The following technical terms describe information used in Digipass S3 documentation.
Term | Description |
|---|---|
AAGUID | Authenticator Attestation GUID for FIDO2 authenticator metadata. |
AAID | Authenticator Attestation ID for UAF authenticator metadata. |
ACKI | Attestation Certificate public key identifier for U2F authenticator metadata. |
Admin Console | Digipass S3 Server Administration Console. This is a web-based app that enables you to configure the authentication behavior that the Auth Server enforces. |
API Server | Digipass S3 API Server. The Digipass S3 API Server handles all communication between the App SDK and the Auth Server. It functions as a gatekeeper for incoming requests and the amount of information that is returned from the Authentication Server to the App SDK. The API Server can optionally
|
App ID | The URL of a file containing your organization's list of trusted applications. Used for UAF configuration. The App ID is associated with the private and public keys created during the registration process. Changing an App ID invalidates existing registrations. |
App SDK | Digipass S3 App SDK, that allows your mobile or web app to communicate with the FIDO components on the device such as the Client and ASMs. |
<APP_SDK_HOME> | References the root path of the Digipass S3 Android or iOS App SDK installation. When using the Android App SDK, this references the AppSDK folder containing all Android Studio projects and javadocs. The zipped package you received from Digipass S3 Labs contains this folder, pre-built APK files, third-party software licenses, and strings for localization. |
ASM | Authenticator Specific Module. Software associated with a FIDO Authenticator that provides a uniform interface between the hardware and FIDO Client software. The Digipass S3 App SDK includes several embedded FIDO ASMs for popular authenticators such as Touch ID/Face ID on iOS and fingerprint on Android devices. |
<ASM_SDK_HOME> | The root path of the Digipass S3 Android or iOS Authenticator SDK installation, i.e. the asm_dev folder. In the Android Authenticator SDK, this references the ASMSDK folder containing all Android Studio projects and javadocs. The zipped package you received from Digipass S3 Labs contains this folder, pre-built APK files, third-party software licenses, and strings for localization. |
Authentication method | General categories of authentication like FIDO, out-of-band (OOB), one-time password (OTP), External and Photo ID. |
Authentication Server or Auth Server | Works with the Digipass S3 App SDK to deliver strong authentication using the existing security features of a user's device (such as a fingerprint sensor) instead of a password. The Authentication Server tailors the authentication methods required for end user verification by evaluating data provided by your app, a small set of user history, and criteria from your organization, which is stored in rulesets. The Digipass S3 Server. Performs cryptographic verification during a FIDO Authentication. Supports FIDO authentication, FIDO OOB, Email OTP, SMS OTP, and Photo ID. Enforces your organization's criteria for which methods a user is allowed to register or authenticate with. The Auth Server is the brain behind Adaptive Registration and Adaptive Authentication because it executes Adaptive Rules against the information provided by client apps and the API Server as well as in its own database. |
BLE | Bluetooth Low Energy. A low-power, wireless technology used to connect devices with each other. |
Client | Digipass S3 App SDK |
Client app or your app | An app that you develop that uses the Digipass S3 App SDK. |
CTAP | Client-to-authenticator Protocol. A specification that describes how a client platform communicates with a roaming, cryptographic authenticator. Used by USB, NFC, Bluetooth, and other methods. |
Device-bound passkey | A passkey that is strongly tied to a specific device or authenticator and cannot leave that boundary. |
DPK | Device-bound Public Key. A key that is strongly bound to a device. |
Enrollment | A process where a user sets up a biometric or other verification method that secures their mobile device against unauthorized use. This enables the user to unlock the device's screen lock. A user must be enrolled to use FIDO authentication. |
Extension | A general-purpose structure specified by the FIDO standard for passing information between a FIDO Client and an authenticator. Can be used to specify filter criteria to control authenticator selection, override the default prompt, customize authenticator behavior, return error information, and so on. See FIDO UAF Protocol Specification for a definition of this structure. |
External Authentication Method | An authentication method not currently supported by Digipass S3. When your app triggers an external authentication method, an external entity attempts the authentication and returns the result. |
Facet ID | A unique identifier (URI) for a platform-specific implementation of your app (application used by your customers on their devices). For example, if you have a web-implementation and Android-implementation of your app, each of these must have a different facet ID. Example facet IDs are shown below.
