User's Manual
9
2.4.3 SMS
The SMS-based protocol, in short WebSMS, has been developed for all those cases in which it is not possible to use the
WebOTP hardware device, because of damage, loss or simply because a USB connection is not available for connecting
it.
Via this protocol the server sends the user an SMS containing a code consisting of letters and/or numbers which the user
will be able to use for authenticating.
2.5 Multi-factor authentication
WebOTP is a device that guarantees a state-of-the-art authentication but which cannot guarantee security against such
events as theft of the device by itself.
In such cases it is advisable to complement the authentication provided by WebOTP with a second authentication
factor. The most common case is using a numerical PIN with a limited number of attempts before being disabled.
The SDK of WebOTP just provides the necessary services for WebOTP authentication and leaves maximum freedom in
choosing further authentication factors.