SlideShare ist ein Scribd-Unternehmen logo
1 von 4
Downloaden Sie, um offline zu lesen
Portable Authentication
      - The concept



Online shopping
 Internet banking
   Online gaming
    Mobile banking
      Online betting
        Enterprise access
- Fight fraud and phishing!
  Todos has developed security solutions based on smart cards
since 1990. Throughout the years, Todos has built up an
extensive in-house expertise in designing cost efficient
identification solutions for the mass market, with focus on
the product, its personalisation, distribution and support.

  Todos eCode is a product portfolio for secure
remote authentication using One Time Passwords
(OTP), Challenge/Response and Electronic Signatures.
The OTPs can be generated by a reader and a smart
card, tokens, printed cards or mobile phones.
                                                                                           Reader and
                                                                                           smart card
  Todos eCode is a cost efficient, portable and
secure authentication solution for e-Banking,
e-Commerce, Online Shopping with 3-D Secure,
Mobile Banking and Enterprise access. Todos eCode
is platform and channel independent, providing
the possibility to simultaneously authenticate users
via Internet, PSTN, mobile network and VPN.

  The end user devices in the eCode solution
are all easy to learn and easy to use. Also, it is easy
to manage for the bank as the devices require no
personalisation. Thus, they are easy and cheap to
distribute and have minimal need for support.

 The Todos eCode solution can be introduced                                           Mobile
gradually, with different security levels, to suit the                                                                            Token
                                                                                                                  Printed OTP
development pace of remote services in the bank.



                                      - Central System
  Todos eCode Central System is the heart of the Todos eCode authentication solution and can operate
in both a Single Issuer and Multi Issuer configuration. Each Issuer is unique and has its own requirements on
authentication method, security, reliability, availability, capacity and integration to its legacy systems. The modularity
and flexibility of the eCode Central System enables it to be fully customized to meet customer requirements.                                VISA
                                                                                                                                   dynamic passcode
                                                                                                                                      authentication
  Todos eCode authentication follows the principle of two factor authentication. Based on something
you know (i.e. a PIN or a Static Password), combined with something you have (e.g. a smart card), a One
Time Password (OTP), a Signature or a Response in a Challenge/Response mechanism is generated.                                     3-D Secure

 Todos eCode supports different carriers, and a variety of medias:
                                                                 • Smart card- or SIM-based:                                              FISC II
                                                                         - One Time Passwords (with or without PIN)                        OTP
                                                                         - Challenge/Response and Signatures
                                                                 • Printed One Time Passwords
                                                                 • Token One Time Passwords                                               Sm@rt
                                                                 • SMS sent One Time Passwords                                              TAN
                                                                 • Java MIDP based:
                                                                         - One Time Passwords (with or without PIN)
                                                                         - Challenge/Response and Signatures                              APACS

                                                                      Todos eCode Central System
                                                                     includes several different functions:                                   SiBS
                                                                 •   Authentication
                                                                 •   Personalisation data generation
                                                                 •   Key management                                                    Interpay
                                                                 •   Customer Support Application
                                                                 •   Static password verification
                                                                 •   Personalisation of tokens and smart cards                     Banksys' R4
                                                                 •   Radius support                                             Authentication
 Todos eCode Central System also supports the latest industrial standards, including 3-D Secure CAP,
MasterCard SecureCode, VISA dynamic passcode authentication, APACS, Interpay, SiBS, Sm@rt TAN, FISC II OTP and
Banksys' R4 Authentication.
Reader and smart card
             In an eCode solution for smart card based One Time                      Signatures. The eCode readers may also display balance and
            Password (OTP), the OTPs, Signatures and Responses are                   transactions of e-purse, loyalty cards and other applications.
            generated in the smart card at the moment of authentication              The readers do not require any personalisation, as the
            and displayed to the user in a portable smart card reader.               security lies in the smart card and the security application.
                                                                                     The user has one (or more) standardised readers, thus
              There are several models of smart card readers available,              reader distribution becomes easier and cheaper.
            with different levels of functionality: Todos eCode Reader,
            Todos eCode Signature, Todos eCode Authenticator and                      The connectable Authenticator combines the portability
            Todos eCode connectable Authenticator. Todos eCode                       and user friendliness of an unconnected reader with PKI
            Signature, Authenticator and connectable Authenticator                   qualified signatures when connected to a PC via USB.
            have small keyboards for PIN entry, Challenge/Response and


