Newsletters   Subscriptions  Forums  Store   Career  Media Kit  About Us  Contact  Search   Home 
fhs
Volume 5, Number 35 -- September 6, 2005

Valid Tech Delivers Biometric Authentication Solution for OS/400


by Alex Woodie


Valid Technologies recently took the wraps off a new product called Valid Secure Systems Authentication (VSSA) that uses fingerprints to grant users access to computers, programs, and data--or more importantly, prevent the wrong person from gaining access. While it can be used to grant access to a variety of applications, the product itself runs only under OS/400, because it is the most secure platform on the market, according to company officials.

In development for the past 20 months, VSSA became generally available in August as version 1.4. The software works in tandem with biometric fingerprint readers from American Power Conversion to bolster password protection in critical applications. When a user tries to access an application, or even just a specific area of an application, he is prompted by a pop-up window to place his finger on the APC reader, which plugs into their workstation via a USB port.

The server component of VSSA requires OS/400 V5R3. Information about users' fingerprints (but not images of the fingerprints) are encrypted and stored on the iSeries server. If the fingerprint data taken from APC readers matches the data gathered during the initial enrollment period, the user is granted access. If it doesn't, the user is denied access, and the event is noted in the log.

The VSSA software development kit provides code samples for embedding the VSSA calls directly into business applications written in ILE RPG, COBOL, C++, Java, and Visual Basic. While it takes a bit of work to open applications and embed the VSSA calls directly into the source code, it's done this way for security reasons, says Greg Faust, president of the Boca Raton, Florida, company. "We don't provide a fence or a wrapper or an API, because they can all be spoofed. All our calls are bound into the source code," he says.

Valid Tech takes security seriously. The company collaborated with IBM engineers in the Rochester, Minnesota, lab to make VSSA work. That work with Pat Botz, an iSeries security expert with IBM, and others appears to have paid off, as VSSA has already achieved ServerProven status.

Faust says IBM officials told him they are not aware of any other biometric authentication engines that run natively on OS/400, making VSSA a one-of-a-kind. But that's not to say Valid Tech was the first to try. Faust and his partner, Tom Secreto, were involved with a previous attempt to bring to OS/400 a Linux-based product called the Ethentica Biometric Trust Engine designed by a company called Security First, which has since been bought or gone out of business (see "Tangent Porting Fingerprint Engine to OS/400").

That port never worked, so Valid Tech started fresh with VSSA, Faust says, although it didn't start entirely from scratch. VSSA uses core fingerprint sensing technologies from AuthenTec. VSSA also integrates with key single sign-on (SSO) technologies, including IBM's Enterprise Identity Mapping (EIM), which correlates users' identities on a variety of platforms, and Kerberos ticketing, which provides a secure, cross-platform method for confirming authorization. ("We are not an SSO solution," Faust says. "We don't identify, and we don't authorize. We authenticate.")

VSSA also works with Microsoft Active Directory, albeit not in its strongest configuration. In fact, Faust has quite a difficult time concealing his astonishment at the number of companies using Windows machines as their main repository for user identities and their main platform for authentication.

"If you use Windows Active Directory, as your domain server, and you just want to take away the password part, we can do that. Personally, I don't care what you do with Windows, because Windows is inherently un-securable," he says. "While we have that, and it seems that 90 percent of the world seems complacent with Windows level of security, and the Windows world wants it, that's not what our recommendation would be."

Valid Tech's recommendation would be to base user authentication solutions for key applications on VSSA running on an iSeries. "Put everything you don't care about on your Windows domain, and put everything else on the i5," Faust says. "If availability and security are important to you, you should be running away from a Windows box as fast as you can."

Users can take as fine-grained an approach to deploying biometric authentication with VSSA as they need. Instead of authenticating a user when he first accesses a system, VSSA can be used to authenticate a user at practically any step along the way, according to Faust. For example, some users may just want to protect access to the accounts payable program, or maybe just to the check writing part of AP. "VSSA can be bound in to as many different applications, and as many parts of applications, as needs will require," Faust says.


Valid Tech also sees a use for VSSA in SSO implementations. While SSO can be a boon to organizations by solving the forgotten password problem, putting all that power into a single password can raise new security concerns, the company says. Implementing biometric authentication provides a level of insurance that the user accessing sensitive data is allowed to be there.

