
Mega AS solutions include:
- The CAT package for enterprises that what to install the CAT Authentication Server in-house.
- The eAuthentication service for SMEs that do not wish to install the CAT in-house but would rather use an Internet based Authentication service. The service is currently free. |
CAT (Cellular
Authentication Token)
The CAT package includes two main components:
CAT Mobile Token – A Java™
based program that is installed and activated on the mobile device.
Once activated, this program will generate a unique One Time Password
(OTP) for each new login session.
CAT authentication server – A software server that
resides at the Internet site server. It includes software API that supports banking industry standards. The authentication
server authorizes the user's incoming login request.
To try our demo product Click here
.
To contact our sales department click
here.
Advantages
- Simplicity
- Does not require any proprietary device
- The authentication process does not require any communication and
therefore it is faster and low cost.
- Security: there is no transmission of any sensitive data, not even
of a one-time password.
- The process allows for multiple PIN strings and multiple different
Authentications for different services in one device.
- To actually get the Authentication code, the user has to know the
PIN. (Not just hold the device).
- Does not require carrying additional Token for security purposes.
- Mega AS Ltd TFA runs on Mobile Phone, Palms, PDA, and Pocket
PC.
- Supports roaming and the traveling business man.
Competitive analysis
SMS for OTP concept weaknesses:
- It requires Over The Air (OTA) connection. In some places there is
no signal.
- The transmission is simple text and can be hacked.
- Somebody else can retrieve last received SMSs from the Mobile Phone
menu and reuse the SMS OTP.
- There is no guarantee to the span of delivery. The password may take
minutes and even longer to arrive due to air network congestion.
- Roaming features for traveling. Not all SMS can be received abroad.
- There is no authentication as to who is holding the cellular when the
password is sent to it. It could have been stolen.
- There is an ongoing cost for organization for each SMS sent out to end-user.
- There is administration involved in case of changing cellular numbers.
- Does not work on Palms or Pocket PCs.