SlideShare una empresa de Scribd logo
1 de 3
Descargar para leer sin conexión
DIGIPASS
for APPS

DIGIPASS for APPS
DIGIPASS for APPS: a 360 degrees framework to secure your critical applications
The current mobile ecosystem is a powerful distribution channel
to put your applications in the hands of millions of potential
users. However, the shift from traditional desktop to online
applications has raised the security stakes. While more and more
people conduct activities online, threats likewise increased as
fraudsters have devised complex fraud schemes to turn security
vulnerabilities in applications to their benefit.
Web application security must be addressed across different
components and at multiple layers. Each component of an
application poses a potential security risk. Circumventing these
threats is a time and resource-consuming effort.
To tackle these potential threats, VASCO has developed DIGIPASS
for APPS. This stands for DIGIPASS for Application Perimeter
Protection SDK. The solution offers you a unique single framework
with a comprehensive set of features giving you all necessary
building blocks to secure your application at every level, from
provisioning to human interface.

COMMUNICATION LAYER
Certain types of information exchanged from the server to the
client application might require an extra security layer as they
contain critical data. Relying on mainstream technologies like
HTTPS may not be enough and could introduce an external risk
in a critical process.
DIGIPASS for APPS provides a secure channel to virtually encrypt
anything (text, photos, QR codes, etc.).The solution can be used
together with QR codes providing end-to-end encryption. The
server side generated QR code can only be used by one specific
person on a specific device.
This end-to-end encryption introduces a new level of services
between server and client applications enabling for instance
“what you see is what you sign” capability on mobile devices.

Scoring
OTP, Signature, ...

DIGIPASS for APPS offers following features:
•	Secure storage
•	Device binding
•	QR code scanner
•	Secure channel
•	Multi-device capacity
•	Secure key provisioning
•	Jailbreak & rootkit detection
•	Geolocation

Cryptogram
Generation

QrCode Scanner
Secure Channel

Root Detection
Malware Detection

Human
Interface

Secure Storage
Device Binding

BUSINESS LOGIC
A secured retail application needs to evaluate the
environment where it resides; therefore a jailbreak or
rootkit detection might be required prior to launching
parts of the application.

Business
Logic

Storage

Comm. Layer

Provisioning &
Lifecycle

Device Binding
Key Provisioning
Multi-Device

Secure Channel
Alert | Notification

Platform
services

Geolocation

DIGIPASS for APPS provides a secure, updatable way to detect
if the remote environment is compromised, in a single function
for all platforms.

The world’s leading software company specializing in Internet Security
DIGIPASS
for APPS

PLATFORM SERVICES

MULTI-DEVICE

Determining the location of an end-user can be of interest when
using mobile applications, e.g. to verify if the user and the device are
recognized and permitted to perform certain activities or to localize
applications for specific geographic regions.

A typical user might have several devices in his personal
ecosystem. DIGIPASS for APPS provides functionalities to allow
an end user to seamlessly use all his devices transparently and
in a secure way with a single license.

DIGIPASS for APPS provides standardized access to location-based
functions, independent of the target platform.

DEVICE BINDING

This function can be used in combination with two-factor
authentication to create a location-dependent one-time password.
This can be of particular interest to enhance the mobile
authentication process of your users in an international setting
whereby authentication requests from non-authorized regions will
not be accepted.
PROVISIONING & LIFE CYCLE MANAGEMENT
A client side application runs on the end user’s device. At times
it is important to know that the application runs on a recognized
and trusted device. The link between the software DIGIPASS and
the device is managed by DIGIPASS for APPSduring all critical
steps of product deployment.

DIGIPASS for APPS also provides device-independent functions
that link a certain user to a specific device. Device binding can
be used together with cryptographic functions to create devicedependent one-time passwords.
STORAGE & PERSISTENT DATA
An application may require persistent data on a remote platform.
These data need to be secured ensuring that they cannot be
accessed by other applications or devices. DIGIPASS for APPS
therefore offers secure storage functionalities allowing an easy
encryption of all application data, independent of any operating
system or device.
This function can be used in combination with the device binding
capacity, ensuring that the secure storage is linked to a specific
device.

