Rebuilding the identity layer of the internet without breaking what already works

Authentication
Ashish Jain,

Passkeys and digital credentials are reshaping digital identity. For enterprises, the real challenge is adopting them at scale without creating disruption or additional complexity.

Our industry has reached an inflection point. Passkeys provide a modern, phishing-resistant way to authenticate without asking users to trade convenience for security. Digital credentials provide a standards-based way to establish and present verified information about who someone is. Together, they are doing something much bigger than replacing passwords or digitizing an ID card: they are helping rebuild the identity layer of the internet.

At the same time, attackers received an upgrade of their own. AI makes attacks faster, cheaper, more scalable, and more convincing. Security can no longer depend on a single control at a single moment. Organizations need active controls such as strong authentication, step-up verification, and transaction signing, combined with passive controls that assess application integrity, device risk, and suspicious behavior.

The goal is straightforward: keep bad actors out without putting unnecessary friction in the path of legitimate users.

"Authentication modernization is not a rip-and-replace exercise. It is the ability to adopt what is next without abandoning what already works."

Coexistence is the new normal

Over the past decade, the industry has built the protocols and platform support needed to move beyond passwords. Passkeys now provide a phishing-resistant authentication method that is natively supported across major operating systems and reduces the traditional trade-off between security and usability. Synced passkeys optimize reach and convenience, while device-bound passkeys and security keys are better suited for higher-assurance use cases.

Alongside passkeys, digital credentials are moving from pilot programs into production. Mobile driver’s licenses, wallet ecosystems, government-issued credentials, and emerging identity frameworks are creating new ways for people to prove who they are.

For large enterprises, however, rollout is rarely straightforward. Two realities get in the way.

The first is heterogeneity. Large enterprises now support a growing mix of hardware tokens, OTP, mobile authenticators, passkeys, security keys, transaction signing, and digital credentials. These methods do not exist because organizations enjoy complexity. They exist because the required level of assurance changes with the user, channel, device, transaction, and regulatory context. A customer using the latest smartphone is not the same as a customer calling a contact center. A routine account login is not the same as changing a beneficiary or approving a high-value payment. A workforce user on a managed device is not the same as a consumer recovering an account on a new phone. At enterprise scale, the so-called edge cases stop being edge cases. They become sizable user populations and a support ticket queue.

The second is migration. The PowerPoint version of modernization is easy: draw an arrow from the current state to the future state. The production version includes millions of users, old devices, recovery flows, call centers, partner integrations, regulatory reviews, and a business that would prefer not to stop while IT rearranges the plumbing.

Technology is only part of the challenge. The harder problem is managing the transition without making users feel abandoned. People have muscle memory. They have workflows built around how they log in and approve transactions. Rip that away in the name of modernization, and you have not modernized anything. You have created an adoption problem and a churn risk.

The better path is progressive adoption: introduce stronger and simpler experiences, give users a clear path to move, and allow existing methods to coexist during the transition. A successful migration should feel uneventful to the user. That may not make for a dramatic keynote demo, but it is usually what good engineering looks like.

Trust cannot stop at authentication

Strong authentication is essential, but it is not sufficient. An organization may successfully authenticate the right user and still be exposed if the application has been tampered with, the device is compromised, or malware manipulates the transaction after login.

Increasingly, attackers are targeting the application and session directly through mobile malware, overlay attacks, code injection, automated abuse, and transaction manipulation. These attacks do not necessarily defeat authentication. They go around it. The user may be legitimate while the application, device, or transaction environment is not.

That is why modern digital trust must combine authentication and verification with continuous protection of the application, device, and transaction. Organizations need to know not only who is interacting with them, but whether the environment around that customer interaction remains trustworthy.

Optionality is an architectural requirement

This reality makes optionality essential. It is not a way to postpone decisions, but a deliberate architectural choice. Organizations need flexibility across customer journeys, deployment models, form factors, authentication methods, recovery flows, and assurance levels. They also need a common way to administer policies, manage accounts, monitor activity, and demonstrate compliance across those choices.

