background image

Use the pcProx Device for Password Security - Complex Passwords

It is possible with certain limitations, to use the proximity token as a password for an application or
operating system log on. The unique card bit-stream converted to either decimal or hexadecimal
becomes the entire or a portion of the password. Enroll this card data to the password of the
operating system application for the user.

Since the proximity token has no read/write memory there is no way go change this or write 
alphanumeric characters such as a user name to the proximity token. Some examples are shown 
below. Please see RF IDeas pcProx Playback Starter Kit or call the Sales Department if this capability 
is needed.

Several companies have adopted a policy that requires users to change their password every xx
number of days to increase security. The PIN is the portion of the password the user changes every
xx number of days. Since the card data is completely numeric, any alpha and upper/lower case letter
constraints are handled in the user supplied PIN.

A two-factor authentication system is made up of:

1. Card ID data
2. Personal Identification Number (PIN)

The device may be configured to allow operation under either a one or two-factor authentication
system.

One-Factor
In a one-factor system, the user simply scans the ID card. The device may be configured to add TAB
keystrokes ahead of the data as well as a TAB or ENTER keystroke after the card data.

Two-Factor
The two-factor approach is especially useful when insisting on password construction rules or 
periodic changing of passwords.

In a two-factor system, the user may enter the PIN either before or after the card data. If the user
adds the PIN before the card data, the device may be configured to append the ENTER keystroke.

Pre and Post Characters
There are some additional measures that can be taken to make it more difficult for unauthorized 
users to reproduce passwords. 

Adding additional keystroke characters to the card information, that is difficult to re-produce, while 
configuring the data. These additional characters are labeled as Sp1, Sp2, and Sp3 on the delimeters 
tab menu selections. 

 

 

68 

Appendix

Summary of Contents for pcProx Plus

Page 1: ...99009010 Rev U pcProx Plus pcProx Enroll Wiegand Converter Configuration Utility User Manual...

Page 2: ...questions or are interested in our OEM and Independent Developer s programs We look forward to your comments and suggestions for our product line Please go to www RFIDeas com and follow the Support a...

Page 3: ...contained electronic modules for easy system integration pcProx Contactless The registered RF IDeas brand name given to all 13 56 MHz contactless card reader products pcProx Proximity The registered...

Page 4: ...D Beeper 13 Chapter 3 Software 13 pcProx Configuration Utility 13 Utility Overview 14 Menu Tool bar 19 Icon Tool bar 22 pcProx Plus Configuration 23 Standard Configuration 23 Connect Tab 25 Output Tes...

Page 5: ...y and reliability Companies using proximity and or contactless technology for building access immediately benefit as their employee identification cards can also be used with the proximity contactless...

Page 6: ...ID Card Reader System Output Formats 6 Chapter 1 The Basics...

Page 7: ...uration and length Frequencies RF IDeas access control readers and credentials utilize the low frequency 125 kHz proximity band and or the high frequency 13 56 MHz contactless band Credential Form Fac...

Page 8: ...lexible and may need to be configured in order to present an exact desired output for the user such as singling out FAC or ID obtaining a desired base i e decimal lowercase upper case hexadecimal Diff...

Page 9: ...mbers associated to card types Housing This option provides the user to select the form factor housing for the desired reader The housings include desktop wall mount USB dongle PCMCIA bare board Expre...

Page 10: ...10 Chapter 2 Hardware Interface Connectors OUTPUT CONNECTORS T...

Page 11: ...number in ASCII characters 2 API defined in the pcProx SDK The device attaches to a computer serial port When it reads card data the active application receives the entire card data Once the configura...

Page 12: ...connections using Device Manager When the software is installed it should recognize these connections in order to configure the appropriate device Once the device is configured and written to its flas...

Page 13: ...ata output and access privileges for cardholders can be established In contrast to the pcProx Enroll readers for which only one configuration can be programmed into the reader the utility allows the p...

Page 14: ...connections Auto Connect to USB on Startup Set as utility default connection Through this connection the utility searches for a USB connection on startup Auto Connect to Serial on Startup With this s...

Page 15: ...guration reader device has different device menu options than a two configuration reader device Single Configuration Readers Reset to Factory Defaults Resets all configuration parameters to factory de...

Page 16: ...onfiguration Area section of this manual For example pressing the F5 key on the keyboard will open the Data Format tab A Test App hot key command is also available in this list This command opens any...

Page 17: ...es before certain utility operations are completed For example if the Show Confirm Dialogue option is selected a confirmation dialogue window will appear when a user clicks to reset their device to fa...

Page 18: ...Website for Software Updates Clicking this option will take users to a location on the RF IDeas software updates portion of the website and will detect what version of the pcProxConfig utility is curr...