SECRET KEY PROVISIONING

HUMAN INTERFACE

Secret key provisioning should be flexible and highly secured.
A provisioned license should also be linked to a specific device.
DIGIPASS for APPS provides a full range of provisioning options
from manual activation to online or QR code-based processes
with different levels of convenience and security.

The manner in which an application will interact with the user
and how he will perceive and use it, will have a tremendous
impact on the adoption rate. DIGIPASS for APPS offers ultimate
user convenience as it supports QR code scanning and graphical
cryptograms such as the CrontoSign technology.

REACTIVATION

Using QR codes or CrontoSign technology reduces manual
input and offers a fast and reliable way of logging on or signing
transactions.

Any retail application needs a procedure in place regarding
lifecycle management as end users will change their devices
from time to time. The process of reactivating registered users
should run as smooth as possible.
DIGIPASS for APPS makes lifecycle management a piece of
cake thanks to a set of protocol independent functionalities and
features that can be used across different platforms.

CRYPTOGRAM GENERATION
DIGIPASS for APPS allows you to add strong authentication
directly to the application without external software interacting
with the company’s system. One-time password and e-signature
capability become thus an integral part of the online application.

The world’s leading software company specializing in Internet Security
www.vasco.com
DIGIPASS
for APPS

DIGIPASS for APPS allows the integration of strong authentication
into any regular software environment. It can also rely on any
external Secure Executive Environment.

BENEFITS

As a result, DIGIPASS for APPS has the best of two worlds: ease
of integration, worldwide support and extended security for
hardware processing. DIGIPASS for APPS is compatible with all
of VASCO’s technologies and can be used in conjunction with any
other authenticator of the DIGIPASS family.

•	Transparent deployment to end users

FEATURES

•	Can be used with PC and other devices as well as specific
environments (JavaCards, SIM cards, tablets, mobile phones,
USB devices...)

•	One-time passwords and e-signatures become an integral part
of the online application
•	Extended set of provisioning options
•	Patented CrontoSign technology, support for an extended list of
QR codes and barcodes

•	Native integration of strong authentication into applications
•	Entire application perimeter is protected in a single SDK
•	Integration efforts are reduced to a minimum
•	No cryptographic skills required
•	Extensible security model
•	Suitable for any server side environment

•	Fully customizable - overcomes GUI issues and meets any
graphical requirement

•	Supports geolocalized OTPs and e-signatures
•	Jailbreak and rootkit detection
•	Device binding
•	Secure storage
•	Out of band login support
•	Multi-device capabalities
•	Available for the most common programming environments,
including iOS, BlackBerry (including latest BB10 versions),
Android, Windows Phone, Java with comprehensive
programming samples

About VASCO
VASCO is a leading supplier of strong authentication and e-signature solutions and services specializing in Internet Security applications and
transactions. VASCO has positioned itself as global software company for Internet Security and designs, develops, markets and supports
DIGIPASS®, CertiID™, VACMAN®, IDENTIKEY® and aXsGUARD® authentication products. VASCO’s prime markets are the financial sector,
enterprise security, e-commerce and e-government.

www.vasco.com
I N T E R N AT I O N A L H Q
ZURICH (Europe)
phone: +41 43 555 3500
email: info_europe@vasco.com

C O R P O R AT E H Q
CHICAGO (North America)
phone: +1 630 932 88 44
info-usa@vasco.com
BRUSSELS (EUROPE)
phone: +32.2.609.97.00
email: info-europe@vasco.com

BOSTON (NORTH AMERICA)
phone: +1.508.366.3400
email: info-usa@vasco.com

S Y D N E Y ( PA C I F I C )
phone: +61.2.8061.3700
email: info-australia@vasco.com

