Draft:X.1280

  • Comment: This is an advertisement for a particular product standard, not an encyclopedic article that covers information about the project as covered in reliable, independent sources. Caleb Stanford (talk) 20:02, 10 May 2025 (UTC)


X.1280
Framework for out-of-band server authentication using mobile devices
StatusIn force (Recommendation)
Year started2022
Latest version1.0
March 1, 2024 (2024-03-01)
OrganizationITU-T
CommitteeITU-T Study Group 17
SeriesX
Related standardsX.509, X.1254
DomainCybersecurity,
Identity management,
Authentication,
biometric authentication
Websitehandle.itu.int/11.1002/1000/15661

X.1280 is an International Telecommunication Union(ITU) standard for verifying a service provider before user information.[1]

The title of x.1280 is out-of-band server authentication. This standard contains out-of-band authentication and mutual authentication. The out-of-band authentication makes it difficult for attackers to intercept because the attackers need to hijack two channels at the same time. [2] Mutual authentication can increase the security level compared to one-way authentication. One-way authentication only verifies the user's identity, but mutual authentication verifies the user and the service providers. In this way, mutual authentication can help stop some kinds of attacks. [3]

  • On-path attacks
  • Spoofing and impersonation
  • Credential theft

X.1280 uses an out-of-band mobile authenticator, typically a smartphone, and may incorporate biometric authentication for applying MFA(Multi-factor authentication). However, a key feature is that no additional hardware, such as dedicated security tokens, is required beyond a smartphone. It allows the use of a unified authenticator across various devices. To authenticate via X.1280, prior registration is required. When a service provider supports X.1280-based authentication, the mobile authenticator must first be registered and then used for authentication.

  1. ^ "Free access for all to ITU-T standards". MIT Libraries. Retrieved 2025-05-16.
  2. ^ "Out-of-Band Authentication". Double Octopus. Retrieved 2025-05-16.
  3. ^ "What is mutual authentication?". Cloudflare. Retrieved 2025-05-16.

© MMXXIII Rich X Search. We shall prevail. All rights reserved. Rich X Search