Risk-Based Authentication Data Flow
The following figure shows a web-based application before it is configured for risk-based authentication (RBA). In this example, the network resource is protected by an SSL-VPN, and the SSL-VPN is configured to validate user logon credentials using an LDAP directory.
Data flow occurs in the following sequence:
The user browses to the SSL-VPN logon page over an HTTPS connection.
The user provides a user name and password.
The SSL-VPN validates the user’s identity using an LDAP directory, the identity source, over an LDAPS connection.
The SSL-VPN grants the user access to the protected resource.
When RBA is enabled, the logon page for the web-based application redirects the user to the AM logon page. The user enters logon credentials, and AM validates the user’s credentials using an LDAP directory as an identity source.
You can deploy RBA so that the workflow is transparent to the user. The redirect is immediate. Also, you can customize the AM logon page.
The following figure shows RBA integrated with the SSL-VPN.
Data flow occurs in the following sequence:
The user browses to the SSL-VPN logon page over an HTTPS connection.
The SSL-VPN redirects the user’s browser to an AM logon page.
The user provides a user name and password.
AM validates the user’s identity using an LDAP directory, the identity source, over an LDAPS connection.
Also, AM assesses the assurance level (the confidence level that determines when the user is challenged for identity confirmation) of the authentication attempt. One of the following occurs:
If the assurance level meets the level that is required by the RBA policy, the workflow continues at step 5.
If the assurance level does not meet the level that is required by the RBA policy, the user is prompted to confirm his or her identity. One of the following happens:
If the user provides identity confirmation, the workflow continues at step 5.
If the user does not provide identity confirmation, AM returns a message to the user’s browser that access is denied, and the workflow ends.
AM redirects the user’s browser to the SSL-VPN with an authentication artifact to confirm that the user’s credentials are valid.
The SSL-VPN validates the authentication artifact over the RSA SecurID protocol, which is the native authentication protocol for AM.
The SSL-VPN grants the user access to the protected resource.
Related Articles
Risk-Based Authentication Policies 25Number of Views Add a Risk-Based Authentication Policy 7Number of Views Methods for Enabling Users for Risk-Based Authentication 6Number of Views Manage Passwords Automatically 18Number of Views Cannot access Security Console after patch installation failed and restored to earlier version. 29Number of Views
Trending Articles
RSA Announces the Release of RSA MFA Agent 2.5 for Microsoft Windows RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to generate a PASSCODE for manual entry on a Ericsson R380 WAP phone How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID Desktop Token 5.0.3 for Windows Administrator's Guide