Blog

Thirty Years of Obsession: Making Digital Identity Authentication Both Secure and Frictionless

Passwords are dying.

Billions of account credentials circulate on the dark web every year. Phishing attacks are growing harder to detect, supercharged by AI. Even companies that have enabled SMS verification codes keep appearing in data breach headlines. The question is no longer “should we strengthen identity authentication”, it’s “how do we do it in a way that actually works.”

This is a question Keypasco has been thinking about for thirty years.

 

It All Started with a Phone

In the 1990s, when most people were still queuing at bank branches to wire money, Keypasco’s predecessor — Sweden’s Todos Data System AB was doing something that seemed far ahead of its time: integrating smart chip card readers into ISDN phones so users could complete banking transactions at home through a closed digital line, no computer or internet required.

That was a full decade before online banking became mainstream.

Image source: Tekniska museet / DigitaltMuseum Todos SurfLite II USB, accession number TEKS0045211

The Todos SurfLite II USB, developed by Todos Data System AB (the predecessor of Keypasco), was an ISDN terminal for Telia’s Duocom service that combined a telephone, ISDN modem, and smart card reader into one device, enabling identity authentication and financial transactions directly through the phone. It was widely distributed through Telia and Telenor nationwide, and is now preserved by Sweden’s National Museum of Science and Technology (Tekniska museet).

 

In the 2000s, Todos developed the e.dentifier2 for Dutch bank ABN AMRO, enabling PIN entry and transaction confirmation to happen entirely on the device itself. Even if a computer was infected with malware, attackers couldn’t intercept anything useful. This design philosophy became the forerunner of today’s hardware security keys.

This history is not nostalgic indulgence. It illustrates one fundamental truth: real security innovation has always started from understanding the nature of threats not from chasing trends.

Image source: ABN AMRO e.dentifier2 / Wikimedia Commons / CC BY-SA 4.0

 

Arriving in Taiwan in 2012 with That Same Obsession

Keypasco (formerly Laiyi Digital Technology Co., Ltd.) was founded in 2012, bringing thirty years of accumulated identity authentication expertise into the mobile era. Headquartered in Taiwan, with an R&D team spanning Taiwan and Sweden, and operational offices in the Netherlands, Japan, the United States, and India, Keypasco serves channel partners across more than 20 countries.

But scale isn’t the point. The point is that from the very beginning, we chose the harder road: proprietary R&D only, no off-the-shelf technology. Pure software architecture only, no following the crowd into hardware tokens.

Photo caption: From left to right: Keypasco Taiwan General Manager Tsai Yi-Lang, Senior Product Manager Lars Andren, Keypasco HQ General Manager Lin Hsin-Yi, Keypasco Founder and Chairman Lin Cheng-I, and Todos Data System AB Founder Lin Mao-Tsung (currently serving as Keypasco Senior Vice President).

 

Two Questions, Two Answers

When designing Keypasco’s core technology, we asked ourselves two questions.

First question: Why is man-in-the-middle attack so hard to defend against?

Because login and authentication share the same channel. All a hacker needs to do is tamper with that channel: whatever you enter, they see; whatever you confirm, they alter.

The answer: a dual-channel authentication architecture that completely separates the login channel from the authentication-encryption channel. Two separate paths means that if one is intercepted, the other’s verification still cannot be forged. This proprietary patented architecture effectively prevents man-in-the-middle attacks, browser-in-the-middle attacks, and phishing fraud, and currently protects hundreds of millions of users worldwide.

Keypasco Two-Channel Architecture diagram

 

Second question: Beyond passwords, what is the hardest thing to forge?

Not SMS verification codes (which can be intercepted). Not push notifications (which can be spoofed). It’s your device itself.

Keypasco’s device fingerprint technology generates a unique identifier by referencing multiple hardware characteristics. No two phones of the same make and model will have the same fingerprint. System updates won’t change it. Even if an account’s username and password are fully compromised, without passing device verification, attackers still cannot log in.

