Checklist for Enabling Challenge Questions Ensure Policies are Available Ensuring KBA PropertiesDefault Properties are Set Ensure Challenge Questions are Available

8-6 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager 9 Setting Up OTP Anywhere 9-1 9 Setting Up OTP Anywhere OTP Anywhere is a secondary risk-based challenge solution consisting of a server generated one time password delivered to an end user via a configured out of band channel. Supported OTP delivery channels include short message service SMS, email, instant messaging and voice. OTP Anywhere can be used to compliment KBA challenge or instead of KBA. As well both OTP Anywhere and KBA can be used alongside practically any other authentication type required in a deployment. Oracle Adaptive Access Manager also provides a challenge processor framework. This framework can be used to implement custom risk-based challenge solutions combining third party authentication products or services with OAAM real-time risk evaluations. This chapter focuses on setting up Oracle Adaptive Access Manager to use OTP for secondary, risk-based user challenges. Out of the box, OAAM provides User Messaging Service UMS as the delivery method. For other custom methods, refer to the Developing Custom Challenge Types chapter of the Oracle Fusion Middleware Developers Guide for Oracle Adaptive Access Manager.

9.1 Introduction and Concepts

This section introduces you to the concept of One Time Password OTP and how it is used in Oracle Adaptive Access Manager.

9.1.1 What is a One Time Password

A one-time password is a randomly generated, single-use authentication credential. OTP is a form of secondary authentication that is used in addition to standard user name and password credentials to strengthen the existing authentication and authorization process, thereby providing additional security for users. When the user is OTP-challenged, a one-time password is generated and delivered to the user through one of the configured channels. The user must retrieve the one-time password and enter it when prompted, before the one-time password expires. The one-time password may be either numeric or alphanumeric and any configured length and the randomization algorithm is pluggable. The following are major benefits of using out-of-band OTP: ■ The one time password is delivered to the valid user through one of the configured channels. These can include SMS, IM, email or voice. ■ The user does not require any proprietary hardware or client software of any kind.