Showing posts with label fingerprint. Show all posts
Showing posts with label fingerprint. Show all posts

Wednesday, 7 September 2016

Apple September Event - Any new Biometrics Features?

The net is buzzing with its usual mixture of the possible, the potential and the damn-right ridiculous predictions on what Apple will announce later today at its September device event. In the mix has been a number of rumours on what Apple may do in terms of supporting biometrics.  Time will tell, but before the event takes place here is a list of some of them with my views on them.

iPhone 7
The most believable is changes to the home button with either a more flushed designed button integrated into the display or removal completely. Most fingerprint sensor designers have been working on integrating a sensor underneath the display (under glass) rather than underneath a coated button and Apple is probably ahead of the curve in its development. 

There is a strong possibility that Touch ID on iPhone 7 will be an under the glass sensor (probably still capacitive) and Apple may have had to either reduce the thickness of the glass or develop a recess in the glass to reduce its thickness to ensure that the sensor's performance is not degraded. 

The integration under glass may also mean the development of 'Force' Touch ID and could mean that the sensor could improve anti-spoof capabilities by measuring the force of its registered user's touch in addition to the usual matching against  stored fingerprint templates. 

With Iris being integrated into the Samsung GN7 (unfortunately recalled) there have also been rumours that iris recognition will be supported in this version. It is likely that this will have to wait until at least iPhone 8. 

Watch 2
The most reliable rumours on new sensors points to GPS. As my Sony SmartWatch 3 has this feature, I can definitely see that having GPS in a watch definitely makes the device more independent and is a great feature when you out running (According to Google Fit this last occurred in February for me - shocking I know). The partnership between Precise Biometrics, FPC, Gemalto and STMicro in developing a biometric platform for wearables has given us a clear indication that integrating biometric sensors into wearables, for authentication and identity, is viable. Whether Apple sees any merit in doing so is questionable. Payments has been a major driving force for biometrics and for Apple to support a standalone payments app on a smartwatch that  replicates the iPhone security environment including the secure enclave is debatable from a business case point of view. 

We may see the watch having more independence from a paired iPhone but I would be surprised to see a decoupling in this context. I would say there is an outside chance of a separate biometric (identity) sensor being integrated into Watch 2. 

I look forward in hearing what Apple will actually do later today and will follow-up this blog with another one with analysis on anything that is important from a security and identity perspective.

Addendum 09/09: After the official announcements from Apple on iPhone 7 and Watch 2, comments on my predictions. Not a lot of direct announcements on biometrics. However, Apple has changed the home button in creating a solid state version with force features and taptic feedback. There was no clarity on whether there is any changes to Touch ID as a result of this change. As predicted, no support for other modalities including Iris and no Biometrics for the Watch. I am currently researching the mobile biometrics market so keep a watch out for further updates in this area. Thanks. Alan

Tuesday, 9 February 2016

Top Trends for Biometrics in Financial Services

Biometrics is certainly a technology that is rapidly being adopted by the Financial Services industry and this is not just confined to mobile deployments. Mobile is a growing channel for the delivery of financial services and will start to dominate most financial sectors over the next five years but other channels are still a vital part of any delivery strategy.

This is an important message that I have learnt after spending the second half of 2015 researching how biometrics is becoming an important tool within the security toolbox that can be utilised in the fight against financial fraud and identity theft.

In a series of analyst reports that I authored in 2015 that were published in June, October and December 2015 by Goode Intelligence, I was able to carry out a deep-dive  into the adoption of biometric technology in financial services. This included banking, payment and mobile-based biometric services.

In the reports I identified five key trends that are currently shaping this market.

Bye Bye PINs for ATM Security

ATMs are unattended and when I type in my PIN I am always uber-aware of who is standing behind me in case they may be attempting to steal my PIN. Being a paranoid sort of person I go through a series of checks that includes checking for ATM skimmers or evidence that a camera may be pointing at the keyboard. Banks have installed awareness notices and stuck-on mirrors to help me protect my PIN but it shouldn't have to be like this. 

Things are changing and banks are modifying their ATM technology to phase out PINs and to embrace biometrics. There is also choice in the biometric deployment method; a bank can either integrate a biometric sensor into the ATM itself (fingerprint, palm-vein, finger-vein and Iris are being used) to go either cardless (my biometric replaces the plastic) or keep the card (the biometric is stored on the card and a biometric is captured at the ATM and then matched against the stored template on the card). There is also a mobile biometric solution that also replaces the need for a plastic bank card or integration of specialist sensors at the ATM; Hoyos Labs has a neat solution where the mobile device interacts with an ATM using a combination of barcode and mobile biometric authentication technology.  And if you like plastic cards then there are solutions as well; a number of vendors, including Zwipe, have integrated a fingerprint sensor into plastic cards to replace PINs. The plastic bank card will only work if the authorised user's fingerprint is first placed on the sensor. 