VSSA, while initially developed to run under WebSphere, has recently been adapted and now runs under OS/400 HTTP Server (which is powered by Apache). There are currently 10 to 12 customers at various stages of deploying VSSA, Faust says.

VSSA will be demonstrated at the upcoming COMMON conference in Orlando, Florida. Valid Tech will be working with its business partner, CMA (Cherbonnier, Mayer and Associates). CMA, an IBM reseller based in Baton Rouge, Louisiana, plans to attend the conference despite the devastation that Hurricane Katrina caused in CMA's hometown, Faust says.

Software license fees for VSSA start at around $10,000, while companies deploying VSSA authentication to larger groups of 500 to 1,000 users will pay initial license fees equal to about $100 per user. The APC biometric sensors cost about $40 each. For more information, visit www.validtech.com.

Sponsored By
SAI NEW TECHNOLOGIES

SAI New Technologies, founded in Limerick, Ireland, has been providing best of breed financial software solutions since 1992. Our products span the globe, servicing clients across Europe, the Americas and Asia/Pacific.

Our niche area of expertise is Cash Management for IBM AS/400 and iSeries platforms. We focus on delivering immediate ROI to our customer base in all areas of cash processing, reconciling, netting, and electronic cash transactions.

We have an established base of over 125 installed customer sites processing funds in excess of $50 billion every year. Our customers include Abbott Laboratories, Atlas Copco, Autobar Group, Boehringer Ingelheim, Bosch, Campbells Grocery Products, Ciba Specialty Chemicals, Elopak, Lucas TRW, Pernod Ricard, and Sumitomo Electric Wiring Systems.

Our areas of expertise are Automated Cash Allocation, Electronic Payments and Direct Debits, E-mail Remittance Advices, Bank Reconciliation, Cash Forecasting, Inter-Company Processing and Custom Cash Management Solutions. Our Cashbook suite of Cash Management solutions comes with a choice of over 150 worldwide bank adaptors for electronic file transmission and bank statement uploads.

We have a solid reputation for delivering quality software and work with select partners in our primary markets. Our aim each year is to continually grow the Cashbook suite of products through technical and business innovation and to continue delivering value to our existing and new customers.

CASHBOOK OVERVIEW

Cashbook is a group of financial software modules that work with ERP Financial software packages. Modules can be implemented individually or as a group.

Cashbook modules provide niche, add-on functionality in the areas of Accounts Payable, Accounts Receivable and Bank Reconciliation. Cashbook can also be customised to deliver Custom Cash Management solutions based on specific company requirements.

Implementation timeframes vary depending on the nature of your project. An implementation of one module at one location can take an average of one to two weeks, depending on the module being installed.

Cashbook is also built to handle multiple currencies, multiple site locations and multiple company environments.

CASHBOOK MODULES

Electronic Vendor Payments
Automated Email Remittance
AR Lockbox
Electronic Customer Direct Debits
Bank Statement Upload
Bank Reconciliation
Customer-Vendor Netting
Custom Cash Management

CONTACT

Please contact us for information on the modules for your Finance department or to organize a demonstration of Cashbook where we can discuss your specific needs.

Show me a demonstration       www.cashbook.com       Send me module descriptions


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.


THIS ISSUE
SPONSORED BY:

SAI New Technologies
LANSA
iTera
Patrick Townsend & Associates
RJS Software Systems


Four Hundred Stuff

BACK ISSUES

TABLE OF
CONTENTS
Valid Tech Delivers Biometric Authentication Solution for OS/400

DataMirror Updates XML Transformation Software

IBM Releases New Workplace Collaboration/Portal Package

SSA Global Wastes No Time Integrating Boniva

News Briefs and Product Shorts


The Four Hundred
The Mysteries of i5/OS V5R3M5 and V5R4

Only One COMMON Per Year? ISVs and Users Respond

IDC Concurs that Q2 Was Pretty Good for Servers

Four Hundred Guru
Let's See Those Command Parameters

Submit a Prompted Command to Batch

Admin Alert: Changing Your Mind When Loading Group PTFs

Four Hundred Monitor


Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc. (formerly Midrange Server), 50 Park Terrace East, Suite 8F, New York, NY 10034
Privacy Statement