Skip to main content

Secured TOTP

Secured TOTP is a provider bound to the user device ID.

The secret key used to generate the one-time code is encrypted and can only be decrypted with a key based on the device ID. Therefore, a particular authenticator can only be registered on a single device.

Secured TOTP can be used for authentication in the following modules:

Prerequisites​

The provider requires the following conditions:

  • Secured TOTP Provider is installed.
  • The Axidian Key mobile application 2.6 or higher is installed.
  • To register Secured TOTP via a link from an email, the following is required:
    • Email OTP Provider is installed and configured.
    • The user email is filled in the Active Directory catalog.
Provider IDs for integration with the NPS Radius Extension module
{F15FD7EC-19EA-4384-846E-A2D0BE149FA2} — Secured TOTP
{882C1787-FD32-44A2-BA89-F1F529FBE7AB} — Passcode + Secured TOTP
{7F3DE86F-59D1-4476-AA5D-F277E5DD5938} — Windows Password + Secured TOTP

Install the provider​

To install Secured TOTP, run the AuthProviders.SecuredTOTP-<version number>.<bitness>.en-us.msi package from the axidian <Version number>\Axidian Providers\Axidian Secured TOTP Provider\<Version number> folder.

Important

If several Core Servers are used in your infrastructure, install the provider on all the servers of the infrastructure.

After the installation is complete, a system restart may be required. If the installation wizard prompts you to restart the system, confirm this action.

To remove or restore the product, open the Control panel menu and use the standard procedure for the supported operating systems.

Access rights​

To grant or revoke the rights to use the authenticator:

  1. In the Management Console, go to Configuration → Authenticators and select the Secured TOTP authenticator from the list.
  2. In the General settings section, configure the following:
    • In the Forbid to use setting, specify whether the user can use or register the selected authenticator.
  3. In the Actions available to the user section, configure the following:
    • In the Register new authenticators setting, specify whether the user can register new authenticators.
    • In the Edit existing authenticators setting, specify whether the user can modify the authenticators that are already registered.
    • In the Delete existing authenticators setting, specify whether the user can delete the authenticators that are already registered.
    • In the Allow editing the authenticator comment setting, specify when the user can edit the comments of the authenticators that are already registered.

Block the authenticator​

To block the authenticator:

  1. In the Management Console, go to Configuration → Authenticators and select the Secured TOTP authenticator from the list.
  2. In the Authenticator blocking settings section, configure the following:
    • Allow or block the use of Secured TOTP in case of a series of failed authentication attempts.
    • In the Number of authentication attempts before blocking field, specify how many times the user can fail authentication before the authentication method is blocked.
    • In the Blocking counter reset field, specify how many minutes must pass after a failed authentication attempt before the counter is reset.
    • In the Timeout before the sign-in method is unblocked field, specify after how many minutes the blocked authentication method becomes available again.

One-time password settings​

The settings are applied to the Axidian Access servers and allow you to define the length of the one-time password and the character groups it contains.

To configure the one-time password generation:

  1. In the Management Console, go to Configuration → Authenticators and select the Secured TOTP authenticator from the list.
  2. In the One-time password generation settings section, configure the following:
    • In the One-time password length field, specify how many characters the one-time password contains.
    • In the Digits setting, specify whether the one-time password contains digits.
    • In the Lowercase Latin letters setting, specify whether the one-time password contains lowercase Latin letters.
    • In the Uppercase Latin letters setting, specify whether the one-time password contains uppercase Latin letters.
    • In the Special characters setting, specify whether the one-time password contains special characters.

Registration in the Management Console​

Secured TOTP can be registered via a link from an email or with a QR code. Both registration methods are available in the Management Console.

Registration via a link from an email requires the following conditions:

  • Email OTP Provider is installed and configured.
  • The Axidian Key mobile application 2.6 or higher is installed.
  • The user email is filled in the Active Directory catalog.

The link is sent to the email address specified for the user in the Active Directory catalog. Optionally, you can duplicate the link to another email address, for example, to the employee manager.

To register the authenticator by email:

  1. In the Management Console, in the Authenticator registration method in the Management Console setting, select the registration by email.
  2. Specify the email subject text.
  3. Specify the email message text. The registration link is specified with the special <regLink> tag.
  4. Specify the link text to replace the explicit spelling.
  5. Then go to the Users section, select a user, and open the Authenticators tab.
  6. Click Register and select Secured TOTP from the list.
  7. In the window that opens, enter the user device ID. You can obtain it in the settings of the Axidian Key application and copy it or send it with the Share button. Optionally, at this step you can specify additional email addresses, separated by commas.
  8. Click Next. After that, the user receives an email with a link to the authenticator registration. Following the link, the user goes to the Axidian Key application, where the authenticator registration starts.
  9. In the Management Console, click Save.

The link to the Secured TOTP authenticator registration and to the Axidian Key application download can be defined manually.

  1. Go to Configuration → Authenticators, to the Registration settings section.

  2. In the Server address used to form the authenticator registration link (deeplink) setting, specify the registration link that is sent by email.

    The following registration links are available (the server location is given in brackets):

  3. In the Additional settings section, specify the link to download Axidian Key.

    The following download links are available (the server location is given in brackets):

Forced authenticator verification​

You can configure forced authenticator verification for the authenticator registration.

  1. Go to Configuration → Authenticators and select Secured TOTP from the list.
  2. In the General settings section, enable the forced verification. An additional confirmation window for entering the authentication data appears during registration.
  3. Enter the authentication data you have received and click Confirm.

Registration in the User Console​

A user can register a new authenticator in the User Console if the administrator has allowed the user to register new authenticators in the Secured TOTP settings in the Management Console.

The Axidian Key application 2.6 or higher must be installed on the user device.

To register the authenticator with a QR code:

  1. In the Management Console, in the Actions available to the user section, allow the user to register new Secured TOTP authenticators.
  2. In the Authenticator registration method in the User Console setting, select the registration with a QR code.
  3. Secured TOTP appears in the list of available authenticators for the user in the User Console.

The user must do the following:

  1. Click the gear icon.
  2. Click Register.
  3. Specify the device ID. To obtain the ID, the user must open the Axidian Key application, click the gear icon, and copy the value from the Device ID field.
  4. Scan the code that appears with the device where the Axidian Key application is open.
  5. If forced authenticator verification is configured, additionally enter the one-time password received.