Beyond Passwords
Computerworld - In the city of Stockholm, 85,000 elementary school students log on to servers inside the city LAN to get their classroom resources. And just like the end users in most businesses and municipalities, the Stockholm students often forget their passwords. Plus, teachers are stuck with the burden of issuing new passwords every 100 days in accordance with city policy.
But corporate America could learn something from the network professionals in Stockholm. In October, the school district embarked on a new authentication method with something they don't need to memorize and can't lose: their fingerprints.
The city's 450-seat pilot project is just the beginning. By March, the $100 fingerprint readers from Bellevue, Wash.-based Saflink Corp. should be in use on all of the school district's 25,000 computers, says Samir Hamouni, project manager in Stockholm's executive IT department. And by next year, he anticipates that all city government workers - 120,000 computers in all - will authenticate using smart cards, tokens or biometrics.
Passwords aren't the only game in town anymore. The smart card and token market is already heating up. What was a $314.5 million market in 2000 will reach $2.2 billion in 2005, according to a November study by IDC in Framingham, Mass. The biometrics market, dominated by fingerprint readers, is also starting to grow, from $119 million in 2000 to a projected $887 million in 2005.
This isn't a situation in which only one technology will prevail, because sophisticated companies may use multiple techniques for network user authentication.
"I think there's going to be a high degree of synergy between biometrics, smart cards and tokens as larger companies broaden their installation of multifactor authentication to a greater number of users," says Chris Christiansen, security research director at IDC. "I like the analogy of apartment doors in New York City. They don't just have a lock. They have a slew of locks and chains and even steel bars."
Despite the many methods available, user authentication falls into one of three broad categories: what you know (passwords, personal identification numbers or other forms of challenge response), what you have (smart cards, tokens or computer hardware identifiers such as serial numbers or IP addresses) and what you are (biometrics). Each form has its drawbacks and benefits, says Richard Smith, author of Authentication: From Passwords to Public Keys (Addison-Wesley, 2001).
For example, there's no way yet to dole out tokens or smart cards to millions of customers for big business-to-consumer applications, so passwords and PINs with Secure Sockets Layer encryption are still the



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- Make the Connection: Better Network Connectivity Drives Transformation
- Network connectivity is more than just plumbing. Leading organizations today see high-performance network connectivity as a critical enabler of competitive advantage, and not...
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Moving Service Management to SaaS
- Today, organizations can enjoy similarly substantial benefi ts by migrating their IT service management functions to a software-as-a-service model. This paper shows how...
- Achieving 360 Degree Network Visibility with Nimsoft
- 360° network visibility is critical for ensuring continuous availability of networks, servers, and applications-anything less could
have costly bottom-line implications.
All Networking White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Unified Communications 101
- What's the best way to implement a unified communications solution for your organization?
- Try the OptiView® XG on your network - FREE
- The OptiView® XG is the first dedicated tablet with automated network and application analysis -- fastest way to root cause. XG raises the...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Networking Webcasts