Authenticated Contactless Mobile Payments

One of the more visible success stories for biometric adoption in financial services has been the development of mobile biometric contactless payments. Apple Pay and Samsung Pay both use integrated fingerprint sensors to secure contactless mobile payments in physical locations. The PIN was adding friction to the physical payment experience so you can either forget about user authentication and limit the transaction amount (tap and pay for low value payments) or replace the PIN with a method that doesn't slow down the experience but still adds a level of security. 

How to tackle rising levels of Card-Not-Present Fraud?

Technology does reduce fraud. The deployment of EMV chip cards has led to a reduction of fraud at the physical point of sale. This has led criminals to move online and attack commerce channels that the EMV chip cannot protect. The rise of Card-Not-Present (CNP) fraud, especially for eCommerce transactions, and the movement towards mobile commerce has created the need for secure and convenient user authentication and transaction verification. Biometrics offers a viable solution. Expect to see the payment networks start to roll-out mobile-based biometric solutions that aims to tackle the CNP fraud problem and even support in 3D Secure 2.0. 

Wearable Payments to support Biometric Authentication 

It is early days for wearables; the market is too fragmented and there are too few devices currently being used by consumers. This will change and as more and more apps are developed to support the delivery of financial services to bands and smart watches then the need to validate identity and to protect commerce will become critical. For wearables, it is important to pick a biometric modality that suits the device and the application so expect to see technology such as heart-rate (ECG), behavioral and vascular being integrated into the next generation of wearable devices. Biometrics that can be captured when a device is close to the skin of its wearer. Brainwave for Glass perhaps?

Financial-Grade multi-modal biometric authentication to become de-facto for mobile banking apps

The final trend that I am pulling out of these reports is part of a movement to increase security of mobile-based biometric solutions without adversely effecting convenience and ensuring that financial services providers maintain ownership of identity. The industry needs to ensure that the biometric technology is hard to spoof, that the protocols cannot be compromised and that the vulnerabilities seen in existing 2FA solutions (including replay and man-in-the-middle attacks) are not introduced. And at the same time being easy to use, scalable and fit into existing identity lifecycle management tools (can I revoke a credential?). The use of more than one biometric modality, face and voice for instance, in a banking app can increase security and also provide choice for consumers. A service provider can also match the right biometric modality to the context of the login or transaction attempt; fingerprint may open the app but a challenge using another modality may be needed to send a payment to a new beneficiary. 

To conclude; both established financial services organisations, challenger banks and the emerging FinTech providers now understand the importance of choosing the most appropriate user authentication and transaction verification technology that can work across all finance channels and can meet the needs of convenience and security. Biometrics certainly ticks the boxes for convenience with millions of customers around the world paying for products and accessing mobile banking with the touch of the finger or by taking a selfie. A number of biometric platforms are also being introduced that also tick security, regulatory and privacy boxes including IEEE's Biometric Open Protocol Standard (BOPS). 

What is exceptional about this market is the sheer scale of deployment that has already taken place and the enormous potential that is yet to come. From millions of Brazilians daily withdrawing cash from biometrically-enabled ATMs, to mobile banking customers accessing their accounts with the touch of a finger or by taking an image of their face, the use of biometrics for financial services is improving security, reducing financial fraud and removing the need for cumbersome authentication solutions that are not fit for purpose in today's hyper-connected world.










Thursday, 2 July 2015

A guide for banks in choosing the most appropriate biometric system

Banks are racing ahead in deploying biometric systems in an attempt to control rising levels of financial fraud and to reduce friction on inconvenient forms of authentication and fraud management. 

There are many different competing biometric modalities that banks can implement but what criteria do (or should) they use to ensure that the biometric system is appropriate.

Through Goode Intelligence, I have been involved in a number of consultancy engagements with banks and suppliers to assist them in assessing and choosing the most appropriate biometric system to meet their requirements.

Based on this experience, and engagements with a wide range of biometric and authentication technology companies, we have devised an assessment methodology that banks and systems integrators can use to ensure that the most appropriate biometric system is chosen. 

The Goode Intelligence Banking Biometric System Assessment (BBSA) tool is based on four interlocking parts, biometric performance, usability, regulation and security. It is also applicable to other highly regulated industries including healthcare, government, telecommunications and utilities. 


The methodology provides guidance to banks in assessing biometric systems and exactly how a bank weights the assessment criteria is dependent on their own set of circumstances such as budget, security policy, bank channel, regulatory environment and risk and privacy models.

There will obviously be other technical and non-technical assessment criteria that a bank will use including integration, scalability and support models etc. 

Biometric Performance: The assessment of the biometric performance and accuracy of a banking biometric system includes measurement of False Reject Rates (FRR), False Acceptance Rates (FAR) and Failure to Enrol Rates (FER). The accuracy of a banking biometric system is expressed as an Equal Error Rate (ERR). It is important to be pragmatic when assessing biometric systems using these standard biometric performance measurements as 'lab conditions' may not match those experienced by a banks' customers when they are using the technology. It is important for a bank to ensure that they can continuously measure the performance of a live  biometric system and banks must ensure that their suppliers can meet this requirement.

Usability: Today’s app-driven world means that getting usability right across a wide-range of devices is essential. What might be an appropriate biometric modality in terms of usability at an ATM might not be appropriate when a bank customer is authenticating themselves via a mobile app or via an Interactive Voice Response (IVR) solution. A pilot or proof-of-concept (POC) provides an opportunity for banks to evaluate a biometric system and different biometric modalities. Financial institutions should build usability measurement into these pilots and POCs and to gather feedback from users in reference to how easy the biometric systems are to use. Regional differences also play an important part in the usability choices of a bank; a biometric system that is suitable for one region may be inappropriate for others.

Security: When evaluating a biometric system for banking, banks should ask whether the system is secure and able to meet internal and external (regulatory) security requirements. Biometric systems must adhere to security policy and regulation and biometric data, including templates, should be securely captured, encrypted and stored. 

Regulation: Banking (industry) regulation is the fourth main component of the assessment of a biometric system for bank use. Biometric systems in banking is currently controlled by a mixture of data protection and privacy regulation, such as the EU’s Data Protection legislation, technology-based guidelines including the US’s FFIEC guidance on the use of authentication in an internet environment, and specific financial services regulation including the EU’s Payment Services Directive II (EU PSD II). 

We have published more information on our banking biometric system assessment methodology / tool in our recently published report; Biometrics for Banking; Market & Technology Analysis, Adoption Strategies and Forecasts 2015-2020. Goode Intelligence's biometric advisory and consultancy service aims to assist organisations in choosing the most appropriate biometric systems - contact us for more information. 

Tuesday, 28 October 2014

The role of the Mobile Network Operator in Authentication Services

In previous posts, I have talked about the need to deliver agile authentication services that are convenient to use and address the needs for proving identity across a wide range of services from a variety of endpoints.

Legacy authentication solutions, especially passwords, are continually proving to be both inconvenient and insecure for both consumers and employees – although the lines between the two are being eroded.

Thankfully, a combination of factors including the development and deployment of open standards,  including OpenID Connect, SAML and FIDO, and the creation of innovative mobile-based  authentication technology, including biometrics, are moving us away from a reliance on legacy authentication solutions. Authentication solutions that allow people to authenticate once with the touch of a finger.

PayPal’s FIDO-enabled biometric authentication solution on Samsung devices and Apple’s Touch ID solution is paving the way for wide-scale adoption of convenient user-centric authentication and getting people used to new methods of proving their identity for digital services.

These services are just the tip of the iceberg in terms of the potential for next generation mobile authentication services and I believe that Mobile Network Operators (MNOs) can play an important role in the new authentication landscape as they logical owners of authentication services in an era where accessing the internet is increasingly being made from mobile devices.

MNOs have long standing relationships with millions of consumers around the world and are considered to be trusted organisations that know how to deliver secure consumer-focused services. 

By owning and managing one of the trusted building blocks of mobile communication, the SIM, MNOs have a part to play in the delivery of authentication services to billions of mobile phone subscribers around the world.

I have just completed a piece of work, commissioned by Nok Nok Labs, that details the important role of Mobile Network Operators in delivering the latest agile authentication solutions. You can download the white paper from the Goode Intelligence website here.

I am also taking part in an online webinar organised by Nok Nok Labs to discuss this research on 4th November 2014 at 16:00 GMT. You can sign up to the webinar here.

Thanks for reading. 

Friday, 19 September 2014

Payments drives consumer biometrics and the push for enterprise

I was fortunate to be out in Washington DC last week (8-11 September) speaking at an RSA Global Summit on the future of authentication and presenting my research on mobile and wearable biometric authentication.

The Summit coincided with Apple's latest product launch on the 9th September and I was able to catch up with the announcements during a couple of breaks - unfortunately not aided by Apple's live streaming debacle that was at times verging on the ridiculous. (I particularly enjoyed the Chinese commentary and some severe editing that left out much of what Cook was saying. I got the applause but not the reason for the applause - perhaps that was Apple's corporate comms team in charge of editing?)

