An improved computer network security system and a personal identifier
device used for controlling network with real time authentication of both
a person's identity and presence at a computer workstation is provided. A
new user is registered to a portable personal digital identifier device
and, within the portable personal digital identifier device, an input
biometric of the user is received and a master template is derived
therefrom and securely maintained in storage. A private key and public
key encryption system is utilized to authenticate a user registered to
the portable personal digital identifier device. The personal digital
identifier device verifies the origin of a digitally signed challenge
message from the network security manager component. A digitally and
biometrically signed challenge response message is produced and
transmitted by the personal digital identifier device in response to the
verified challenge message.