MDL activation operations (SOAP API)

Prev Next

The activation of authenticators compliant with the multi-device licensing (MDL) model, as initiated by an OneSpan Authentication Server administrator, consists of the following administrative operations:

Once an authenticator instance has been activated for a specific authenticator device, that authenticator instance can be deactivated with the deactivate operation (see Deactivate operation).

Generate activation message operation

The generate activation message operation allows an administrator to generate Activation Message 1 for a particular authenticator license. This operation is used as the first step in the multi-device activation (MDA) process. It returns Activation Message 1. To generate the device code, Activation Message 1 must be transferred to the authenticator. This can be done encoded as a QR code or a color QR code, which the user scans with the camera of the device.

The generate activation message operation is followed by an add device operation (see Add device operation).

To execute this operation, the registered client application must send a digipassExecute SOAP request to OneSpan Authentication Server, where the value for the cmd element is  DIGIPASSCMD_GENERATE_ACTIVATION_MESSAGE.

At a minimum, this SOAP command requires the following set of field attributes to perform this operation:

  • DIGIPASSFLD_SERNO

For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.

Add device operation

The add device operation allows an administrator to register a new or additional device for a particular authenticator license. The device must include authenticator software and/or firmware that is compliant with the multi-device licensing (MDL) model.

This operation is used as the second step in the multi-device licensing (MDL) process. This operation verifies the device code generated by the authenticator based on Activation Message 1. It creates a new authenticator instance for the authenticator license and returns Activation Message 2, which must then be transferred to the authenticator to create the authenticator instance on that device. This operation is optionally followed by a test signature operation (see Test signature with Secure Channel operation).

Activation Message 2 must be transferred to the authenticator. This can be done encoded as a QR code or a color QR code, which the user scans with the camera of the device.

To execute this operation, the registered client application must send a digipassExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is  DIGIPASSCMD_ADD_DEVICE.

At a minimum, this SOAP command requires the following set of field attributes to perform this operation:

  • DIGIPASSFLD_SERNO

  • DIGIPASSFLD_DEVICE_CODE

For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.

Test signature with secure channel operation

The test signature with secure channel operation allows an administrator to validate the confirmation code generated by the newly created authenticator instance after Activation Message 2 has been processed by the authenticator.

This operation is optional and the final step in the multi-device activation (MDA) process. It verifies the signature generated by the authenticator based on Activation Message 2. In case the authenticator software running on the device is based on Mobile Security Suite, no signature may be returned after Activation Message 2 has been processed. For more information about the authenticator software running on the relevant device, contact your vendor.

To execute the operation, the registered client application must send a digipassapplExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is DIGIPASSAPPLCMD_TEST_SIGNATURE.

At a minimum, this SOAP command requires the following set of field attributes to perform this operation:

  • DIGIPASSAPPLFLD_SERNO

  • DIGIPASSAPPLFLD_APPL_NAME

  • DIGIPASSAPPLFLD_REQUEST_KEY

  • DIGIPASSAPPLFLD_SIGNATURE

For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.

Deactivate operation

The deactivate operation allows an administrator to generate a deactivation message for a specific authenticator instance. This operation expires and deactivates all authenticator applications for the selected authenticator instance.

To execute this operation, the registered client application must send a digipassExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is DIGIPASSCMD_DEACTIVATE.

At a minimum, this SOAP command requires the following set of field attributes to perform this operation:

  • DIGIPASSFLD_SERNO

For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.