Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Requirements for an ASM

Prev Next

A customer-facing ASM must operate properly and have the right level of security, as defined by the following requirements.

Operational Requirements

An ASM must meet the following operational criteria:

  • Less than 1 in 20 false negatives on first attempt

  • Less than 1 in 2000 two false negatives in a row

  • Less than 1 in 10K three false negatives in a row

  • Less than three false negatives for 1 in 10K users

  • % of false positives is less than 0.01%, so unauthorized access is almost impossible

  • The sample size for the above tests is large enough (> 10,000 tries)

False negative means “Failing to authenticate even with valid credentials”. False positive means “Successful authentication with invalid credentials”.

Integration Requirements

An authenticator implementation must use the API interfaces defined in the Digipass S3 Authenticator SDK.

Security Requirements

  • For software-based authenticators:

    • Use security libraries provided by Digipass S3

    • Use approved methods of protecting authentication template data:

      • Data is encrypted with operating system service, if available, such as CryptoAPI

      • Data is encrypted with a NIST-recommended encryption algorithm with an obfuscated key

  • For hardware-based authenticators:

    • Anti-hammering in hardware

    • Approved methods of protecting keys:

      • Stored in hardware (required)

      • Protected by hardware (if possible)

      • Uses elliptic curve (if possible), otherwise uses RSA

    • Approved methods of protecting authentication template data:

      • Stored in hardware (required)

      • Protected by hardware (if possible)