   Printed OTP                                                                                                                    OTP Token
    The OTPs are generated                                                                                                        In an eCode solution for
  centrally, then securely transferred                                                                                          Token based OTPs, the OTP is
  to a personalisation bureau                                                                                                   generated inside the token at
  which prints the OTPs onto                                               Reader and                                           the moment of authentication
  a card or a PIN envelope.                                                smart card                                           and displayed to the user
                                                                                                                                on the token display.
    To protect from shoulder                          Printed
  surfing, an aluminium foil                           OTP                                                                       The user interface of Todos
  scratch layer protects the not                                                                                                eCode ezToken consists of a
  yet used OTPs. Combined with                                                                                                  display and one single button.
  a static password you achieve                                                                                                 With a press on the button an
  a two-factor authentication.
                                                                                                              OTP               OTP is generated. Combined
                                                                                                             Token              with a static password, this
   Benefits with Printed OTP:                                                                                                   provides a strong two-factor
     • Low initial cost.                                               Central System                                           authentication.
     • Easy to deploy, learn and use.
     • Portability: always                                                                                                        Data for Todos eCode
       in your wallet.                                                                                                          ezToken personalisation
     • Easy to distribute using
                                                        Mobile                                                                  is generated by the Todos
       postal services.                              - SIM, MIDP                                                                eCode Central System.
                                                                   Java
                                                                   J2ME
   Printed OTP is a good intermediate                                                   Mobile                                     OTP Token is a good
  solution if EMV cards have not yet                                                                                            intermediate solution
                                                                                        - SMS
  been rolled out.                                                                                                              if EMV cards have not
                                                                                                                                yet been rolled out.

              Mobile - SIM and MIDP
               By placing the security application on the SIM                         Mobile - SMS
             you can use a standard mobile phone for all your                          In an eCode solution for OTP sent by SMS, the OTP is generated
             bank errands. It is also possible to download a                         in the eCode Central System upon a request from the user, sent
             Java application directly to your handset.                              by SMS to a predefined mobile card and displayed to the user.

               The mobile handset is a device most people carry with them               The eCode Central System has the central
             all the time and care about. With Todos eCode Mobile SIM or             functions for generating the OTP and sending
             MIDP inside, the authentication device is always close at hand.         it, in addition to the verification.

              Todos eCode Mobile supports multiple banks and service                   The mobile handset is a device most people carry with
             providers on the same SIM card. Each bank/service provider can          them all the time and care about. With Todos eCode Mobile
             control their own personalised information independently.               SMS, the authentication device is always close at hand.




   Example of dynamic
  authentication solution:
                                                                Todos eCode Mobile

                                                                                                    Todos eCode Authenticator

                         Todos eCode ezToken
                        Todos eCode Central System


     Starting off with                     Introducing eCode Mobile              EMV card rollout                     Phase out tokens                    Bank
Central System and tokens                   New customer segment          Introducing smart card readers                                              development
Case studies



