The Digipass family of products includes a wide range of hardware and software elements used for complex security solutions based on strong authentication within various applications.

Strong authentication

A special device is used for authentication – a token. The token cannot be used without the knowledge of the PIN that protects its use. The authentication is then based on the combination of two factors:
  Ownership of the token

  Knowledge of its PIN

Principle of strong authentication

The authentication is based on the usage of single-use authentication codes. Authentication codes are generated on the basis of a token's internal parameters, so every token generates a different sequence of codes (the tokens are not interchangeable).
Besides the internal parameters, the calculation of an authentication code depends on other (variable) information that differs according to the mode used:
Mode
Data for authentication code generation
Internal parameters
Time
Input (data entered by user)
Response only
Yes
Yes
No
Challenge/Response
Yes
Optionally
Yes: Challenge (code) sent by server
Digital Signature
Yes
Yes
Yes: Selected data that should be protected against unauthorized modification
The Response only and Challenge/Response modes are used, e.g., to verify the identity of the user of an application, etc. The Digital Signature mode is suitable when it is necessary to protect the integrity of certain data for which otherwise there is a danger of unauthorized modification, such as entering bank transactions and other applications.

Where strong authentication can be used

Strong authentication can be used to protect access to private data (e.g., in the health service sector, education, and many other areas), IT resources (applications, operating systems), transaction authorization (financial sector, e.g., e-banking), and to secure a wide range of other business applications.
Fields for Token Usage
  Banking and financial sectors

  Company networks

  Education

  Health services

  Public administration

Equipment for implementation of authentication technology

Besides the equipment needed by clients (actual tokens), the Digipass family of products includes a complete range of products for the implementation of authentication technology on the part of the provider (server):
  Authentication server solutions,

  Software for application integration,

  Hardware and software for the initialization of tokens (which is connected to the configuration of their functions).