Signature validation using secure channel

Prev Next

To perform signature validation using secure channel, the following two operations must be executed in this particular order:

  1. Get signing request (see genRequest operation)

  2. Secure channel message signature validation (see authSignature operation)

For this operation to succeed, the following administrative tasks should be performed in OneSpan Authentication Server:

To configure OneSpan Authentication Server for the get signing request operations

  1. Use the pre-defined IDENTIKEY Signature Validation with Secure Channel policy or define a policy that inherits from that policy.

  2. Register a client component and assign the policy to it.

  3. Import authenticators that are compliant with multi-device licensing (MDL) and support Secure Channel.

  4. Create users, assign authenticator licenses to them, and activate a new authenticator instance for their devices.

genRequest operation

The get signing request operation enables a user to generate a signed request message, which can be used to initiate a signature validation operation using secure channel.

The get signing request operation can send two types of requests to OneSpan Authentication Server:

  1. A request that includes a list of key/value data fields (which will be used to generate a request body and the signed request message).

  2. A request that includes a custom request body (which will be transparently used to generate the signed request message).

At a minimum, the genRequest command requires the following set of signature field attributes to perform this operation:

  • SIGNFLD_COMPONENT_TYPE

  • SIGNFLD_USERID

  • dataFieldList with at least one key/value dataField

    -OR-

    SIGNFLD_REQUEST_BODY

    For more information, see genRequest SOAP request structure.

By default, OneSpan Authentication Server uses the first applicable authenticator application that is allowed by the effective policy. If you need to use a specific authenticator application for the Secure Channel signature verification process, you can specify it by using one of the following attributes when you call the genRequest operation:

  • SIGNFLD_CRYPTO_APP_INDEX

  • SIGNFLD_CRYPTO_APP_NAME

The specified authenticator application must be allowed by the effective policy. Any subsequent call of authSignature related to the generated request message will automatically use the specified authenticator application.

If you really need to specify the authenticator application, we recommend to use SIGNFLD_CRYPTO_APP_NAME whenever possible, because it is more reliable. The difference is that the application name is explicitly specified in the DIGIPASS export file (DPX), whereas the application index is dynamically created during the DPX import process based on the authenticator application order in the DPX.

For more information about the required and optional attributes for this command, see SOAP signature validation.

authSignature operation

The secure channel message signature validation operation enables a user to verify a signature against a signed request message using secure channel.

At a minimum, the authSignature command requires the following set of signature field attributes in order to perform signature validation:

  • SIGNFLD_COMPONENT_TYPE

  • SIGNFLD_USERID

  • SIGNFLD_SIGNATURE

  • SIGNFLD_REQUEST_KEY

For more information about the required and optional attributes for this command, see SOAP signature validation.