of CD ROM |
n/a |
n/a |
n/a |