Copyright © 2013 VASCO Data Security, Inc, VASCO Data Security International GmbH. All rights reserved. VASCO®, CertiID™, VACMAN®, IDENTIKEY®, aXsGUARD®,
®
™
DIGIPASS®, the
logo and the
logo are registered or unregistered trademarks of VASCO Data Security, Inc. and/or VASCO Data Security International
GmbH in the U.S. and other countries. VASCO Data Security, Inc. and/or VASCO Data Security International GmbH own or are licensed under all title, rights and interest
in VASCO Products, updates and upgrades thereof, including copyrights, patent rights, trade secret rights, mask work rights, database rights and all other intellectual
and industrial property rights in the U.S. and other countries. Other names may be trademarks of their respective owners. 	
LE201311-v1

SINGAPORE (ASIA)
phone: +65.6323.0906
email: info-asia@vasco.com

www.vasco.com
www.vasco.com

Más contenido relacionado

La actualidad más candente

Introduction to Android Application Security Testing - 2nd Sep 2017
Introduction to Android Application Security Testing - 2nd Sep 2017Introduction to Android Application Security Testing - 2nd Sep 2017
Introduction to Android Application Security Testing - 2nd Sep 2017Satheesh Kumar V
 
Next-generation Zero Trust Cybersecurity for the Space Age
Next-generation Zero Trust Cybersecurity for the Space AgeNext-generation Zero Trust Cybersecurity for the Space Age
Next-generation Zero Trust Cybersecurity for the Space AgeBlock Armour
 
2014 IoT Forum_ Fido Alliance
2014 IoT Forum_ Fido Alliance2014 IoT Forum_ Fido Alliance
2014 IoT Forum_ Fido AllianceCOMPUTEX TAIPEI
 
Cyber Threat Intelligence: Highlights and Trends for 2020
Cyber Threat Intelligence: Highlights and Trends for 2020Cyber Threat Intelligence: Highlights and Trends for 2020
Cyber Threat Intelligence: Highlights and Trends for 2020DevOps.com
 
The samsung knox platform 0
The samsung knox platform 0The samsung knox platform 0
The samsung knox platform 0Javier Gonzalez
 
The Present and Future of IoT Cybersecurity
The Present and Future of IoT CybersecurityThe Present and Future of IoT Cybersecurity
The Present and Future of IoT CybersecurityOnward Security
 
FIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok Labs
FIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok LabsFIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok Labs
FIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok LabsNok Nok Labs, Inc
 
FIDO Alliance: Year in Review Webinar slides from January 20 2016
FIDO Alliance: Year in Review Webinar slides from January 20 2016FIDO Alliance: Year in Review Webinar slides from January 20 2016
FIDO Alliance: Year in Review Webinar slides from January 20 2016FIDO Alliance
 
Feb 18-2015 vasco investor presentation
Feb 18-2015 vasco investor presentationFeb 18-2015 vasco investor presentation
Feb 18-2015 vasco investor presentationVASCO Data Security
 
Sholove cyren web security - technical datasheet2
Sholove cyren web security  - technical datasheet2Sholove cyren web security  - technical datasheet2
Sholove cyren web security - technical datasheet2SHOLOVE INTERNATIONAL LLC
 
Unicom Conference - Mobile Application Security
Unicom Conference - Mobile Application SecurityUnicom Conference - Mobile Application Security
Unicom Conference - Mobile Application SecuritySubho Halder
 
Security Matters : The Evolution of Samsung KNOX™
Security Matters: The Evolution of Samsung KNOX™Security Matters: The Evolution of Samsung KNOX™
Security Matters : The Evolution of Samsung KNOX™Samsung at Work
 

La actualidad más candente (20)

Introduction to Android Application Security Testing - 2nd Sep 2017
Introduction to Android Application Security Testing - 2nd Sep 2017Introduction to Android Application Security Testing - 2nd Sep 2017
Introduction to Android Application Security Testing - 2nd Sep 2017
 
Next-generation Zero Trust Cybersecurity for the Space Age
Next-generation Zero Trust Cybersecurity for the Space AgeNext-generation Zero Trust Cybersecurity for the Space Age
Next-generation Zero Trust Cybersecurity for the Space Age
 
Cyber Security Coverage heat map
Cyber Security Coverage heat map Cyber Security Coverage heat map
Cyber Security Coverage heat map
 