Page 19: ...port connections Once the utility detects a device connection the Device List pull down menu in the Standard Configuration Area displays the interface connection firmware and LUID information for the...

Page 20: ...t Cont If an attempt to connect to a device is made and the utility does not detect a device through any of the available interface connections a no devices found message will display in the utility s...

Page 21: ...turn from green to gray Additionally the status bar will display a Disconnected message Write Settings Write Active The Write Settings icon button prompts the utility to write the current defined conf...

Page 22: ...uration to read only 26 bits and the other configuration to read only 35 bits Configuration Number This option provides the ability to switch between configurations Users can set and edit settings for...

Page 23: ...col The utility will then proceed to scan any available USB bus for connected devices Serial RS 232 and Virtual COM Ports This option provides devices that are RS 232 or Virtual COM port logical proto...

Page 24: ...use only Find Next IP Button Looks for other readers on the same ethernet connection Device List Pull down Lists the devices that the utility is actively connected to For Example if you have an RJ45...

Page 25: ...he selection may conflict with the menus and drop downs due to the fact that the cursor will attempt to move back into the test area If this problem arises simply uncheck the box The Auto Clear box au...

Page 26: ...illustrates the various characters that can be displayed upon a card detection by a connected device The number portions of the diagram are values that are displayed from a card The letter portions o...

Page 27: ...ount Sets the number of bits in the ID field from 0 to 80 Fix length FAC ID Fields This option will make the FAC and ID a fixed length FAC Digits This will alter the FAC output by forcing a set length...

Page 28: ...the end of serial data It emulates the serial data format to match HID Corp Prox Pro reader by sending a 2 byte checksum after the card data Delimiters Tab Use this tab to configure pre and post data...

Page 29: ...led NONE Once a chosen delimter is inserted the virtual keyboard will close Revert Takes user back to previously inserted delimeter choice None Deletes any selected inserted delimter Insert Applies se...

Page 30: ...user Continuous Read Sends Data Upon Read When a card is placed on a device this option will al low the data to be sent continuously Lock Out Time for Repetitive Reads The time that it takes the reade...

Page 31: ...ted Halt Keyboard Send serial out is disabled all card data must be read via the SDK functions LED The LED section allows users to control the LED light actions on the device to provide users info reg...

Page 32: ...vide when in use Long Beep s Check the box to configure a long beep of 375 msec By default the beep is set to a short beep of 125 msec 2 long beeps or 5 short beeps are allowed only The number value i...

Page 33: ...GetQueuedID Click to display the last card data read This returns 255 bits maximum Clear Lockout Check to clear the time remaining to allow the device to read the next card immediately Clear UID If c...

Page 34: ...34 Chapter 3 Software GetQueuedID Data Display HH MM SS displays 00 00 06...

Page 35: ...enable the highlighted field This allows the delimiters to be output and the corresponding card field to be processed and output All green fields are enabled All red fields are disabled Keyboard Clic...

Page 36: ...location of the card binary data In the example below the Personal ID starts at bit 111 is 50 bits long and is 10 digits The Bit Range is 111 160 and the card bit pattern is highlighted This output f...

Page 37: ...ong and is 5 digits The location of the agency data is highlighted in the binary bit pattern The Bit Range is 6 25 The actual card data displays in blue below the binary bit pattern layout The interpr...

Page 38: ...e The Start Bit changes the actual location of the selected field on the binary bit pattern Note The that display to the right of the Digits field indicate the BCD parity is incorrect Verify the corre...

Page 39: ...n Click on the appropriate field button and uncheck Enable to remove field data from being displayed In the example below the Agency Personal ID and Expiration Date fields have been removed Additional...

Page 40: ...rokes If Enable is checked for a field specific keystrokes can be assigned to precede card data output Note The Scan Code output for the key selected displays above the list of keys Click Clear to rem...

Page 41: ...41 Chapter 3 Software Each single keystroke entered to precede card data equals 1 byte of memory...

Page 42: ...42 Chapter 3 Software If any special character is selected with a keystroke this equals 2 bytes of memory...

Page 43: ...ct the appropriate field Click the keyboard icon Check Left Control Check Left Alt Click n Click Insert Click Flash to write this configuration to flash memory Verify the active window is OpenOffice S...

Page 44: ...ine bit length and format Click GetID and present the card to the reader Define the fields to match the specific output Configure any additional fields as appropriate Flash the configuration to memory...

Page 45: ...the command line All commands begin with the prefix rfid and end with a Return key CR or LF Determine the COM Port Windows Use device manager to display the COM ports Open the serial COM port If it is...

Page 46: ...l and set the Speed baud to 9600 Data bits to 8 Stop bits to 1 and Parity to None Flow control is not needed as there is no software or hardware handshaking Click Session Note Use Hyper Terminal inste...

