Stratégies Télécoms & Multimédia

français
  • Home Page
  • Newsletter
  • Sitemap Page
  • Contact
  • Home Page
  • Services
  • Events
  • European Webzine
  • Interview
  • News
  • Innovators’ Profiles
  • Trends
  • Agenda
  • About
  • Past Issues
KerPass’ mobile authentication and transaction validation application
Font size up Font size down Print Send to a friend RSS field

To send this page
Supplement all the fields below and click on "OK" button...

Name: Add a message:
E-Mail Address*:
Recipient's Email adress*:
Reset   Send
(*) Mandatory fields Close
29 February 2008 - Innovators’ Profiles

The challenge: static password flaws

In today distributed organizations, delivering reliable end user authentication is a difficult problem in search of a workable solution. Password based authentication is the workhorse of online authentication, and will remain so in the years to come as it delivers the simplest solution that can possibly work. The drawbacks of using this simple ubiquitous authentication method are well known: good passwords are hard to remember and shall be used only for a limited period time.

Innovative vision : one time and SMS passwords

For application that requires higher level of security than static password can deliver, KerPass provide a one time password based on time-synchronization between the authentication server and the client providing the password. Moreover, to adapt to deployment cases where the end user can not install the KerPass mobile application onto its phone, sms can be used to leverage on phone sim/usim identity module thanks to an innovative "multipass" message format.

The solution: Authentication & transaction validation

Once installed on a Java enabled cellular phone, the KerPass mobile client allows setting a dedicated token that generates OATH (time synchronous) one time password. A new "PassCode" can be generated every 30 seconds, and it remains valid for at most 5 minutes. As for sms based authentication, the KerPass web api allows to maintain a low cost of operation in such cases. KerPass tokens allow reliable transaction validation by mean of electronic signatures. Transaction validation as allowed by the KerPass mobile token allows to definitely solve the security problems (phishing...) encountered in today e-commerce transactions such as online payment or order confirmation.

The innovator

KerPass is a division of AmvTek , an IT company operating from the city of Timisoara in the republic of Romania. Email : contact@kerpass.com. Phone [GMT +02:00 ] : ++ 40 256 201 693

Subscribe to the Newsletter      Top of the page

 Your e-Mail address: 
Subscribe Unsubscribe
Free subscription
The last news - Flux RSS
• ETSI works on quantum cryptography for communication security
(3 November 2008 - News)
ETSI has launched an Industry Specification Group dedicated to quantum cryptography.
• Open Access to EU funded Research Articles
(6 October 2008 - Trends)
The European Commission will give unrestricted online access to EU-funded research results under FP7 program.
• Alcatel-Lucent introduces its “Internet of things” service
(6 October 2008 - News)
Alcatel-Lucent Ventures has launched “tikitag”, a consumer service based on NFC technology.
Diary

Have a look on the next Events:

ICT 2008, Lyon, France, 25-27 November 2008 , The biennial ICT Event (...) ... [more] NPSec, 4th workshop on Secure Network Protocols, October 19-22, 2008, Orlando, Florida, ... [more]


   Stratégies Télécoms & Multimédia - Direct Links

e-Smart- The "e-Smart" conference is the summit conference you should attend to cover your interest expectations and requirements on shaping the future of (...) World e-ID- The "World e-ID" conference is the summit conference you should attend to cover your interest and requirements on the deployment of trusted (...) Smart Mobility- Smart Mobility is a new conference focused on the emergence of Trusted Mobile Applications. Smart University- "Smart University" is an educational programme dedicated to advanced technologies of Smart Card, e-ID, Mobile Telecoms and (...) Serenity- Launched in January 2006, SERENITY (System Engineering for Security and Dependability) is a R&D project funded by the European (...) SIMagine- Worldwide Mobile Communication and Java Card™ developer contest.
  • Home Page
  • Services
  • Events
  • European Webzine
  • Newsletter
  • Sitemap Page
  • Legal Mentions
  • Contact