|
FIDO | Fast IDentity Online. A set of specifications for simpler, stronger authentication that are embodied in the UAF and FIDO2 protocols. See fidoalliance.org. |
FIDO Authenticator | A FIDO Authenticator is responsible for user verification and maintaining the cryptographic material required by FIDO authentication on behalf of the relying party authentication. |
FIDO Authenticator Specific Module (ASM) | Software associated with a FIDO Authenticator that provides a uniform interface between the hardware and FIDO Client software. The Digipass S3 App SDK includes several embedded FIDO ASMs for popular authenticators such as Touch ID/Face ID on iOS and fingerprint on Android devices. |
FIDO Client | A FIDO Client is software responsible for processing FIDO messages, and coordinating between an application and FIDO authenticators. The Digipass S3 App SDK includes an embedded FIDO Client. The App SDK can also use an external FIDO Client that may be preloaded on a device by the manufacturer. |
FIDO Policy | Specifies the set of UAF and FIDO2 authenticators that are allowed to be registered by a user or used for authentication. FIDO policies enforce your organization's choice of valid authenticators. |
FIDO Protocol or Protocol | A FIDO protocol, or protocol, is a set of specifications for simpler, stronger authentication, these include FIDO UAF and FIDO2. See https://fidoalliance.org/specifications/. Within the Digipass S3 documentation, these are referred to collectively as FIDO. Digipass S3 supports the protocol specifications published by the FIDO Alliance.
|
GUI | Graphical User Interface typically containing a desktop and browser. |
Inline Registration | When inline registration is enabled, if the end user signs in with a username and password and they have no strong authentication method already registered, then the sign-in page immediately prompts the end user to register a strong authentication method as their second-factor authenticator. Examples of strong authentication methods include FIDO or an adaptive authentication option like Email OTP or SMS OTP. Supported for the Digipass S3 PingFederate Adapter. |
<JAVA_HOME> | The full path to the JDK install directory. |
JWK | JSON Web Key. A JSON that represents a cryptographic key. Used by the API Server along with an algorithm to sign or encrypt a JWT. |
JWS | JSON Web Signature (JWS) is information that is secured with a digital signature. See RFC 7515. |
JWT | JSON Web Token. Digipass S3 Software uses JWT as a compact and self-contained way for securely transmitting information between your app, your app backend, and the Digipass S3 Server. This information can be verified and trusted because it is digitally signed. To understand how Digipass S3 Software uses JWTs as session tokens and how to configure them, see Understanding the API Server's Session Token and Configuring JWT Generation and Validation, respectively. |
<MFAS_HOME> | The path to the mfas directory that is created when you extract the server tgz package |
NNL | Digipass S3 Labs |
<NNL_HOME> | The full path of the Digipass S3 Server installation, for example: /opt/mfas |
OOB | Out-of-band authentication. If your web app is running on a computer that doesn't support biometric authentication, you can use a mobile phone to complete registration or authentication. OOB is a proprietary feature developed by Digipass S3 on top of the FIDO protocol. |
OTP | One-time passcode. An authentication method that sends the user a passcode, typically through phone or email. The user must enter that passcode into the app or web page to verify their identity. The passcode is only valid for one login session, or transaction |
Passkey | A FIDO credential that can be used for passwordless authentication. There are synced passkeys and device-bound passkeys. |
Relying Party (RP) | The organization responsible for registering and authenticating customers. Typically, the relying party has implemented one or more web or mobile apps for their customers to use. This is your organization. |
RP ID | The domain for your organization, like example.com. Used for FIDO2 configuration. The RP ID is associated with the private and public keys created during the registration process. Changing an RP ID invalidates existing registrations. |
Server | Digipass S3 Server |
Session key | A subfield of the SessionData object that holds the session token for an authenticated end user. This JWT can be sent from the client to the server for operations that require a session. The session key is also sent from the server to the client after a successful authentication. |
SMS | Short messaging service. A text messaging service component. |
SPC | Secure Payment Confirmation. A WebAuthn API that provides evidence that the user has seen and approved important transaction details. |
Synced passkey | A passkey that can be backed up and restored to a different device. |
Tenant | A logical grouping of your users and their data within the same Server. Your Digipass S3 deployment supports multi-tenancy and allows tenant-specific configuration. For example, a company with two subsidiaries may want to keep the two user groups, as well as adaptive rules and FIDO policies, entirely separate. This can be done by creating two different tenants. |
TLS Certificate | A digital certificate used to secure communications and control access to a server by enabling encrypted connections and verifying the server’s identity. |
<TOMCAT_HOME> | The full path of the Tomcat installation used when installing the Digipass S3 Server. |
User Verification Index (UVI) | An extension to UAF which allows the Server to determine which finger was matched during registration and authentication. Using UVI, the Server can limit authentication to a specific biometric template, sets of biometric templates, or any biometric template enrolled on the device. |
User verification method | How the user is verified by an authenticator like biometric, PIN, password, presence (yes/no), and silent. See the FIDO Alliance Registry of Predefined Values for a complete list. |
WebAuthn | The Web Authentication API is a specification written by the W3C and FIDO that allows servers to register and authenticate users using public key cryptography instead of a password. |
Web origin or origin | The source of a request. A web origin is defined by the scheme (protocol), host (domain), and port of the URL used to access it. The default port for the HTTPS scheme is 443. |