As well as a number of new hardware launches including bigger bolder iPhones and a watch....(will it support biometrics for authentication?). We saw Apple make a push into payments with 'Apple Pay'; using the Touch ID fingerprint system to provide authentication for payments (both online and physical). I have been watching Apple create the building blocks for this payment solution over the last couple years - Passcode, iBeacon, Passbook, Touch ID, Secure Enclave and finally NFC. Nice to see the finished solution.

As I said in a couple of interviews with the press last week, what Apple has done is not revolutionary; what it has successfully done is to cement a number of emerging technologies into a usable solution. This is backed by strategic partnerships with the world's largest retail payment  providers and links over 800 million global iTunes users to a mobile payments solution. And from a biometric authentication point of view, with Touch ID, it offers quite possibly the best user experience and the highest penetration of available mobile devices - a frictionless payment tool in a sleek piece of metal and glass. It will be interesting to see how it links other features such as loyalty, social and coupons to the payment app to make it any more appealing than using a plastic card - the value is not in the payment transaction per se.

By also opening up the Touch ID environment to third parties (Touch ID API) it allows other service providers (including financial services providers) to take advantage of this frictionless authentication solution. We have already seen announcements from MINT and Simple bank that they are utilising Touch ID for their mobile banking apps plus a proof of concept from Nok Nok Labs with a FIDO Ready solution. I expect that we will see many more announcements as the devices start to get in the hands of consumers (there is apparently pent-up demand for the latest iPhone from 4S and 5 users wanting to upgrade).

It is quite possible that the trend of Bring Your Own Identity (BYOI) may be accelerated as a result of Apple's Touch ID solution. All a service provider need do is to build an app that uses the Touch ID API and that's my authentication sorted - right?

Talking of FIDO, this year has also seen the world's two largest Internet payment companies, PayPal and Alipay adopt FIDO standards (through Nok Nok Lab's S3 Authentication Suite) to leverage mobile-based fingerprint sensors to provide the prime authentication solution for mobile payments (where the device obviously supports it).

Payments is definitely driving consumer biometrics.

So what about the enterprise? Are they ready to embrace BYOI and adopt authentication solutions for their employees and business partners? I think the answer is a guarded yes but it may take some time.

My time spent at the RSA Global Summit last week in DC was very informative in listening to the thoughts and opinions of enterprise users. Consumer is definitely driving innovation in authentication and this is taking its time to trickle down into the enterprise. In the main, they have BYOI and consumer-based mobile biometric authentication technology on their radar but also need some assurances that the trust, privacy and security models (there is obvious overlap between these three) employed by mobile device OEMs (including Apple, Samsung and Huawei) is good enough to meet security policy and industry regulation.

FIDO can help; by creating a user authentication standard fit for a modern connected world, ratified by some of the world's leading technology companies and service providers, organisations and end users can have a higher level of assurance that trust, privacy and security demands are met. FIDO has real positives in the 'first mile' of authentication but also needs connections to subsequent miles of the authentication and authorisation journey.

Enterprise users in particular demand comprehensive and integrated authentication solutions that combine convenient user authentication (probably on a mobile or wearable device) with other associated risk and security solutions including single sign on/federation, risk based authentication and risk management, business aware authorisation that is context aware and threat intelligence/threat analytics, That's potentially a lot of integration work!

Please free to leave a comment on this blog - I am always interested in receiving feedback and openly discussing this fascinating topic.

Thank you, Alan.




Thursday, 5 June 2014

Touch ID - The Cornerstone of Apple's Authentication Framework

This is an extract from an upcoming Goode Intelligence Analyst Report entitled "Mobile & Wearable Biometrics for Authentication Applications"

Apple caught much of the analyst and biometric community by surprise with the announcement that it was to open up its Touch ID fingerprint biometric environment to third-parties using an API at its annual developer conference, WWDC2014, on 1 June 2014.

Apple announced that once iOS 8 launches (possibly September or October 2014) third party developers will be able to access the Touch ID environment and leverage the benefits of mobile fingerprint biometrics.

During the presentation given by Apple's SVP Craig Federighi, Apple referenced Touch ID being used to authenticate into a personal financial application called Mint.

Apple’s Touch ID Local Authentication Framework (LocalAuthentication.framework) will enable third-party app developers to make use of Touch ID and benefit from its convenient personal authentication features.

Touch ID has been a great success for Apple; Apple also announced some stats for its Passcode phone unlock feature at WWDC. 83 percent of users were turning on the Passcode phone lock feature compared with 49 percent of general iOS users. That equates to millions more iOS devices being protected against unauthorised access and a great deterrent to theft.

Apple has been steadily building up its product and software portfolio to offer a wide range of connected services and it appears that they intend to use Touch ID as the foundation for identity verification on the Apple ecosystem.

