Embedded Security Token
SolidPass is a software-based two-factor authentication token built such that it can be used as a standalone product or embedded in mobile applications such as mobile government. Thus strong authentication can be built into standalone applications. This is especially useful for mobile banking security, where SolidPass can be embedded in a mobile banking application for seamless authentication. Any combination of the following authentication methods can be embedded into applications:
- Event-based One-Time Password (OTP)
- Time-based One-Time Password (OTP)
- PIN control mandatory/optional
- Security Question
- Challenge-Response
- Transaction Data Signing (TDS)
- Mutual Authentication
Embedded tokens prevent the following attacks:
- Man-In-The-Middle
- DNS Cache Poisoning
- Trojans
- Man-In-The-Phone
- Browser Poisoning
The embedded token works on a number of different mobile platforms. The supported mobile platforms include:
- Android
- Blackberry
- Brew
- iPhone
- Java ME (J2ME)
- Linux
- Palm
- Symbian
- Windows Mobile
Desktop Soft Token
SolidPass also supports desktop-based software tokens as well. The Desktop Operating Systems and Browsers supported are:
- Toolbar Token
- Java Token
- Linux Token
- Mac Token
- Windows Token
Regulatory Compliance
Regulatory requirements are pressuring organizations to adopt
stronger authentication methods and to secure access to data
systems and applications. Static username/password identity
management no longer provide enough security to authenticate
users accurately. This has led to adopting two-factor
authentication systems. Legislation from the Sarbanes-Oxley
Act (SOX), guidelines from the Federal Financial Institutions
Examination Council (FFIEC), and recommendations from the
Health Insurance Portability and Accountability Act (HIPAA)
all require that organizations use stronger forms of
authentication to mitigate data theft, prevent fraud, protect
customer information and patient privacy. SolidPass helps
organizations and enterprises comply with regulatory regimes
that cover authorization rules and auditing protocols.
In addition to non-compliance, organizations that continue to use static username/passwords face numerous problems ranging from brute force attacks, dictionary attacks, guessing and social engineering.
OATH Compliant 2FA Tokens
As a member of the Initiative for Open Authentication, SolidPass 2FA tokens are built OATH compliant.