A customer-facing ASM must operate properly and have the right level of security, as defined by the following requirements.
Operational Requirements
An ASM must meet the following operational criteria:
Less than 1 in 20 false negatives on first attempt
Less than 1 in 2000 two false negatives in a row
Less than 1 in 10K three false negatives in a row
Less than three false negatives for 1 in 10K users
% of false positives is less than 0.01%, so unauthorized access is almost impossible
The sample size for the above tests is large enough (> 10,000 tries)
False negative means “Failing to authenticate even with valid credentials”. False positive means “Successful authentication with invalid credentials”.
Integration Requirements
An authenticator implementation must use the API interfaces defined in the Digipass S3 Authenticator SDK.
Security Requirements
For software-based authenticators:
Use security libraries provided by Digipass S3
Use approved methods of protecting authentication template data:
Data is encrypted with operating system service, if available, such as CryptoAPI
Data is encrypted with a NIST-recommended encryption algorithm with an obfuscated key
For hardware-based authenticators:
Anti-hammering in hardware
Approved methods of protecting keys:
Stored in hardware (required)
Protected by hardware (if possible)
Uses elliptic curve (if possible), otherwise uses RSA
Approved methods of protecting authentication template data:
Stored in hardware (required)
Protected by hardware (if possible)