Showing posts with label goode intelligence. Show all posts
Showing posts with label goode intelligence. Show all posts

Wednesday, 21 June 2017

Tackling Regulatory Change Through Automation and Machine Learning



Machine learning and AI technologies are starting to support compliance management functions. The ability to automate resource and data intensive processes is beneficial to compliance management functions struggling with increasing levels of regulatory data. 

Financial services organizations are dealing with a tidal wave of regulatory change that shows little sign of abating. As part of my research for a new study published by Goode Intelligence investigating how machine learning and automation can get regulation under control, I interviewed compliance officers and Regtech experts in both the UK and the US. A compliance officer based in London told me that the financial services industry is facing "mountains and mountains of regulation". This statement is echoed by industry experts including the Boston Consulting Group who believe that "regulation must be considered a permanent rise in sea level - not just a flowing tide that will ebb or even cresting tsunami that will recede."(1)

The combination of information overload and manual regulatory change analysis is creating headaches for many organizations that cannot afford to invest in large specialist compliance teams or automation. The reliance on under-staffed compliance teams to sift through vast reams of complex regulatory data can lead to mistakes – mistakes that organizations cannot afford to make when failure to comply to regulation can lead to financial penalties that can run into the millions, even billions, of dollars. Since the global financial crisis of 2008, banks globally have paid $321 billion for a number of regulatory failings from money laundering to market manipulation. (2)

To reduce the ever-increasing burden on compliance teams, financial service organizations can turn to new regulation change management solutions that automates resource-intensive tasks through machine learning technology.

Just as financial services organizations are increasingly turning to FinTech tools to take advantage of advancements in areas like automation, machine learning and cloud computing, these firms can also turn to the new sector of RegTech to better manage regulation and turn it into an advantage.

Leveraging expert-in-the-loop (EITL) machine learning for automating document frees up compliance professionals to focus their time on the details of actually helping their organizations comply with regulations, rather than just laying the groundwork. 

A smart machine learning compliance solution must offer the following core competencies:
  1. Aggregation - from a comprehensive variety of sources
  2. Normalization - of millions of documents, citations, rulings and publications
  3. Curation & Classification - based on expansive EITL machine learning model foundation
  4. Trend analysis - transform raw regulatory data and peer-review trends into distilled insight
  5. Personalization and notification - follow specific regulatory topics
I explore this further in a white paper that references the latest Regtech solution from Compliance.ai entitled "Getting regulation under control with Compliance AI".







(1) Global Risk 2017: Staying the Course in Banking / March 2017 published by the Boston Consulting Group https://www.bcg.com/en-gb/publications/2017/financial-institutions-growth-global-risk-2017-staying-course-banking.aspx
(2) Boston Consulting Group February 2017

Thursday, 1 June 2017

Five Considerations for Selecting a Consumer Authentication Vendor

In today's mobile-first world, consumer authentication is driven by the need of having a smooth user experience. Of course, it has to be secure and tick all of the boxes for privacy and regulation but when I talk with clients, both authentication vendors and service providers, they all say that the number one priority is having a great user experience (UX). If the authentication user experience fails then customers will simply walk away and go somewhere else or choose an alternative payment method.

I was recently asked to create a white paper for RSA and EyeVerify on key considerations for selecting a consumer authentication vendor. I identified five key considerations:

  1. Consumer choice
  2. Convenience
  3. Demonstrable fraud reduction
  4. Meeting a 'mobile first' strategy'
  5. Regulation compliance
These five considerations are powerful criteria for organizations when assessing authentication solutions and vendors.

Consumers must be given a choice of convenient, easy to use authentication services. The availability of a wide range of device-based authentication technologies including multiple biometric solutions supports this requirement. Convenience and consumer choice can also be combined in a well-designed consumer authentication solution. The combination of risk based authentication (RBA) and mobile biometric authentication services (MBAS) can meet this criteria. Risk based authentication can meet a good percentage of normal authentication scenarios and mobile biometrics can be applied to authentication scenarios that require further ‘proof’ of true identity; a combination of frictionless and friction-light authentication.

