November 2007

BioPassword Enterprise Edition 3.2

Flexible, effective, software-only two-factor authentication
RSS
Subscribe to Windows IT Pro | See More Windows OSs Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

BioPassword Enterprise Edition 3.2 (BPE) enhances the security of corporate networks by adding a second, biometric component to the standard Windows logon / authentication sequence. As a software-only solution, it does so without the need for the additional client hardware required by other modes of biometric authentication such as fingerprint identification or retinal scanning. Instead, BPE relies upon the consistent, distinctive pattern of each person’s keyboard keystrokes during the logon process.

BPE’s streamlined design will appeal to small organizations, and its support for a variety of environments lets it integrate easily into large enterprises. Supported environments include Citrix and RDP / Terminal Server users; selected thin clients with embedded Windows XP; and integration with Microsoft Outlook Web Services. Web application support allows you to integrate BPE into your own forms-based authentication screens.

BPE improves the standard Windows authentication sequence by extending the Active Directory (AD) schema within the AD domain tree hosting user IDs, and by inserting BPE GINA (Graphical Identification and Authentication) stub modules into the domain’s GINA chain. This requires that you install BPE on all domains that host either User or Computer accounts that will participate in BPE’s two-factor authentication. BPE is active during the primary AD login sequence and will optionally run during secondary logon sequences, such as Run As, Connect As, and Net Use.

BPE works by using client software to record keystroke timings as users complete the User ID and Password fields of an authentication form. Keystroke timings include the dwell (how long a key is held down) and flight (the time between key strokes) times. Using the timings, the authenticating domain controller (DC) calculates a Security Level score. That score is compared to a template created when the user first entered the user ID and password combination. To enroll, a user keys the user ID and password several times until BPE identifies the user’s consistent pattern. In my testing, this required eight or more repetitions. As administrator, you may configure enrollment to complete at the user’s first logon attempt, or gradually (and transparently to the user) over successive logon attempts.

The implementation process has many steps, but is fairly straightforward. Basic AD installation updates the AD schema, then installs software on all PDC emulators in the tree, on all authenticating DC’s, and on all client computers. Other supported environments require additional installation steps. BPE isn’t enabled upon installation, and it won’t participate in the authentication process until you enable it both for the participating domains and for the participating user IDs.

To test BPE, I installed it to a domain with a single DC. I installed the client component to several computers that were members of that domain and to a computer that was joined to a trusted domain and enabled BPE authentication for them. You can enable user accounts for BPE either individually or by enabling a group they belong to for BPE authentication. Figure 1 shows the BPE properties panels used to enable and configure BPE for a group. Finally, I enabled BPE for the domain.

BPE caused me to pay close attention to the logon process, as BPE requires a continuous flow of keystrokes. I enlisted several other regular users of computers in the testing, to see if the “wrong” user could successfully authenticate. This occurred only once in the course of my testing. Administrators can determine how stringent or relaxed their authentication environment will be by requiring a higher or lower BPE security level score.

I found BPE to be effective and relatively easy to work with. BPE provides an evaluation kit to facilitate testing and configuration. Many people will find that installing BPE isn’t a trivial process in their environments, but the added level of security will make it all worthwhile for many of you. The implementation flexibility that BioPassword has designed into the product will help ease that effort, and the support for several popular ways users access their applications makes this a viable product for many enterprises. For those seeking to add multifactor authentication as a way to increase system security, I recommend that you take a look at BPE.

Summary
BioPassword Enterprise Edition 3.2
PROS: Effective two-factor authentication without the need for special hardware; support for many application access modes, including Citrix, RDP and embedded XP terminals
CONS: Requires an AD schema update; installation is not trivial for large enterprises
RATING: 4.5 / 5
PRICE: $50/user perpetual license + maintenance or $19/user annual subscription, with volume discounts.
RECOMMENDATION: BioPassword is an impressive product, with a lot of implementation flexibility. I heartily recommend it to those seeking to implement multifactor authentication.
CONTACT: BioPassword, Inc. - www.biopassword.com - 425-649-1100

End of Article



Windows IT Pro Community
Blogs





Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

No Jobs, No Excitement at Apple's Last Macworld Keynote

Apple CEO Steve Jobs made the right move in skipping out on his company's last appearance at Macworld: In a Tuesday keynote address at the conference, Apple had no interesting new products to sell, opting instead to spend mind-numbing amounts of time on ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Related Events Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Cloud Computing Forum: Integrating Software, Server and Storage as a Service into Your Enterprise IT Delivery Model

Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


SQL Server Magazine Office & SharePoint Pro Windows Dev Pro ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing