Oracle® Adaptive Access Manager Concepts Release 10g (10.1.4.5) Part Number E12049-03 |
|
|
View PDF |
Device registration is a feature that allows a user to flag the computer he is using as a safe device. The customer can then configure the rules to challenge a user that is not coming from one of his registered devices.
Device registration is available as a standard feature in Oracle Adaptive Access Manager. The feature can be turned on, although it is off by default in the product.
Adaptive Strong Authenticator and Sample (an application that is packaged with Oracle Adaptive Access Manager as an example for customers) have a property driven feature that allows device registration for users. When the property is set to true, configurable messaging and a checkbox appears on the challenge screen under the QuizPad. For information on enabling the device registration feature, refer to the Oracle Adaptive Access Manager Developer's Guide.
The device registration text and checkbox is only shown during the login flow challenge. By default the checkbox will be checked; however, this default state will be configurable via properties. When the checkbox is checked, the device is added to the user's profile as a registered device. If a device is already registered, the checkbox and messaging is not displayed on the screen.
If a user chooses not to register a device (un-checks the box) and then logs in successfully, the next time he logs in with that device, the box will be unchecked. The User Preferences page will contain actions to unregister the current device and one to unregister all his devices.
A rule to check for registration is available in Oracle Adaptive Access Manager. This rule triggers if the device has been registered in the past by the current user. Also, a rule is available to check if a device has been used before by this user and is not registered. A model containing these rules is available as part of the base models package. This model will be disabled by default so users can enable it only if they want to use device registration.