 23 individual banks using Todos                                            Developing next generation eBanking terminal
eCode in a Multi Issuer setup
                                                                             ABN AMRO is a prominent international bank, with European
                                       SpareBank 1 Alliance                roots dating back to 1824. ABN AMRO ranks eighth in Europe
                                      is a Nordic bank and product         and 15th in the world based on tier 1 capital. In 2003, ABN AMRO
                                       collaboration where the             began an evaluation process for a new generation eBanking
                                       SpareBank 1 banks in                terminals, a project called TRaP (Token Replacement Project).
                                       Norway collaborate through
                                    the jointly owned group                 ABN AMRO's main selection criteria were:
                      SpareBank 1 Gruppen AS. SpareBank 1                     • A secure end user device that implements "Sign what you
       Gruppen AS was established in 1996, and is one of the                    see" functionality for both unconnected and connected use.
       largest providers of financial services in the Norwegian               • A device that will be used as the
      market. The Alliance consists of 23 individual savings banks              security device over the next 5-10          "Sign what
    and the product companies of SpareBank 1 Gruppen AS.                        years, and must offer long-term               you see"
                                                                                support for the ABN AMRO card              functionality
  SpareBank 1 Gruppen AS is using the Todos eCode solution                      products today and tomorrow.
in a Multi Issuer setup, where all SpareBank 1 banks are using the            • A supplier with cutting edge technology and know-how,
same eCode Central System, but each individual savings bank has                 being able to turn customer's business and product
its own operational keys and eCode database.                                    requirements into a solution that meets customer demands
                                                                                in the areas of security, smart cards and quality.
                                                                              • A device that has ABN AMRO look and feel.
  The Todos eCode authentication solution in this                             • Pricing.
case represents the authentication of end users to their
own certificates in a net centric key store system, in
which the private keys are securely hosted in a central                      After a thorough evaluation of the alternatives, ABN
server. This is part of the national ID scheme BankID.                     AMRO (BUNL) selected Todos for the development of their
                                                                           new secure end user device "e.dentifier2". A final contract was
                                                                           signed on August 24, 2005, comprising the development of
  Says Eldar Skjetne, Director payment services,
                                                                           the reader and rollout of more than 2.5 million readers.
SpareBank 1 Gruppen AS: “We think that we have together with
Todos Data System AB found a solution which is easy to use for the
customers. With the security application hosted in the smart card,
the customer can easily see the connection between traditional
payments with his/her Visa card, and the use of the same card for            For further information regarding the different parts of
authentication on the Internet. Customers who wish to have more            the Todos eCode portfolio please see respective product brochure
than one eCode Reader will be able to buy the additional number            or contact the Todos sales team. All brochures are available for
of readers they like from the bank.”                                       download at www.todos.se.




                                                          TODOS DATA SYSTEM AB
                                   7331887 ----- 061024
                                                          www.todos.se   sales@todos.se         Todos Data System reserves the right to change the specifications at any time and without notice.
                                                                                                All trademarks or trade names are the property of their respective owners.

Weitere ähnliche Inhalte

Was ist angesagt?

Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...OKsystem
 
The Belgian E Id Hacker Vs Developer
The Belgian E Id Hacker Vs DeveloperThe Belgian E Id Hacker Vs Developer
The Belgian E Id Hacker Vs Developerbeires
 
Cryptomach_En
Cryptomach_EnCryptomach_En
Cryptomach_Ende77
 
Government Citizen ID using Java Card Platform
Government Citizen ID using Java Card PlatformGovernment Citizen ID using Java Card Platform
Government Citizen ID using Java Card PlatformRamesh Nagappan
 
Vanderhoof smartcard-roadmap
Vanderhoof smartcard-roadmapVanderhoof smartcard-roadmap
Vanderhoof smartcard-roadmapHai Nguyen
 
company product
company productcompany product
company productzishan
 
Smart Cards & Devices Forum 2012 - European mobile NFC update
Smart Cards & Devices Forum 2012 - European mobile NFC updateSmart Cards & Devices Forum 2012 - European mobile NFC update
Smart Cards & Devices Forum 2012 - European mobile NFC updateOKsystem
 
Security applications with Java Card
Security applications with Java CardSecurity applications with Java Card
Security applications with Java CardJulien SIMON
 
SMARTGUARD SYSTEMS
SMARTGUARD SYSTEMSSMARTGUARD SYSTEMS
SMARTGUARD SYSTEMSGPARWANI
 
Softpro e signing solutions for front office, mobile on-boarding & web portal
Softpro e signing solutions for front office, mobile on-boarding & web portalSoftpro e signing solutions for front office, mobile on-boarding & web portal
Softpro e signing solutions for front office, mobile on-boarding & web portalYoucef Hamadache
 
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlManaging PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlRamesh Nagappan
 
