APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Datablink Inc.

Lawrence Ang, Vice President, APAC Sales

Redefining Stronger Authentication for 21st Century

Lawrence Ang

Lawrence Ang

As the threat landscape constantly evolves and especially more rapidly in the last 5 years over the internet highway, the Authentication Industry need to constantly redefine with urgency what stronger authentication means and what new features needto be incorporated into the hardware and software tokens with affordability in mind so that its purpose can still stand relevant in the 21st Century.

OTP Tokens

Back in the 90s, the first concept of strong authentication is that a one-time password is proven to be more secure than a static password, especially a user-created password, which is typically weak. “Transaction Signing is a term used in Internet Banking that requires customers to digitally “sign” transactions in order to preserve the authenticity and integrity of the online transaction.”

A one-time password (OTP) token, which is a key fob that flashes a new number every few seconds that acts as a password.

The Authentication Industry soon learnt that a key fob can be subjected to social engineering hack where the hacker (for example pretends to be a bank officer) asked you to read the OTP from your key fob to verify your account.

Certificate-Based Tokens

PKI Tokens or Smart card tokens or Certificate-based authentication employs public key cryptography to generate public and private keys. Private keys may be stored on a portable device, such as a USB drive, or stored safely on a user’s computer.

Most people have heard that 1024 bit RSA keys have been hacked and not used any more for websites or PGP. So, there is a need for 4096 bits and above. Also, there are issues with certificate expiration.

From security point of view, USB PKI-based tokens can also introduce all kinds of security issues as USB can be used to introduce Trojans into the network or laptop. Also, there can be the weakness in client software that circumvent the token’s security and diminishes their effectiveness.

In addition, the cost of implementing certificate-based authentication (PKI or Smart Card Tokens) is multiple times more (single digit dollar times at least) expensive than  OTP tokens making it difficult for large scale deployments like in internet banking.

Context Based Tokens

Context-based authentication uses information about a user, such as geographical location to authenticate them. Context-based authentication is generally used in conjunction with other authentication methods. For highly secure environments, for example, a user may be required to provide a username, password, OTP and pass verification on the geographical location of the device initiating the session. Other techniques include device registration or fingerprinting, source IP address reputation and behavioral analysis.

Context Based Tokens especially Biometric Scanners are the most expensive as a high end processor is needed as the base of such a scanner. The cost of implementing Biometric Token solutions will easily run into double digits dollars times per token.

Internet Based Attacks change Stronger Authentication Concepts

In recent years, there is some debate within the information security community about the reliability of OTP tokens, Certificate-based Tokens or Context-based Tokens for authentication. Critics claim a hacker can defeat the device with a man-in-the-middle (MITM) attack, which is when a hacker intercepts the token value (regardless of whether it is OTP tokens, PKI Tokens or Biometric) in real time, along with the user ID and password from a targeted phishing site.

In the latest draft version of its Digital Authentication Guideline in July 2016, the United States National Institute of Standards and Technology (NIST) is also discouraging companies from even using SMS-based authentication in their two factor authentication schemes.

The reason is that there has been a significant increase in attacks targeting SMS-based two-factor authentication recently. SMS messages can be hijacked over some VoIP services. Security researchers have used weakness in the SMS protocol to remotely interact with applications on the target phone and compromising users. One example is that the malware can be implantedonto an Android Smartphone to redirect the SMS OTP to the hacker phone.

Major Features of Next Generation Advanced Authentication

Transaction Signing is a term used in Internet Banking that requires customers to digitally “sign” transactions in order to preserve the authenticity and integrity of the online transaction. While performing any of the above online transactions, you will obtain a challenge code.

So, the next generation strong authentication hardware token needs to incorporate a cost efficient and energy efficient optical sensor (as an example instead of a keypad type of hardware token) to change the dynamics of inputting the transaction data into the token so that it can be used to generate the Transaction Signature (like the OTP) without much hassle like when the keypad is locked.

The next generation strong authentication software tokens needs to incorporate at least one of these useful features like QR Code (in the event if there are no Telco connections at that instant); Push Technology that accepts or declines a transaction with a push of a button (with tokens verified and embedded with the push feature) and/or Secure Messaging (to provide enhanced user experience with much reliability and reliable online marketing to their client base compared to SMS).

Any vendor(s) that can incorporate these two types of next generation strong authentications for hardware and software tokens in their product portfolio will ultimately be the clear winner in this strong authentication space for the 21st century.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    ISS Facility Services Australia & New Zealand

    The Right Technology And Reliable Partners; The Business Next Frontier

    Luke O'Brien, CIO

  • Willis Towers Watson

    BPAY Group

    Building BPAY Group's New Digital Foundation

    Angela Donohoe, Chief Information Officer

  • Willis Towers Watson

    Bvn Architecture

    How Have Recent Advancements in Big Data Been Impacting Businesses?

    Marc Solomon, CIO

  • Willis Towers Watson

    Tassal Operations

    BI & Analytics in Aquaculture

    Matthew Leary, CIO

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cyber-security.apacciooutlook.com/leadership-perspective/redefining-stronger-authentication-for-21st-century-nwid-3253.html