< Back to Security information for Smart ID Mobile App
Excerpt |
---|
Online authenticationOnline Authentication | Security Features |
---|
Image Modified | - Smart ID Messaging
- Messaging server (Hermod) which provides a secure communication channel between the Mobile App/SDK and server-side components for Identity Management, Digital Access, Digital Signing and so on
- Messaging server actively takes part in an Online PIN process (see section "Distributed security model") invoked in online scenarios where the private key needs to be used in a cryptographic process (Not applicable for offline OTP scenarios)
- HTTPS communication based on TLS with server side authentication
- Verification
- Session verification by verification images being displayed both on server side and in the Smart ID Mobile App
- Certificate pinning
- Provides means to control that the Smart ID Mobile SDK can only communicate with a dedicated Messaging server
|
|