- 22 Jan 2025
- 3 Minutes à lire
- SombreLumière
- PDF
AAL2DeriveTokenBlobs
- Mis à jour le 22 Jan 2025
- 3 Minutes à lire
- SombreLumière
- PDF
Function prototype
aat_int32 AAL2DeriveTokenBlobs (
TDigipassBlob *DPData[8],
TKernelParms *CallParms,
aat_int16 *Appl_Count,
aat_ascii *Challenge,
aat_ascii *Derivationcode,
aat_word32 DerivationCodeFormat);,
Description
This function derives the Digipass data of a software Digipass authenticator based on the Digipass SDK 4.0 or later for software Digipass authenticators compliant with the standard one-step activation (in the context of single-device licensing (SDL)). Refer to the Authentication Suite Server SDK Product Guide for more information.
Digipass data derivation is allowed only for applications supporting the feature (Call the AAL2GetTokenProperty function with property DERIVATION_SUPPORTED to check if a authenticator application supports the feature).
If supported by the software Digipass authenticator, this feature is used to bind a software Digipass authenticator with its hosting device. In this case, during the activation process, the software Digipass authenticator can create a diversifier based on a device’s fingerprint and can provide a derivation code based on the diversifier, an OTP, and an optional challenge.
AAL2DeriveTokenBlobs allows applying the derivation to the authenticator application BLOBs on the server-side.
When reactivating the same Digipass authenticator on another device, the Digipass data must be derived again on the server-side using AAL2DeriveTokenBlobs with the new derivation code. The Digipass instance on the old device will not work anymore.
The derivation code is validated using the first authenticator application BLOB of the authenticator application BLOB table (DPData) input parameter. This first authenticator application BLOB MUST match the authenticator application used for generating the derivation code on the client. This first authenticator application BLOB MUST support either Response-Only or Challenge/Response authentication.
For example, it means that when the application named AUTH_APP1 is used for generating the derivation code on the client-side, the first authenticator application BLOB must relate to the AUTH_APP1 application.
Application names are exposed during import process.
In addition, the derivation will fail if one or more authenticator application BLOB does not support the derivation feature.
Score-based Digipass
For Digipass devices that integrate the score-based algorithm, Authentication Suite Server SDK performs a score-based authentication to validate the derivation code. This allows retrieving the Digipass scoring value. Once Authentication Suite Server SDK has successfully validated the BLOBs, it returns either SUCCESS or SUCCESS with the relevant scoring warning code. See the list of return codes in AAL2DeriveTokenBlobs for more details.
Parameters
Return codes
* Specific score-based authentication codes. For more information, refer to Score-based Digipass.