The activation of authenticators compliant with the multi-device licensing (MDL) model, as initiated by an OneSpan Authentication Server administrator, consists of the following administrative operations:
Generate activation message (see Generate activation message operation)
Add device (see Add device operation)
Test signature with secure channel (see Test signature with Secure Channel operation)
Once an authenticator instance has been activated for a specific authenticator device, that authenticator instance can be deactivated with the deactivate operation (see Deactivate operation).
Generate activation message operation
The generate activation message operation allows an administrator to generate Activation Message 1 for a particular authenticator license. This operation is used as the first step in the multi-device activation (MDA) process. It returns Activation Message 1. To generate the device code, Activation Message 1 must be transferred to the authenticator. This can be done encoded as a QR code or a color QR code, which the user scans with the camera of the device.
The generate activation message operation is followed by an add device operation (see Add device operation).
To execute this operation, the registered client application must send a digipassExecute SOAP request to OneSpan Authentication Server, where the value for the cmd element is DIGIPASSCMD_GENERATE_ACTIVATION_MESSAGE.
At a minimum, this SOAP command requires the following set of field attributes to perform this operation:
DIGIPASSFLD_SERNO
For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.
Add device operation
The add device operation allows an administrator to register a new or additional device for a particular authenticator license. The device must include authenticator software and/or firmware that is compliant with the multi-device licensing (MDL) model.
This operation is used as the second step in the multi-device licensing (MDL) process. This operation verifies the device code generated by the authenticator based on Activation Message 1. It creates a new authenticator instance for the authenticator license and returns Activation Message 2, which must then be transferred to the authenticator to create the authenticator instance on that device. This operation is optionally followed by a test signature operation (see Test signature with Secure Channel operation).
Activation Message 2 must be transferred to the authenticator. This can be done encoded as a QR code or a color QR code, which the user scans with the camera of the device.
To execute this operation, the registered client application must send a digipassExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is DIGIPASSCMD_ADD_DEVICE.
At a minimum, this SOAP command requires the following set of field attributes to perform this operation:
DIGIPASSFLD_SERNODIGIPASSFLD_DEVICE_CODE
For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.
Test signature with secure channel operation
The test signature with secure channel operation allows an administrator to validate the confirmation code generated by the newly created authenticator instance after Activation Message 2 has been processed by the authenticator.
This operation is optional and the final step in the multi-device activation (MDA) process. It verifies the signature generated by the authenticator based on Activation Message 2. In case the authenticator software running on the device is based on Mobile Security Suite, no signature may be returned after Activation Message 2 has been processed. For more information about the authenticator software running on the relevant device, contact your vendor.
To execute the operation, the registered client application must send a digipassapplExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is DIGIPASSAPPLCMD_TEST_SIGNATURE.
At a minimum, this SOAP command requires the following set of field attributes to perform this operation:
DIGIPASSAPPLFLD_SERNODIGIPASSAPPLFLD_APPL_NAMEDIGIPASSAPPLFLD_REQUEST_KEYDIGIPASSAPPLFLD_SIGNATURE
For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.
Deactivate operation
The deactivate operation allows an administrator to generate a deactivation message for a specific authenticator instance. This operation expires and deactivates all authenticator applications for the selected authenticator instance.
To execute this operation, the registered client application must send a digipassExecute SOAP command to OneSpan Authentication Server, where the value for the cmd element is DIGIPASSCMD_DEACTIVATE.
At a minimum, this SOAP command requires the following set of field attributes to perform this operation:
DIGIPASSFLD_SERNO
For more information about the required and optional attributes for this command, see the OneSpan Authentication Server SDK SOAP Reference.