This topic describes the a provisioning scenario that extends the multi-device activation (MDA) scenario with FIDO2 device binding using the Vision FX provisioning protocol. This protocol is applicable for authenticators that combine Cronto visual cryptography with FIDO2 hardware-bound credentials, such as DIGIPASS FX2. As such, it incorporates the FIDO2 protocol for user authentication and the Cronto protocol for transaction data signing.
For more information about multi-device licensing and multi-device activation, see Authenticator licensing and activation.
Activation with FIDO2 binding provisioning (overview)
The server and the authenticator perform a FIDO2 provisioning, using the regular WebAuthn client registration protocol.
The authenticator now contains WebAuthn credentials (public/private key pair) to authenticate to the server, which stores the public key.
The server and the authenticator perform a Cronto provisioning, using an adapted Cronto activation protocol.
The server allocates a Cronto license to the user account. The Cronto license is identified by a serial number and is linked to a certain activation key.
The server generates Activation Message 1 and presents it to the authenticator as a Cronto image.
Apart from the regular activation message data, it contains a message authentication code (MAC) of the WebAuthn public key generated with the activation key.
The authenticator scans the Cronto image that encodes the Activation Message 1.
If the verification of the Activation Message 1 data is successful, the authenticator stores the Cronto license serial number and the activation key.
The authenticator calculates the device code and sends it to the server.
The device code consists of an internal device ID and a signature of the Activation Message 1 calculated using the activation key.
The server validates the device code.
If the validation is successful, the server stores the device ID. Furthermore, it generates one or more authenticator application keys.
The server generates an Activation Message 2 and presents it to the authenticator as a Cronto image.
The authenticator scans the Cronto image that encodes the Activation Message 2.
The authenticator generates an OTP and sends it to the server.
The OTP is calculated over the Activation Message 2 data and the device ID using the authenticator application key.
The server validates the OTP.