2014 IoT Forum_ Fido Alliance
2014 IoT Forum_ Fido Alliance2014 IoT Forum_ Fido Alliance
2014 IoT Forum_ Fido Alliance
 
Cyber Threat Intelligence: Highlights and Trends for 2020
Cyber Threat Intelligence: Highlights and Trends for 2020Cyber Threat Intelligence: Highlights and Trends for 2020
Cyber Threat Intelligence: Highlights and Trends for 2020
 
The samsung knox platform 0
The samsung knox platform 0The samsung knox platform 0
The samsung knox platform 0
 
The Present and Future of IoT Cybersecurity
The Present and Future of IoT CybersecurityThe Present and Future of IoT Cybersecurity
The Present and Future of IoT Cybersecurity
 
Symantec Code Sign (NAM)
Symantec Code Sign (NAM)Symantec Code Sign (NAM)
Symantec Code Sign (NAM)
 
Check Point NGFW
Check Point NGFWCheck Point NGFW
Check Point NGFW
 
Check Point Corporate Overview 2020 - Detailed
Check Point Corporate Overview 2020 - DetailedCheck Point Corporate Overview 2020 - Detailed
Check Point Corporate Overview 2020 - Detailed
 
FIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok Labs
FIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok LabsFIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok Labs
FIDO & The Mobile Network Operator - Goode Intelligence & Nok Nok Labs
 
FIDO Alliance: Year in Review Webinar slides from January 20 2016
FIDO Alliance: Year in Review Webinar slides from January 20 2016FIDO Alliance: Year in Review Webinar slides from January 20 2016
FIDO Alliance: Year in Review Webinar slides from January 20 2016
 
Symantec Code Signing (UK)
Symantec Code Signing (UK)Symantec Code Signing (UK)
Symantec Code Signing (UK)
 
Feb 18-2015 vasco investor presentation
Feb 18-2015 vasco investor presentationFeb 18-2015 vasco investor presentation
Feb 18-2015 vasco investor presentation
 
Vasco Investor Presentation
Vasco Investor PresentationVasco Investor Presentation
Vasco Investor Presentation
 
Mind the gap_cpx2022_moti_sagey_final
Mind the gap_cpx2022_moti_sagey_finalMind the gap_cpx2022_moti_sagey_final
Mind the gap_cpx2022_moti_sagey_final
 
Fortinet Broşür
Fortinet BroşürFortinet Broşür
Fortinet Broşür
 
Sholove cyren web security - technical datasheet2
Sholove cyren web security  - technical datasheet2Sholove cyren web security  - technical datasheet2
Sholove cyren web security - technical datasheet2
 
Unicom Conference - Mobile Application Security
Unicom Conference - Mobile Application SecurityUnicom Conference - Mobile Application Security
Unicom Conference - Mobile Application Security
 
Security Matters : The Evolution of Samsung KNOX™
Security Matters: The Evolution of Samsung KNOX™Security Matters: The Evolution of Samsung KNOX™
Security Matters : The Evolution of Samsung KNOX™
 

Destacado

μπουντακασ μπητροσ-ασκηση 1
μπουντακασ μπητροσ-ασκηση 1μπουντακασ μπητροσ-ασκηση 1
μπουντακασ μπητροσ-ασκηση 1kopritispapagalos
 
ασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυοασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυοkopritispapagalos
 
θανατική ποινή4
θανατική ποινή4θανατική ποινή4
θανατική ποινή4kopritispapagalos
 
ασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυοασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυοkopritispapagalos
 

Destacado (6)

μπουντακασ μπητροσ-ασκηση 1
μπουντακασ μπητροσ-ασκηση 1μπουντακασ μπητροσ-ασκηση 1
μπουντακασ μπητροσ-ασκηση 1
 
aXsGuard Gatekeeper
aXsGuard GatekeeperaXsGuard Gatekeeper
aXsGuard Gatekeeper
 
ασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυοασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυο
 
