The Usher server is a power tool that uses industry security standards of encryption and authorization to make all Usher features possible. None of Usher's features would be possible without this powerful tool.

Usher's security architecture leverages defense in depth applying multiple security layers and simultaneously extending configurable friction controls to satisfy policy without sacrificing user experience. Usher is a safe and secure identity and authentication solution that exceeds key standards and delivers next-generation capability to digitize your operations, including your physical and logical infrastructure. Usher delivers a personalized and interactive experience via a virtual layer on top of existing systems and applications. Usher can complement or replace passwords, hardware tokens, and physical keys and badges.
The Usher server architecture is built on Public Key Infrastructure (PKI) to ensure that only authorized Usher users communicate with the Usher server, and only from authorized Usher-enabled devices. The Usher server has the sole authority to convert a mobile device into an Usher-enabled device by granted it a signed client certificate. This process ensures that rogue devices or applications cannot masquerade as Usher-authorized devices by presenting unknown certificates to the server.

A secure chain-of-trust is established early by Usher and maintained throughout the lifecycle of the user's identity and device. The Usher server is responsible for receiving the client public key and Certificate Signing Request from the mobile client, and generating a certificate along wit maintain an encrypted copy to provide secure authentication for many enterprise needs. The Usher server and the underlying Identity Management Systems (IDMS) use the TLS protocol with 256-bit AES cipher to sent identity request and verified identities to one another.
Proven and widely adopted standards are used to federate one or more components of identity, authentication, and/or authorization supported by Usher including SAML, OAuth, and Open ID Connect. The Usher platform architecture is built using OAuth 2.0 standards, an open standard for authentication and authorization.
•The Usher server includes an authorization layer in the Usher server to authorize requests on behalf of users to gain access to resources.
•The Usher server uses access tokens to authenticate users, instead of their usernames and passwords.
•The Usher server is the "Registration Authority," which, upon successfully verifying the identity of a user, registers the user in its database and issues and access token.
•First-time user authentication can be achieved out-of-band, such as sending an authorization code to a registered email, which can be users to complete the registration process.