Gemalto releases a self-contained network security device

Opinion
Feb 19, 20075 mins

* Gemalto Network Identity Manager

There were lots of product announcements at the recent RSA Conference, and I’ll be talking about those for quite a while. Today I want to mention one from Gemalto, the company formed by the merger of Axalto and Gemplus last year.

Just released is the Gemalto Network Identity Manager (NIM), a self-contained, portable, network security solution that plugs into a USB port. It works with a standard browser, runs on any PC and does not require any software installations or downloads. An onboard network computer and Internet software create a PIN-protected digital safety zone, impervious to malware lurking in the PC or on the Internet. Yet, the company promises, it is simple and intuitive for anyone to use. In addition, the NIM supports the VeriSign Identity Protection (VIP) Network, so consumers can use Gemalto’s latest innovation with many different online businesses such as Northern Trust, Charles Schwab, PayPal, eBay and Yahoo.

This completely new Gemalto digital security product claims a number of industry firsts:

* The first ‘zero-infrastructure’ smart card type of device — no special readers, drivers, downloads or software installation are required — so it can be used easily on any PC.

* The NIM is also the first portable online security solution that is completely self-contained with its own Internet software and hardware. It only uses the host PC as a launching pad, so Trojans and other hostile software hiding in wait are made irrelevant. It verifies Web sites are authentic, removing the guesswork of sniffing out a fake site from the consumer. And it establishes an encrypted, mutually authenticated browser session directly with the desired online business. The result is a unique and direct connection, a sort of “sealed tunnel” that provides an end-to-end digital security solution that protects consumers against identity theft and account hijacking.

* Finally, it is the first portable security device based completely on existing Internet standards like TLS/SSL. This means Web service providers do not have to make major changes to support the Gemalto NIM. For issuers, it means no software or public key infrastructure to develop, buy and distribute for clients. Minimal IT and customer support on the help desk is required, resulting in lower operational costs and complexity.

Gemalto’s primary target market for NIM is online consumer transactions. The company will work with leading organizations with large online communities that will issue NIM devices to their customers. VeriSign VIP-enabled NIMs will be useable with any Web site that supports the VeriSign network. More information on the Gemalto Network Identity Manager is available at the product Web site. Samples are available to potential customers by request.

For the more inquisitive readers, here’s how it works. For the rest of you, see you next issue!

When inserted into a USB port, the NIM opens its own secure browser window on the desktop. It is a “zero-infrastructure” solution, meaning it does not require any software installations, downloads or drivers. These features make it very easy and familiar to use.

Using a randomized screen-based pad, the owner enters their PIN and unlocks the NIM, which in turn presents a list of Web site links to the user. Since it is completely self-contained with its own Internet software and screen-based PIN pad, it is not vulnerable to any threats on the user’s PC, such as a keyboard-logging Trojan program. The PIN blocks anyone other than its owner from using the NIM, preventing lost or stolen devices from misuse. It also locks itself after a small number of wrong PIN entries to prevent a brute force “guessing” attack.

Using the NIM is intuitive because the user selects their Web destination as they normally would by clicking a link in the secure browser window. The NIM then goes to work, using its onboard computer and Internet software to completely bypass the PC and any Internet address lookup servers. It directly accesses the desired site and uses a certificate to make sure it is authentic. It then establishes a secure end-to-end tunnel directly between the NIM and the site using standard Internet security techniques, completely protecting the user while online.

By circumventing the PC, authenticating the web site and directly connecting end-to-end, the NIM provides a bulletproof solution to the most pernicious of online security problems — phishing, pharming, spoofing, logging and man-in-the-middle attacks. Any would-be attacker would not be able to decipher communication passing through, nor could they succeed with relaying or hijacking attacks.

From the point of view of the Web service provider, the NIM is the first personal security device they can put in the hands of their customers that is completely self-contained and not dependent at all on the PC for its security. Another advantage for the service provider is that it is also a “zero-infrastructure” solution — meaning service providers don’t have to make changes to support it — as it uses standard Internet security protocols and certificates.

Finally, an option for challenge response mutual authentication using NIM-based certificates is also available. The NIM is a two-factor authentication solution because servers can detect if the NIM is present or not.