SAP Brief Mobile Services from SAP SAP Authentication 365 Objectives Protect Your Customers and Brands with Multichannel Two-Factor Authentication
Protecting your most valuable asset your customers Protecting your most valuable asset your customers As the digital world experience evolves, so does the need to protect the identity and account data of enterprise customers, who expect a secure digital experience from businesses. The SAP Authentication 365 mobile service enables multichannel two-factor authentication, adding another layer of security to customers online accounts, beyond their login and password. The growing use of mobile and cloud-based services significantly increases the probability of companies experiencing a costly data breach, with some estimates suggesting that 30% to 50% of online accounts have been breached over the past two years. Two-factor authentication (2FA) has been demonstrated to reduce online account hacks and help prevent fraud. Today, SMS-based 2FA and multifactor authentication are primary ways to verify an online user s identity when resetting passwords, authorizing account access, and validating transactions. Our multichannel authentication, including SMS-based and CaaS authentication service, provides a simple yet highly secure method for validating a variety of online and mobile transactions for online commerce, financial services, and more. 2 / 8
The SAP Authentication 365 mobile service simplifies the fortification of online and mobile engagement environments. The service enables you to configure tokens such as one-time passwords (OTPs), personal identification numbers (PINs), and verification codes that are tailored to businesses and particular use cases. The authentication service generates secure tokens that are based on SAP s implementation of industry standard security algorithms. To simplify integration into your security solution or Web site, SAP provides a RESTful API cloud service for both token generation and token authentication. We also provide an administrative user interface that allows you to establish default token configurations. Additionally, our authentication service provides robust analytics. This gives you the ability to monitor authentication token requests and spot geographic or contextspecific situations to improve the identity authentication process. Continued on next page 3 / 8
A complete 2FA solution is composed of an application-to-person (A2P) messaging service that combines extensive global reach, operator-approved routes, scalability, and local expertise and an authentication service with secure, geographically redundant servers for generating and authenticating industry standard tokens. See the figure on the next page. SAP provides an end-to-end 2FA solution that includes an API for token generation and an extensive network to deliver SMSs. 4 / 8
End-user customer 2:55 MESSAGES 10936 Your one-time Enterprise Mobile services from SAP passcode is: 5AY2A7e9 Reply 4 Authentication token entered 3 Authentication token generated and sent via SMS 6 Access granted if token valid 5 Token authenticated; status to enterprise SAP Mobile Services Global enterprise messaging network 1 User ID authentication triggered; please enter code 2 Authentication token requested Figure: Two-Factor Process Flow 5 / 8
SAP Authentication 365 uses SMS-based two-factor authentication. It can work with SAP SMS 365, enterprise service, or with any SMS solution our customers may have in place. With its unique combination of API and SMS interconnection, our authentication service supports a variety of use cases across all industry segments. Our service delivers verification codes and one-time passwords and PINs via SMS to authenticate user identity. This functionality gives enterprises a low-risk solution that offers greater confidence in your online service, leading to higher customer satisfaction, loyalty, and sales. In addition, SMS costs less and is faster to implement than traditional hardware- or software-based solutions. SMS also allows enterprises to deliver messages across geographies and, since it is available on all devices, enables ubiquitous coverage for all customers. To help ensure speed and reliability in SMS delivery, the service uses an advanced mobile number resolution system in conjunction with high-quality, mobile operator approved routes for message delivery and fail over. SAP Authentication 365 offers a flexible design that enables customized, transaction-level authentication services. 6 / 8
Simplifying authentication for the digital world Simplifying authentication for the digital world With the SAP Authentication 365 mobile service, SAP Mobile Services, a division of SAP, has delivered a simple, secure, reliable multichannel end-to-end solution that helps protect your customers as well as your brand. The authentication service uses the reach and power of SAP SMS 365, enterprise service, to provide you with a simple, high-quality identity authentication service that can be deployed quickly with minimal disruption to your digital operations. SAP SMS 365, enterprise service, combines extensive global coverage, high-quality delivery, and a comprehensive feature set that enables enterprises to engage with customers using SMS. Available from SAP Mobile Services, this SMS delivery service removes the complexity from developing and implementing SMS-based mobile services. Key benefits of enabling two-factor authentication with mobile services from SAP include: Broad reach in application-to-person (A2P) SMS services, with over 980 mobile operators in over 200 countries Reliable service and accurate delivery of messages due to high-quality, mobile operator approved routes and number resolution functionality Service transparency via robust reporting, which includes standardized delivery receipts, authentication token requests, and token authentication confirmations 7 / 8
www.sap.com Objectives Summary The SAP Authentication 365 mobile service is an end-to-end service that enables you to implement a multichannel two-factor authentication (2FA) service quickly and securely, with authentication tailored to your digital business. It helps protect the identity and data of your enterprise customers by enabling authentication via SMS. RESTful API from SAP simplifies generation and authentication of tokens such as one-time passwords. Objectives Deliver a secure online experience to customers to drive trust and customer value Strengthen security with two-factor authentication Validate digital and mobile transactions End-to-end SMS-based and multichannel two-factor authentication service for confirming identities simply and securely Simple RESTful API for requesting generation and authentication of 2FA tokens High-quality, mobile operator approved routes for fast and secure SMS delivery Administrative user interface for configuration and analytics Reduced risk of identity theft and fraud Greater confidence in security of digital transactions Improved user loyalty and trust Increased security of business critical systems and data Learn more To learn more about this service and how your business can benefit, visit www.sap.com/sapmobileservices. 8 / 8 Studio SAP 40012enUS (15/09)
No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forward-looking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions.