HID Global®, a worldwide leader in secure identity solutions, has enhanced its ActivID® authentication offering for digital banking with a push notification solution that gives financial institutions a secure channel and easy method for notifying customers about pending transactions on their phones or tablets, and then proceeding with execution after receiving their authorization.

ActivID Trusted Transactions Solution

“Customers are finding it increasingly difficult to differentiate between legitimate websites, emails, and phone calls originating from their own bank versus those created by fraudsters, making it more difficult for them to spot fraudulent transactions,” said Tim Phipps, vice president of product marketing, Identity Assurance with HID Global. “With our ActivID Trusted Transactions solution, banks can offer far more convenient out-of-band transaction notification and authorization on mobile devices, which provides customers real-time alerts prior to a suspicious transaction being applied to their account. This places the control back in the customer’s hands by providing them with simple way to confirm the legitimacy of a pending transaction.”

Financial institutions using mobile banking channels have typically relied on simple passwords or out-of-band transaction verification based on one time passwords (OTP) tokens sent via SMS to customers’ mobile devices. Cybercriminals have attacked the end-user’s web browser or this insecure OTP authentication method with SMS malware to take over accounts and make unauthorized transactions, such as large money transfers. These attacks use a variety of phishing, vishing, SMS malware, man-in-the-middle and man-in-the-browser techniques and have eroded consumer confidence in digital banking.

ActivID Authentication Server

To solve this problem, HID Global’s “phone as a token” out-of-band verification solution uses transaction signing with private key cryptography over a trusted and secure electronic channel. All communication is encrypted with mutual authentication between the user’s mobile device and the financial institution’s online banking application. Transaction non-repudiation is ensured by generating the private key outside the financial institution’s backend system and then protecting it to prevent extraction, cloning or access from another application. When a transaction is initiated, the ActivID Authentication Server uses its Mobile Push capability to send an authorization notification to the user’s registered mobile device with all relevant information and a request to accept or reject it using the server’s ActivID Mobile Signing Software Developer Kit (SDK). Signed responses are returned to the server, which validates and forwards them to the online banking system to grant or deny transactions.

"Trust, total cost of ownership (TCO) and user experience (UX) vary among individual phone-as-a-token methods. Out-of-band (OOB) authentication using push modes offers the best balance of trust and UX, making it the best choice across many use cases," said Ant Allan, analyst with Gartner.

Availability

HID Global’s ActivID Trusted Transactions with Mobile Push capability is available now with the company’s latest ActivID Authentication Server v7.3 release.

Share with LinkedIn Share with Twitter Share with Facebook Share with Facebook
Download PDF version Download PDF version

HID Global news

ISC West 2019 Day Two: Explaining The New And The Tried-And-True

There are many new technologies at ISC West this year. There are also some tried-and-true solutions on display. More mature products have the benefit of being fully vetted and battle-tested, which may make them a more comfortable choice for security customers. I had a couple of discussions on Day 2 of the show about the advantages, and possible drawbacks, of new products. “To a security director, when you say ‘new,’ he translates that into ‘risk,’” says Bill...

Mail.Ru Selects HID Global For Enabling Secure Access Control Using Smartphones

HID Global, a trusted identity Solutions Company announced that Mail.Ru has chosen its HID Mobile Access solution for secure and convenient access control using smartphones and other cellphone devices. Need for access control Mail.Ru reaches over 91% of all Russian internet users via its mail platform and social networks. The company has more than 7,000 employees and a high volume of visitors to its Moscow offices, necessitating an access control solution that provides best-in-class secur...

Genea Officially Joins HID Global’s Advantage Partner Program

Genea Energy Partners, Inc. (Genea), a Software-as-a-Service (SaaS) company specializing in cloud-based building technology systems, announced its partnership with HID Global through its participation in the HID Global Advantage Partner Program. The program provides Genea optimal integration of its non-proprietary Access Control system with HID Global’s physical access control cloud platform, HID Origo. “HID Global has been and continues to be a trusted partner in the identity...

HID Global case studies

HID Global Civil Registry Solution Advances Antigua And Barbuda’s Transformation To A Digital Society

HID Global, an identity solutions company announces that Antigua and Barbuda have deployed HID® Integrale™ for CRVS to modernize the country’s civil registry system. The solution helps the country embark on a digital transformation by enabling the secure registration and reporting of life events of residents and visitors, and offers a single, true source of verifiable identity information. The Government of Antigua and Barbuda (GOAB), the Ministry of Information, Broa...

HID Global Deploys Its Secure HID Integrale End-To-End Solution For Libya’s First Diplomatic And Special ePassport Program

HID Global, the globally renowned company in trusted identity solutions, has announced that it has deployed the government of Libya’s first diplomatic and special ePassport program. HID Integrale HID Global provided Libya’s Ministry of Foreign Affairs (MOFA) with HID Integrale, a secure end-to-end solution that expedites the application and issuance processes and manages the entire ePassport lifecycle. For improved security, the redesigned and modernized booklets include a durable...

Access IS Delivers Contactless Transit Payment Solutions For Storstockholms Lokaltrafik To Secure Stockholm’s Public Transport

Access IS, part of HID Global, is delighted to celebrate the successful launch of contactless payments across the Stockholm region by SL (Storstockholms Lokaltrafik). Building on the successful mass deployment of Access-IS ticket readers and validators back in 2019, the latest upgrade to the system sees Access-IS devices in train gates and ticket offices as well as bus mounted validators being upgraded to permit full cEMV contactless payment capability. Contactless ticketing Ticket reading is...