φυλλομετρητεσ
φυλλομετρητεσφυλλομετρητεσ
φυλλομετρητεσ
 
θανατική ποινή4
θανατική ποινή4θανατική ποινή4
θανατική ποινή4
 
ασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυοασφάλεια στο διαδίκτυο
ασφάλεια στο διαδίκτυο
 

Similar a DIGIPASS for Apps

Case StudyAutomotive - SSLVPN case study DIGIPASS BY VA
Case StudyAutomotive - SSLVPN case study DIGIPASS BY VACase StudyAutomotive - SSLVPN case study DIGIPASS BY VA
Case StudyAutomotive - SSLVPN case study DIGIPASS BY VAMaximaSheffield592
 
GOAppZone Data Sheet
GOAppZone Data SheetGOAppZone Data Sheet
GOAppZone Data Sheetykaralis
 
Array Networks - Secure Access Gateways
Array Networks - Secure Access GatewaysArray Networks - Secure Access Gateways
Array Networks - Secure Access Gateways Array Networks
 
2FA Advanced Authentication for Public Safety
2FA  Advanced Authentication for Public Safety2FA  Advanced Authentication for Public Safety
2FA Advanced Authentication for Public Safety2FA, Inc.
 
AGORA enables security companies to sell innovative remote services
AGORA enables security companies to sell innovative remote servicesAGORA enables security companies to sell innovative remote services
AGORA enables security companies to sell innovative remote servicesAGORA
 
Mobile Enterprise Application Platform
Mobile Enterprise Application PlatformMobile Enterprise Application Platform
Mobile Enterprise Application PlatformNugroho Gito
 
App gate sdp_use_case_secure_cloud_access
App gate sdp_use_case_secure_cloud_accessApp gate sdp_use_case_secure_cloud_access
App gate sdp_use_case_secure_cloud_accessCristian Garcia G.
 
Enterprise secure identity in the cloud with Single Sign On and Strong Authen...
Enterprise secure identity in the cloud with Single Sign On and Strong Authen...Enterprise secure identity in the cloud with Single Sign On and Strong Authen...
Enterprise secure identity in the cloud with Single Sign On and Strong Authen...GARL
 
Veracode Corporate Overview - Print
Veracode Corporate Overview - PrintVeracode Corporate Overview - Print
Veracode Corporate Overview - PrintAndrew Kanikuru
 
Market Study on Mobile Authentication
Market Study on Mobile AuthenticationMarket Study on Mobile Authentication
Market Study on Mobile AuthenticationFIDO Alliance
 
Mobile Payment Security with CA Rapid App Security
Mobile Payment Security with CA Rapid App SecurityMobile Payment Security with CA Rapid App Security
Mobile Payment Security with CA Rapid App SecurityCA Technologies
 
Samsung knox the most secure android solution
Samsung knox   the most secure android solutionSamsung knox   the most secure android solution
Samsung knox the most secure android solutionJavier Gonzalez
 
Samsung KNOX - The Most Secure Android Solution
Samsung KNOX - The Most Secure Android SolutionSamsung KNOX - The Most Secure Android Solution
Samsung KNOX - The Most Secure Android SolutionSamsung Biz Mobile
 
The Future of Mobile Application Security
The Future of Mobile Application SecurityThe Future of Mobile Application Security
The Future of Mobile Application SecuritySecureAuth
 
sb-checkpoint-matrix42
sb-checkpoint-matrix42sb-checkpoint-matrix42
sb-checkpoint-matrix42Wayne Phillips
 

Similar a DIGIPASS for Apps (20)

Case StudyAutomotive - SSLVPN case study DIGIPASS BY VA
Case StudyAutomotive - SSLVPN case study DIGIPASS BY VACase StudyAutomotive - SSLVPN case study DIGIPASS BY VA
Case StudyAutomotive - SSLVPN case study DIGIPASS BY VA
 
Insecure mag-19
Insecure mag-19Insecure mag-19
Insecure mag-19
 
Checkpoint Overview
Checkpoint OverviewCheckpoint Overview
Checkpoint Overview
 
GOAppZone Data Sheet
GOAppZone Data SheetGOAppZone Data Sheet
GOAppZone Data Sheet
 
