Re: Looking for system/device authentication solution for web app




<bobrich@xxxxxxxxx> wrote in message
news:1139491447.317185.233040@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Rereading my post, i realized that what i'm attempting to do isn't very
clearly stated.

When i say client, i mean the actual machine. The goal is to implement
a solution that will identify which machine a user is coming from. The
user will be logging in with a userid and password, but we want to
detect if the user is coming from a known system (has specific software
packages installed, has been 'registered') or from home/unknown system.

It's not for security as much as it is for presenting options to a user
that wouldn't work/make sense outside the context of the 'known' system.

You might look into Intel's TPM module. It will permit the development of
per=machine
authentication. If you are not worried about hackers, you could also use
IPSEC to establish
communications. That would do the trick as well.

Since the web is designed for "stateless" communication, you will have to do
something special to fish out the credentials for a machine, pass them to a
server, and then "verify them".
Ed


.



Relevant Pages

  • Re: TCP/IP comms problems between WinXP and DOS
    ... I have written client and server versions ... In the instance where I have a problem the DOS system is running as client, ... implementation of the communications of the DOS client. ...
    (microsoft.public.dotnet.languages.vc)
  • Re: Option in US & Europe
    ... Presently undergoing CCSP ... Quite a lot of security work involves communications with others -- ... personnel to be able to communicate clearly in English. ...
    (comp.security.firewalls)
  • RE: SMBmount conspiracy
    ... My local security policy settings are like this: ... Microsoft network client - digitally sign communications - ... Microsoft network server - digitally sign communications - ...
    (RedHat)
  • [Full-Disclosure] Re: [VulnDiscuss] HP Full Disclosure Story
    ... > communications like this. ... > policy regarding security and can help sysadmins, developers, security ... HP has a policy in place. ... fact that English is obviously not your first language, ...
    (Full-Disclosure)
  • Re: Bringin down Echelon
    ... Echelon is perhaps the most powerful intelligence gathering ... communications to and from North America. ... This massive surveillance system apparently operates with little ... > afsatcom, CQB, NVD, Counter Terrorism Security, Rapid Reaction, ...
    (alt.gathering.rainbow)