MobileCare™ Monitor Operator’s Manual
Copyright 2008 © AFrame Digital, Inc.
32
AFrame System uses the same strong SSL encryption used by leading financial
institutions to protect high-value financial transactions on the Internet.
A spoofing attack is an attack where a malicious entity on the Internet pretends to be
a legitimate entity in order to violate security in some way. To prevent spoofing, all
AFrame components carefully authenticate their peers before communicating with
them. This authentication is performed as follows:
The Panda authenticates the AFrame Server using SSL and a 1024-bit
RSA public-key certificate. This is the same mechanism used to
authenticate banking web sites on the Internet.
The AFrame Server authenticates PANDAs using standard HTTP Basic
Authentication. Each request from the PANDA includes a username and
password that authenticates the request. If the request contains a valid
username and password, then the server will accept the message from
the PANDA. If there are any discrepancies in the credentials the request
will be rejected. This username and password travels over the SSL
authenticated and secured connection such that they are protected
against disclosure.
When caregivers access the CareStation
™ application on the server, the
server authenticates the user with a unique username and password.
Passwords are required to meet complexity requirements to ensure that
they cannot be guessed. This username and password travels over the
SSL authenticated and secured connection such that they are protected
against disclosure.
The Web browser used by the caregivers authenticates the AFrame
Server using the same SSL and 1024-bit RSA public-key certificate
mechanism described above. The AFrame server name shown while the
caregiver checks the security on the caregiver secure page provides
strong assurance that the caregiver is communicating with the correct
server.
After requests are authenticated using the mechanisms described above, other
validations are performed to provide additional security. For example, when the
server processes the message from the PANDA, it validates that the Extended
Unique Identifier (EUI) presented has been registered on the server as a valid
PANDA. Similarly, when a PANDA sends watch information to the server, the server
validates that the EUI of the watch has been registered with the system. The
message will be rejected if the EUI is not registered.
Содержание MobileCare
Страница 2: ......