Identity Challenge Card
Identity Challenge Card 是一张印有词对的网格卡。无需手机、无需应用、无需网络。员工读出一次性坐标,身份即在本地完成验证:在服务台、在登录时、在重置密码时。
- 每一位员工,每一种环境
- 一小时内完成部署
- 无需 MDM、无需应用、无需硬件
- 多语言 — 含 RTL 与 CJK
- 轻松重新注册 — 无需配对设备

Protecting the world’s workforce since 1997 • Over 15 Million Licenses Sold












































应用场景
三个场景,一张印刷卡片
同一张卡片覆盖凭据被证明、被替换、被找回的三个时刻——在服务台、在登录时、在重置时。播放任意讲解视频,并跟随同步滚动的文字稿。
- 应用场景 01文字稿点击任意词从该处播放
A help desk agent is deciding whether to trust a voice on the phone.
Instinct shouldn't be the deciding factor.
Texting a code to the caller's phone assumes the phone is theirs.
Not a device the attacker may already control.
The Identity Challenge Card changes the question.
The agent reads a coordinate down the line.
The caller reads the word back off a printed card.
And that value is spent.
The old script was a list of questions an attacker can research.
What's on that card isn't online or on a device.
Service desk leaders get a live identity check on every call.
Security and technology leaders get one that holds when the identity provider doesn't.
Avatier's Identity Challenge Card.
Verify the human, not the device.
Try it at identitychallengecard.avatier.com.
- 应用场景 02文字稿点击任意词从该处播放
This workstation had a different worker an hour ago.
The question isn't the password, it's which one of you this is.
Some sites sign in without a password, some keep the password and add a factor.
The card is the factor, either way.
Without a password, on shared workstations and virtual desktops, the factor isn't provisioned into the machine.
It's in the worker's pocket.
Keep the password and the card answers the MFA challenge.
Password accepted. The screen types out a coordinate.
The worker reads the matching word off the printed grid, then adds the private PIN.
Directory Identity resolves automatically, nothing to approve.
The card sits alongside the MFA you already run, and policy routes each worker to the right method, even where device MFA can't reach.
Login, with or without a password.
identitychallengecard.avatier.com. Try it, or book a meeting.
- 应用场景 03文字稿点击任意词从该处播放
You're locked out, and the thing that would prove it's you is a phone that's dead out of signal or in a locker.
In most enterprises, the front door got strong.
The way back in, didn't.
Recovery has to know who's asking, first.
The new password field waits.
A coordinate appears.
You read the word off your printed card, add your private PIN, and your employee ID is verified automatically.
Then, the password changes.
No call, no ticket, no escalation to security, no manager override, no waiting for systems to come back.
The lockout queue stops being your bottleneck, and every challenge and re-issue lands in the identity governance you already run.
Self-service password reset.
Proof first, then the password.
Try the live card at identitychallengecard.avatier.com.
同时提供
Apple Wallet 版 Identity Challenge Card
把人的验证装进口袋。快速访问与安全的备份身份,在标准 MFA 失效时随时可用——与印刷卡片并行,而非取代它。

