Assurity to offer extra layer of digital protection
It strikes deal with V-Key to deliver a new form of authentication via the latter's mobile soft token application called V-Tap
Singapore
ASSURITY Trusted Solutions, owned by Government Technology Agency (GovTech), signed an agreement on Tuesday with V-Key, a leading player in digital mobile security solutions, to deliver a new form of authentication via V-Key's mobile soft token application called V-Tap.
Assurity manages the National Authentication Framework (NAF), an initiative to strengthen cybersecurity through identity and access authentication. Singapore-headquartered V-Key is accredited by the Infocomm Media Development Authority (IMDA).
V-Tap will provide a new level of security for consumers who use commercial online services delivered through NAF. This includes securities trading firms, banks and insurance companies. The mobile soft token will be offered in addition to Assurity's hardware and SMS authentication solutions.
Assurity will start implementing the new soft token solution by the end of February. The company is in talks with its customers to implement this new authentication solution.
Users will have to download the new V-Tap enabled OneKey mobile app onto their mobile device and enrol with a registration code. This effectively binds their identity to their mobile device after which they can authenticate themselves and authorise transactions by means of the soft token.
The software token from V-Key is also deployed by top banks in Singapore. It combines the security of hardware tokens with the convenience of SMS-based One-time Password (OTP). Unlike SMS-based OTPs, however, soft token-based OTPs are able to work offline and do not require mobile network connections, eliminating latency and delivery issues.
V-Tap is built on top of V-OS, V-Key's virtual secure element, which the company says equals or betters smart chip security specifications.
According to Assurity, the authentication framework offers robust protection for its application, including multi-layered protection against advanced threats targeting mobile applications. Besides being a layer of security, the soft token authentication solution can also be easily migrated to a new mobile device in case of loss, or change of the device.
The company added that if a person loses or replaces their phone, they should contact their service provider to reactivate the application on their new phone. Reactivation will deactivate the old application on their previous phone and is a secure and yet easy process. Compared to a hard token limited by battery life, a soft token app can be upgraded over time and requires next to no maintenance and very little cost.
Assurity CEO Charles Fan noted that with cyberthreats becoming more sophisticated and an increasing number of people accessing their online accounts via mobile applications, there is a need to outpace these threats and provide end-users with a highly secure and yet convenient authentication option.
"The launch of this new soft token solution underscores our commitment to constantly seek safe and innovative solutions that cater to consumers' security and lifestyle needs, such as enabling quick access to multiple online services with the use of a single authentication device," he added.
Benjamin Mah, V-Key's CEO said: "We are meeting the demands for heightened mobile security in Singapore's Smart Nation drive. The new authentication solution exemplifies a global standard of convenient security in software, as it will allow users to access online services safely and securely, from any location. This authentication solution enables the end-user to log into e-services almost instantaneously."
Edwin Low, director of accreditation@IMDA added: "V-Key's solutions are heralding a new phase in security by providing a deep security layer around the app itself. With the smartphone rapidly becoming a primary channel for organisations and consumers alike, the need to secure the mobile apps has become more important."