

CA CloudMinder Advanced Authentication › How Advanced Authentication Works › End User Authentication Flows › ArcotID OTP Flows › ArcotID OTP Roaming Flow
ArcotID OTP Roaming Flow
This section describes the authentication flow for an end user who is either not enrolled for advanced authentication, or does not have access to the ArcotID OTP application or the mobile device to which the ArcotID OTP credential was provisioned.
End users are authenticated as follows:
- When trying to access a protected resource in a browser, the end user is prompted for their user name and OTP.
- The end user clicks the Help icon next to the One Time Password field.
The resulting help page provides three links to enroll for advanced authentication, reset PIN, and perform roaming authentication.
- The end user clicks the My phone is unavailable link to perform roaming authentication.
- On the resulting page, the end user is prompted for their user name.
- If the user name is valid, the end user is prompted for secondary authentication using the security question or security code mechanism.
- If the authentication is successful, then depending on whether two-step authentication is enabled or not, either of the following steps take place:
- If two-step authentication is not enabled, an ArcotID OTP credential associated with that end user is provisioned to the web browser store, and the end user is prompted for their PIN.
- If two-step authentication is enabled:
- The end user is authenticated again using another form of secondary authentication.
Note: If security question was used the first time, then security code is used in this step. Conversely, if security code was used the first time, then security question is used in this step.
- If the verification is successful, an ArcotID OTP credential associated with that end user is provisioned to the web browser store, and the end user is prompted for their PIN.
- If the PIN is correct, a JavaScript client on the end user's device implicitly generates an OTP and sends it to the Advanced Authentication service.
- The Advanced Authentication service verifies the OTP and authenticates the end user.
- If authentication is successful, the end user is granted access to the resource.
Copyright © 2012 CA.
All rights reserved.
 
|
|