设备依赖MFA无法保护没有设备的人
市场上的每一款MFA产品都假定在认证时有一台可信设备可用。对大多数员工来说,这个假设是错误的。
全球80%的员工是无桌面员工。工厂、医院、现场服务、零售、物流、教育、建筑 — 这些让业务运转的员工很少携带公司电话,而携带的人在车间里也无法使用。
结果是一个有据可查的覆盖缺口。组织为无法触及的员工撰写MFA例外。那些例外就是对手首先会映射的攻击面。1,2,3
80 percent
全球80%员工是无桌面员工
全球27亿员工不坐在桌前,不携带公司电话,也无法安装认证应用 — 他们正是大多数组织没有覆盖的员工。
20 industries
Industries
5 to 88 percent
Device MFA reach
Deviceless MFA弥合了红色。设备依赖MFA在没有电话、应用、令牌或网络的情况下无法触及它。
For the CFO: every uncovered frontline worker is an uninsured breach vector — one stolen credential from a seven-figure incident, a denied cyber-policy claim, and an audit finding that pushes your next renewal. Deviceless MFA is how that math stops working against you.
Fifteen minutes. We'll map your coverage gap and what it's costing you today.
来源
Fortune 500员工构成源自10-K申报文件、美国劳工统计局的行业就业构成,以及Gallup的2024年全球职场状况。各行业无桌面员工比例基于Emergence Capital的Deskless Workforce Report。完整方法论可应要求提供。
- [1] Enterprise VC research — State of Technology for Deskless Workers (2020)
- [2] Global strategy consultancy — Making Work Work Better for Deskless Workers (Dec 2022)
- [3] Industry analyst firm — 75% of new mobile initiatives target frontline workers
- [4] Business publication — 2025 ranking of largest U.S. companies by revenue (June 2025)
伊朗Handala对Stryker的攻击就是Deviceless MFA的存在理由。
Handala 与伊朗结盟。他们要的不是赎金——他们要让你彻底停摆。
有国家背景的擦除型攻击团伙不会谈判;他们打造的载荷就是为了让你的员工持续被锁在系统之外。然后,服务台的电话响了。“我是心内科的 John——我现在就需要恢复访问权限。”接电话的技术人员怎么知道对方真的是 John——而不是早已控制了 John 手机的攻击者?
设备依赖MFA vs Deviceless认证
设备依赖MFA
Deviceless认证
有了这一备用身份层,Stryker的重建将是几天而不是几周。
三个因素。零设备依赖。
Deviceless MFA解决三个独立因素 — 全部本地,全部无设备,全部在10秒内。
Challenge Card因素
一张印刷的单词对网格。登录时,系统请求特定坐标 — 用户直接从卡片读取答案。无网络调用。无设备。
私密知识因素
只有用户知道的短PIN。按策略绑定到卡片,并在内存中验证,使重放和暴力破解没有攻击面。
身份锚定因素
用户的目录身份 — Employee ID、徽章或SCIM提供的主体。将挑战绑定到特定人员,具有完整的审计跟踪。
观看Deviceless认证。试用。60秒内理解。
Self Enrollment or Auto Enroll Everyone at Once.
Deviceless MFA、卡片和三因素本地解决方案的叙事导览。
这就是Deviceless MFA。试试吧。→
无需注册。无需下载。在这里对着一张印刷的卡片实时解决三因素挑战 — 这就是员工在身份宕机期间执行的相同流程。
无需电话
无需应用
无需网络
无需硬件令牌
不依赖已被入侵的系统
可在任何语言下工作,包括RTL和CJK
| # | A | B | C | D | E |
|---|---|---|---|---|---|
| 1 | INSTALL POWDER | GARDEN BRIDGE | MARBLE SILVER | ROCKET WINDOW | GUITAR CASTLE |
| 2 | PLANET ANCHOR | TURTLE FOREST | BASKET TEMPLE | VELVET PIRATE | COTTON DRAGON |
| 3 | CANYON MAGNET | PUZZLE ORANGE | VIOLET BEACON | COPPER JUNGLE | CARPET MONKEY |
| 4 | HARBOR KNIGHT | VISION QUARTZ | JASPER WILLOW | SUMMIT STREAM | PARROT FABRIC |
| 5 | MEADOW COBALT | FABRIC SPHINX | FALCON BINARY | ORCHID PRISM | LANTERN OXYGEN |
坐标 C2 — 上面的单词
您的PIN 1234
Employee ID EMP-48291
三因素如何工作
· Challenge Card因素 — 找到坐标(如A1、B3)并输入上或下的单词
· 私密知识因素 — 读取您的4位PIN并在PIN字段中输入
· 身份锚定因素 — 您的Employee ID自动验证
· 三个因素都需要 — 单词和PIN都必须正确才能访问
· 新挑战 — 点击「新游戏」获取随机坐标和PIN
Deviceless MFA业务价值映射到采购方
每位利益相关者获得不同的成果。Identity Challenge Card是CISO、CIO、CFO、CEO、服务台和分析师各自获得自己答案的那种罕见控制。
准备好用Deviceless MFA弥合您的合规缺口了吗?
预约一个适合您员工的20分钟演示 — 我们会在您挂电话前将您的例外映射到部署计划。
为全球员工打造
Identity Challenge Card以34种语言交付,包括阿拉伯语和希伯来语的RTL以及中文、日语和韩语的CJK。相同的卡片、相同的三因素流程 — 为每位员工本地化。
Deviceless MFA,受监管环境中值得信赖
从第一天起就为CMMC、HIPAA、PCI-DSS、GDPR和FERPA负载设计。三个架构支柱使合规故事比设备绑定MFA更简单,而不是更难。
按架构的隐私
认证机制上的零个人数据
- 无电话号码、生物识别或个人数据触及卡片
- 没有用户PIN,卡片内容是不透明的
- 来自认证通道的零GDPR暴露
- 用户和挑战之间无第三方处理器
- 撤销是即时的 — 无上游清理
完整的生命周期控制
受治理的颁发、撤销和审计
- 每张卡片都通过现有的IGA工作流颁发
- 每次挑战和重新颁发都写入不可变的审计记录
- 过期和重新注册窗口按策略强制执行
- 带身份验证的重新颁发关闭社会工程路径
- 颁发者、批准者和审计者之间的角色分离
设计上抗钓鱼
无推送、无重放、无中继
- 无推送通知 — 推送疲劳没有攻击面
- 每个坐标值都是一次性的 — 重放在结构上不可能
- 气隙验证 — 无网络攻击面
- 无需窃取的TOTP共享密钥
- 无需设备即可与FIDO2相当的抗钓鱼性
在 Gartner Peer Insights 上获得认可
4.4
基于 Avatier 的 14 条经核实的评价Identity Governance and Administration
在 Gartner Peer Insights 上阅读评价常见问题
在每一次CISO、CIO、CFO、CEO、服务台和分析师的通话中都会出现同样的问题。答案如下 — 选择您的简介。
面向100%员工的抗钓鱼MFA
什么是Deviceless MFA — 以及Identity Challenge Card与所有其他MFA有何不同?
印刷的卡片真的安全吗?丢失的卡片意味着凭据被入侵。
我们已经有MFA了。为什么我们的解决方案留下一个有据可查的缺口?
推送轰炸或重放能对它起作用吗?
查看Deviceless MFA在您的环境中的位置
无义务 · 30分钟Deviceless MFA导览 · 当天回复
与Identity Challenge Card背后的团队交谈 — 第一个在生产中的Deviceless MFA。
Further reading
Related from the Identity Challenge Card library

Phishing-Resistant MFA for Enterprise in 2026
Phishing-resistant MFA is the term CISA, NIST 800-63B Rev. 4, and Executive Order 14028 use for the authentication category that survives the attack patterns that defeated SMS, OTP, and push-approval MFA. The 2026 enterprise reference on what qualifies, what doesn't, and the deployment architecture across mixed workforces.
Read more
Beyond Foundational MFA in 2026: The Recovery Channel Gap
Phishing-resistant MFA is the right answer for the front door. It does not protect the recovery channel, which is where the 2026 attacks are landing.
Read more
The Best Multi-Factor Authentication Solutions for Enterprises in 2026
A 2026 buyer's guide to enterprise MFA solutions, segmented by workforce type. Compare 12 vendors across desk, frontline, contractor, and customer use cases.
Read more


