Untitled Document
 Register Now & Save!

Untitled Document
2007 West Gold Sponsors
Untitled Document
2007 West Silver Sponsor
2007 East

PLATINUM SPONSORS:
IBM
The Case for an SOA Foundation

GOLD SPONSORS:
Laszlo
Presentation & Demo
Parasoft
Presentation & Demo
webMethods/SoftwareAG
Customer - SOA at National Bank of Canada

SILVER SPONSORS:
Active Endpoints
Wake Up to the Power of ActiveBPEL
WSO2
Session by Asankha Perera

EXHIBITOR PLUS:
Nastel
Monitoring Messaging based SOA
Nexaweb
Enterprise Web 2.0 Reference Architecture - AJAX, SOA, and Open Source
Solstice Software
Presentation & Demo

POWER PANELS:
Virtualization Power Panel
Moderator: Alessandro Perilli - Speakers: Toufic Boubez and Jonathan Clark
SOA Power Panel
Moderator Sean Rhody - Speakers: Fred Holahan and Dave Mavashev and Asankha Perera and Ian Thain
EOS Power Panel
Moderator: Roger Strukhoff - Speakers: Doug Levin and David Temkin

Click For 2006 Event Webcasts
Can't Miss RSS Feed
Subscribe to the RSS Feed & Get All The Conference News As It Happens!
soawse-eos-banner

The Most Significant SOA and Open Source Events of 2007!

Mass-Market Two-Factor Authentication using Open Source Technologies
Mass-Market Two-Factor Authentication using Open Source Technologies

One-time password (OTP) based two-factor authentication solutions are commonly used to secure VPNs, web sites, and online transactions. They are much more secure than authentication methods based on static passwords. In fact, the US government mandates that all online banking services must adopt two-factor authentication by the end of 2006. However, existing OTP systems are expensive to implement for mass market online services for two reasons: first, a security token device, which generates OTPs, must be distributed to the user and properly managed; second, the authentication software is expensive and integration with existing Java EE web sites is not trivial. Recent advances in open source security solutions in both Java EE and Java ME allow us to develop cheap two-factor authentication solutions for the mass market.

In this hands-on session, we will discuss how to integrate a stack of open source tools and frameworks to enable end-to-end two-factor authentication for Java EE servers. Any user with a Java ME mobile phone will be able to use the service. Open source tools covered in this talk include: Apache Directory Server (a pure Java directory server with Kerberos authentication service support, see http://directory.apache.org/), Haukey (the J2ME OTP generator for mobile phones, see http://hauskeys.safehaus.org/), and Triplesec (server side OTP generator, the management interface and application server integration kits, see http://triplesec.safehaus.org/). At the end of the session, you will be able to add two-factor authentication services to better protect your web site users (and yourself) for free.

About Michael Juntao Yuan
Michael Juntao Yuan is a member of JDJ's editorial board. He is the author of three books. His latest book, "Nokia Smartphone Hacks" from O'Reilly, teaches you how to make the most out of your mobile phone. He is also the author of "Enterprise J2ME" - a best-selling book on mobile enterprise application development. Michael has a PhD from the University of Texas at Austin. He currently works for JBoss Inc. You can visit his Web site and blogs at www.MichaelYuan.com/.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

The first company in the market to offer J2ME based TFA OTP was Mega AS Ltd (www.megaas.co.nz) who designed and applied for patents in 2003 for its J2ME OTP Cellular Authentication Token (CAT).
Using the CAT, Mega AS has also developed the concept of eAuthentication Service and offers it to SMEs who don't want to install and manage its own Server Authentication module.

It is recommended to use authorized and patented solutions rather then Open Source that may be open for IP charges.

The first company in the market to offer J2ME based TFA OTP was Mega AS Ltd (www.megaas.co.nz) who designed and applied for patents in 2003 for its J2ME OTP Cellular Authentication Token (CAT).
Using the CAT, Mega AS has also developed the concept of eAuthentication Service and offers it to SMEs who don't want to install and manage its own Server Authentication module.

It is recommended to use authorized and patented solutions rather then Open Source that may be open for IP charges.

The first company in the market to offer J2ME based TFA OTP was Mega AS Ltd (www.megaas.co.nz) who designed and applied for patents in 2003 for its J2ME OTP Cellular Authentication Token (CAT).
Using the CAT, Mega AS has also developed the concept of eAuthentication Service and offers it to SMEs who don't want to install and manage its own Server Authentication module.

It is recommended to use authorized and patented solutions rather then Open Source that may be open for IP charges.

For those who don't want to program yet want to have an Open Source-based two-factor enterprise-class authentication solution (with Radius server), there is smsRadius:

http://smsradius.us/images/architecture.jpg

smsRadius sends and receives short messages, connects with any network resources that use Radius authentication (e.g. most hardware firewalls), and includes a full-fledges PKI with Web-based certificate management for users.


