Mobile Application
The mobile app is any application on a mobile device that you implement and requires authentication. This can be an Android or iOS app running on the user’s device. In the architecture, the mobile app makes requests for authentication operations and acts as a conduit for authentication messages between the server side and on-device components of the S3 Suite. If you do not have a mobile app but you are interested in supporting authentication in your web apps, Nok Nok provides a mobile app called Nok Nok Passport. This Passport App acts as the authenticating mobile app. For details about Passport App, see Integrating with Passport App.
Web Browser
Desktop web browsers can make use of strong FIDO authentication by prompting the user to interact with an external authenticator such as a smartphone or a security key (also known as a token). Web applications can use bound-to-device authenticators, such as those based on fingerprint or face recognition biometrics, and external authenticators like security keys.
Nok Nok App SDK
To provide Nok Nok authentication in your app, you need to integrate with the Nok Nok App SDK (App SDK). The App SDK supports iOS, Android, Cordova, and Web. The App SDK embeds the requisite technology to implement FIDO standards-based authentication within your app and allows your app to perform user authentication related operations like registration and authentication. See Supported Authenticators for a list of included FIDO authenticators.
Apps developed with the Android App SDK are fully supported on devices using either Google Play Services or Huawei Mobile Services.
In addition, the Nok Nok App SDK includes an embedded FIDO Client that processes messages received from the FIDO server and generates responses. It returns the responses to your app via the App SDK API. The FIDO client discovers and communicates with available FIDO authenticators.
FIDO Platform Authenticators
The S3 Suite supports all FIDO authenticators including platform authenticators. A device may have one or more FIDO2 and/or UAF platform authenticators that may be used as a replacement for passwords. A platform authenticator may qualify as multi-factor if it requires user verification (for example, a biometric scan or knowledge such as a PIN) in addition to possessing the authenticator. A platform authenticator has two roles:
Verifies the user: The authenticator may use a mechanism such as fingerprint biometrics, voice biometrics, or PIN code verification to verify the user. The authenticator encapsulates the underlying hardware used for verifying the user (e.g. a fingerprint sensor). The authenticator is responsible for the User Interface (UI) shown during user verification. For example, the Touch ID/Face ID authenticator on iOS may show a dialog asking the user to authenticate. The authenticator may use secure hardware such as a Trusted Execution Environment (TEE) or a Secure Element (SE) to protect user verification material such as biometric templates and verification operations.
Performs cryptographic operations: Cryptographic operations cover generating cryptographic keys and signing of FIDO challenges. The authenticator must ensure that it signs the challenge only after the user is successfully verified. The authenticator may use secure hardware such as a TEE or SE to protect key storage and key operations.
An authenticator may sign some responses using an attestation key. This allows the FIDO server to verify that the response was generated by a genuine authenticator with a known set of security characteristics.
Some authenticators may be identified by a unique Authenticator Attestation ID (AAID or AAGUID). Authenticators might support one or more modalities, such as fingerprint, PIN, facial recognition, and so on. One Authenticator Attestation ID reflects a set of defined authenticator security characteristics (for example, key protected by hardware versus software).
Nok Nok offers the Nok Nok Authenticator SDK to device OEMs and third-party authenticator vendors to enable them to build FIDO-compliant authenticators.
FIDO External Authenticators
The S3 Suite supports all FIDO authenticators including external authenticators. These authenticators share similar characteristics with platform authenticators, such as performing cryptographic operations during registration and authentication and prompting the user to interact with the device. FIDO external authenticators are typically not bound to any multi-purpose computing device but can be connected to it via Bluetooth LE, NFC, or USB. During the authentication process, the user is prompted to interact with their authenticator, thereby detecting that a real person – and not malware – is attempting to authenticate. If the key confirms a specific user, this is called user verification, otherwise it performs a user presence check.
An external authenticator may also qualify as multi-factor if it requires user verification (such as a biometric scan or knowledge such as a PIN). Some older security keys detect user presence but do not actually verify the user. That is, these security keys do not verify user biometrics nor a PIN entry. These security keys may not meet the multi-factor requirements by themselves. Such authenticators may still be used in combination with a password or another authenticator that verifies the user, such as a password or a biometric.