I believe that Touch ID will be used to authenticate in the following scenarios (some of these are available now and some are predictions):
  • To replace the PIN for Passcode (device unlock)
  • To provide authentication for Apple ID (iTunes purchases)
  • To verify identity for an Apple payments product (both for online and physical store purchases)
  • To provide authentication for Apple’s CarPlay in-car service
  • To verify identity for Apple’s mobile healthcare solution “Healthkit”
  • To provide authentication for Apple’s connected home solution “Homekit"
    • This includes  the ‘Secure Pairing’ feature where only authorised users can unlock a home door or change the temperature of a room via a smart thermostat
Apple’s vision is to merge the logical and physical worlds using an iDevice (iPhone, iPad or even iWatch) as the smart controller with Touch ID providing convenient biometric authentication for this uber connected world. 

Wednesday, 16 April 2014

The Samsung Galaxy S5 fingerprint sensor has been spoofed - what can be done to prevent it

With the recent news that researchers from SR Labs in Germany have successfully fooled (spoofed) the Samsung Galaxy S5's integrated fingerprint sensor; allowing unauthorised access to the device and the ability to make payments using the PayPal app, there are questions as to how secure fingerprint biometrics are for authentication. These questions are justified. 

An authentication solution can be convenient but it must also be secure.  

A fingerprint biometric can be more convenient than using a PIN or password especially on a mobile phone. By touching or swiping a finger over a sensor a person can quickly unlock a device, gain access to an account or make a payment. However, if the sensor can be easily fooled than the solution is fundamentally flawed. 

The key point in my last sentence was "easily fooled". Attacks on fingerprint biometric systems are relatively difficult to carry out. As Marc Rogers from Lookout Mobile Security pointed out in his blog from last year -  "Why I hacked Apple's Touch ID and still think its awesome" - an attacker needs access to the device and then use a lot of kit to physically create the fake fingerprint. As Rogers stated this can be "tricky" and probably not within the reach of your average street thief. However, with the right equipment and a little ingenuity it can be done. 

So what can be done to ensure we benefit from the convenience of biometric authentication on mobile devices but also have a level of assurance that the solution is difficult to spoof and attack? 

One solution is to improve the anti-spoofing solutions within the biometric system. NexID Biometrics develops spoof mitigation and liveness detection solutions including its Mobile Live Finger Detection (LFD) software. The company claims that the solution can help ensure that the fingerprint system is not spoofed and states that authentication accuracy is as high as 94-97 percent. 

I spoke with NexID Biometrics' COO, Mark Cornett, to get his views on this and he said; "While Apple validated the convenience of fingerprint authentication on mobile devices, the spoof of the iPhone 5S should have sent a signal to other device manufacturers that while providing users with convenient authentication, the current level of security is vulnerable to spoofing. The layers of security for unlocking mobile devices and their applications needs to be stronger to properly meet the needs of users, and facilitators of mobile commerce and BYOD policies. Now that the two largest distributors of mobile devices in the world have had their solutions spoofed, they will hopefully add liveness detection solutions to mitigate this vulnerability and thereby instil confidence in the use of mobile device fingerprint authentication."

As well as anti-spoofing and liveness detection solutions there are other tools that can be deployed to improve the security of these emerging authentication solutions. This include combining biometric authentication with other factors as part of a multi-factor authentication solution - especially useful for step-up verification where a highly level of user assurance is required. 

I am a big fan of behavioural, or gesture, biometrics where the device learns about how a specific user engages with their mobile device to create a profile that can be used as part of a risk-based authentication solution. By combining behavioural biometrics with fingerprint authentication a greater level of trust in who is actually using the device can be created. And when an unauthorised user attempts to spoof the system by using a gummy bear or wood glue mould then the authentication service can request for another level of authentication to ensure that it is the valid owner of the phone and service. The link between the end user authentication client and cloud-based risk-based (anti-fraud) solutions, especially in financial services, cannot be underestimated. 

There are ways in which you can improve the security of mobile-based biometric authentication solutions and deter the type of spoofing attack that has been witnessed with the Samsung Galaxy S5 - I have just touched the surface in what is possible. 

However, an enhancement to the security of the biometric solution should not come at the expense of convenience and usability. 

Mobile device manufacturers and service providers are turning to biometrics because they can enhance the usability of the authentication experience - this must not be altered.

Wednesday, 26 February 2014

Samsung leads the way in mobile biometrics with the Samsung Galaxy S5

In an announcement to a packed auditorium at Mobile World Congress 2014 on the evening of the 24 February 2014, Samsung launched their latest flagship Galaxy smartphone, the S5, containing an integrated fingerprint sensor.



