Header
  Home // Technology

Secure Internet Portal

Security

The Secure Internet Portal addresses all of the major threats that currently face online services like banking services:

  • Phishing attacks - the CD-ROM token forms an integral part of the authentication process, so even if a client can be coaxed into providing their password the key material on the token is still inaccessible to an attacker
  • Man at the end attacks - the browser used by the client for the online service is stored on the CD-ROM token, which is read-only and therefore not vulnerable to being compromised by malicious software
  • SSL man-in-the-middle attacks - the browser on the CD-ROM token is customised to trust only a single SSL server certificate, so SSL man-in-the-middle attacks are prevented
  • Key loggers - even if the client's password is captured, the key material on the CD-ROM token is still required before an attacker can masquerade as the client.

The CD-ROM token may be copied, like any CD (although this can be made difficult), but this requires physical access to the token, which attackers almost never have. Even if a CD-ROM token is copied, there is no way to determine the client's password from information on the token.

 

  • Home
  • About us
    • Who we are
    • Our people
    • Our leaders
    • What makes Castelain different?
    • What we do
      • Security systems architecture and design
      • Program and project management
      • Systems integration
      • Independent testing
      • Education and training
    • Our Partners
  • Expertise
    • Application security
    • Transaction security
    • Public key cryptography and digital signatures
    • Public key infrastructure
    • Identity management and access control
    • Mergers and acquisitions
    • Security policy and compliance
    • Risk management
    • Security controls
  • Clients
    • Commerce
      • KAZ
      • Altnet
    • Finance
      • Major Australian bank
      • Commonwealth Bank
    • Government
      • New Zealand Government Ministry of Justice
      • Australian Customs Service
      • Australian Tax Office
      • Department of Industry, Tourism and Resources
      • NSW Office of State Revenue
      • CrimTrac
      • Department of Health and Ageing
    • Utility
      • Integral Energy
  • Technology
    • Secure Internet Portal
      • Overview
      • Security
      • Integration
  • Publications
  • Contact
Contact us