Sway3-1 NabiTel Component : Global Sign-On User Administration : 사용자 등록 관리 Global Sign-On : 사용자 Log On 관리 Security Manager : 보안 정책 생성 및 적용 관리 Policy Director : 웹 서버 접근 관리 Privacy Manager : 개인 정보 접근 관리 Risk Manager : 침입 위험 관리 PKI : 공개 키를 이용한 인증 관리 User Administration : 사용자 등록 관리 Global Sign-On : 사용자 Log On 관리 Security Manager : 보안 정책 생성 및 적용 관리 Policy Director : 웹 서버 접근 관리 Privacy Manager : 개인 정보 접근 관리 Risk Manager : 침입 위험 관리 PKI : 공개 키를 이용한 인증 관리
Sway3-2 NabiTel Component : Global Sign-On - 특징 One time Log on but can access all permitted resources Built on a robust, secure, and centralized authentication Interoperable with existing security environments Uses Kerberos secret key authentication for the initial logon Uses 56-bit DES: authentication server -> user's workstation Logon information ID, password, host name, and so on Never cached or stored on the user's workstation One time Log on but can access all permitted resources Built on a robust, secure, and centralized authentication Interoperable with existing security environments Uses Kerberos secret key authentication for the initial logon Uses 56-bit DES: authentication server -> user's workstation Logon information ID, password, host name, and so on Never cached or stored on the user's workstation
Sway3-3 NabiTel Component : Global Sign-On - 특징 ( 계속 ) Two methods of strong authentication Smart cards PKCS#11 smart-card interface standard Tested Schlumberger Cryptoflex SmartCard from Litronic Inc. IBM SmartCard Biometrics SecureTouch fingerprint reader from Biometric Access Corporation Two methods of strong authentication Smart cards PKCS#11 smart-card interface standard Tested Schlumberger Cryptoflex SmartCard from Litronic Inc. IBM SmartCard Biometrics SecureTouch fingerprint reader from Biometric Access Corporation
Sway3-4 NabiTel Component : Global Sign-On - 특징 ( 계속 ) Tivoli Management Integrates with Tivoli SecureWay User Administration Integration supports role-based administration Tivoli Plus module : automated installation and configuration The included distributed monitoring support Monitor allowed from Tivoli Enterprise Console Monitor allowed from Tivoli Distributed Monitoring. Tivoli Management Integrates with Tivoli SecureWay User Administration Integration supports role-based administration Tivoli Plus module : automated installation and configuration The included distributed monitoring support Monitor allowed from Tivoli Enterprise Console Monitor allowed from Tivoli Distributed Monitoring.
Sway3-5 NabiTel Component : Global Sign-On - 특징 ( 계속 ) Extensible and Flexible Extensible to any application that requires logon Using program-template files and scripting Allows logon to applications or systems that provide Command line interface (CLI) Application programming interface (API) Supports 3270 emulation, 5250 emulation, and many others Supports a standard Windows dialog box for logon/password Uses window-watching adapter code Example : Lotus cc:Mail, many Internet-based applications Extensible and Flexible Extensible to any application that requires logon Using program-template files and scripting Allows logon to applications or systems that provide Command line interface (CLI) Application programming interface (API) Supports 3270 emulation, 5250 emulation, and many others Supports a standard Windows dialog box for logon/password Uses window-watching adapter code Example : Lotus cc:Mail, many Internet-based applications
Sway3-6 NabiTel TSO NT Apps LAN Server Netware Server Notes Server Targets Databases VM GSO Client Programs: - PCOM (3270 emul) - NT client - Netware client -Notes client GSO Server - VM - TSO - NT Apps - Netware Server - LAN Server - Notes Server User's Target info Request authentication from server SMART CARD U/P Single Logon Securely retrieve target info Get local logon mechanisms Logon to targets User Admin Software Distribution Event Console Distributed Monitor Component : Global Sign-On - Architecture
Sway3-7 NabiTel Target application 이 GSO 의 “out of the box” 로 구현될 수 없을 경우 Target 을 지원하도록 GSO 를 확장 GSO 는 다음을 경유한 logon 을 사용하는 Application 에 대해 확장될 수 있음 Application Programming Interface (API) Command Line Interface (CLI) Windows dialog box Terminal Emulation (via EHLLAPI) Software Development Guide (SDG) 사용 확장 예 : Peoplesoft, SAP, cc:Mail, Web Server GUI, Tivoli Desktop, etc. Component : Global Sign-On - Target 확장성
Sway3-8 NabiTel Component : Global Sign-On - 효과 Userid, Password 단일화 관리 단순 분실 / 노출 위험 감소 접근 통제의 집중화 효과적 통제 일관성 유지 Virtual Single System Image 생산성 증대 관리 효율성 향상 Userid, Password 단일화 관리 단순 분실 / 노출 위험 감소 접근 통제의 집중화 효과적 통제 일관성 유지 Virtual Single System Image 생산성 증대 관리 효율성 향상 Sun HP AIX NetWare NT End User Notes/Domino OS/390 AS/400 Unix OS/2 GSO 1 id, 1 pwd
Sway3-9 NabiTel Component : Global Sign-On - Platform Client Windows 95 Windows 98 Windows NT 4.0 Client Windows 95 Windows 98 Windows NT 4.0 Target 3270 mainframe applications 5250 applications (OS/400R) Novell NetWare Windows NT Server LAN Server/Warp Server Lotus Notes UNIX systems Other systems and applications Using CLI Using API Using window-watching Target 3270 mainframe applications 5250 applications (OS/400R) Novell NetWare Windows NT Server LAN Server/Warp Server Lotus Notes UNIX systems Other systems and applications Using CLI Using API Using window-watching Server Windows NT 4.0 AIX Sun Solaris Server Windows NT 4.0 AIX Sun Solaris