Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

OATH: One Token To Rule Them All: Page 3 of 3

IT departments looking to roll out multifactor authentication to internal users would do well to look into OATH-based offerings. While corporate choices aren't as well fleshed out as VeriSign's e-commerce program, the comprehensive OATH framework and large number of companies developing to it show the promise of an increasing number of compelling and competitively priced products over the next few years. Two OATH-based products available now are from Innovative Card Technologies and Authenex.

TIMELINE: OATH
April 2004
IBM, Gemalto, VeriSign, and others meet to lay out a governance structure

February 2005
Nine vendors demonstrate compatibility among their OATH products at the RSA conference

December 2005
RFC 4226 "HMAC One-Time Passwords" approved as standard by IETF
June 2007
PayPal starts distributing its Security Key using OATH-based tokens and VeriSign service
September 2007

Reference Architecture 2.0 released, with authentication based on risk scoring

December 2007
Sixth revision of draft spec for OATH Challenge Response Algorithm submitted to IETF

--Avi Baumstein ([email protected])

More Strategic Security:
Stop! There Goes My Phone!