The DIGIPASS secrets are stored on DIGIPASS 110, not on a computer. A Java applet on the PC creates, together with the secrets stored on the USB stick, time-based one-time passwords that are validated by VACMAN Controller. This zero-footprint approach meets large volume e-commerce and retail e-banking market requirements.
DIGIPASS 110 reduces data security concerns associated with online purchases, password sharing, account access, and financial transactions. By replacing static passwords with a solution that generates dynamic one-time passwords and electronic signatures, organizations are able to secure access to their critical applications without impacting the customer’s user experience.
DIGIPASS 110 cryptographic functions can only be used in conjunction with the java-applet that the end-user downloads on his PC. Cryptographic keys always remain in the DIGIPASS 110 USB stick.
The applet design prevents the most advanced man-in-the-middle attacks (including real-time man-in-the-middle attacks).