That is the idea behind a modular, extensible platform: support the capabilities organizations need today, provide a practical bridge to emerging approaches, and avoid creating a new operational silo every time the market invents another acronym.

Introducing DigipassONE™

The next generation of digital trust requires authentication, verification, and continuous protection, supported by insights across the entire interaction. At OneSpan, we built DigipassONE around this reality. DigipassONE is our unified authentication modernization platform, designed to help organizations progressively adopt new technologies while continuing to support existing ones.

DigipassONE marketecture

 

DigipassONE brings four capabilities together through a shared foundation:

  • Authenticate: Risk-based authentication across passkeys, security keys, hardware and software authenticators, OTP, and transaction signing, designed to support secure, high-assurance experiences across diverse users, devices, and channels.
  • Verify: Digital credential issuance and verification across emerging wallet ecosystems, supporting trusted onboarding, login, recovery, and transaction workflows without turning credentials into another disconnected identity project.
  • Protect: Runtime protection for mobile applications through in-app shielding, adaptive defenses, malware and threat detection, and real-time visibility into attacks.
  • Insights: Platform-wide analytics covering adoption, device usage, authentication activity, operational performance, and emerging threats, so decisions are based on what is actually happening throughout the user population.

Across these capabilities, DigipassONE provides consistent administration, user and account management, policy management, roles and entitlements, auditing, compliance logging, reporting, and analytics. Organizations can start with what they need and expand over time without adding a separate management layer for each new requirement.

Modernization is a capability, not a destination

Passkeys are an important step forward. Digital credentials will change how identity information is issued, carried, and presented. New threat signals and fraud controls will continue to improve how organizations distinguish legitimate activity from abuse. But none of them is the final destination.

Standards will evolve. Regulations will change. Attackers will adapt. User expectations will continue to rise. The strategic advantage is not selecting a technology that never changes; it is building the ability to change continuously without repeatedly re-platforming the business.

Built on experience, designed for what comes next

Many vendors approach this shift either through a point solution or as one capability within a broader security portfolio. OneSpan approaches it with more than three decades of authentication expertise, backed by experience deploying authentication at scale across some of the world’s most demanding and regulated environments.

That experience has reinforced a simple truth: modernization succeeds when new technologies can function alongside existing systems, rather than forcing a choice between them. Achieving that kind of flexibility depends on open standards and interoperability, which is why we made them cornerstones of the DigipassONE platform. As a founding member of the FIDO Alliance, OneSpan has helped advance those standards for years, and DigipassONE reflects that same commitment to modernization without disruption.

Why OneSpan stats

As Andrew Shikiar, CEO and Executive Director of the FIDO Alliance, recently noted:

“FIDO’s mission is to put trust and simplicity at the center of interactions among people, services, and devices. As digital ecosystems evolve, we are enabling the next wave of identity technologies based on open standards. These foundations will help verifiable digital credentials and other technologies reach their full potential, with the same simplicity, trust, and interoperability that passkeys brought to authentication. We’re pleased to see companies like OneSpan supporting the use of open standards to modernize authentication and making these capabilities accessible to customers worldwide.”

DigipassONE is the first visible step in our broader platform strategy. Our goal is not to dictate a single modernization journey. It is to make that journey easier by helping customers strengthen authentication, verify identity, protect applications and transactions, and gain the insights needed to improve continuously.

The next era of digital trust will not be defined by a single authentication method, identity technology, or security control. Organizations that can evolve confidently, support diverse user populations, and make continuous modernization an operational capability will be best positioned to lead.

Learn more about DigipassONE and our approach to authentication modernization.

Ashish Jain, Chief Technology Officer at OneSpan, leads the global R&D organization to drive innovation in digital identity & authentication technologies. A recognized expert in digital identity, Ashish brings over two decades of experience developing & scaling secure platforms for some of the world’s most trusted brands. Prior to OneSpan, he held senior leadership roles at Arkose Labs, eBay, and VMware, where he built solutions that advanced Zero Trust security and protected millions of users