Jointly Developed Implementation with
Passfaces
and the Netscreen Secure Access Products
Group
The
solution meets a major, geographically
dispersed organization’s requirement for
strong authentication security and high
usability for reliable access to email
from anywhere.
The Problem
A large, security conscious organization
identified a requirement to provide a
secure method for email access from any
World Wide Web location for their user
community. The IT support organization
realized that any outward facing web
site that could be linked to this
organization would be a prime target for
hackers as evidenced by persistent
attacks on their existing web site. With
this new web service providing access to
highly sensitive and confidential
information, finding a very robust
security solution was a given. In
addition, it was required that this
security should be achieved without any
compromise of user convenience or system
reliability.
Secure Web Access with Strong
Authentication
The target security solution defined by
the IT staff was an SSL VPN underpinned
by strong user authentication. After an
evaluation of several SSL VPN providers,
the customer selected Netscreen’s
Neoteris IVE platform as their
application security gateway solution.
This decision was made in large part
because of the flexible authentication
architecture offered by the IVE.
A number of possible authentication
methods – so-called “strong passwords”,
tokens, and biometrics – were considered
and rejected for reasons of poor
security, usability and reliability.
Following an extensive evaluation,
Passfaces™ for Web Services product was
chosen to provide strong authentication
for users coming in to the IVE.

The
Passfaces and Netscreen team quickly
developed an integrated solution whereby
a custom web interface, provided by
Passfaces and accessible via
Microsoft’s Internet Information Server,
sits in front of the Netscreen IVE box
collecting the users’ credentials and,
after verification, enables
initialization of the SSL VPN
connection. Being Web-based, the
solution requires no client software
installation and can be deployed and
scaled extremely rapidly across any size
user population. Following
demonstrations of the solution and
initial testing by the customer, the
integrated system was implemented in a
pilot deployment project. The pilot
solution met performance criteria and
was well received by the user community.
The system is now extensively deployed
across the organization.