User's Manual

54
Use the pcProx Device for Password Security - Complex Passwords
It is possible with certain limitations, to use the proximity token as a password for an application or
operating system log on. The unique card bit-stream converted to either decimal or hexadecimal
becomes the entire or a portion of the password. Enroll this card data to the password of the
operating system application for the user.
Sincetheproximitytokenhasnoread/writememorythereisnowaygochangethisorwrite
alphanumeric characters such as a user name to the proximity token. Some examples are shown
below. Please see RF IDeas AIR ID Playback Starter Kit or call the Sales Department if this capability
is needed.
Several companies have adopted a policy that requires users to change their password every xx
number of days to increase security. The PIN is the portion of the password the user changes every
xxnumberofdays.Sincethecarddataiscompletelynumeric,anyalphaandupper/lowercaseletter
constraints are handled in the user supplied PIN.
A two-factor authentication system is made up of:
1. Card ID data
2. Personal Identification Number (PIN)
The device may be configured to allow operation under either a one or two-factor authentication
system.
One-Factor
In a one-factor system, the user simply scans the ID card. The device may be configured to add TAB
keystrokes ahead of the data as well as a TAB or ENTER keystroke after the card data.
Two-Factor
The two-factor approach is especially useful when insisting on password construction rules or
periodic changing of passwords.
In a two-factor system, the user may enter the PIN either before or after the card data. If the user
adds the PIN before the card data, the device may be configured to append the ENTER keystroke.
Pre and Post Characters
There are some additional measures that can be taken to make it more difficult for unauthorized
users to reproduce passwords.
Adding additional keystroke characters to the card information, that is difficult to re-produce, while
configuring the data. These additional characters are labeled as Sp1, Sp2, and Sp3 on the delimeters
tab menu selections.
Appendix