| 
An RS-Computer Security Product |
General
Consumers are more and more susceptible to fraud through phishing
schemes & attacks. Phishing: (fish-ing) is, the process
of creating a replica of an existing web page to fool a user into submitting personal data,
passwords and other personal information such as social security numbers or bank accounts.
Many times this results in identity theft.
Passwords are necessary for securing online identities,
but they are insufficient to meet the increasing security demands of either the
consumer or the online business.
Current password practices leave consumers vulnerable, and they also put e-business at risk for fraud. |
| |
RS-PassID
For two-way-authentication, users enter their own secure PIN No.
via use of the RS Security Token, (an authenticator, the size of a house key) to gain secure access. This alone doesn’t protect the user from phishing.
Therefore
Our Password Manager program used with RS-PassID provides secure protection against the vast majority of password phishing schemes, as it utilizes an unique RS-PassID
which changes at every logon. Logon into this secured internet-area can take place only with the RS Token.
On the Server side, an authentication manager system creates & verifies the new unique RS-PassID code (256 Bit AES algorithm) on every request.
The real password will never be transferred via the Internet.
So, hackers cannot steal pass codes for later use.
Phishing can now become neutralized. |
| |
Process Flow Schematic Diagram of internal RS-PassID
|
|
| |
| |
|
|
|
| Registration: |
|
Establish contact with the PassID server
(first time only). The users receives a registration code with which he activates the RS-PassID within the password manager program.
|
| Login: |
|
A new and unique, 1 time use only RS-PassID is generated after successful activation
of the RS-PassID upon each logon by the user within the password manager program.
|
| Time Modul: |
|
The PassID-Server Time Modul administers &
manages time based subscription programs: ex:
allows for a user to logon to a fee based content
provider server. Module allows for user to logon &
receive data for a preset time period based on an
hourly allocation of time.
|
| Admin-Tools: |
|
A total Administrator’s toolset. Multiple Admin
levels. Allows for inquiries, changes, locks, adding
and deleting of users and administrators, tracks all
usages of the PassID server System. Generates a
wide variety of reports for network administration
and tracking.
|
| API: |
|
C-Interface, to the control of the RS PassID
server. With this interface, Admin-Tools can be
also constructed by the individual need.
|
| Samples: |
|
Explanation of the C-API interface by a simple
example program with source code.
|
| PassID Server: |
|
The real service, which processes the commands of
the API interface.
|
| Database: |
|
Database of the PassID-Server, where the
accounts of the users and administrators are put
stored in an encoded environment.
|
| |
 |
Benefits
|
RS-PassID
|
• |
24 digit alpha/numeric PassID
encoded with 256 Bit AES algorithm |
• |
Automatic transmition, must not read
and type |
• |
Each customer has his own RS-PassID
with the registration |
• |
PassID generation can be changed by
a different software and is variable &
dynamic, nobody can calculate the
PassID on ex:04.07.2006 at 8:41 am |
• |
No extra power required, power is
provided by USB port to the RS Token |
• |
Less expensive, with additional
benefits & value |
• |
Helps achieve complience measures in
various industries, such as banking,
ebusiness, healthcare and financial
markets
|