Page 47: ...ase sensitive All commands begin with a prefix string followed by one or more token strings with a period delimiter character between multiple tokens Functions must end with a CR or LF Variables can b...

Page 48: ...een curly braces for easy parsing For example the rfid qid function output displays 0x00BB 1 0x0000 80 0x000000801CD1931B2F14 Assign a Variable There are three types of variables 1 Boolean 2 Integer 3...

Page 49: ...lues from 0x00 0x1F and 0x7F 0xFF will be with a leading backslash lowercase x and the two digit upper case hex number The output of the variable displays between curly braces For example RF IDeas rfi...

Page 50: ...chr count trail rfid qid hold rfid chr eol rfid qid id rfid chr fac rfid qid id hold rfid chr gone 1 rfid time hold rfid chr gone 2 rfid var Function rfid cmd echo rfid wieg id bits rfid cmd prompt rf...

Page 51: ...rue current configuration is given priority over the alternate configuration rfid cfg card list pcProx Plus only Function View list of supported card types and their hexadecimal entries for the rfid c...

Page 52: ...r set Length of facility code output up to 25 digits BOOL R W IF True enable facility code output as hex BOOL R W Enable output of facility code BOOL R W Set to True to separate ID and FAC False proce...

Page 53: ...F04 rfid qid hold Function Read the card data and reset lockout timer Once the function is called a new card can be read immediately after without waiting for the lock out time period to expire rfid q...

Page 54: ...ters Then rfid count trail can have a value of 0 1 or 2 If rfid count lead is 2 chr 1 and chr 2 are set as leading delimiters Then only chr 3 can be set as a trailing delimiter However they are used t...

Page 55: ...When the configuration is changed all other related settings reflect that configuration number Example To set configuration 1 to keystroke out card ID preceded by 1 the following would be entered rfi...

Page 56: ...s command sets the digits so the left most significant digits will be truncated For example if the card data is 1234 and id digits 3 then only 234 displays If the card data 8 formats the display width...

Page 57: ...ticks the card device has to wait for no card in the RF field to begin accepting new card data This prevents the same card data from being read over and over If op cont is true this value has no effec...

Page 58: ...from the most significant bits rfid wieg strip trail bits 1 This command strips 0 15 bits from the least significant bits ACP Error Codes ACP Errors Descriptions Error 1 Illegal Command Will return Tr...

Page 59: ...e software configuration screen agrees with the device attached 4 Verify the port agrees with the workstation connector 5 If the device still does not work unplug it remove General USB Device using Wi...

Page 60: ...u can simply email us at sales RFIDeas com with the number and we will contact you Solutions for Identification Solutions for Integrators When I present my card to the pcProx Enrollment reader the num...

Page 61: ...u are using If you do need to configure them we have a free download The Configuration Utility for USB and RS 232 readers can be found at http www rfideas com Software pcProxConfig exe What configurat...

Page 62: ...the OS every 10msec the same speed your keyboard and mouse is We use feature report packets to configure the readers We also communicate to the DLL API through Feature Reports for HID devices The AK0...

Page 63: ...e being used Have this information ready so that your call will be routed to the correct specialist For Assistance Ph 847 870 1723 E TechSupport RFIDeas com Talking To The Technician Provide the reade...

Page 64: ...opies shall be used only for personal purposes and are not to be republished or distributed either in hard copy or electronic form beyond the user s premises and with the following exception you may u...

Page 65: ...e specific legal rights in addition to any rights that you have under the laws of the state in which your business resides or operates Returns RF IDeas products which require Limited Warranty service...

Page 66: ...Disconnect 21 Write Active 21 Write Settings 21 ID Digits 27 K Key Press Time 30 Key Release Time 30 L LED 30 31 Lock Out Time 30 Logical Unit ID 32 M Manufacturer Card Compatibility See Card Compatib...

Page 67: ...bits 8 bit facility code F and 16 bit card number fields B This format displays below PFFFFFFFFBBBBBBBBBBBBBBBBP EXXXXXXXXXXXX XXXXXXXXXXXXO Bit Coding P Parity O Odd Parity E Even Parity X Parity mas...

Page 68: ...case letter constraints are handled in the user supplied PIN A two factor authentication system is made up of 1 Card ID data 2 Personal Identification Number PIN The device may be configured to allow...

Page 69: ...cturers proximity cards labels and key fobs Marked with data code and ID number available in several Wiegand formats pcProx Read Write Contactless Reads and writes directly to the smart cards pcProx W...

Page 70: ...assumes no responsibility with regard to the performance or use of these products All understandings agreements or warranties if any take place directly between the vendors and the prospective users P...

Reviews: