★ wanayoo — archive 1999 http://www.networkcomputing.com/1006/1006f1.htmlNouvelle recherche | Portail wanayoo

       
NWC     Internet   Site Map

Getting StartedTechnology GuideDepartmentsresearch CenterSales & Marketing
FAQs Site Map Staff Article Index Current Issue





The New Face of Single Sign-On
March 22, 1999
Side Bars
Executive Summary: Single Sign-On Security

Traditional SSO Case Study:
Duke Energy Reduces Inefficiencies in User ID Management

Web SSO Case Study:
Quantum Corp. Moves Toward a Single Web Experience for Customers and Employees

Related Links
Guarding The Flank With RADIUS & TACACS+,
Workshops, February 1, 1998

RFP: Security Services,
Features, April 1, 1998

"Missing Links: Authentication and Single Sign-On",
Features, February 22, 1999

Company Directory
Browse our directory to get data, starting with a particular company.
Reader Service
Allows you to request additional product information from our advertisers.
Print The Full Article
ClickHere
E-mail this URL
Clicke-mailHere
Buy the Book



Keyword Search:



By Philip Carden
our customizable newsletter, sends you security alerts, product updates and software patches on the products you use. Sign up now at www.networkcomputing.com /express/
 With single sign-on (SSO), the password is simplicity. An SSO solution lets users identify themselves just once to access information on any of several systems. The username-password combination is the most common form of ID; SSO solutions assist users by reducing the number of passwords they must remember, making systems easier to use, reducing support calls and boosting security by eliminating the need to jot down passwords where unauthorized users can find them.

While password reduction was the original goal of SSO, other forms of user authentication now in use, such as PKI certificates, smartcards, tokens and biometrics, may also form part of a contemporary SSO solution. But user ID is not the primary function of an SSO solution. Indeed, an SSO solution may rely on completely separate authentication mechanisms. What distinguishes a single sign-on solution is that the user authenticates his or her identity once, and thereafter is transparently granted access to a variety of permitted resources with no further identification required.

Security Is More Than SSO
SSO traditionally has been considered a security technology. In particular, it addresses one or both of two primary security subdisciplines, authentication and authorization. Authentication is the process by which the system verifies the user's identity, while authorization determines what that user is allowed to do (traditionally based on role in the organization). Most SSO approaches simply centralize authentication. Authorization typically continues to be managed on the target resources, though some sophisticated SSO solutions centralize the authorization process. An in-between approach to authorization is taken by centralized "security administration" products, which centralize the administration of user privileges but leave the actual authorization process to target resources. Simply centralizing security administration does not reduce user sign-on complexity, but such solutions are increasingly becoming integrated with available SSO products.

There is, of course, more to security than just SSO and centralized security administration. Today, firewalls, virtual private networks (VPNs), file encryption, hardened operating systems and other technologies can operate independent of an SSO or security administration solution. Over time, many of these technologies will become more user-specific and will be candidates for tighter integration with SSO solutions. For example, rather than just allowing specific kinds of services to reach specific IP addresses, firewalls will rely on additional information about the user attempting the connection. Also, as VPNs become prevalent, it will become common to be a member of more than one VPN (for instance, a corporate VPN and an industry-specific community-of-interest VPN). Validation of user identity and VPN membership will be expected to occur transparently (meaning there's some form of SSO solution in the background).


Page 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | Next Page
Advertisement


Broadcast Fax Services
Article
Guide
Full Chart
Customize Chart
Product Directory
Search

Find more Buyer's Guides.
tools
arrow Attend Live Events.
arrow Get IT Training.
arrow Research Companies.
arrow Find DSL Services.
arrow Build Your Own RFP!
arrow Get a Job.
arrow Shop Our Advertisers.
arrow Contact Our Advertisers.

Storage Shoot-Out
Looking for the perfect Storage solution? Come to our full-day event this September and see vendors respond to a live RFP. You can register to attend, participate, or sponsor our event here.

Attend other events.

Beginning Perl Part Three
With the help of Wrox Press, we've got a few more pearls of wisdom from the experts in our latest Network Design Manual chapter, "Beginning Perl". In this installment, we discuss permissions, piping in and out, directories, and file tests.

Read more Design Manual chapters.


Get NWC
Subscribe to Network Computing magazine and our Free, weekly E-Mail newsletter.


Spotlight
E-Commerce Survey!
Are you conducting E-business? If so, we want to hear from you. Please take a few minutes and fill out our online questionnaire on payment services. You could win a $200.00 American Express gift certificate!


UnixWorld | Network Design Manual | Interactive Buyer's Guide | WANsites | Real-World Labs | Learn IT | Careers | Article Index |

Home | Technology Guides | Site Map | FAQ | Subscriptions | Contacts | Sales & Marketing | 2000 Edit Calendar |

Network Computing

Byte.com |  Bank Systems & Technology |  CMPmetrics |  eBusiness Expo |  File Mine |  InformationWeek |  Insurance & Technology | 
InternetWeek |  PC Expo |  Planet IT |  TechCalendar |  TechEncyclopedia |  TechLearning | 
TechShopper |  TechWeb News |  TechWeb Today |  Wall Street & Technology |  WebTools |  Winmag.com | 


TechWeb is brought to you by CMP Media, Inc., Copyright © 2000 - Privacy Statement