Value Journal - October 2020
Value Journal - October 2020Value Journal - October 2020
Value Journal - October 2020
 
Array Networks - Secure Access Gateways
Array Networks - Secure Access GatewaysArray Networks - Secure Access Gateways
Array Networks - Secure Access Gateways
 
2FA Advanced Authentication for Public Safety
2FA  Advanced Authentication for Public Safety2FA  Advanced Authentication for Public Safety
2FA Advanced Authentication for Public Safety
 
AGORA enables security companies to sell innovative remote services
AGORA enables security companies to sell innovative remote servicesAGORA enables security companies to sell innovative remote services
AGORA enables security companies to sell innovative remote services
 
SECURE ACCESS GATEWAYS
SECURE ACCESS GATEWAYSSECURE ACCESS GATEWAYS
SECURE ACCESS GATEWAYS
 
Mobile Enterprise Application Platform
Mobile Enterprise Application PlatformMobile Enterprise Application Platform
Mobile Enterprise Application Platform
 
App gate sdp_use_case_secure_cloud_access
App gate sdp_use_case_secure_cloud_accessApp gate sdp_use_case_secure_cloud_access
App gate sdp_use_case_secure_cloud_access
 
Enterprise secure identity in the cloud with Single Sign On and Strong Authen...
Enterprise secure identity in the cloud with Single Sign On and Strong Authen...Enterprise secure identity in the cloud with Single Sign On and Strong Authen...
Enterprise secure identity in the cloud with Single Sign On and Strong Authen...
 
Veracode Corporate Overview - Print
Veracode Corporate Overview - PrintVeracode Corporate Overview - Print
Veracode Corporate Overview - Print
 
Market Study on Mobile Authentication
Market Study on Mobile AuthenticationMarket Study on Mobile Authentication
Market Study on Mobile Authentication
 
Mobile Payment Security with CA Rapid App Security
Mobile Payment Security with CA Rapid App SecurityMobile Payment Security with CA Rapid App Security
Mobile Payment Security with CA Rapid App Security
 
Samsung knox the most secure android solution
Samsung knox   the most secure android solutionSamsung knox   the most secure android solution
Samsung knox the most secure android solution
 
Samsung KNOX - The Most Secure Android Solution
Samsung KNOX - The Most Secure Android SolutionSamsung KNOX - The Most Secure Android Solution
Samsung KNOX - The Most Secure Android Solution
 
SecurePass at OpenBrighton
SecurePass at OpenBrightonSecurePass at OpenBrighton
SecurePass at OpenBrighton
 
The Future of Mobile Application Security
The Future of Mobile Application SecurityThe Future of Mobile Application Security
The Future of Mobile Application Security
 
sb-checkpoint-matrix42
sb-checkpoint-matrix42sb-checkpoint-matrix42
sb-checkpoint-matrix42
 

Más de VASCO Data Security (9)

Increasing your mobile banking business
Increasing your mobile banking businessIncreasing your mobile banking business
Increasing your mobile banking business
 
MYDIGIPASS.COM leaflet
MYDIGIPASS.COM leafletMYDIGIPASS.COM leaflet
MYDIGIPASS.COM leaflet
 
We Authenticate the World
We Authenticate the WorldWe Authenticate the World
We Authenticate the World
 
Secure Online Banking
Secure Online BankingSecure Online Banking
Secure Online Banking
 
Identikey
IdentikeyIdentikey
Identikey
 
MYDIGIPASS.COM
MYDIGIPASS.COMMYDIGIPASS.COM
MYDIGIPASS.COM
 
Password fatigation
Password fatigationPassword fatigation
Password fatigation
 
Infosec1november
Infosec1novemberInfosec1november
Infosec1november
 
Infosec31october
Infosec31octoberInfosec31october
Infosec31october
 

Último

DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
What is Artificial Intelligence?????????
What is Artificial Intelligence?????????What is Artificial Intelligence?????????
What is Artificial Intelligence?????????blackmambaettijean
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 

Último (20)

DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
What is Artificial Intelligence?????????
What is Artificial Intelligence?????????What is Artificial Intelligence?????????
What is Artificial Intelligence?????????
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 