We still need more information on the specifics of how the sensor will operate and interact with the associated services but this is what we know.

The S5 fingerprint sensor is a swipe located on the front of the device underneath the physical home button.

In a promising move from Samsung, they have initially linked the sensor to four consumer and enterprise services that include:
  • Phone unlock
  • Private Mode protection. To protect important documents contained in a secure vault
  • Mobile payments via the pre-installed PayPal app
  • As part of a multifactor authentication (MFA) solution (Fingerprint + Password) for Knox 2.0 authentication
According to reports, the fingerprint service cab register three separate fingerprints and takes up to eight swipes to initially register a user's fingerprint as part of the enrolment process.

The mobile payments app is provided by PayPal who have been working on the development of the supporting ecosystem for a number of years. By leveraging a combination of hardware and software services that include:
  • Integrated fingerprint sensor
  • Hardware security environment provided by TrustZone (Secure Element, SE and Trusted Execution Zone, TEE)
  • Secure authentication protocol and infrastructure (mobile client and server) as part of FIDO Alliance OSTP and commercialised by Nok Nok Labs
  • Merchant service infrastructure to support PayPal mobile payments



Hill Ferguson, chief product officer, PayPal, commented on the development; "By working with Samsung to leverage fingerprint authentication technology on their new Galaxy S5, we are able to demonstrate that consumers don't need to face a tradeoff between security and convenience."

By leveraging the FIDO-ready software, PayPal says that customers can use their finger to pay on the device securely without revealing their fingerprint templates. The FIDO-aware software, created by Nok Nok Labs, communicates between the fingerprint sensor on their phone and its service in the cloud. The only information the device shares with PayPal is a unique encrypted key that is used for identifying the customer without having to store any biometric information on PayPal’s servers.

The fingerprint template is securely stored within the SE and is protected by ARM’s TrustZone environment. This makes it difficult to access or tamper with the biometric template and also allays privacy concerns of having to store a fingerprint in a networked database.

This is extremely positive news for the whole industry.

This is an extract from an analysis of the Samsung S5 found in a Goode Intelligence Market Intelligence report (Fingerprint Biometrics Market Intelligence third edition)


Tuesday, 21 January 2014

From Swipe to Touch to Invisible Touch - The Evolution of Fingerprint Sensors in Smart Mobile Devices

From Swipe to Touch to Invisible Touch - The Evolution of Fingerprint Sensors in Smart Mobile Devices


Readers of a certain age will possibly remember Genesis, the English prog-rock band that featured first Peter Gabriel and then Phil Collins on vocals. In the 1980s they released a rather poor 13th album called ‘Invisible Touch’. Little did they know that we would use that title in a rather obscure pun in an article on the evolution of fingerprint sensors in smart mobile devices (SMD) – the album cover is rather relevant though! And if you hear ‘Invisible Touch’ wafting over the speakers at a product launch at MWC 2014 – you know where they got their idea from.


This blog explores the evolution of fingerprint sensors designed for consumer electronic devices including smart mobile devices; from swipe to touch to ‘invisible touch'. This blog first appeared in the January 2014 edition of the Goode Intelligence Market Intelligence publication; "Fingerprint Biometrics Market Intelligence" (published 28 January 2014). 

Smartphone OEMs rush to embed fingerprint sensors

Despite the intense media attention that accompanied Apple’s launch of Touch ID embedded fingerprint sensors on mobile phones have been around since 1998. Ever since Siemens developed its prototype device back in 1998 there has been steady stream of handsets being biometric-enabled.

Fingerprint sensors are becoming a common-feature of flagship smartphones with an increasing number of mobile device OEMs joining Apple in launching high-end devices during the latter part of 2013. This included HTC, Fujitsu and Pantech. So far, all these Android-based devices have used swipe fingerprint sensors, sourced from either Fingerprint Cards (FPC) or Validity Sensors. For these android devices, the sensor is being located on the rear of the smartphone (see image of HTC One max below).

HTC One max (with Validity swipe sensor located underneath rear camera)

















Apple Touch ID - leader for smartphone touch sensor

Apple is so far the only mobile device OEM to have launched a device with an embedded Touch Capacitive sensor (shown below). The sensor uses capacitive touch technology to take a high resolution (500 pixels per inch or ppi) from small sections of a fingerprint (from the subepidermal layers of the skin).