Cidway Byod Authentication
Cidway Byod AuthenticationCidway Byod Authentication
Cidway Byod Authenticationlfilliat
 

Was ist angesagt? (18)

Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
 
The Belgian E Id Hacker Vs Developer
The Belgian E Id Hacker Vs DeveloperThe Belgian E Id Hacker Vs Developer
The Belgian E Id Hacker Vs Developer
 
2D barcode publishing a guide to best practices
2D barcode publishing a guide to best practices2D barcode publishing a guide to best practices
2D barcode publishing a guide to best practices
 
Cryptomach_En
Cryptomach_EnCryptomach_En
Cryptomach_En
 
Siast212 phphi
Siast212 phphiSiast212 phphi
Siast212 phphi
 
Government Citizen ID using Java Card Platform
Government Citizen ID using Java Card PlatformGovernment Citizen ID using Java Card Platform
Government Citizen ID using Java Card Platform
 
Rklb57 rwklb575 ds_en
Rklb57 rwklb575 ds_enRklb57 rwklb575 ds_en
Rklb57 rwklb575 ds_en
 
Vanderhoof smartcard-roadmap
Vanderhoof smartcard-roadmapVanderhoof smartcard-roadmap
Vanderhoof smartcard-roadmap
 
company product
company productcompany product
company product
 
Smart Cards & Devices Forum 2012 - European mobile NFC update
Smart Cards & Devices Forum 2012 - European mobile NFC updateSmart Cards & Devices Forum 2012 - European mobile NFC update
Smart Cards & Devices Forum 2012 - European mobile NFC update
 
Security applications with Java Card
Security applications with Java CardSecurity applications with Java Card
Security applications with Java Card
 
SMARTGUARD SYSTEMS
SMARTGUARD SYSTEMSSMARTGUARD SYSTEMS
SMARTGUARD SYSTEMS
 
Softpro e signing solutions for front office, mobile on-boarding & web portal
Softpro e signing solutions for front office, mobile on-boarding & web portalSoftpro e signing solutions for front office, mobile on-boarding & web portal
Softpro e signing solutions for front office, mobile on-boarding & web portal
 
Smart Card Security
Smart Card SecuritySmart Card Security
Smart Card Security
 
Sploitego
SploitegoSploitego
Sploitego
 
CCTV Catalogue
CCTV CatalogueCCTV Catalogue
CCTV Catalogue
 
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlManaging PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
 
Cidway Byod Authentication
Cidway Byod AuthenticationCidway Byod Authentication
Cidway Byod Authentication
 

Ähnlich wie OTP Solution - Mat khau su dung mot lan

Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12lfilliat
 
Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12lfilliat
 
Authentication.Next
Authentication.NextAuthentication.Next
Authentication.NextMark Diodati
 
Smart Card EMV for Dummies
Smart Card EMV for DummiesSmart Card EMV for Dummies
Smart Card EMV for DummiesSilly Beez
 
Smartcards and Authentication Tokens
Smartcards and Authentication TokensSmartcards and Authentication Tokens
Smartcards and Authentication Tokenssaniacorreya
 
Data Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information PresentationData Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information PresentationData Securities
 
Data Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information PresentationData Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information Presentationguestf018d88
 
Signify Passcode On Demand
Signify Passcode On DemandSignify Passcode On Demand
Signify Passcode On Demandkate_holden
 
Signify Passcode On Demand
Signify Passcode On DemandSignify Passcode On Demand
Signify Passcode On Demandpjpallen
 
2FA OTP Token
2FA OTP Token2FA OTP Token
2FA OTP Token2FA, Inc.
 
