Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Terminology

Prev Next

The following technical terms describe information used in Digipass S3 documentation.

Term

Description

AAGUID

Authenticator Attestation GUID for FIDO2 authenticator metadata.

AAID

Authenticator Attestation ID for UAF authenticator metadata.

ACKI

Attestation Certificate public key identifier for U2F authenticator metadata.

Admin Console

Digipass S3 Server Administration Console. This is a web-based app that enables you to configure the authentication behavior that the Auth Server enforces.

API Server

Digipass S3 API Server. The Digipass S3 API Server handles all communication between the App SDK and the Auth Server. It functions as a gatekeeper for incoming requests and the amount of information that is returned from the Authentication Server to the App SDK.

The API Server can optionally

  • generate a transaction confirmation token

  • handle communication when your company server performs an external authentication method

  • package and return EMV 3DS Session data

  • trigger push notifications for OOB authentication

  • identify the client platform or browser for web apps

  • extract and send the IP address from the request header

  • enable FIDO2 and WebAuthn authentication where the username is known up front

App ID

The URL of a file containing your organization's list of trusted applications. Used for UAF configuration. The App ID is associated with the private and public keys created during the registration process. Changing an App ID invalidates existing registrations.

App SDK

Digipass S3 App SDK, that allows your mobile or web app to communicate with the FIDO components on the device such as the Client and ASMs.

<APP_SDK_HOME>

References the root path of the Digipass S3 Android or iOS App SDK installation. When using the Android App SDK, this references the AppSDK folder containing all Android Studio projects and javadocs. The zipped package you received from Digipass S3 Labs contains this folder, pre-built APK files, third-party software licenses, and strings for localization.

ASM

Authenticator Specific Module. Software associated with a FIDO Authenticator that provides a uniform interface between the hardware and FIDO Client software. The Digipass S3 App SDK includes several embedded FIDO ASMs for popular authenticators such as Touch ID/Face ID on iOS and fingerprint on Android devices.

<ASM_SDK_HOME>

The root path of the Digipass S3 Android or iOS Authenticator SDK installation, i.e. the asm_dev folder. In the Android Authenticator SDK, this references the ASMSDK folder containing all Android Studio projects and javadocs. The zipped package you received from Digipass S3 Labs contains this folder, pre-built APK files, third-party software licenses, and strings for localization.

Authentication method

General categories of authentication like FIDO, out-of-band (OOB), one-time password (OTP), External and Photo ID.

Authentication Server or Auth Server

Works with the Digipass S3 App SDK to deliver strong authentication using the existing security features of a user's device (such as a fingerprint sensor) instead of a password. The Authentication Server tailors the authentication methods required for end user verification by evaluating data provided by your app, a small set of user history, and criteria from your organization, which is stored in rulesets.

The Digipass S3 Server. Performs cryptographic verification during a FIDO Authentication. Supports FIDO authentication, FIDO OOB, Email OTP, SMS OTP, and Photo ID. Enforces your organization's criteria for which methods a user is allowed to register or authenticate with. The Auth Server is the brain behind Adaptive Registration and Adaptive Authentication because it executes Adaptive Rules against the information provided by client apps and the API Server as well as in its own database.

BLE

Bluetooth Low Energy. A low-power, wireless technology used to connect devices with each other.

Client

Digipass S3 App SDK

Client app or your app

An app that you develop that uses the Digipass S3 App SDK.

CTAP

Client-to-authenticator Protocol. A specification that describes how a client platform communicates with a roaming, cryptographic authenticator. Used by USB, NFC, Bluetooth, and other methods.

Device-bound passkey

A passkey that is strongly tied to a specific device or authenticator and cannot leave that boundary.

DPK

Device-bound Public Key. A key that is strongly bound to a device.

Enrollment

A process where a user sets up a biometric or other verification method that secures their mobile device against unauthorized use. This enables the user to unlock the device's screen lock. A user must be enrolled to use FIDO authentication.

Extension

A general-purpose structure specified by the FIDO standard for passing information between a FIDO Client and an authenticator. Can be used to specify filter criteria to control authenticator selection, override the default prompt, customize authenticator behavior, return error information, and so on. See FIDO UAF Protocol Specification for a definition of this structure.

External Authentication Method

An authentication method not currently supported by Digipass S3. When your app triggers an external authentication method, an external entity attempts the authentication and returns the result.

Facet ID

A unique identifier (URI) for a platform-specific implementation of your app (application used by your customers on their devices). For example, if you have a web-implementation and Android-implementation of your app, each of these must have a different facet ID.

Example facet IDs are shown below.

  • Android: android:apk-key-hash:SvYZ4Sgas9T2+6DpNj566iscuns

  • iOS: ios:bundle-id:com.noknok.ios.tutorialappplus

  • Web: https://example.com

FIDO

Fast IDentity Online. A set of specifications for simpler, stronger authentication that are embodied in the UAF and FIDO2 protocols. See fidoalliance.org.

FIDO Authenticator

A FIDO Authenticator is responsible for user verification and maintaining the cryptographic material required by FIDO authentication on behalf of the relying party authentication.

