|
|
Security Server for RSA SecurID ® Authentication
RSA ACE/Server® is the management component of the RSA SecurID® product family, used
to verify authentication requests and to administer policies for enterprise networks.
Do you really know who's accessing your
most sensitive networked information assets? Unfortunately, security built
on static, reusable passwords has proven easy for hackers to beat. With
the advent of e-business, the need for rock-solid user authentication has
never been more urgent.
RSA SecurID two-factor Authentication is based on something you
know (a password or PIN), and something you have (an authenticator)
-- providing a much more reliable level of user authentication than reusable
passwords.
RSA SecurID Two-Factor User Authentication System Turnkey Interoperability High Performance Design, Proven Scalability Manageability and Control
Define User Hierarchies
Administrative Roles and Scope Compatible with Leading Standards Cross-Realm Support for Traveling Users Security Features
Audit and Reporting Reliability and Failover — Hot Backup Application Program Interfaces
The Power to Protect Your Net
An
enterprise-class solution, RSA ACE/Server scales to protect hundreds of thousands of users across dozens of physical sites. Features like remote administration, segregation of duties, administrative scoping, cross-realm authentication of traveling users, hot backup and failover protection make it an ideal solution for large networks where performance and iron-clad reliability are a must.
The RSA SecurID family of two-factor user authentication products provides patented, state-of-
the-art performance, ease of use and enterprise-class scalability. The complete system
consists of three main components: easy-to-use RSA SecurID authenticators which are
distributed to end users, the RSA ACE/Server security management server and RSA
ACE/Agent software to protect specific information resources on the network.
RSA ACE/Server is instantly interoperable with virtually all available network equipment,
including more than 150 products from over 75 vendors, providing your organization with
maximum flexibility and investment protection. Through the RSA SecurID Ready partner
program, leading vendors of remote access products, Internet firewalls, network operating
systems and application software have built RSA ACE/Server compatibility directly into their
products.
RSA ACE/Server is built upon an enterprise-class, multiprocessor architecture, capable of handling
Hundreds of thousands of users per server
and high numbers of simultaneous authentications. Today, RSA ACE/Server is deployed in more than 10,000 authentication installations world-wide - ranging from consumer Internet stock trading, to banking, government, manufacturing, high technology, medical applications and more.
RSA ACE/Server offers a greater level of management flexibility and control than any other
authentication server product on the market today.
![]()
It can be managed directly from the server console or remotely from a Windows interface.
![]()
Multiple forms of RSA SecurID authenticators can be managed from the same server
console for single users, for volume token assignment and for batch replacement of
aging tokens.
![]()
Temporary passwords can be provided to users who have misplaced their tokens.
Streamline your user management process by defining user hierarchies, including groups,
sites and realms; and applying authentication rules to the entire group. You can also restrict
login time of any group to control when users have access to network resources.
Delegate the tasks and user groups that
each administrator in your organization has
rights to manage; and control the entries
that appear in the user interface for those
administrators. Select a "canned" task list,
or create your own administrative roles, to
allow administrative access to only a basic
set of functions.
RSA ACE/Server includes Livingston 2.0
RADIUS server, so you can manage user
accounts from a single database for both
RADIUS and RSA SecurID authentication.
RSA ACE/Server is also compatible with
other leading authentication technologies,
such as TACACS+ and Kerberos.
Users can authenticate to an RSA ACE/Server
other than their home server without
additional administration effort. After the
first login, the user's home realm informa-tion
is cached locally, allowing authentication
with minimum network traffic.
RSA ACE/Server utilizes industry-leading
RSA encryption expertise and technology
to provide a hacker-proof solution.
![]()
All key aspects of the system are
encrypted to prevent illegal access,
including user PIN; agent and server
communications, the server database,
and remote administration sessions.
![]()
Evasion of attack logic detects attempted
intrusions or use of stolen tokens.
![]()
Remote administrators must authenticate
with RSA SecurID before gaining access to the server.
Because RSA ACE/Server logs all transactions
and user activity, you can use it as an
audit and accounting tool. Included are
several report templates you can easily
tailor to your needs — including activity,
exception, incident and usage summaries.
With the use of a backup or slave server,
RSA ACE/Server provides end users with
uninterrupted authentication, even if the
master server goes down.
An administrator toolkit allows you to
integrate RSA ACE/Server management
into custom applications through C and
TCL routines. Program interfaces let you
extract information from the server logs
for reporting and auditing. And a multi-threaded
agent API lets you build your own
custom RSA ACE/Agents.
How RSA SecureID Agents Can Secure Your Website