Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 2007

BioPassword Enterprise Edition 3.2

Flexible, effective, software-only two-factor authentication
RSS
Subscribe to Windows IT Pro | See More Windows OSs Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

BioPassword Enterprise Edition 3.2 (BPE) enhances the security of corporate networks by adding a second, biometric component to the standard Windows logon / authentication sequence. As a software-only solution, it does so without the need for the additional client hardware required by other modes of biometric authentication such as fingerprint identification or retinal scanning. Instead, BPE relies upon the consistent, distinctive pattern of each person’s keyboard keystrokes during the logon process.

BPE’s streamlined design will appeal to small organizations, and its support for a variety of environments lets it integrate easily into large enterprises. Supported environments include Citrix and RDP / Terminal Server users; selected thin clients with embedded Windows XP; and integration with Microsoft Outlook Web Services. Web application support allows you to integrate BPE into your own forms-based authentication screens.

BPE improves the standard Windows authentication sequence by extending the Active Directory (AD) schema within the AD domain tree hosting user IDs, and by inserting BPE GINA (Graphical Identification and Authentication) stub modules into the domain’s GINA chain. This requires that you install BPE on all domains that host either User or Computer accounts that will participate in BPE’s two-factor authentication. BPE is active during the primary AD login sequence and will optionally run during secondary logon sequences, such as Run As, Connect As, and Net Use.

BPE works by using client software to record keystroke timings as users complete the User ID and Password fields of an authentication form. Keystroke timings include the dwell (how long a key is held down) and flight (the time between key strokes) times. Using the timings, the authenticating domain controller (DC) calculates a Security Level score. That score is compared to a template created when the user first entered the user ID and password combination. To enroll, a user keys the user ID and password several times until BPE identifies the user’s consistent pattern. In my testing, this required eight or more repetitions. As administrator, you may configure enrollment to complete at the user’s first logon attempt, or gradually (and transparently to the user) over successive logon attempts.

The implementation process has many steps, but is fairly straightforward. Basic AD installation updates the AD schema, then installs software on all PDC emulators in the tree, on all authenticating DC’s, and on all client computers. Other supported environments require additional installation steps. BPE isn’t enabled upon installation, and it won’t participate in the authentication process until you enable it both for the participating domains and for the participating user IDs.

To test BPE, I installed it to a domain with a single DC. I installed the client component to several computers that were members of that domain and to a computer that was joined to a trusted domain and enabled BPE authentication for them. You can enable user accounts for BPE either individually or by enabling a group they belong to for BPE authentication. Figure 1 shows the BPE properties panels used to enable and configure BPE for a group. Finally, I enabled BPE for the domain.

BPE caused me to pay close attention to the logon process, as BPE requires a continuous flow of keystrokes. I enlisted several other regular users of computers in the testing, to see if the “wrong” user could successfully authenticate. This occurred only once in the course of my testing. Administrators can determine how stringent or relaxed their authentication environment will be by requiring a higher or lower BPE security level score.

I found BPE to be effective and relatively easy to work with. BPE provides an evaluation kit to facilitate testing and configuration. Many people will find that installing BPE isn’t a trivial process in their environments, but the added level of security will make it all worthwhile for many of you. The implementation flexibility that BioPassword has designed into the product will help ease that effort, and the support for several popular ways users access their applications makes this a viable product for many enterprises. For those seeking to add multifactor authentication as a way to increase system security, I recommend that you take a look at BPE.

Summary
BioPassword Enterprise Edition 3.2
PROS: Effective two-factor authentication without the need for special hardware; support for many application access modes, including Citrix, RDP and embedded XP terminals
CONS: Requires an AD schema update; installation is not trivial for large enterprises
RATING: 4.5 / 5
PRICE: $50/user perpetual license + maintenance or $19/user annual subscription, with volume discounts.
RECOMMENDATION: BioPassword is an impressive product, with a lot of implementation flexibility. I heartily recommend it to those seeking to implement multifactor authentication.
CONTACT: BioPassword, Inc. - www.biopassword.com - 425-649-1100

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
No Jobs, No Excitement at Apple's Last Macworld Keynote

Apple CEO Steve Jobs made the right move in skipping out on his company's last appearance at Macworld: In a Tuesday keynote address at the conference, Apple had no interesting new products to sell, opting instead to spend mind-numbing amounts of time on ...

Where is Microsoft NetMeeting in Windows XP?

...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Related Events Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Cloud Computing Forum: Integrating Software, Server and Storage as a Service into Your Enterprise IT Delivery Model

Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing