Token Types and Usage
There are four types of tokens:
- Static password.
- Synchronous dynamic password
- Asynchronous password
- Challenge response
This article currently focuses on synchronous dynamic password tokens.
The simplest security tokens do not need any connection to a computer. The client enters the number to a local keyboard as displayed on the token (second security factor), usually along with a PIN (first security factor), when asked to do so. Being disconnected from the authenticating server, however, renders such tokens vulnerable to man-in-the-middle attacks.
Virtual Token MFA is a newer token concept introduced by the security company Sestus in 2005. Virtual token MFA is fundamentally different from "soft" tokens in that soft tokens require the deployment of software to end users, while virtual token MFA does not.
Other tokens connect to the computer using wireless techniques, such as Bluetooth. These tokens transfer a key sequence to the local client or to a nearby access point.
Alternatively, another form of token that has been widely available for many years is a mobile device which communicates using an out-of-band channel (like voice, SMS, USSD). Like physically disconnected tokens, out-of-band delivered tokens are also vulnerable to man-in-the-middle attacks.
Still other tokens plug into the computer. For these one must:
- Connect the token to the computer using an appropriate input device.
- Enter the PIN if necessary.
Depending on the type of the token, the computer OS will then either
- read the key from token and perform cryptographic operation on it or
- ask the token's firmware to perform this operation
A related application is the hardware dongle required by some computer programs to prove ownership of the software. The dongle is placed in an input device and the software accesses the I/O device in question to authorize the use of the software in question.
Read more about this topic: Security Token
Famous quotes containing the words token, types and/or usage:
“The token woman carries a bouquet of hothouse celery
and a stenographers pad; she will take
the minutes, perk the coffee, smile
like a plastic daisy and put out
the black cat of her sensuous anger
to howl on the fence all night.”
—Marge Piercy (b. 1936)
“Our children evaluate themselves based on the opinions we have of them. When we use harsh words, biting comments, and a sarcastic tone of voice, we plant the seeds of self-doubt in their developing minds.... Children who receive a steady diet of these types of messages end up feeling powerless, inadequate, and unimportant. They start to believe that they are bad, and that they can never do enough.”
—Stephanie Martson (20th century)
“...Often the accurate answer to a usage question begins, It depends. And what it depends on most often is where you are, who you are, who your listeners or readers are, and what your purpose in speaking or writing is.”
—Kenneth G. Wilson (b. 1923)