SOA World Latest Stories
Cloud Computing Journal caught up with the CEO of a major new player in the fast-emerging Cloud ecosystem - a CEO who has taken an interesting and unusual decision. While signing up as the Platinum Plus Sponsor of the 5th International Cloud Expo, he and his company have decided to rem...
Lately there has been a lot of buzz around HTML5 Web Sockets, which defines a full-duplex communication channel that operates through a single socket over the Web. HTML5 Web Sockets is not just another incremental enhancement to conventional HTTP communications; it represents a colossa...
What are the attributes that attract applications to public clouds? Why implement private clouds? When is it appropriate to use both in a Hybrid Cloud approach? Can legacy applications be moved unchanged to the cloud or do they have to be rewritten as Web 2.0 apps? What are the implica...
Data accumulation rates are growing astronomically and managing data in traditional ways is getting difficult in the same proportion. Hadoop is emerging as a champion in large-scale data management needs; however, it requires a lot of IT infrastructure investment and expertise. In hi...
We are constantly bombarded with articles and presentations about the security risks in cloud computing and why organizations need to be concerned about them as they consider a move. The truth is that organizations do need to be concerned about security – but they needn’t be paralyzed ...
From internal collaboration to supplier and customer interactions, enterprises are discovering new ways of increasing productivity, process accountability, and connecting those challenging "white spaces" that exist between processes, ERP, and legacy systems. In his session at the 5th...
Untitled Document
 Call 201 802-3020 or Click Here to Save $100!
Save $100

 Sponsorship Opportunities
SOAWorld will deliver the #1 i-technology educational and networking opportunity of the year.


Please call
(201)802-3020

 Who Should Attend?
CEOs and CTOs, senior architects, project managers, Web programmers, Web designers, technology evangelists, user interface architects, consultants, and anyone looking to stay in front of the latest Web technology!

 Brought To You By:
SOAWorld Magazine is the leader in delivering technical and strategic insights on the worlwide adoption of web services as the key distributed computing paradigm, and as those services are deployed through specific service-oriented architectures (SOAs).
Virtualization Magazine is the breakthrough publication covering the architectural concepts and implementation of IT asset virtualization as realized through the adoption of distributed computing paradigms, including the deployment of service-oriented architectures (SOAs).

SOAWorld 2007 West Speakers Include...


MALLADI
eBay

GABHART
Web Age
Solutions

LIPTON
CA

THAIN
Sybase

JAAMOUR
Parasoft

RIX
SAIC

TEMKIN
Laszlo

GENDRE
ILOG

CHAPPELL
Oracle

ALUR
JackBe

RODRIGUEZ
TwoConnect

JACOBI
Kaazing

QUINN
TIBCO

PELLEGRINI
Active Endpoints

MATSUMURA
webMethods

KARUNASENA WS02

SYS-CON EVENTS


 Past Events Archive
SOAWorld Conference & Expo 2007 West
www.soaworld2007.com
Virtualization Conference & Expo 2007 West
virt2007west.sys-con.com
AJAXWorld 2007 Conference & Expo West
ajaxoct07.sys-con.com
SOAWorld Conference & Expo 2007 East
soa2007east.sys-con.com
Virtualization Conference & Expo 2007 East
virt2007east.sys-con.com
AJAXWorld 2007 Conference & Expo East
ajaxmarch07.sys-con.com
Real-World AJAX Seminar
www.ajaxseminar.com
Ruby on Rails Seminar
www.rubyonrailsseminar.com
Real-World Flex Seminar
www.flexseminar.com
Other SYS-CON Events
events.sys-con.com

 SOAWorld 2007 East Delegates Represented...
• AccuRev
• Adea Solutions
• Adobe Systems, Inc [3 delegates]
• ADP
• Aeropostale, Inc
• Aetna
• Akbank Training Center
• American Family Insurance
• American International College
• American Modern Insurance
• Amphion Innovations
• Amplify LLC, Clipmarks [2 delegates]
• Anderson Consulting
• Arrow Electronics [3 delegates]
• Ashcroft Inc
• Athabasca University
• ATS
• Audatex
• Avanade, Inc.
• Avaya Inc. [5 delegates]
• Azul [2 delegates]
• Backbase [2 delegates]
• Bank of America
• Bank of NY
• Barnes and Noble
• Barnex Investment International Limited
• BEA
• Bear Stearns [2 delegates]
• Bendel Newspaper Company Limited
• BizInnovative
• Bloomberg [2 delegates]
• BlueBrick Inc.
• BMC Software
• Boeing
• Bottomline Technologies [2 delegates]
• BP
• Broadcom
• CA [2 delegates]
• CalAmp [2 delegates]
• California Department of Social Services
• Cape Clear
• CareFirst, Inc.
• Car-Part.com [2 delegates]
• Centric CRM [4 delegates]
• Chariot Solutions [4 delegates]
• Chordiant Software [2 delegates]
• Cisco Systems [2 delegates]
• Citrix Systems, Inc.
• City of New York
• Cneils
• Comcast [2 delegates]
• Community Connect [2 delegates]
• Composite Software [5 delegates]
• Conservation International
• Consultant eds / wamventures.com
• Control Module, Inc.
• Corporate Technology Partners
• CorraTech [2 delegates]
• Cortlandt Technology Partners [2 delegates]
• CPUC
• Credit Suisse
• CRIMSONLOGIC PTE LTD [2 delegates]
• Critical Resource Tech
• Crosscheck Networks
• Cyberboom
• Cynergy Systems, Inc. [2 delegates]

   read more...