FIDO Authenticator Specific Module (ASM)

Software associated with a FIDO Authenticator that provides a uniform interface between the hardware and FIDO Client software. The Digipass S3 App SDK includes several embedded FIDO ASMs for popular authenticators such as Touch ID/Face ID on iOS and fingerprint on Android devices.

FIDO Client

A FIDO Client is software responsible for processing FIDO messages, and coordinating between an application and FIDO authenticators. The Digipass S3 App SDK includes an embedded FIDO Client. The App SDK can also use an external FIDO Client that may be preloaded on a device by the manufacturer.

FIDO Policy

Specifies the set of UAF and FIDO2 authenticators that are allowed to be registered by a user or used for authentication. FIDO policies enforce your organization's choice of valid authenticators.

FIDO Protocol or Protocol

A FIDO protocol, or protocol, is a set of specifications for simpler, stronger authentication, these include FIDO UAF and FIDO2. See https://fidoalliance.org/specifications/. Within the Digipass S3 documentation, these are referred to collectively as FIDO.

Digipass S3 supports the protocol specifications published by the FIDO Alliance.

  • UAF provides strong authentication backed by biometrics.

  • FIDO2 supports registration and authentication with web and mobile apps that implement the Web Authentication API as defined by the W3C.

GUI

Graphical User Interface typically containing a desktop and browser.

Inline Registration

When inline registration is enabled, if the end user signs in with a username and password and they have no strong authentication method already registered, then the sign-in page immediately prompts the end user to register a strong authentication method as their second-factor authenticator. Examples of strong authentication methods include FIDO or an adaptive authentication option like Email OTP or SMS OTP. Supported for the Digipass S3 PingFederate Adapter.

<JAVA_HOME>

The full path to the JDK install directory.

JWK

JSON Web Key. A JSON that represents a cryptographic key. Used by the API Server along with an algorithm to sign or encrypt a JWT.

JWS

JSON Web Signature (JWS) is information that is secured with a digital signature. See RFC 7515.

JWT

JSON Web Token. Digipass S3 Software uses JWT as a compact and self-contained way for securely transmitting information between your app, your app backend, and the Digipass S3 Server. This information can be verified and trusted because it is digitally signed.

To understand how Digipass S3 Software uses JWTs as session tokens and how to configure them, see Understanding the API Server's Session Token and Configuring JWT Generation and Validation, respectively.

<MFAS_HOME>

The path to the mfas directory that is created when you extract the server tgz package

NNL

Digipass S3 Labs

<NNL_HOME>

The full path of the Digipass S3 Server installation, for example: /opt/mfas

OOB

Out-of-band authentication. If your web app is running on a computer that doesn't support biometric authentication, you can use a mobile phone to complete registration or authentication. OOB is a proprietary feature developed by Digipass S3 on top of the FIDO protocol.

OTP

One-time passcode. An authentication method that sends the user a passcode, typically through phone or email. The user must enter that passcode into the app or web page to verify their identity. The passcode is only valid for one login session, or transaction

Passkey

A FIDO credential that can be used for passwordless authentication. There are synced passkeys and device-bound passkeys.

Relying Party (RP)

The organization responsible for registering and authenticating customers. Typically, the relying party has implemented one or more web or mobile apps for their customers to use. This is your organization.

RP ID

The domain for your organization, like example.com. Used for FIDO2 configuration. The RP ID is associated with the private and public keys created during the registration process. Changing an RP ID invalidates existing registrations.

Server

Digipass S3 Server

Session key

A subfield of the SessionData object that holds the session token for an authenticated end user. This JWT can be sent from the client to the server for operations that require a session. The session key is also sent from the server to the client after a successful authentication.

SMS

Short messaging service. A text messaging service component.

SPC

Secure Payment Confirmation. A WebAuthn API that provides evidence that the user has seen and approved important transaction details.

Synced passkey

A passkey that can be backed up and restored to a different device.

Tenant

A logical grouping of your users and their data within the same Server. Your Digipass S3 deployment supports multi-tenancy and allows tenant-specific configuration. For example, a company with two subsidiaries may want to keep the two user groups, as well as adaptive rules and FIDO policies, entirely separate. This can be done by creating two different tenants.

TLS Certificate

A digital certificate used to secure communications and control access to a server by enabling encrypted connections and verifying the server’s identity.

<TOMCAT_HOME>

The full path of the Tomcat installation used when installing the Digipass S3 Server.

User Verification Index (UVI)

An extension to UAF which allows the Server to determine which finger was matched during registration and authentication. Using UVI, the Server can limit authentication to a specific biometric template, sets of biometric templates, or any biometric template enrolled on the device.

User verification method

How the user is verified by an authenticator like biometric, PIN, password, presence (yes/no), and silent. See the FIDO Alliance Registry of Predefined Values for a complete list.

WebAuthn

The Web Authentication API is a specification written by the W3C and FIDO that allows servers to register and authenticate users using public key cryptography instead of a password.

Web origin or origin

The source of a request. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The default port for the HTTPS scheme is 443.