Overview

Features:

The OCRA Token serves an important function as a PIN protected offline time or event based authentication token but it can also be utilized as a tool for digital signing of online transactions. When performing an online banking operation a user can enter the account details and the intended amount of funds into the OCRA keypad, the device will take this information along with the time and the user's unique key to generate and attach a digital signature to the exchange, ensuring that any unwarranted third party data modification will immediately be detected.

It offers Secure Digital Signing with:

Cross Validation                                                                                         

The OCRA challenge response process can be used to authenticate the identity of users in a variety of situations not strictly limited to online, for instance over the telephone, the process of deriving a seed based response from a specific challenge sequence can be used to validate the identity of a token operator. This identification interaction can be used to authenticate the validity of the institution or organization requesting personal information from the token operator as well.

'Dual Authentication' confirms the legitimacy of a website or server

Before a password is revealed the user must satisfy the challenge factor presented by the token. The challenge response system is based on a shared secret key which can also be used to verify the legitimacy of a website or server requesting personal information from a token user. "Dual Authentication" as this process is known, is becoming an ever more important precaution as instances of illegitimate data requests from cleverly constructed imposter sites are steadily on the rise.

 Specification:

User Interface 8-character high contrast LCD display
Built-in keypad
Security Algorithms OATH compliant challenge-response OCRA
Memory Type Random Access Memory (RAM)
Endurance More than 10,000 clicks
Battery Lifecycle 5 years
Operating Temperature -10°C ~ 50°C
(14°F ~ 122°F)
Storage Temperature -20°C ~ 70°C
(-4°F ~ 158°F)
Humidity 5% ~ 90% without condensation
Physical Resistance Tamper evident
IP54 ingress protection (under evaluation)
*Feature varies according to product model

Certification& Compliance

        •  OATH OCRA Compliant
        •  RoHS
        •  CE FCC
        •  WEEE

Benefits:

Multiple high level security featured based on one PIN centric OTP device

Enjoy the benefits of having a single hardware device which can provide on board clock (time) based one time password (OTP) unique log-on credentials, in addition to the challenge and response (OCRA) code for sophisticated two way authentication between entities with knowledge of the unique key, in addition to the secure signing of data, transactions, emails, or other sensitive information.

Dynamic Password as established through a Challenge and Response

OCRA Token by Feitian can generate a dynamic one time password (OTP) in response to a challenge factor sent by an authentication server. The dynamic challenge-response algorithm, responsible for password sequence creation, which serves as the foundation of OCRA Token is based on the criteria of the Open Authentication consortium of open source security providers. Before a password is revealed the user must satisfy the challenge factor presented by the token. The challenge response system is based on a shared secret key which can also be used to verify the legitimacy of a website or server requesting personal information from a token user.

Available as part of a complete solution with FEITIAN FOAS

FEITIAN OATH Authentication Server (FOAS) is a trusted and secure back end server engineered to operate seamlessly with all FEITIAN products. Utilizing OCRA Token as part of a complete solution saves organizations on IT overhead, maintenance, and upkeep.

OATH based algorithms interoperate with any compliant back end server

As a member of the Open Authentication consortium FEITIAN Technologies Co. Ltd. manufactures products that are fully interoperable with back end authentication systems engineered to comply with the international OATH standards.

Features:

      • Multi-functional PIN protected token provides higher security feature
        • PIN protected device. After a limited number of invalid PIN login, the device is blocked automatically.
        • Support secure remote token unblock mechanism
        • Dynamic password generation uses both the challenge code from authentication server and time factor. Multi-factor algorithm brings higher security than single -factor dynamic password.
        • Transaction signature protects the integrity of transmitted data
        • Server authentication guarantee the validity of service provider to prevent fraud attack
        • Two-way authentication brings higher security for both the application server and the end-users
      • OATH compliant challenge-response OCRA token
        • Compliant with OATH open algorithm
        • Easy to be integrated with 3rd party OATH authentication system
        • PSKC format seed code available
      • Easy to use and portable
        • Zero software install at client side
        • Zero footprint authentication
        • Simple one-click to generate the one-time-password
        • Independent to end-user environment. No external connection is needed
        • Compact casing design. Easy to carry
      • OTP hardware token with built-in PIN pad
        • Large buttons PIN pad
        • High contrast LCD display
        • Accurate Real Time Clock (RTC)
        • Non-replaceable built-in battery
        • Secure Random Access Memory (RAM)
        • Unique token serial number
      • Secure, robust and long life hardware design
        • Battery lifetime expectancy 5 to 7 years
        • Seed code stored with encryption and protection
        • Tamper evidence
      • Flexible customization options
        • Customizable pass code length and welcome screen
        • Customizable OTP refresh frequency (for time based algorithms)
        • Faceplate, casing color and serial number customizable
        • Customizable industrial and end-user packaging
      • Highly applicable device supports FOAS server
        • Protect application servers of computer system, such as computer login, network login, WLAN login, server login, Website login, mail system login, database login and other application server login.
        • Protect network devices such as routers, exchange servers, firewalls, VPNs, as far as the device supports RADIUS protocol for authentication.
        • Protect application servers of telephone networks, such as telephone banking, telephone stock market and telephone shopping etc.
        • Protect application servers of mobile phone networks, such as mobile phone banking, mobile phone stock market and mobile phone shopping etc.
        • Protect application servers of digital TV (DTV) networks, such as DTV banking, DTV stock market, DTV gaming and DTV shopping etc.
        • Broadly used in finance, insurance, taxation, customs, business, offices, education and entertainment areas with no special request on application server terminals.

About us

 Ro Interactive Technologies has been active in the field of software protection and security for business since 1994. For more details contact us here!

 Phone:004 0264-418929

 Mobile: 004 0744-799248

 e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

Go to top
Cookies make it easier for us to provide you with our services. With the usage of our services you permit us to use cookies.
Ok Decline