A small tool helps keep things safe. 

A small tool helps keep things safe. 
You use this tool with a secret word. It can hold a tiny picture of your fingerprint. Some tools have a small screen. 
Some tools plug into a computer. Others use wireless signals to talk. This helps prove who you are. It is a smart way to stay safe.
A security token is a tool used to prove who you are. It helps you gain access to things that are locked. You might use one to open a door. You might also use one for online banking. 
Tokens can work in different ways. Some are disconnected. These do not plug into a computer. Instead, they have a tiny screen. You look at the screen and type a number into your computer. 
Other tokens are connected. These might plug into a USB port. They can also use wireless signals. Some use Bluetooth or NFC, which is a way to talk over a short distance. These tokens can send your secret info to the computer automatically. 
Tokens hold secret data. This can be a password or a fingerprint. Some tokens use a math rule called an algorithm. This rule makes a new code every minute. Because the code changes, it is hard for others to guess. This helps keep your private information safe.
A security token is a special tool used to prove your identity. It helps people gain access to things that are electronically restricted. You might use a wireless key card to open a locked door. You could also use a banking token to sign in to your bank online. 
There are different ways these tools work to keep you safe. Some are called disconnected tokens because they do not plug into a computer. These often have a tiny screen that shows a number. You must look at that number and type it into your keyboard yourself. 
Some tokens use math to create ever-changing codes. A common way is using a timer to rotate through different combinations. This is called a synchronous dynamic password token. The token and the computer must have clocks that match perfectly. 
Many different types of technology make these tokens work. Some use Bluetooth or Near-field communication, which is also called NFC. These allow the token to talk to a device over a short distance without wires. There are also smart cards that can be very cheap to make. These are often used by banks for cash cards. Some tokens are even certified by the United States to meet high security standards called FIPS 140.
Think of a security token like a secret handshake. A password is like knowing a secret word, but the token is the proof that you are truly who you say you are. Some tokens are like a physical key you carry in your pocket. Others are more like a digital badge that talks to a reader. Whether they use a USB plug or a wireless signal, they all serve one big goal. They make sure only the right people can get through the door.
A security token is a peripheral device used to gain access to electronically restricted resources. It serves as a tool to prove a user's identity, often working alongside a password or replacing one entirely. These devices can store various types of sensitive information. This includes passwords, cryptographic keys for digital signatures, or even biometric data like fingerprints. 
Tokens function through several different mechanisms to transmit secret information. In a static password token, the device holds a password that remains physically hidden from the user. This password is transmitted during each authentication attempt, though it is vulnerable to replay attacks. A synchronous dynamic password token uses a timer to rotate through combinations created by a cryptographic algorithm. For this to work, the token and the authentication server must have synchronized clocks. If the clocks drift apart, the system may fail, though some systems like RSA's SecurID allow users to re-synchronize by entering consecutive passcodes.
Other tokens use different mathematical approaches to generate security codes. Asynchronous password tokens generate a one-time password without needing a clock. They may use a one-time pad or a specific cryptographic algorithm to do this. Some systems use a complex mathematical process called a hash chain. This creates a series of one-time passwords from a secret shared key. Each password is unique and observably unpredictable. Even if an adversary learns previous passwords, they cannot guess the next one. 
Security tokens are categorized by how they connect to a computer or user. Disconnected tokens have no physical or logical connection to the client computer. These are very common in two-factor authentication for online identity. They usually feature a built-in screen that displays authentication data, which the user must enter manually via a keypad. 
Wireless technologies allow for even more variety in token design. Contactless tokens form a logical connection without needing physical contact. This makes them convenient for electronic payments or keyless entry systems. These often use Radio-frequency identification (RFID) to transmit data. However, researchers at Johns Hopkins University and RSA Laboratories found that RFID tags could be cracked or cloned. Bluetooth tokens provide another wireless option, often using Bluetooth Low Energy to extend battery life. Near-field communication (NFC) tokens can also be used, sometimes working alongside Bluetooth to provide both proximity and data provision.
There are specific physical formats and standards that define these devices. Smart cards are a widespread form of connected token and can be very inexpensive, costing around ten cents. While they are efficient, their computational performance is often limited by low power requirements and thin designs. Some USB tokens actually contain a smart card chip inside to combine the benefits of both formats. In the United States, certain token designs are certified to meet the FIPS 140 federal security standard. This certification indicates that the device has undergone rigorous testing and independent audits to ensure high cryptographic security.
Security tokens play a vital role in modern digital infrastructure and software protection. A related application is the hardware dongle, which is used to prove ownership of specific computer programs. The software accesses the dongle to authorize its own use. Furthermore, some single sign-on (SSO) solutions use tokens to store software that allows for seamless authentication. By storing a cryptographic hash of a password on the token, these systems protect the actual password even if the device is compromised. While theft and loss remain the simplest vulnerabilities, these tools provide a robust layer of defense for many digital systems.
🖼️ Images & Media (3)
More to explore
✨ What else?
Related topics you might enjoy
🔬 Go deeper
More advanced topics to explore
🪜 Step back
Simpler topics to build understanding
What is Nepedia?
A free, ad-free encyclopedia for children. Every article is written at five reading levels, so the same page works for a five-year-old and a fifteen-year-old — use the level switcher above to see this one change. No account needed to read.