The Purdue BoilerKey is a form of two-factor authentication, a system that requires two forms of verification of identity before a person can access protected computer resources.
At Purdue, these two forms of verification are something you know (career account username and either a password or PIN) and something you have (a physical token or the Duo Mobile application on your smartphone). These two items are used in place of your password alone to gain access to computer applications and systems.
The BoilerKey comes in two forms. One is the Duo Mobile application for your smartphone that either displays a push notification used when you enter your PIN or a randomized six-digit code. The other is a small electronic device, known as a hard token, which displays a series of six digits when activated.
The primary reason for using the BoilerKey is that it is more secure. It uses two-factor authentication to increase the level of security. Two-factor authentication uses something you know (career account username and either a password or PIN) and something you have (a physical token or the Duo Mobile application on your smartphone).
As the number of systems using the BoilerKey for access increases, your value in using the BoilerKey also increases.
Two-factor authentication is the use of two separate requirements that must be used together to gain access to an application or portal. In our solution, it is something you know (career account username and either a password or PIN) and something you have (a physical token or the Duo Mobile application on your smartphone).
For example, if you use your bank card to obtain cash from the ATM, the card is something you have and your ATM PIN is something you know. Combined, these two factors reduce the likelihood that an unauthorized person could obtain access to your account.
The Purdue BoilerKey comes in two forms, one of which is a small electronic device (known as a hard token) that displays a series of six digits when activated and the other is an application for your smartphone (known as a soft token) that displays the six digit code.
You can request and configure BoilerKeys here.
You can request and configure BoilerKeys here.
A BoilerKey passcode is a 6-digit number that is generated by pressing the button on your BoilerKey token. If you have set up a Duo Mobile BoilerKey with the Duo Mobile app on your smartphone, you can also generate a BoilerKey passcode with the Duo Mobile app:
The option to use a four (4) digit personal identification number (PIN) instead of your Purdue Career Account Password as your BoilerKey password is available. You can set and change your BoilerKey PIN here.
Use your career account username and your BoilerKey password when logging in. Your BoilerKey password consists of either a BoilerKey PIN or your career account password, a comma, and then either the word push or a 6-digit BoilerKey token code (or Duo Mobile passcode).
If you are unsuccessful and using a BoilerKey token, go here and choose "Manage my BoilerKey Tokens". There's an option to fix your token, that will require you to enter three codes from your token to "resynchronize" it.
No. Once you have been set up to use the BoilerKey, you must use your BoilerKey password. If your BoilerKey token or smartphone with your Duo Mobile BoilerKey is temporarily unavailable and you need access, please contact your Distributed IT Support Group or the ITaP Customer Service Center. They can issue you a 9-digit Duo Bypass code, which can be used in your BoilerKey password instead of the word push, or a BoilerKey token code. So your BoilerKey password would look like BoilerKey PIN,123456789.
You are still required to follow the every 180 day (or 90 day if you have additional privileges) password change policy for your Purdue Career Account.
If the BoilerKey token is lost or stolen, you should immediately report the BoilerKey as lost. Please contact your Distributed IT Support Group or the ITaP Customer Service Center.
If you have a problem with your smartphone containing your Duo Mobile BoilerKey, your Distributed IT Support Group or the ITaP Customer Service Center can issue you a 9-digit Duo Bypass code, which can be used in your BoilerKey password instead of the word push. So your BoilerKey password would look like BoilerKey PIN,123456789. Your smartphone will not be needed to use the Duo Bypass code. A Duo Bypass code can only be used once, and will expire one day from when it is issued.
Download the free application from your device's app store:
Duo Mobile on Apple App Store | Duo Mobile on Google Play | Duo Mobile in Windows Store
Duo Mobile BoilerKeys are created and configured with the BoilerKey web application.
The steps involved in creating a Duo Mobile BoilerKey are shown in the following video.
If your phone is not connected to the internet, ask your Duo Mobile app for a randomized 6-digit passcode to use in your BoilerKey password in place of the word push. Instead of "pin,push" as a BoilerKey password, you'll use "pin,6-digit-passcode".
If you're interested in reading more about the Duo Mobile app:
Duo Mobile Guide for Android phones
Duo Mobile Guide for iPhone
Duo Mobile Guide for Windows phones
If you are trying to authenticate with your Duo Mobile BoilerKey, and the Duo Mobile app on your smartphone says "Account Not Found - A request was received for an account that is no longer paired to this device. To re-enable it, please contact your administrator.", then the Duo Server and your Duo Mobile smartphone app do not have the same BoilerKeys on file.
To fix this, remove any Duo Mobile BoilerKeys from your smartphone and from the BoilerKey web application, and then set up a new Duo Mobile BoilerKey in the BoilerKey web application.
To remove a Duo Mobile BoilerKey from your smartphone, press and hold where it says "Purdue University", and there should be a menu that pops up with a remove option.
No. There are two reasons why it would be unusable to a would-be hacker. First, they do not have access to your Purdue Career Account password or BoilerKey PIN, and probably wouldn't know your career account username. Both of those would also be required to login. Second, by just notifying us that it has been lost or stolen, we can quickly disable the BoilerKey, preventing it from being used to gain access to any resources.
It could of course be opened if the would-be hacker has the time and tools to do it. Opening the BoilerKey would most likely disable it, however. It would require an extensive effort to gain any information of value and by then you would have notified us that you no longer have the BoilerKey.
A BoilerKey that is not functioning properly can be replaced. Contact your Distributed IT Support Group or the ITaP Customer Service Center.