Strong Customer Authentication

Strong Customer Authentication is a mechanism used to authenticate a user that initiates a payment or accesses banking information via a TPP application. Authentication can be configured using two or more of the following factors to minimise fraudulent activities by preventing identity theft. It authenticates the user using the following factors one at a time:

  • Knowledge: Things only the user knows, such as passwords.
  • Possession: Things only the user has, such as ATM cards.
  • Inherence: Things only the user is, such as a fingerprint.

authentication factors

Note

In SCA, it is mandatory to use at least two of the authentication factors mentioned above.

You can enforce SCA for the WSO2 Open Banking solution with the use of authentication mechanisms supported in WSO2 Identity Server. For more information:

Info

These additional layers of authentication in SCA could lead to bad user experiences when there is no risk involved. Therefore, Transaction Risk Analysis (TRA) is introduced as a balancing mechanism between user experience and SCA.

Top