DIGIPASS for Apps

  • 1. DIGIPASS for APPS DIGIPASS for APPS DIGIPASS for APPS: a 360 degrees framework to secure your critical applications The current mobile ecosystem is a powerful distribution channel to put your applications in the hands of millions of potential users. However, the shift from traditional desktop to online applications has raised the security stakes. While more and more people conduct activities online, threats likewise increased as fraudsters have devised complex fraud schemes to turn security vulnerabilities in applications to their benefit. Web application security must be addressed across different components and at multiple layers. Each component of an application poses a potential security risk. Circumventing these threats is a time and resource-consuming effort. To tackle these potential threats, VASCO has developed DIGIPASS for APPS. This stands for DIGIPASS for Application Perimeter Protection SDK. The solution offers you a unique single framework with a comprehensive set of features giving you all necessary building blocks to secure your application at every level, from provisioning to human interface. COMMUNICATION LAYER Certain types of information exchanged from the server to the client application might require an extra security layer as they contain critical data. Relying on mainstream technologies like HTTPS may not be enough and could introduce an external risk in a critical process. DIGIPASS for APPS provides a secure channel to virtually encrypt anything (text, photos, QR codes, etc.).The solution can be used together with QR codes providing end-to-end encryption. The server side generated QR code can only be used by one specific person on a specific device. This end-to-end encryption introduces a new level of services between server and client applications enabling for instance “what you see is what you sign” capability on mobile devices. Scoring OTP, Signature, ... DIGIPASS for APPS offers following features: • Secure storage • Device binding • QR code scanner • Secure channel • Multi-device capacity • Secure key provisioning • Jailbreak & rootkit detection • Geolocation Cryptogram Generation QrCode Scanner Secure Channel Root Detection Malware Detection Human Interface Secure Storage Device Binding BUSINESS LOGIC A secured retail application needs to evaluate the environment where it resides; therefore a jailbreak or rootkit detection might be required prior to launching parts of the application. Business Logic Storage Comm. Layer Provisioning & Lifecycle Device Binding Key Provisioning Multi-Device Secure Channel Alert | Notification Platform services Geolocation DIGIPASS for APPS provides a secure, updatable way to detect if the remote environment is compromised, in a single function for all platforms. The world’s leading software company specializing in Internet Security
  • 2. DIGIPASS for APPS PLATFORM SERVICES MULTI-DEVICE Determining the location of an end-user can be of interest when using mobile applications, e.g. to verify if the user and the device are recognized and permitted to perform certain activities or to localize applications for specific geographic regions. A typical user might have several devices in his personal ecosystem. DIGIPASS for APPS provides functionalities to allow an end user to seamlessly use all his devices transparently and in a secure way with a single license. DIGIPASS for APPS provides standardized access to location-based functions, independent of the target platform. DEVICE BINDING This function can be used in combination with two-factor authentication to create a location-dependent one-time password. This can be of particular interest to enhance the mobile authentication process of your users in an international setting whereby authentication requests from non-authorized regions will not be accepted. PROVISIONING & LIFE CYCLE MANAGEMENT A client side application runs on the end user’s device. At times it is important to know that the application runs on a recognized and trusted device. The link between the software DIGIPASS and the device is managed by DIGIPASS for APPSduring all critical steps of product deployment. DIGIPASS for APPS also provides device-independent functions that link a certain user to a specific device. Device binding can be used together with cryptographic functions to create devicedependent one-time passwords. STORAGE & PERSISTENT DATA An application may require persistent data on a remote platform. These data need to be secured ensuring that they cannot be accessed by other applications or devices. DIGIPASS for APPS therefore offers secure storage functionalities allowing an easy encryption of all application data, independent of any operating system or device. This function can be used in combination with the device binding capacity, ensuring that the secure storage is linked to a specific device. SECRET