Source: Apple

There are advantages in using a touch sensor over a swipe sensor on a mobile device:
  • The user experience is usually superior
  • Greater accuracy;  there appears to be fewer failures as the finger is better positioned for touch. For swipe, the finger has to be swiped accurately over the sensor to ensure that the fingerprint is read correctly. On some smartphone implementations, especially on larger devices (phablets), the location of the sensor on the rear of the device makes this difficult when holding the device with one hand 
  • The sensor can be built into a hard button on the front of the mobile device, e.g. home/power button

Non-Apple smartphones - first swipe then touch


Goode Intelligence believes that for the first quarter of 2014 a number of Tier 1 mobile device OEMs will launch flagship models that incorporate a swipe sensor. This will include further HTC models and releases from LG, Lenovo and Samsung (Samsung may want to launch with a touch sensor to match the user experience of Apple’s Touch ID).

The three remaining fingerprint sensor manufacturers who can supply to the mobile device industry, Fingerprint Cards, Idex and Validity Sensors (part of Synaptics) are all in the process of commercialising their versions of the mobile-ready touch sensor.

Fingerprint Cards is probably in a more advanced state of commercialisation and has gone on record to say that their touch sensor (FPC1020) has been sold to a “Tier 1 OEM” for a “flagship smartphone with a targeted launch date in the summer of 2014”[1]

Idex and Validity will follow FPC in launching their own touch sensors during 2014 and GI expects to see them appear in smart mobile devices and other consumer electronic devices.

Next generation consumer fingerprint sensors - Invisible Touch

The third stage to the evolution of mobile device-based fingerprint sensors is driven by the need for greater user convenience combined with a trend to remove physical buttons from smart mobile devices. Partly as a result of the reduction of the bezel-size and driven by the trend for larger touch screen sizes.

The elimination of physical buttons creates a problem for component suppliers including fingerprint sensor manufacturers as it removes an obvious place to position the sensor. It also provides them with an opportunity for new markets for their products.

The positioning of the fingerprint sensor underneath, or within the touch screen, is the next stage in the evolution of consumer fingerprint biometrics and enables mobile device OEMs to remove physical buttons. It also ensures that the convenience of identification, touching a finger on the front of a mobile device, is maintained.

GI believes that all of the fingerprint sensor manufacturers currently operating in the consumer and mobile space are well advanced in their research and development efforts to make this a reality:
  • Idex released this video after demonstrating a proof-of-concept device that placed the fingerprint sensor within the touch screen display
  • Validity Sensors is now part of Synaptics who are one of the world’s largest suppliers of touchscreen technology. Synaptics are also developing fingerprint sensors built into the touchpads that are embedded into laptops and notebooks
  • FPC has demoed demoed touch sensor capabilities with Windows for integration into Windows 8 (8.1) products and also works with CrucialTec, manufacturer of the optical TrackPad (OTP)
This includes Apple and the resources that were integrated as a result of the AuthenTec acquisition.

‘Invisible Touch’ is not only suitable for smart mobile devices; any consumer electronic device that uses a screen has the potential to integrate a touch fingerprint under or within the screen. This could include smart TVs, single-use gaming handhelds, tablets, touchscreen monitors, hybrid notebooks and touchscreens integrated into domestic appliances and smart house control technology. Whether anybody would want to authenticate using their fingerprint for their fridge is debatable (although perhaps if you wanted to stop a young child from turning on an oven or keeping your teenager out of your wine cooler?).

This is a potentially huge market and is part of the wider Consumerisation of biometrics that will revolutionise how we interact with technology.

This opportunity will be explored in an upcoming analyst report published by Goode Intelligence; "Emerging Markets for Fingerprint Biometrics".




[1] FPC wins first 1020 touch sensor DW from Global Tier 1 OEM for their flagship smartphone. 20 December 2013: http://www.fingerprints.com/blog/2013/12/20/fpc-wins-first-1020-touch-sensor-dw-from-global-tier-1-oem-for-their-flagship-smartphone/



Wednesday, 6 November 2013

Bring Your Own Finger - The Consumerisation of Biometrics on Mobile Devices

Firstly, let me apologise for jumping on the BYO bandwagon. I did grimace a bit when writing it but in a way it is rather apt. Biometrics are always with you and you do bring them with you; to the shops, to work, when travelling.....

That's what makes them a very attractive proposition for identification purposes. With the ever-growing list of super-long passwords that we are required to use for an increasingly long list of digital services, the search for an agile method for securely identifying people has been the Holy Grail for some time. Link that with the move towards accessing digital services on mobile devices and you have a situation that creates a perfect environment for easy-to-use, convenient, authentication and identity verification services.

Without even considering the rush by mobile manufacturers to embed fingerprint sensors into their latest smart mobile devices, mobile devices have many sensors that can be leveraged for biometric identification purposes. Cameras (front and rear with the support to capture HD video, high quality microphones, accelerometers for behavioural biometrics etc.