Keypasco Device Fingerprint diagram

 

The Choice of Taiwan’s Financial Sector and Public Agencies

The market speaks for technology quality.

Keypasco has been successfully deployed in Taiwan’s central government agencies, financial institutions, and high-tech manufacturing industries, serving as the core line of identity authentication defense in demanding, high-standard environments. From strictly regulated financial transactions to government digital services where efficiency cannot compromise security, Keypasco’s proven real-world deployments across diverse industries are the truest testament to its technical maturity.

Keypasco’s confidence comes from thirty years of technological accumulation. Rooted in Swedish R&D heritage, with an engineering team spanning Taiwan and Sweden, Keypasco continues to compete on the international stage alongside top-tier players. We currently hold invention patents in 16 countries, serve markets across the Americas, Europe, and Asia, have amassed over ten million end users, and have achieved SOC 2 Type II international certification, meeting the most stringent cybersecurity standards demanded of vendors in financial services, healthcare, and cloud services industries in the West. This global footprint continues to expand: in 2026, Keypasco officially entered the Australian market, extending its services into the education sector.

 

MFA Doesn’t Have Just One Look

Entering the Australian campus market confronted Keypasco with a challenge rarely seen in other industries but extremely common in education: not all users can use a personal phone.

These are real-world constraints. Frontline nurses in hospitals need to switch quickly between multiple shared computers. Factory workers are in rotating shifts in zones where personal devices are banned. Students at schools use equipment issued or managed by the institution, not their own phones.

Keypasco’s answer: let students complete MFA identity verification login directly on school-provided computers, with no personal phone required. The principle behind this case represents Keypasco’s core position on “trusted devices”: MFA should be bound to trusted devices appropriate for the specific usage context. A personal phone is one such device; a school- or enterprise-managed device can equally be one.

A truly flexible identity authentication solution should adapt to the scenario. This is precisely the core advantage of Keypasco’s pure software architecture, and the key reason we are able to operate across diverse verticals including finance, government, manufacturing, and education.

 

What’s Next: When AI Becomes the Attacker’s Most Powerful Weapon

Threats never stop evolving. And the rise of generative AI is driving the barrier to attack lower at an unprecedented pace.

Phishing emails that once required meticulous crafting can now be generated by AI in seconds, perfectly mimicking the tone, style, and even personal habits of your most trusted colleagues or supervisors. Deepfake technology means that faces and voices are no longer reliable identity indicators; the face you see and the voice you hear in a video call may both be synthesized in real time. AI can also predict password combinations from social media and leaked databases, automatically match large volumes of credentials to find exploitable accounts, and even launch personalized social engineering attacks at scale. Tactics that once required extensive human labor can now be executed fully automatically. Even more alarming is the rise of AI Agents: automated attack programs that can continuously attempt, learn, and adapt without human oversight, mounting large-scale, high-frequency infiltration against enterprise identity verification systems.

In this environment, “something you know” (passwords) and “something you receive” (verification codes) are far from sufficient. Identity authentication must evolve from “verification at the moment of login” to “continuous evaluation of every action.”

Facing these trends, Keypasco holds to the conviction carried forward from the Todos era: threats evolve, so our R&D cannot stop. We continue to deepen our work in device trustworthiness, contextual risk analysis, and behavioral anomaly detection. Not to chase trends, but because we believe security in the digital world deserves to be taken seriously.

 

Thirty Years On, We’re Still Asking the Same Question

From ISDN smart card phones in the 1990s to MFA multi-factor authentication solutions in 2026, Keypasco has always been answering the same question:

How do we let the right person access what they should access in the most frictionless way possible while ensuring the wrong person can never get in?

This question has no end. But we’re glad we started thinking about it thirty years ago.

Explore Keypasco’s Enterprise MFA Solutions
Platform  |  Enterprise  |  ZTA
Strengthen Your Identity Authentication. Elevate Enterprise Security

Keypasco is delighted to share more about our exclusive technologies and products with you! Tell us your needs and goals, and let Keypasco deliver the most suitable solution—becoming your dedicated identity authentication technology advisor.

Contact Us