|
Mobile Authentication - Overview
Mobile users have moved from talking, texting and browsing to conducting personal and corporate business with their smart phones. In this environment, authentication is the key to verifying and protecting the identity of the mobile user. Likewise, the mobile device can be used to authenticate a user when accessing personal or corporate information remotely.
Mobile Authentication Options
1) Mobile Phone as an Authentication Factor
In this case the phone is used as an authentication device when shopping online, logging into an account, or accessing a Web portal or VPN from your computer. Typically, the application that you are trying to access sends an OTP to your phone via SMS or email, or calls you and speaks the password through IVR technology. You then enter the password into the prompt and authenticate to the application.
2) Web Transactions and Account Access Directly from the Phone
Increasingly people are using their phones in place of their computers to shop online or access accounts through the Internet. In this environment, people use their phone as both the device to access the application AND to authenticate the user. Typically, simple passwords are used in this case. However, better authentication methods are required.
Arcot Provides Multiple Mobile Authentication Solutions
Arcot mobile authentication solutions address both cases. We offer multiple authentication choices on mobile devices.
Standard OTP via SMS/email
The Arcot Authentication Server can generate and send an OTP to the phone via SMS or email.
ArcotOTP Secure Password Generator
Arcot can generate the OTP directly on the phone so the user doesn't have to depend on the message delivery mechanism to authenticate. ArcotOTP is an application that runs on mobile devices and generates an OTP. When the user is asked to authenticate to an application or provide a dynamic passcode to shop online, they run the ArcotOTP app on their phone, enter their PIN and an OTP is displayed on the phone. They then enter the OTP into the application prompt. ArcotOTP supports both EMV and HOTP authentication standards.

Larger Image
ArcotID Secure Software Credential
This PKI-based, two-factor credential is placed directly and transparently on the phone. When prompted by the application, the user simply enters their password. Behind the scenes, the password interacts with the ArcotID and sends a response to the application that identifies the user and allows access.
|