In my latest report for Goode Intelligence, "Mobile Biometric Security - Market Forecast Report 2013-2018", I have revised the forecasts from the original report, published in June 2011, to take into consideration the rapidly changing landscape. My research into this sector has discovered that in the last two years the following factors has created an environment that will create a market that is worth US$8.3 billion by 2018:

The Consumerisation of Biometrics: Apple has changed everything and has again disrupted a market and rebranded biometrics as a convenient method of communicating with consumer technology. Previously, Biometrics has largely been associated with high-end security; border control, national ID solutions and for providing access control for high-security buildings. This has all changed with the Apple iPhone 5s and Touch ID

Convenient mobile device protection: Existing mobile device authentication is cumbersome and inconvenient.  This means that many devices are left with no protection. Replacing a PIN or Passcode with an easy-to-use biometric can reduce this burden

 Mobile Commerce: Mobile devices have become the prime method of carrying out digital commerce yet identity verification and payment authorisation has not yet been updated to match this form factor. Biometrics can offer a convenient and secure method to prove identity and to authorise payments

As part of a multi-factor authentication solution: Most of the major authentication vendors support, or have plans to support, biometrics in their authentication products. This will be supported by authentication standards initiatives such as the FIDO Alliance that will enable biometrics to be easily utilised, when available, on mobile devices

Mobile devices are getting more secure: Apple’s Touch ID fingerprint solution makes use of a ‘secure vault’ to ensure that the fingerprint templates are stored in a secure area of the hardware. It is thought that Apple is leveraging ARM’s TrustZone, a hardware-security environment for secure storage and trusted execution. Security services are being built into all mobile platforms to counteract malware and to protect sensitive information and transactions. Complimentary services such as Mobile Device Management (MDM), Secure Containers and Mobile Application Management (MAM) create a trusted platform to support biometric security on consumer mobile devices

Friday, 27 July 2012

What does Apple's acquisition of AuthenTec tell us about biometrics on mobile devices?


I am not surprised with the news that Apple has acquired mobile security and fingerprint sensor vendor AuthenTec in a deal worth $356m. 

I have been following the mobile security market since 2004 and this has included the publication of a report for my research and consultancy company, Goode Intelligence, on mobile biometric security published in June of 2011. Smart Mobile Devices (SMDs), a term that we use to define smart phones and tablets, have become the portable computer of choice for both personal and business use. However, questions remain as to the effectiveness of security controls for these devices with the recent Black Hat conference in Las Vegas being dominated by presentations that detail the vulnerabilities of these devices. 

Apple's acquisition of AuthenTec, who are not just about fingerprint sensors, is a positive move by the Cupertino-based company and could lead to next generation Apple products having embedded security controls, both hardware and software-based. 

As seen in the Goode Intelligence annual mSecurity survey report, Apple iOS has become the number one choice for the enterprise. This position will be well and truly cemented if Apple strengthens its security as a result of the AuthenTec acquisition. 

Will this mean embedded fingerprint sensors in next generation Apple products including the iPhone and the iPad? With the acquisition of AuthenTec this has become more likely. I interviewed AuthenTec as part of my research into the mobile biometric market and back in May 2011 they said this; “the integration of fingerprint sensors into wireless smart phones, feature phones and tablets is in its early stages and will accelerate.” Accelerate as a result of being in every iPhone and iPad? A distinct possibility.

Embedded fingerprint sensors on mobile devices are being used to protect the phone (augment standard phone lock as my Motorola Atrix 4G admirably does) and to provide authentication to support NFC-based transactions, including payments, at physical locations. AuthenTec has been doing well in this market since 2004 when it first supplied fingerprint sensors for Fujitsu mobile phones to be used to secure mobile payments for NTT DoCoMo in Japan. With rumours that the next generation iPhone (iPhone 5) will support NFC, will Apple be combining biometric authentication through the use of an embedded fingerprint sensor for mobile payments at the physical point-of-sale?

I was pretty cautious when forecasting the growth of mobile biometric security products and services back in 2011, predicting that the market would grow to 39 million users by 2015. This quote from the report highlights this; "The market is currently slow; but pressure is growing. Things could change rapidly, from an interesting concept to a 'must have' for all smart mobile devices."

I did go on to make a conditional statement that is very relevant with this news;

"However, this could all be thrown on its head with the introduction of embedded biometrics on mobile devices by one of the major manufacturers – and not just a single product line but standard on all mobile phone products. The market is always eagerly waiting for the next generation of Apple iPhones and rumours are circulating that Apple iPhone 5 may include some form of biometric technology."

Could this news be the catalyst to accelerate the adoption of biometric security onto smart mobile devices - there is now much more of a chance of this happening. I look forward to seeing how Apple build on AuthenTec's success in the mobile security world.

For news, opinion and analysis on all things mobile security follow me on Twitter - @goodeintel