Saltar al contenido principal
RSA SecurID® 
for Microsoft® 
Windows® 
Gary Lau 
CISSP, CISA 
Principal Consultant 
North Asia
Agenda 
• RSA SecurID – the standard for 
Strong 2 Factors Authentication 
• Authentication in the Enterprise 
• Authentication to Microsoft Windows 
• How It Works 
• Other MS Solutions that are RSA Ready
Need to access 
information 
Need to protect 
corporate resources 
The Business Problem
The Business Problem 
• Low security of static password 
• Difficult to remember 
• Inconsistent user experience 
• Users write them down 
• Help desk costs 
• Unproductive users 
• Frustration
Passwords Are a Big Problem 
Problems with passwords were mentioned spontaneously in 2 
2003 focus groups: 
• “You have to log in and have complicated, long passwords with 
numbers and digits” 
• “I just see my friends trying to use (their passwords) and 
forgetting them all the time” 
• Many consumer applications force multiple logons with different 
user names, passwords, account numbers
Consumer fraud complaints for 2003 
• Identity theft 43% 
• Internet auctions 13% 
• Internet services, computer 
complaints 6% 
• Shop-at-home, catalog offers 5% 
• Advance fee loans, credit 
protection 5% 
• Prizes/sweepstakes/gifts 4% 
• Foreign money offers 4% 
• Business opportunities, work-at-home 
plans 3% 
• Magazines, buyers clubs 2% 
• Telephone services 2% 
• Healthcare 2% 
Source: Federal Trade Commission
The Fastest Growing Crime 
almost $53 billion in the previous year. $53 Billion 
In September 2003, the Federal Trade Commission (FTC) reported 
that identity theft had affected nearly 10 million Americans and cost 
by 2005. $2 Trillion 
Worldwide, identity theft and related crimes are projected to cost an 
estimated $221 billion in 2003. If the current 300% compound annual 
growth rate continues, annual losses worldwide could top $2 trillion
Auditing 
• Multiple access points 
• Multiple logs 
• Compliance requirements
Methods of Authentication 
• Something you know 
—Password, PIN, “mother’s maiden 
name” 
• Something you have 
—magnetic card, smart card, token, 
Physical key 
• Something unique about you 
—Finger print, voice, retina, iris 
“1059” 
Bank 
1234 5678 9010
Solving the Password Problem 
• Combine something you have ... 
— your ATM card, for example 
++ PPIINN 
• ... with something you know ... 
— your PIN 
== TTwwoo--ffaaccttoorr aauutthheennttiiccaattiioonn!!
Grant access: 
Y/N? 
User enters 
Passcode 
(PIN + token code) 
Security 
• Proven security 
• 15 million users 
• 14,000 customers
RSA SecurID Product Family 
Components 
ACE / Server 
ACE / Agents 
SecurID Authenticators
Two-factor Authentication 
with RSA SecurID 
Login: GLAU 
Passcode: 2468234836 
PASSCODE = PIN + TOKENCODE 
Token code: 
Changes every 60 
seconds 
Unique seed 
Internal 
battery 
Clock 
synchronized 
to UCT / GMT
How Customers Use RSA SecurID 
E-Business 
Enterprise Web Server or 
Portal Server 
Intranet 
AApppplliiccaattiioonnss 
&& 
RReessoouurrcceess 
RAS 
RSA 
Agent 
Remote Access 
RSA 
ACE/Server 
Internet 
RSA 
Agent 
Internet 
Access 
VPN or 
Firewall 
Enterprise 
Access 
Others 
WLAN
Authentication in the Enterprise 
Past: Strong Authentication for Remote Access 
RSA SecurID users 
Sysadmins 
Mobile 
workforce 
~20% 
RAS/VPN 
Enterprise 
Mobile workforce 
required to strongly 
authenticate 
Everyone else uses 
passwords. Why? 
•Assumption that 
because a person is 
in the building, I can 
better trust them 
•No real alternative
Authentication in the Enterprise 
Present: Network is opening up, getting more porous 
Mobile 
workforce 
Enterprise 
Customers 
& Partners 
WLAN 
Web Sysadmins 
~30% 
RAS/VPN 
Strong authentication 
being required to use 
• WLAN 
• Web 
• SSL VPN 
But passwords still the 
way to authenticate to 
Windows 
•No real alternative 
RSA SecurID users
Authentication to Microsoft Windows 
Today: Username and password 
Today a user types 
in his Username 
and Windows 
password to 
authenticate to the 
network.
