This section describes the authentication and risk flow for an end user who is either not enrolled for advanced authentication, or does not have access to the ArcotID OTP application or the mobile device to which the ArcotID OTP credential was provisioned.
End users are authenticated as follows:
The resulting help page provides three links to enroll for advanced authentication, reset PIN, and perform roaming authentication.
Note: If security question was used the first time, then security code is used in this step. Conversely, if security code was used the first time, then security question is used in this step.
Notes:
For example, if security question or security code over email is enabled for roaming authentication, and security question or security code over SMS is enabled for risk authentication, and if the end user selects security question first and is authenticated successfully, they are not authenticated again during the risk flow. However, if the end user selects security code over email the first time and is authenticated successfully, then in the risk flow, the user is authenticated again using security question.
In another example where security question or security code over email is enabled for roaming authentication, and security question and security code over SMS are enabled for risk authentication, if the end user selects security question in the roaming flow and is authenticated successfully, then in the risk flow, the security code over SMS method is invoked. However, if the end user selects security code over email in the roaming flow, then both security question and security code over SMS are invoked in the risk flow.
A DeviceID is recorded on the end user's device. During subsequent logins, the risk history is used to decide whether to grant access to the end user after authentication.
|
Copyright © 2012 CA.
All rights reserved.
|
|