
Identity & Access Management
Mobile-First Authentication
Passwordless mobile-first MFA for banks with NIST post-quantum cryptography and device binding.
Mobile-First Authentication Overview
What it does
Mobile-First Authentication is a passwordless multi-factor authentication (MFA) product for banks and fintech companies, built on Wultra's PowerAuth protocol. It replaces passwords and one-time codes with device-bound cryptographic keys unlocked by biometrics or PIN, turning the customer's phone into a phishing-resistant authenticator for logins and transaction signing. Its distinctive mechanism is postquantum authentication: hybrid cryptographic suites pair elliptic curve P-384 with the NIST-standardized ML-DSA signature algorithm, keeping authentication secure against future quantum attacks.
How it works
Banks integrate the product through a mobile SDK embedded in their own app, a whitelabel mobile app, or a whitelabel web application, backed by a PowerAuth server deployed on-premises or consumed as a managed cloud service. During activation the mobile SDK generates device signing key pairs (ECDSA and optionally ML-DSA) and establishes a shared secret using ECDHE or ML-KEM key encapsulation. Users then approve logins, payments, and 3-D Secure transactions by signing them on the device under Face ID or PIN, with proximity checks and resistance to OTP interception, SIM swap, and overlay attacks. The Raiffeisenbank deployment serves 1.5M+ users handling 20M+ daily transactions.
Credentials and traction
Wultra is ISO 27001 certified, with the certificate published for download on its compliance page, and is the sole Sample Vendor named for postquantum authentication in the 2025 Gartner Hype Cycle for Digital Identity. Its PowerAuth technology is embedded in YRIS, the French digital ID whose SDK was reviewed by the French cybersecurity agency ANSSI and certified for CSPN, and in the Czech MojeID authenticator certified at eIDAS substantial assurance level. Customers include Raiffeisenbank, OTP Bank, NLB Group, Moneta, and Saldo Bank, among 70+ clients in 25+ countries.
Key Capabilities
mapped to solution categoriesBinds passkeys to specific device hardware (TPM, Secure Enclave), the private key cannot be exported or used from a different device.
Implements FIDO2/WebAuthn for phishing-resistant authentication, binding credentials cryptographically to the registered origin to prevent use on phishing domains.
Implements CRYSTALS-Kyber (ML-KEM, FIPS 203), for key encapsulation and CRYSTALS-Dilithium (ML-DSA, FIPS 204), for digital signatures, the NIST-standardized post-quantum algorithms.
Supports hybrid key exchange combining classical (ECDH), and post-quantum (ML-KEM) algorithms, maintaining compatibility with non-PQC endpoints during the migration period.
Lets an organization swap cryptographic algorithms without re-architecting applications, so quantum-vulnerable algorithms can be replaced as standards evolve.
Compliance
certificationsImplementation & support
Info last updated on July 30, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.