Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Architecture

Prev Next

Overview

An Authenticator Specific Module (ASM) is a platform-specific component developed by authenticator vendors which can be plugged into FIDO UAF Clients.

An ASM implements the UAF ASM API, which is how a FIDO UAF Client communicates with it. If the ASM is for a hardware-based authenticator, the ASM is typically implemented on top of a hardware driver, which then talks to the authenticator device. If the ASM is for a software-based authenticator, the ASM is typically implemented on top of an authenticator-specific SDK.

The ASM is responsible for:

  • Receiving the authenticator data provided by the RP, e.g., origin and challenge, and returning the response.

  • Hiding authenticator communication specifics from the FIDO UAF Client, e.g., authenticator algorithms, low level drivers, USB, SPI, Bluetooth, and NFC.

  • Implement authenticator specific UI for registration and authentication operations.

  • Providing authenticator management capabilities, e.g., changing enrollment settings and changing authenticator state.

The following diagram represents the ASM Architecture:

ASM Core

The ASM Core is registered allowing it to be discovered by the Digipass S3 App SDK depending on whether the ASM is local or remote.

Authenticator Core

The authenticator core handles the orchestration with the authentication process. The authenticator core is designed to be flexible to accommodate different modes of user verification. This is a common implementation for all authenticators.

IAuthenticatorDescriptor

IAuthenticatorDescriptor defines an interface to expose authenticator-specific attributes. Each authenticator implements an authenticator-specific descriptor object defining its attributes. The application should add all implementations of IAuthenticatorDescriptor to ASM. The attributes returned by the IAuthenticatorDescriptor object determine the construction of an authenticator object.

IMatcher

The matcher is responsible for verifying the user, for example, by asking for a PIN or a fingerprint swipe. Each authenticator will implement an IMatcher interface.