Hitachi ID Systems, Inc.

Hitachi

Features Self-Service Password Reset

Self-Service Password Reset

(1)Users who have forgotten a password or triggered an intruder lockout can sign into P-Synch® with another form of authentication to perform self-service password reset. Supported authentication factors include answering personal questions in the form of Q-A (Question-and-Answer), using a hardware token (e.g., SecurID, SafeWord), using a biometric sample and smart cards.

Automated password reset allows locked out users to reset their own passwords, effectively addressing the problem of forgotten passwords. P-Synch creates a secure and efficient process for users to reset their passwords, thus minimizing the help desk call volume and time spent with the help desk resetting the passwords.

Once authenticated, users can reset their own passwords without calling the help desk. Tickets can be automatically created on a call tracking system.

Self-service password reset is available from:

Process

Self-service password reset works as follows:

If users have forgotten or locked out their initial workstation login password, they can access a kiosk-mode web browser either by typing help and pressing enter (as described below), or by pushing a help button on the login screen, using an optional GINA (Graphical Identification and Authentication library) DLL deployed to the desktop, thus starting the process to recover or reset the password.

  1. User: forgets password or triggers intruder lockout.

  2. User: types `help' at the login prompt of his own workstation, enters a blank (no password) or easy-to-remember password and presses Enter.

  3. Workstation: logs "help" user into the domain.

  4. Workstation: applies "help" security policy.

  5. Workstation: launches UNC from P-Synch server as a replacement shell.

  6. P-Synch shell: finds user's default web browser in registry.

  7. P-Synch shell: launches web browser in kiosk mode to P-Synch self-service password reset URL.

  8. (2) P-Synch web server: prompts user to type his network login ID.

  9. User: types his network login ID.

  10. P-Synch web server: prompts user to answer some personal questions.

  11. User: types answers to personal questions.

  12. P-Synch web server: validates user-entered answers (internally or against an existing directory / database / etc.).

    ... repeat previous steps as many times as required, with different sets of questions or a security token.

  13. P-Synch web server: prompts user to enter a new password.

  14. User: types a new password, selects some or all accounts.

  15. P-Synch web server: validates password quality, possibly returns user to previous step.

  16. P-Synch web server: resets password on selected systems to the new value.

  17. P-Synch web server: displays a status page to the user.

  18. P-Synch web server: writes a ticket to a call tracking system.

  19. P-Synch web server: sends the user a confirmation e-mail.

User Interfaces

Self-service password reset is available from a web browser, from the workstation login prompt and from a telephone, as described here.