Smart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud ComputingSmart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud ComputingOKsystem
 
Embedded System Security: Learning from Banking and Payment Industry
Embedded System Security: Learning from Banking and Payment IndustryEmbedded System Security: Learning from Banking and Payment Industry
Embedded System Security: Learning from Banking and Payment IndustryNarudom Roongsiriwong, CISSP
 
Flyer Letter Gen Vasco
Flyer   Letter Gen   VascoFlyer   Letter Gen   Vasco
Flyer Letter Gen VascoLeenVerleyen
 
Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdf
Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdfVerifiable Credentials_Kristina_Identiverse2022_vFIN.pdf
Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdfKristina Yasuda
 
Passwords and Fingerprints and Faces—Oh My! Comparing Old and New Authentication
Passwords and Fingerprints and Faces—Oh My! Comparing Old and New AuthenticationPasswords and Fingerprints and Faces—Oh My! Comparing Old and New Authentication
Passwords and Fingerprints and Faces—Oh My! Comparing Old and New AuthenticationPriyanka Aash
 
Futurex Slides at ACI Exchange 2013, Boston
Futurex Slides at ACI Exchange 2013, BostonFuturex Slides at ACI Exchange 2013, Boston
Futurex Slides at ACI Exchange 2013, BostonGreg Stone
 
Strong Authentication State of the Art 2012 / Sarajevo CSO
Strong Authentication State of the Art 2012 / Sarajevo CSOStrong Authentication State of the Art 2012 / Sarajevo CSO
Strong Authentication State of the Art 2012 / Sarajevo CSOSylvain Maret
 
HITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and Friends
HITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and FriendsHITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and Friends
HITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and FriendsMerchant Link
 
Understanding the Role of Hardware Data Encryption in EMV and P2PE
Understanding the Role of Hardware Data Encryption in EMV and P2PEUnderstanding the Role of Hardware Data Encryption in EMV and P2PE
Understanding the Role of Hardware Data Encryption in EMV and P2PEGreg Stone
 

Ähnlich wie OTP Solution - Mat khau su dung mot lan (20)

Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12
 
Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12
 
Authentication.Next
Authentication.NextAuthentication.Next
Authentication.Next
 
Wisekey italia presentation 2012
Wisekey italia presentation 2012Wisekey italia presentation 2012
Wisekey italia presentation 2012
 
Smart Card EMV for Dummies
Smart Card EMV for DummiesSmart Card EMV for Dummies
Smart Card EMV for Dummies
 
Smartcards and Authentication Tokens
Smartcards and Authentication TokensSmartcards and Authentication Tokens
Smartcards and Authentication Tokens
 
Data Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information PresentationData Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information Presentation
 
Data Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information PresentationData Securities Corporate Technology Information Presentation
Data Securities Corporate Technology Information Presentation
 
Signify Passcode On Demand
Signify Passcode On DemandSignify Passcode On Demand
Signify Passcode On Demand
 
Signify Passcode On Demand
Signify Passcode On DemandSignify Passcode On Demand
Signify Passcode On Demand
 
2FA OTP Token
2FA OTP Token2FA OTP Token
2FA OTP Token
 
Smart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud ComputingSmart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud Computing
 
Embedded System Security: Learning from Banking and Payment Industry
Embedded System Security: Learning from Banking and Payment IndustryEmbedded System Security: Learning from Banking and Payment Industry
Embedded System Security: Learning from Banking and Payment Industry
 
Flyer Letter Gen Vasco
Flyer   Letter Gen   VascoFlyer   Letter Gen   Vasco
Flyer Letter Gen Vasco
 
Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdf
Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdfVerifiable Credentials_Kristina_Identiverse2022_vFIN.pdf
Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdf
 
Passwords and Fingerprints and Faces—Oh My! Comparing Old and New Authentication
Passwords and Fingerprints and Faces—Oh My! Comparing Old and New AuthenticationPasswords and Fingerprints and Faces—Oh My! Comparing Old and New Authentication
Passwords and Fingerprints and Faces—Oh My! Comparing Old and New Authentication
 
Futurex Slides at ACI Exchange 2013, Boston
Futurex Slides at ACI Exchange 2013, BostonFuturex Slides at ACI Exchange 2013, Boston
Futurex Slides at ACI Exchange 2013, Boston
 
Strong Authentication State of the Art 2012 / Sarajevo CSO
Strong Authentication State of the Art 2012 / Sarajevo CSOStrong Authentication State of the Art 2012 / Sarajevo CSO
Strong Authentication State of the Art 2012 / Sarajevo CSO
 
HITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and Friends
HITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and FriendsHITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and Friends
HITEC 2012: Hard Codes to Crack: Tokenization, Encryption-at-Swipe and Friends
 
Understanding the Role of Hardware Data Encryption in EMV and P2PE
Understanding the Role of Hardware Data Encryption in EMV and P2PEUnderstanding the Role of Hardware Data Encryption in EMV and P2PE
Understanding the Role of Hardware Data Encryption in EMV and P2PE
 

Mehr von THANK Truong

Tele conference solution - Hoi nghi truyen hinh
Tele conference solution - Hoi nghi truyen hinhTele conference solution - Hoi nghi truyen hinh
Tele conference solution - Hoi nghi truyen hinhTHANK Truong
 
[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOU
[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOU[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOU
[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOUTHANK Truong
 
[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOU
[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOU[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOU
[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOUTHANK Truong
 
Card issuance solution - Giai phap phat hanh the tai chinh
Card issuance solution - Giai phap phat hanh the tai chinhCard issuance solution - Giai phap phat hanh the tai chinh
Card issuance solution - Giai phap phat hanh the tai chinhTHANK Truong
 
C3000 & c6000 card delivery system - He thong long ghep phong bi
C3000 & c6000 card delivery system - He thong long ghep phong biC3000 & c6000 card delivery system - He thong long ghep phong bi
C3000 & c6000 card delivery system - He thong long ghep phong biTHANK Truong
 
MK Smart - SAS Certificate
MK Smart - SAS CertificateMK Smart - SAS Certificate
MK Smart - SAS CertificateTHANK Truong
 
Multi Loyalty Solution (Quan ly khach hang than thiet)
Multi Loyalty Solution (Quan ly khach hang than thiet)Multi Loyalty Solution (Quan ly khach hang than thiet)
Multi Loyalty Solution (Quan ly khach hang than thiet)THANK Truong
 
Photo Reportage Year End Party 2008
Photo Reportage   Year End Party 2008Photo Reportage   Year End Party 2008
Photo Reportage Year End Party 2008THANK Truong
 

Mehr von THANK Truong (9)

Tele conference solution - Hoi nghi truyen hinh
Tele conference solution - Hoi nghi truyen hinhTele conference solution - Hoi nghi truyen hinh
Tele conference solution - Hoi nghi truyen hinh
 
[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOU
[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOU[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOU
[VN] E-commerce - Tim hieu thuong mai dien tu by SEIKOU
 
[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOU
[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOU[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOU
[VN] E-Payment - Tim hieu thanh toan dien tu by SEIKOU
 
Card issuance solution - Giai phap phat hanh the tai chinh
Card issuance solution - Giai phap phat hanh the tai chinhCard issuance solution - Giai phap phat hanh the tai chinh
Card issuance solution - Giai phap phat hanh the tai chinh
 
C3000 & c6000 card delivery system - He thong long ghep phong bi
C3000 & c6000 card delivery system - He thong long ghep phong biC3000 & c6000 card delivery system - He thong long ghep phong bi
C3000 & c6000 card delivery system - He thong long ghep phong bi
 
Diadiem 6.0
Diadiem 6.0Diadiem 6.0
Diadiem 6.0
 
MK Smart - SAS Certificate
MK Smart - SAS CertificateMK Smart - SAS Certificate
MK Smart - SAS Certificate
 
Multi Loyalty Solution (Quan ly khach hang than thiet)
Multi Loyalty Solution (Quan ly khach hang than thiet)Multi Loyalty Solution (Quan ly khach hang than thiet)
Multi Loyalty Solution (Quan ly khach hang than thiet)
 
Photo Reportage Year End Party 2008
Photo Reportage   Year End Party 2008Photo Reportage   Year End Party 2008
Photo Reportage Year End Party 2008
 

