Showing posts with label Biometrics. Show all posts
Showing posts with label Biometrics. Show all posts

Saturday, September 21, 2013

iPhone 5S: A Biometrics Turning Point?

Future: Mobile Devices Will Boost Interest in Advanced Authentication

Apple's decision to include a fingerprint scanner in its new iPhone 5S is an important step toward bringing biometrics-based authentication into the mainstream. But there's still a long way to go before biometrics supplant usernames and passwords at the enterprise level.

Owners of the new phone can use a fingerprint to physically unlock their devices instead of using a numeric passcode. Apple will also let users confirm purchases from the iTunes store by swiping a finger on the sensor.

Apple have not yet revealed whether they will allow third-party developers to take advantage of the new TouchID fingerprint technology to build biometrics-based authentication into their apps. While TouchID is an important milestone toward getting users comfortable with using biometrics as an authentication credential, the technology has to expand beyond the Apple universe before it can truly be considered a game-changer or a significant security breakthrough.

Biometrics authentication is not new to the mobile space. Some laptop vendors, including Lenovo, have included fingerprint readers in their devices for several years. Plus, a number of smart phones and tablets already incorporate biometrics to authenticate users. And security vendor McAfee recently introduced an online file storage service that relies on voice recognition to authenticate users. But all of these vendors use closed, proprietary models, which has made it difficult for biometrics to gain traction in the marketplace.

Market penetration for PCs and laptops with fingerprint sensors is about 20 percent, according to the FIDO Alliance, an industry group focused on open standards for authentication. Even if a majority of iPhone users opt for the iPhone 5S, overall smart phone market penetration for fingerprint scanners will remain low, considering that research firm IDC estimates Apple has about 17 percent smart phone market share.

The iPhone's popularity and its reputation as a trendsetter could help more consumers feel comfortable with the idea of using fingerprint scanners on a regular basis. And once they are used to the idea of fingerprint scanners, other types of biometrics won't be far behind. TouchID is the "first example of the potential for large-scale mass-market mobile biometric authentication.

Monday, July 11, 2011

Biometrics Seen as SecurID Alternative?

Exploring Multifactor Authentication

RSA customers who feel victimized by last March's breach of the security vendor's computers have viable options that include continued use of the SecurID authentication tokens, those offered by competitors, or something entirely different: biometrics.

In March, RSA revealed intruders broke into its computers, exposing secret codes for its two-factor authentication SecurID token. Since then, RSA has been working closely with its customers to assure the safety of the product.

The proper precautions RSA provides could satisfy many SecurID user but there is an another option of switching to a competitors' product. Still, at the end of the day, the use of these technologies maintains the status quo. They let you do the same-as-usual type of security. If attacked once, and hacked once, it can certainly be done again. Another approach, would be to implement an alternative factor, such as biometrics.

The concept behind multifactor authentication is that the user provides at least two different factors - something the user has, such as a token; something the user knows, such as a password; and something the user is, such as a fingerprint. In the case of tokens such as SecurID, the factors are what the user has and knows. But users jittery about the security of the has factor could substitute it with the is factor, such as an image of the eye's iris or the sound of a voice.

The enterprise security expert points out that many users own smartphones that, with the right, inexpensive software, can scan an iris or record a voice to produce biometrics that can be employed for authentication. It's not something that can be easily copied from a forensic perspective. Biometrics are a strong play, and they're gaining a lot more acceptance in the industry. What do you think?

Wednesday, June 24, 2009

Australia's first voiceprint recognition telephone banking

NAB tests voiceprint recognition

NAB is the first local institution to give customers an opportunity to enrol in a voiceprint recognition system, dispensing with the need to remember PINs and passwords or provide personal information when calling the bank. Customers enrolled in National Australia Bank's new voice biometrics system for phone banking may be able to use the same system to authenticate their internet banking activities.

NAB direct channels speech program manager Sam Jackel said voiceprints could be used as a second-factor authentication method for internet banking transactions independently verified at present via an SMS message sent to the customer's mobile phone. Users had to open the message to retrieve a single-use passcode and enter it into the onscreen session, he said.

Staff tested the voice registration and identity verification system for several weeks and it was being offered initially to customers who had difficulties with the automated check and required personal attention.

After callers have registered their unique voiceprint, they simply recite their individual account number at the beginning of each call and the system will verify their identity before the call centre agent picks up the call. Customer identification and verification used to take two to three minutes a call, but now this has been cut to about 20-30 seconds.

NAB is using Salmat VeCommerce's VeSecure voice biometric technology, which sits on top of VeConnect, a speech recognition system installed earlier this year to allow automatic routing of phone calls to the right service area and to support the launch of a single number, 136 NAB, to manage all NAB customer inquiries.

Thursday, November 20, 2008

My thoughts on Biometrics / Face Recognition

What's your take on Face Recognition Technology?

Biometrics are biological authenticators, based on some physical characteristic of the human body. The list of biometric authentication technologies in still growing. Authentication with biometrics has advantages over passwords because a biometric cannot be lost, stolen, forgotten, lent, or forged and is always available, always at hand. Last and this year we saw heaps of laptops coming up with fingerprint reader as standard.

Now some of the
Lenovo notebooks are coming with face recognition software, which is actually a reemergence of an old idea. Now that some systems include integrated cameras with much better quality (1.3MP), facial recognition has become much better. In practice this works very well and is extremely fast at recognition.

The included software lets you log onto your Windows account simply by sitting in front of your system. Your face is your password.

Depending on the software used, face recognition uses multiple techniques to identify a person’s face. Some of the more advanced programs use texture mapping in which a person’s skin texture is analyzed and matched. Most however, define nodal points on a person’s face and then use software to mathematically represent those points. Things measured include distance between the eyes, width of the nose, length of the jaw line, or shape of the cheekbones. Together these concatenate a numerical code which is stored in a database for later retrieval.




Biometrics can become a single of failure though. Consider a retail application in which a biometric recognition is linked to a payment scheme:

As one user puts it, "If my credit card fails to register, I can always pull out a second card, but if my fingerprint is not recognized, I have only that one finger." Forgetting a password is a user's fault; failing biometric authentication is not.

Although equipment is improving, there are still false readings. I think biometrics as unique parts of an individual, forgeries are possible. The most famous example was an artificial fingerprint produced by researchers in Japan.

My thoughts are, forgery in biometrics is difficult and uncommon, forgery will be an issue whenever the reward for a false positive is high enough.