Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Attestation

Prev Next

Overview

Attestation allows an authenticator to prove its identity in a secure way to the Authentication Server. In addition to authenticator attestation, the integrity of the application and the user's device can be established using Google Play Integrity for Android and Apple App Attest for iOS devices.

The attestation information is used by the Authentication Server policies to check attestation status and take action to satisfy your security requirements. For example, you can configure a policy to request the attestation information from the client and reject if missing or invalid.

For more information about authenticator characteristics and attestation, see Authenticator and Device Characteristics.

For more information about Apple App Attest and Google Play Integrity and how to configure applications and policies, see Attestation.

Enterprise Attestation

In addition to authenticator and device attestation, your enterprise may need to track security keys used by employees and partners, and take action when they are used. For example, you can create Authentication Server policies to identify security key serial numbers and reject authentication for specific or missing serial numbers. Note that not all security keys support enterprise attestation.