OTP Solution - Mat khau su dung mot lan

  • 1. Portable Authentication - The concept Online shopping Internet banking Online gaming Mobile banking Online betting Enterprise access
  • 2. - Fight fraud and phishing! Todos has developed security solutions based on smart cards since 1990. Throughout the years, Todos has built up an extensive in-house expertise in designing cost efficient identification solutions for the mass market, with focus on the product, its personalisation, distribution and support. Todos eCode is a product portfolio for secure remote authentication using One Time Passwords (OTP), Challenge/Response and Electronic Signatures. The OTPs can be generated by a reader and a smart card, tokens, printed cards or mobile phones. Reader and smart card Todos eCode is a cost efficient, portable and secure authentication solution for e-Banking, e-Commerce, Online Shopping with 3-D Secure, Mobile Banking and Enterprise access. Todos eCode is platform and channel independent, providing the possibility to simultaneously authenticate users via Internet, PSTN, mobile network and VPN. The end user devices in the eCode solution are all easy to learn and easy to use. Also, it is easy to manage for the bank as the devices require no personalisation. Thus, they are easy and cheap to distribute and have minimal need for support. The Todos eCode solution can be introduced Mobile gradually, with different security levels, to suit the Token Printed OTP development pace of remote services in the bank. - Central System Todos eCode Central System is the heart of the Todos eCode authentication solution and can operate in both a Single Issuer and Multi Issuer configuration. Each Issuer is unique and has its own requirements on authentication method, security, reliability, availability, capacity and integration to its legacy systems. The modularity and flexibility of the eCode Central System enables it to be fully customized to meet customer requirements. VISA dynamic passcode authentication Todos eCode authentication follows the principle of two factor authentication. Based on something you know (i.e. a PIN or a Static Password), combined with something you have (e.g. a smart card), a One Time Password (OTP), a Signature or a Response in a Challenge/Response mechanism is generated. 3-D Secure Todos eCode supports different carriers, and a variety of medias: • Smart card- or SIM-based: FISC II - One Time Passwords (with or without PIN) OTP - Challenge/Response and Signatures • Printed One Time Passwords • Token One Time Passwords Sm@rt • SMS sent One Time Passwords TAN • Java MIDP based: - One Time Passwords (with or without PIN) - Challenge/Response and Signatures APACS Todos eCode Central System includes several different functions: SiBS • Authentication • Personalisation data generation • Key management Interpay • Customer Support Application • Static password verification • Personalisation of tokens and smart cards Banksys' R4 • Radius support Authentication Todos eCode Central System also supports the latest industrial standards, including 3-D Secure CAP, MasterCard SecureCode, VISA dynamic passcode authentication, APACS, Interpay, SiBS, Sm@rt TAN, FISC II OTP and Banksys' R4 Authentication.
  • 3. Reader and smart card In an eCode solution for smart card based One Time Signatures. The eCode readers may also display balance and Password (OTP), the OTPs, Signatures and Responses are transactions of e-purse, loyalty cards and other applications. generated in the smart card at the moment of authentication The readers do not require any personalisation, as the and displayed to the user in a portable smart card reader. security lies in the smart card and the security application. The user has one (or more) standardised readers, thus There are several models of smart card readers available, reader distribution becomes easier and cheaper. with different levels of functionality: Todos eCode Reader, Todos eCode Signature, Todos eCode Authenticator and The connectable Authenticator combines the portability Todos eCode connectable Authenticator. Todos eCode and user friendliness of an unconnected reader with PKI Signature, Authenticator and connectable Authenticator qualified signatures when connected to a PC via USB. have small keyboards for PIN entry, Challenge/Response and Printed OTP OTP Token The OTPs are generated In an eCode solution for centrally, then securely transferred Token based OTPs, the OTP is to a personalisation bureau generated inside the token at which prints the OTPs onto Reader and the moment of authentication a card or a PIN envelope. smart card and displayed to the user on the token display. To protect from shoulder Printed surfing, an aluminium foil OTP The user interface of Todos scratch layer protects the not eCode ezToken consists of a yet used OTPs. Combined with display and one single button. a static password you achieve With a press on the button an a two-factor authentication. OTP OTP is generated. Combined Token with a static password, this Benefits with Printed OTP: provides a strong