| Customers: Nordea Nordea
Contractors: Active Soft (rutoken) Product: RutokenProject date: 2010/09
|
The Aktiv company, the developer of software and hardware tools of authentication Rutoken, completed the first stage of the project on delivery of a batch of the tokens designed to provide authentication of users of a system "Bank Client" of JSC Nordea Bank and to guarantee safe storage of the EDS keys.
A system "Bank Client" was implemented for quality improvement of customer service and allows to organize document flow on paperless technology thanks to what the client of Nordea Bank has an opportunity quickly to trace account statements and to conduct settlings with Bank and partners, without leaving a workplace, or far off from every spot on the globe where there is an Internet access.
The technology of work with a system provides signing of the documents transferred to Bank from client name, the necessary number of the electronic digital signatures (EDS) of the persons authorized by Client. Use of the electronic digital signature which is an electronic analog of the sign manual of the authorized person Kliyenta excludes a possibility of transfer of documents by other persons on behalf of this authorized person. An important task of Bank in this case is security of secret key, an exception of a possibility of hit of this information in hands of the third parties.
JSC Nordea Bank carried out market research of the software and hardware tools of data protection capable to provide not only strict authentication of users in a system "Bank Client", but also to guarantee high security of secret keys of the EDS. As a result of monitoring of products of different producers Rutoken's solution of Aktiv company was selected.
Rutoken certified by the Federal Service for Technical and Export Control (FSTEC) provides reliable storage of the classified information thanks to two-factor authentication. Rutoken forms a basis the microcontroller which executes cryptographic data translation, and memory in which data of the user are reliably stored (passwords, certificates, encryption keys, etc.). For authorization in a system the Client needs to connect Rutoken in the USB connector of the computer or the notebook, and for carrying out financial transactions in a system - to gather the PIN code (after 15 incorrect inputs of the PIN code the token is blocked).
