Introduction
Nok Nok, now part of OneSpan, is excited to introduce the latest business-critical enhancements in the S3 Authentication Suite - Version 9.4. OneSpan continues to advance interoperability, ensuring compatibility with the latest smartphones, operating systems, web browsers, and databases. In addition, all user interface elements of the Admin Console and the example UIs in our App SDKs are fully accessible to the visually impaired.
The S3 Suite includes our documentation inside the OneSpan Documentation Portal. This knowledge base organizes the documentation in a logical hierarchy and features advanced search capabilities. When searching the knowledge base, always prefix your query with “S3 Suite.”
New App SDK features and enhancements
Modern threading: The Android and iOS App SDKs now include non-blocking APIs to support modern threading. These enhancements improve your application’s responsiveness and enable a smoother experience for your end users.
Passkey account creation: The iOS App SDK implements the Apple Passkey Account Creation API in its sign-up flow. This allows the end user to create an account and register a passkey in one step.
Multi-version app configuration: The web page that you use to configure the tutorial app supports multiple versions of the App SDK.
Quick authentication: The WebAuthn Conditional UI works with Quick Authentication. This is implemented in a way that helps protect against denial-of-service attacks.
Liquid Glass UI : The iOS App SDK supports Apple's Liquid Glass UI.
App IQ: The logs generated by Nok Nok's App IQ error reporting service contain the username field in the data record.
Automatic deletion of deregistered credentials: Supported for UAF credentials in previous releases, the opportunistic deletion of all WebAuthn credentials is implemented in the current release of the iOS and Web App SDKs. When a FIDO2 platform authenticator or a UAF authenticator is deregistered, the App SDK tries to delete the corresponding credential from the end user's device on supported platforms and browsers.
New server features and enhancements
API Server plugins can have multiple configuration parameters: Your custom API Server Plugin can now have multiple configuration parameters, making configuration more convenient and flexible. For example, your custom plugin can have one configuration parameter that defines custom settings, and another configuration parameter that defines JWT generation options. Before, custom plugins only supported a single configuration parameter.
Enable Inline Registration support for non-FIDO authentication methods: When inline registration is enabled and the end user only has a password, the system automatically prompts the end user to register a second-factor authentication method. Inline registration supported only FIDO authentication methods in v9.3.
Preregister OneSpan Digipass security keys: You can purchase Digipass security keys from OneSpan and request that they be pre-provisioned for the end users of the S3 Authentication Server. After you import these credentials, your end users can sign in immediately, skipping the registration process.
Support for related origins: A list of related origins can be configured for a single RP ID. As a result, end users can use a single credential for all of your organization's origins.
Specify public key credential hints: You can specify the order that the server presents registrations to the end user’s FIDO2 platform during authentication, streamlining the user experience by presenting your preferred options first. A FIDO policy allows you to order the presentation of current device, security key, and passkey on second device.
Register a passkey with no user interaction: The ability for the App SDKs to silently register a new FIDO2 passkey was implemented in v9.3. Support for the silent registration of a UAF passkey is added in v9.4. These features allow end users to create a passkey and sign in in one step. Since these capabilities can be enabled from the server, the application need not be modified.
Enable "Conditional-create" from the server: The ability for the App SDKs to silently register a new passkey was implemented in v9.3. This allows end users to sign up and create a passkey in one step. In v9.4 this feature can be enabled or disabled from the server without modifying the application code.
More details about authenticator strength: Receive more detailed metadata from the Server after a successful registration or authentication. Additional information about authenticator security characteristics allows the customer to categorize the security strength of the authenticator.
Add a dynamic claim to an adaptive authentication rule. Previously you could add a static claim with a hardcoded value to the JWT that results from an authentication. Now you can also add a dynamic claim whose value is determined at runtime. For example, you can easily convey to your application server whether the end user authenticated with a password, an OTP, or a passkey.
Additional administration capability: An Admin user can add another Admin user to a different tenant, provided they have user management permissions in both tenants. Previously only Super Admins could add an Admin user to a tenant.
For more information on this release and for evaluations, please contact Nok Nok support.