two-factor • Low initial cost. Central System authentication. • Easy to deploy, learn and use. • Portability: always Data for Todos eCode in your wallet. ezToken personalisation • Easy to distribute using Mobile is generated by the Todos postal services. - SIM, MIDP eCode Central System. Java J2ME Printed OTP is a good intermediate Mobile OTP Token is a good solution if EMV cards have not yet intermediate solution - SMS been rolled out. if EMV cards have not yet been rolled out. Mobile - SIM and MIDP By placing the security application on the SIM Mobile - SMS you can use a standard mobile phone for all your In an eCode solution for OTP sent by SMS, the OTP is generated bank errands. It is also possible to download a in the eCode Central System upon a request from the user, sent Java application directly to your handset. by SMS to a predefined mobile card and displayed to the user. The mobile handset is a device most people carry with them The eCode Central System has the central all the time and care about. With Todos eCode Mobile SIM or functions for generating the OTP and sending MIDP inside, the authentication device is always close at hand. it, in addition to the verification. Todos eCode Mobile supports multiple banks and service The mobile handset is a device most people carry with providers on the same SIM card. Each bank/service provider can them all the time and care about. With Todos eCode Mobile control their own personalised information independently. SMS, the authentication device is always close at hand. Example of dynamic authentication solution: Todos eCode Mobile Todos eCode Authenticator Todos eCode ezToken Todos eCode Central System Starting off with Introducing eCode Mobile EMV card rollout Phase out tokens Bank Central System and tokens New customer segment Introducing smart card readers development
  • 4. Case studies 23 individual banks using Todos Developing next generation eBanking terminal eCode in a Multi Issuer setup ABN AMRO is a prominent international bank, with European SpareBank 1 Alliance roots dating back to 1824. ABN AMRO ranks eighth in Europe is a Nordic bank and product and 15th in the world based on tier 1 capital. In 2003, ABN AMRO collaboration where the began an evaluation process for a new generation eBanking SpareBank 1 banks in terminals, a project called TRaP (Token Replacement Project). Norway collaborate through the jointly owned group ABN AMRO's main selection criteria were: SpareBank 1 Gruppen AS. SpareBank 1 • A secure end user device that implements "Sign what you Gruppen AS was established in 1996, and is one of the see" functionality for both unconnected and connected use. largest providers of financial services in the Norwegian • A device that will be used as the market. The Alliance consists of 23 individual savings banks security device over the next 5-10 "Sign what and the product companies of SpareBank 1 Gruppen AS. years, and must offer long-term you see" support for the ABN AMRO card functionality SpareBank 1 Gruppen AS is using the Todos eCode solution products today and tomorrow. in a Multi Issuer setup, where all SpareBank 1 banks are using the • A supplier with cutting edge technology and know-how, same eCode Central System, but each individual savings bank has being able to turn customer's business and product its own operational keys and eCode database. requirements into a solution that meets customer demands in the areas of security, smart cards and quality. • A device that has ABN AMRO look and feel. The Todos eCode authentication solution in this • Pricing. case represents the authentication of end users to their own certificates in a net centric key store system, in which the private keys are securely hosted in a central After a thorough evaluation of the alternatives, ABN server. This is part of the national ID scheme BankID. AMRO (BUNL) selected Todos for the development of their new secure end user device "e.dentifier2". A final contract was signed on August 24, 2005, comprising the development of Says Eldar Skjetne, Director payment services, the reader and rollout of more than 2.5 million readers. SpareBank 1 Gruppen AS: “We think that we have together with Todos Data System AB found a solution which is easy to use for the customers. With the security application hosted in the smart card, the customer can easily see the connection between traditional payments with his/her Visa card, and the use of the same card for For further information regarding the different parts of authentication on the Internet. Customers who wish to have more the Todos eCode portfolio please see respective product brochure than one eCode Reader will be able to buy the additional number or contact the Todos sales team. All brochures are available for of readers they like from the bank.” download at www.todos.se. TODOS DATA SYSTEM AB 7331887 ----- 061024 www.todos.se sales@todos.se Todos Data System reserves the right to change the specifications at any time and without notice. All trademarks or trade names are the property of their respective owners.