aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
User Authentication Process
3.8.2
Using a Host Code
A DIGIPASS Host Code is computed as follows:
1.
The DIGIPASS device generates a One Time Password, and splits it into two parts. The first part is used for
end user authentication. The second part is the ‘Host Code’ and is used for authentication of the server.
2.
The end user sends the first part to the server as proof of identity and keeps the second part secret.
3.
The server verifies the One Time Password for end user authentication. If valid, the end user is authenticated
to the server. The server then computes the second part of the One Time Password, i.e. the Host Code.
4.
The server sends the Host Code to the end user, who verifies (visually) whether it matches the Host Code
generated by the DIGIPASS device.
Host Code generation is passed as a parameter in the authentication request. There are two options:
Optional - only return a Host Code if the DIGIPASS device is Host Code capable
Required - DIGIPASS device must be Host Code capable or the request will fail
Note:
Host code generation is only supported by SOAP.
©
2009 VASCO Data Security
53