Access control systems have been widely deployed in enterprises, where employees must carry a badge containing their enrolled information. There are mainly three types of badges on the market today: a badge without any protection, a badge with a PIN, and a badge with a fingerprint reader. The problem is that all of these solutions have disadvantages. A badge without any protection obviously has security vulnerabilities, while a PIN offers better protection but is less convenient to remember — not to mention that a PIN is easier to hack than a biometric. A biometric reader improves security but increases the cost for the enterprise, and in this approach the enterprise must collect employees' personal information, especially their fingerprints, and store it on its server.
FEITIAN has introduced its first biometric fingerprint card solution, which makes access more convenient and secure without requiring the user to remember a PIN code. FEITIAN's fingerprint card is based on a standard Java Card structure, making it easier to deploy in enterprise scenarios such as access control for buildings and company devices.
With a fingerprint sensor embedded in a Java Card, access control becomes easier and more secure than ever before. With a simple touch, employees can easily access company facilities by verifying their fingerprint, and biometric verification is always more secure than a PIN-based solution.
For a biometric access control card deployment, FEITIAN provides the card and the software for registering fingerprints on the card. FEITIAN can also help clients integrate the biometric access control card with their existing systems, including the reader and the authentication system.
FEITIAN installs a FIDO2 applet in the card by default, which enables passwordless login to many services, including Azure AD, Microsoft account and Dropbox.
Traditional authentication relies on accounts protected by passwords, which are widely considered insecure. The most common attacks are phishing and man-in-the-middle attacks. Hackers trick users into visiting and logging in to a fake website, where the user gives away sensitive login data and performs a fraudulent transaction. Man-in-the-middle attacks are even more aggressive: they hijack the communication between the user and the service and automatically redirect the user to the fake website.
To prevent such attacks, FIDO has introduced U2F as a second factor for authentication. However, this solution increases user inconvenience by adding one more authentication factor.
Today FEITIAN introduces the first FIDO2 biometric solution to eliminate passwords and strengthen security. To get here, the company has worked tirelessly with Microsoft and the FIDO2 development teams. We see FIDO2 solutions as having a very significant impact on enterprise security and cloud solution functionality. We believe this collaboration will be a significant development in FIDO2 technology, and innovation in the FIDO space is crucial to industry development. FEITIAN is dedicated to improving the FIDO2 security solution to secure enterprises while increasing usability for the individual.
The leap that FIDO has made reduces users' reliance on passwords and makes authentication more secure and less cumbersome. Biometric security keys provide a better authentication experience than a local PIN code, letting users log on to Azure AD and all Microsoft services with a "touch-and-go" experience. Biometric verification also prevents the sharing of local PINs and the problems caused by overly simple local PINs.
By adding fingerprint technology to our FIDO2 security keys, FEITIAN delivers a passwordless experience with our biometric solution, offering a convenient and ultimately more secure passwordless experience.
PKI tokens are already widely used for 2FA in many fields — by banks, enterprises, government agencies and end users — to protect online transactions, document signing, online tax and other services. Another important feature is protecting user system logon.
Logging on to a system may be the most common task users perform every day. Users must enter a password each time and may worry about losing it or about weak security if the password is too simple. Traditional passwords are therefore inefficient and offer a low security level, so a more secure and easier method helps users improve both efficiency and security. FEITIAN's system logon solution brings such a method to users.
FEITIAN, as a world-leading identity authentication provider, solves users' concerns by offering a system logon solution for PKI products on Windows and Mac OS. The solution works together with third-party software:
Windows system
Works with EIDAuthenticate (from https://www.mysmartlogon.com/). While most logon programs require a specific smart card driver, storage on the smart card itself or user-process authentication, EIDAuthenticate performs authentication inside the Windows security kernel (lsass.exe), so even with a signature-only card your data stays safe. For example, EIDAuthenticate is the only solution that natively supports the Windows "force smart card logon" policy, used to secure local administrator accounts in data centers or to comply with HSPD-12.
FEITIAN ePass PKI tokens provide a secure medium for storing the system logon digital certificate generated by EIDAuthenticate, and implement Windows system logon with a token PIN after the EIDAuthenticate configuration is completed. A smart card account appears in the Windows logon interface after restarting the system and plugging in the ePass PKI token — simply click the account and enter the token PIN to log on.
Mac OS with FEITIAN PIV
Mac OS already supports PIV natively. Simply enable the pairing function in the system and plug the PIV token/card into the system to complete pairing. After that, restart or log off, and the logon interface will show the logon option with PIN.
Mac OS with FEITIAN GIDS
Works with OpenSCToken (rebuilt by FEITIAN) to implement macOS smart card logon. OpenSCToken uses CryptoTokenKit, Apple's framework for programmatic access to smart cards and other tokens. It provides both low-level access to tokens (comparable with PC/SC) and high-level access for system-wide token integration (comparable with the Windows Smart Card Minidriver).
The FEITIAN GIDS token/card works with the OpenSCToken application. Simply install the OpenSCToken rebuilt by FEITIAN on macOS, enable the pairing function, and plug the GIDS token/card into the system to complete pairing. After that, restart or log off, and the logon interface will show the logon option with PIN.
PKI tokens are already widely used for 2FA in many fields — by banks, enterprises, government agencies and end users — to protect online transactions, document signing, online tax and other services. The PIN is the most basic and commonly used protection for a PKI token, guarding access to the certificates and key pairs stored inside the token.
A PIN can be set with different levels of complexity according to the user's habits, using letters, digits and special symbols. However, a more complicated PIN is harder to remember, so some users forget their PIN and lock the token. The traditional way to unlock a PIN requires the user to bring the token to an administrator or an appointed location, which can be time-consuming and inconvenient. The remote PIN unlock solution solves this problem and provides a quick and convenient way for users.
FEITIAN, as a world-leading identity authentication provider, solves users' concerns by offering an online remote PIN unlock solution for ePass series products. The solution consists of a remote unlock client tool and a backend server. The unlock process is as follows:
Remote unlock client tool
When the token PIN is locked, the user can download and start the tool. The tool reads the serial number and certificate file (.cer file) from the token, generates a session key, and sends all of this to the backend server in cipher text.
*Note: The remote unlock client tool is for Windows only.
Backend server
The server receives the information from the client tool, decrypts it to obtain the token serial number and certificate file, and calculates the SO PIN from the token serial number. It then encrypts the SO PIN with the session key. Meanwhile, the server parses the user's email address from the certificate file and sends a generated verification code to that email.
*Note: Each token has a different SO PIN, calculated from its unique token serial number.
User
The user checks their email for the verification code, enters it into the client tool and clicks Unlock. The client tool sends the verification code to the backend server in cipher text; after successful verification on the server side, the server sends the encrypted SO PIN to the client tool, and a reset-PIN window pops up. The user can then reset the PIN and complete the unlock procedure.
*Note: During the entire unlock procedure, the token must remain connected and must not be accessed by other applications; otherwise the unlock will fail and must be redone.