Sarah Lefavrais | IAM Product Marketing Manager
More About This Author >
Sarah Lefavrais | IAM Product Marketing Manager
More About This Author >
Summary: Banks deploying FIDO2 security keys at scale need a practical way to get them to employees, customers, and partners without creating more work for internal teams. Provisioning keys before they are shipped and delivering them directly to users can make large deployments faster and easier to manage.
In previous articles, I explained how financial institutions, driven by regulatory pressures and a surge in phishing attacks, are adopting the FIDO2 standard to secure their transactions and reduce frauds and data breaches.
Under the FIDO standard, various types of authenticators - from synchronized passkeys to those bound to a mobile or hardware security keys – are offering distinct benefits in terms of user convenience and assurance levels. Device-bound passkeys and especially hardware security keys, provide the highest level of assurance and are recommended by analyst and regulatory bodies for workforce authentication and strong customer Authentication. Consequently, Thales has observed major banks considering the adoption of FIDO security keys and has supported them in large-scale deployments.
Choosing a FIDO2 security key is only the start. Banks still need to work out how those keys will reach employees, customers, and partners, particularly when there is no IT team on hand to issue them.
This becomes more complicated when these users are remote and spread across different countries. Shipping from one central location can mean longer delivery times, higher costs, customs delays, and more work for internal teams receiving and redistributing devices.
Handing keys out through an IT desk may work for employees based at headquarters, but it quickly becomes impractical for a remote or international workforce. The same problem arises when a bank needs to distribute physical security keys to thousands of digital banking customers.
If keys first arrive at one central location, the bank must receive the shipment, sort the devices, and send them out again to individual users or regional offices. Banks relying on international delivery services also must account for customs, tariffs, and the delays these can cause.
Last-mile delivery can take those steps out of the logistics. A FIDO security key can be sent to the intended recipient without first being shipped to an office for manual setup. A network of fulfillment centers, like the one owned by Thales for Payment card issuance, can also allow FIDO security keys to be shipped from locations closer to the people receiving them, rather than sending every key from a single country.
This can make a considerable difference at banking scale. One large European bank needed phishing-resistant authentication for digital banking customers who could or prefer not to use a mobile app to access its banking application. Thales created authentication kits containing FIDO USB-C NFC tokens, USB-C to USB-A converters, key cords, and manuals. In total, hundreds of thousands of kits were fulfilled and delivered to end users.
Getting a key to someone's door is not the end of the process. There is also a practical reason to reduce the work left for the user. A key that arrives blank still must be registered before it can be used. That creates another step between delivery and first login and can lead to users contacting support if they have problems getting started. The closer the key is to being ready to use when it arrives, the less work remains for both the user and the bank.
A FIDO2 security key needs to be linked to the right user before it can provide the assurance the bank expects from it. NIST calls this authenticator binding, where a specific authenticator is associated with a subscriber account and recorded against that account. The optimal solution is using a centralized management platform that enables the FIDO key to be assigned to the end user, configured and registered to online services, as well as additional operations to effectively manage FIDO keys from activation to revocation.
Banks can handle registration to online services in different ways.
Banks do not have to use the same model for every population. A centrally managed group of privileged employees may have different requirements from a large retail banking customer base, for example.
FIDO security key delivery starts before a device leaves the manufacturer. Authenticator provisioning can take place before shipping, reducing the amount of work left for the bank or the user when the key arrives.
Pre-registration can move some of the setup away from the end user. Depending on the provisioning model, keys can arrive with less configuration left to complete, reducing the chance of setup errors and making it easier to onboard large groups of users quickly. This makes it possible to deploy phishing-resistant MFA across large user populations in days rather than weeks.
The key itself can also be customized before it is shipped. Authentication devices can carry the bank's branding and colors, while packaging can include instructions and any accessories the user needs to get started. Doing this before fulfillment means the bank does not have to manage customization and distribution separately.
Handling customization and delivery as one continuous process also avoids the coordination gaps that come from using separate vendors for design and fulfillment, where a device can be produced correctly but still stall before it reaches the user.
For customers, receiving a branded key with the information they need to use it can also build trust and encourage adoption from the moment it arrives.
By leveraging these various tools and services - such as pre-provisioning, direct shipping to the user, and customization - banks can significantly increase user adoption of FIDO2 security keys, while simultaneously improving operational efficiency and reducing costs.
To learn about the benefits Financial Services can get from Thales FIDO security keys, management tools and delivery services, consult this web page.