|
|
|||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||
|
The Digipass family of products includes a wide range of hardware and software elements used
for complex security solutions based on strong authentication within various applications.
Strong authenticationA special device is used for authentication – a token. The token cannot be used without the
knowledge of the PIN that protects its use. The authentication is then based on the combination of
two factors:
Principle of strong authenticationThe authentication is based on the usage of single-use authentication codes. Authentication
codes are generated on the basis of a token's internal parameters, so every token generates a
different sequence of codes (the tokens are not interchangeable).
Besides the internal parameters, the calculation of an authentication code depends on other
(variable) information that differs according to the mode used:
The Response only and Challenge/Response modes are used, e.g., to verify the identity of the
user of an application, etc. The Digital Signature mode is suitable when it is necessary to protect
the integrity of certain data for which otherwise there is a danger of unauthorized modification,
such as entering bank transactions and other applications.
Where strong authentication can be usedStrong authentication can be used to protect access to private data (e.g., in the health
service sector, education, and many other areas), IT resources (applications, operating systems),
transaction authorization (financial sector, e.g., e-banking), and to secure a wide range of other
business applications.
Fields for Token Usage
Equipment for implementation of authentication technologyBesides the equipment needed by clients (actual tokens), the Digipass family of products
includes a complete range of products for the implementation of authentication technology on the
part of the provider (server):
|
|||||||||||||||||||||||||||||