KEY PROVISIONING HUMAN INTERFACE Secret key provisioning should be flexible and highly secured. A provisioned license should also be linked to a specific device. DIGIPASS for APPS provides a full range of provisioning options from manual activation to online or QR code-based processes with different levels of convenience and security. The manner in which an application will interact with the user and how he will perceive and use it, will have a tremendous impact on the adoption rate. DIGIPASS for APPS offers ultimate user convenience as it supports QR code scanning and graphical cryptograms such as the CrontoSign technology. REACTIVATION Using QR codes or CrontoSign technology reduces manual input and offers a fast and reliable way of logging on or signing transactions. Any retail application needs a procedure in place regarding lifecycle management as end users will change their devices from time to time. The process of reactivating registered users should run as smooth as possible. DIGIPASS for APPS makes lifecycle management a piece of cake thanks to a set of protocol independent functionalities and features that can be used across different platforms. CRYPTOGRAM GENERATION DIGIPASS for APPS allows you to add strong authentication directly to the application without external software interacting with the company’s system. One-time password and e-signature capability become thus an integral part of the online application. The world’s leading software company specializing in Internet Security
  • 3. www.vasco.com DIGIPASS for APPS DIGIPASS for APPS allows the integration of strong authentication into any regular software environment. It can also rely on any external Secure Executive Environment. BENEFITS As a result, DIGIPASS for APPS has the best of two worlds: ease of integration, worldwide support and extended security for hardware processing. DIGIPASS for APPS is compatible with all of VASCO’s technologies and can be used in conjunction with any other authenticator of the DIGIPASS family. • Transparent deployment to end users FEATURES • Can be used with PC and other devices as well as specific environments (JavaCards, SIM cards, tablets, mobile phones, USB devices...) • One-time passwords and e-signatures become an integral part of the online application • Extended set of provisioning options • Patented CrontoSign technology, support for an extended list of QR codes and barcodes • Native integration of strong authentication into applications • Entire application perimeter is protected in a single SDK • Integration efforts are reduced to a minimum • No cryptographic skills required • Extensible security model • Suitable for any server side environment • Fully customizable - overcomes GUI issues and meets any graphical requirement • Supports geolocalized OTPs and e-signatures • Jailbreak and rootkit detection • Device binding • Secure storage • Out of band login support • Multi-device capabalities • Available for the most common programming environments, including iOS, BlackBerry (including latest BB10 versions), Android, Windows Phone, Java with comprehensive programming samples About VASCO VASCO is a leading supplier of strong authentication and e-signature solutions and services specializing in Internet Security applications and transactions. VASCO has positioned itself as global software company for Internet Security and designs, develops, markets and supports DIGIPASS®, CertiID™, VACMAN®, IDENTIKEY® and aXsGUARD® authentication products. VASCO’s prime markets are the financial sector, enterprise security, e-commerce and e-government. www.vasco.com I N T E R N AT I O N A L H Q ZURICH (Europe) phone: +41 43 555 3500 email: info_europe@vasco.com C O R P O R AT E H Q CHICAGO (North America) phone: +1 630 932 88 44 info-usa@vasco.com BRUSSELS (EUROPE) phone: +32.2.609.97.00 email: info-europe@vasco.com BOSTON (NORTH AMERICA) phone: +1.508.366.3400 email: info-usa@vasco.com S Y D N E Y ( PA C I F I C ) phone: +61.2.8061.3700 email: info-australia@vasco.com Copyright © 2013 VASCO Data Security, Inc, VASCO Data Security International GmbH. All rights reserved. VASCO®, CertiID™, VACMAN®, IDENTIKEY®, aXsGUARD®, ® ™ DIGIPASS®, the logo and the logo are registered or unregistered trademarks of VASCO Data Security, Inc. and/or VASCO Data Security International GmbH in the U.S. and other countries. VASCO Data Security, Inc. and/or VASCO Data Security International GmbH own or are licensed under all title, rights and interest in VASCO Products, updates and upgrades thereof, including copyrights, patent rights, trade secret rights, mask work rights, database rights and all other intellectual and industrial property rights in the U.S. and other countries. Other names may be trademarks of their respective owners. LE201311-v1 SINGAPORE (ASIA) phone: +65.6323.0906 email: info-asia@vasco.com www.vasco.com www.vasco.com