Description
SAP access control remains the pending subject to most of implementations
Traditional access control methods has several issues, such as :
- - Multiple passwords to cover different applications
- - Need to change passwords regularly
- - Possibility of intercept them via keyboard or network sniffers
- - Impersonation risk if password is compromised
The problem exponentiates when dealing with multiple applications, existing in most of the companies ( SAP servers, mail servers, Intranet, Internet... ).
Solution
Thymbra will help you in determining the best global solution for your SAP environment. We can offer different schemas from Single Sign On, Central User Administratin or even advanced ACLs for heterogeneous environments.
We are SECUDE partners, a company specialized in computer security. SECUDE was pioneer in integrating Single Sign On schemas and Secure & Forward to SAP.
Single Sign On and Secure Store and Forward models makes your life easier and your company more secure. You will only need one passphrase for all your systems. You will be able to digitally sign documents from you SAP system.
Specifications
- Single pass-phrase for all your systems (SAP, mail, web, Portals )
- Digital Certificates Authentication Model (without login screen)
- Allows you to digitally sign SAP transactions
- SAProuter, SAPLPD Integration
- Portable : Standard protocols
- Great for users on the go (laptops).
Security
Due to the fact that SSO and SSF make use of public key cryptography, the following concepts are guaranteed :
- Authentication : It only allows access to the right person.
- Confidentiality : Data can not be deciphered in transit.
- Integrity : Information can not be altered.
- Non-repudiation : Quien access the system is the owner the private key.
At the same time, there is the possibility of storing the certificates in tokens. When you use these types of devices - way more versatile than traditional smartcards - you increase the security level of your company. Since the certificate resides outside the computer, is imposible that, even knowing the private key ( via keyboard sniffers ) someone could access to the target system.