Authentication to Microsoft Windows 
Tomorrow: Username and passcode 
Supports: 
•Local 
•Domain 
•Terminal Services 
•Password Integration 
•Online and Offline
RSA SecurID Login
Simplicity 
• Simple 
• Consistent 
• Secure 
VPN 
Windows 
Wireless 
Web portal 
Applications
Auditability 
• Centralized logging 
• Robust reporting 
VPN 
Windows 
Wireless 
Web portal 
Applications
RSA SecurID for Microsoft Windows 
Configuration Requirements 
Desktop/Laptop Domain Controller RSA ACE Server 
RSA ACE/Agent 6.0 Client RSA ACE/Agent 6.0 RSA ACE/Server 6.0 
Window: 2000, XP, 2003 Microsoft: 2000 & 2003 Microsoft Server: 2000 & 2003 
GINA Replacement AD userid and RSA ACE/Server 
userid must be the same 
Auto Install via MSI
RSA SecurID 
Architecture 
RSA 
ACE/Agents 
Web Server 
RSA 
Firewall ACE/Agent 
RSA 
ACE/Server 
(replica) 
Firewall IInnttrraanneett 
VPN 
DDMMZZ 
RSA 
ACE/Server 
(primary) 
RSA 
ACE/Agents 
PDC 
RAS
How It Works 
User on-line (Network Connected) 
Domain 
Controller 
RSA 
hashed 
Passcode 
store 
RSA 
ACE/Server 
1. Username and passcode 
2. Username and passcode provided 
to ACE/Server along with date/time of 
last available passcode 
5. Username, Windows 
password supplied to AD 
3 and 4. Agent is told Authentication 
was successful and is provided: 
- Windows password 
- Ticket for hashed passcode retrieval 
7. ACE/Server provides to passcode 
store: 
- Hashed passcodes 
- Emergency access password 
- Encrypted Windows password (for 
use when offline) 
6. Kerberos Ticket 
supplied to desktop
RSA 
hashed 
Passcode 
store 
How It Works 
User off-line (Network disconnected) 
Microsoft’s 
cached 
credentials 
5. Username, Windows password 
RSA ACE/Server 
1. Username and passcode, 
or emergency access code 
2. Username and Passcode 
(or emergency access code) 
6. Offline 
Kerberos ticket 
3 and 4. Authentication successful 
- Decrypted Windows password 
Laptop
RSA SecurID for Microsoft Windows 
Windows Password 
• Windows Password Security Policy Options 
— Make the password long, complicated and static since its of no 
use without Strong Authentication 
— Continue forced MS password change: 
• Admin forces a password change or it expires 
• Old password automatically filled in by RSA ACE/Server 
• New password typed by end user and stored in RSA 
ACE/Server 
• Handled gracefully in online and offline mode
RSA SecurID for Microsoft Windows 
Administrative Configuration Options 
• System-wide Settings 
— Allow/deny – offline use 
— # of days users can be offline 
— Warn user of limited offline days 
— # of bad passcodes before locking user’s token 
— Accept an offline authentication or require re-authentication upon 
reconnect 
— Bring log of offline events from clients into A/S log database 
• Emergency Access 
— Help desk can provide end user emergency access code for 
when end user forgets PIN, forgets token, or runs out of offline 
days
Other Microsoft Solutions that are 
RSA Ready
Already Certified MS Solutions 
• MS Active Directory Application 
Mode 
• MS Active Directory 
• MS Certificate Services 
• MS Crypto API 
• MS Exchange ActiveSync 
• MS Exchange Server 
• MS Internet Explorer 
• MS IIS 
• MS ISA Server 
• MS Mobile Information Server 
• MS Office XP 
• MS OWA 
• MS Outlook/Outlook Express 
• MS Routing and Remote 
Access 
• MS Windows 2000 
• MS Windows NT 
• MS Windows XP 
Sources: www.rsasecured.com
RSA SecurID with Microsoft Exchange 
ActiveSync 
Start -> ActivEenStyenrc UsernaEmnteer Username and 
Success and start 
synchronization! 
PASSCODE
RSA SecurID with Microsoft ISA Server 
(VPN)
RSA SecurID with Microsoft OWA
RSA SecurID with Microsoft Mobile 
Information Server
Summary 
RSA SecurID for 
Microsoft Windows 
• Secure 
• Simple 
• Auditable
RSA SecurID for Microsoft Windows
Thank you!! 
Please visit www.rsasecured.com for other RSA certified products. 
khlau@rsasecurity.com 
www.rsasecurity.com