Service providers are increasingly pressured to support legacy service channels including physical (bank branch and retail store) and telephony at the same time as evolving their offering to work across a wide range of new technology, first web, now mobile and moving swiftly into the Internet of Things (IoT). When choosing an agile technology partner that can support multiple delivery channels, omnichannel support, an organization must ensure that they choose an authentication solution that can operate across a wide range of these channels. The mobile first strategy can allow organizations to design and deploy effective authentication services that meet this consideration.

Fraud is rising in all sectors. A consumer authentication vendor must be able to demonstrate fraud reduction as a result of deploying the chosen authentication solution – measurable and tangible fraud reduction benefits.

Around the world, regulatory powers are adapting existing regulation or introducing new ones to ensure that consumers are protected when using the latest digital services. A trusted technology partner must be able to demonstrate:
  1. It can help organizations address the latest federal and industry regulations; and
  2. It actively participates in influencing regulatory bodies to ensure that convenience and ease of use are not sacrificed at the expense of over rigid security requirements.

Getting the balance between security and convenience is an essential ingredient in supporting flexible digital service delivery.

To read the white paper in full, you can download it from the Goode Intelligence website here.

Thank you - Alan

Wednesday, 7 September 2016

Apple September Event - Any new Biometrics Features?

The net is buzzing with its usual mixture of the possible, the potential and the damn-right ridiculous predictions on what Apple will announce later today at its September device event. In the mix has been a number of rumours on what Apple may do in terms of supporting biometrics.  Time will tell, but before the event takes place here is a list of some of them with my views on them.

iPhone 7
The most believable is changes to the home button with either a more flushed designed button integrated into the display or removal completely. Most fingerprint sensor designers have been working on integrating a sensor underneath the display (under glass) rather than underneath a coated button and Apple is probably ahead of the curve in its development. 

There is a strong possibility that Touch ID on iPhone 7 will be an under the glass sensor (probably still capacitive) and Apple may have had to either reduce the thickness of the glass or develop a recess in the glass to reduce its thickness to ensure that the sensor's performance is not degraded. 

The integration under glass may also mean the development of 'Force' Touch ID and could mean that the sensor could improve anti-spoof capabilities by measuring the force of its registered user's touch in addition to the usual matching against  stored fingerprint templates. 

With Iris being integrated into the Samsung GN7 (unfortunately recalled) there have also been rumours that iris recognition will be supported in this version. It is likely that this will have to wait until at least iPhone 8. 

Watch 2
The most reliable rumours on new sensors points to GPS. As my Sony SmartWatch 3 has this feature, I can definitely see that having GPS in a watch definitely makes the device more independent and is a great feature when you out running (According to Google Fit this last occurred in February for me - shocking I know). The partnership between Precise Biometrics, FPC, Gemalto and STMicro in developing a biometric platform for wearables has given us a clear indication that integrating biometric sensors into wearables, for authentication and identity, is viable. Whether Apple sees any merit in doing so is questionable. Payments has been a major driving force for biometrics and for Apple to support a standalone payments app on a smartwatch that  replicates the iPhone security environment including the secure enclave is debatable from a business case point of view. 

We may see the watch having more independence from a paired iPhone but I would be surprised to see a decoupling in this context. I would say there is an outside chance of a separate biometric (identity) sensor being integrated into Watch 2. 

I look forward in hearing what Apple will actually do later today and will follow-up this blog with another one with analysis on anything that is important from a security and identity perspective.

Addendum 09/09: After the official announcements from Apple on iPhone 7 and Watch 2, comments on my predictions. Not a lot of direct announcements on biometrics. However, Apple has changed the home button in creating a solid state version with force features and taptic feedback. There was no clarity on whether there is any changes to Touch ID as a result of this change. As predicted, no support for other modalities including Iris and no Biometrics for the Watch. I am currently researching the mobile biometrics market so keep a watch out for further updates in this area. Thanks. Alan

Thursday, 14 July 2016

Will Brexit affect PSD2's Strong Customer Authentication Requirements?

There is no doubting that Brexit is having a profound affect on the UK and ripples of disruption have been felt around the world as result of the UK's decision to leave the EU.

I have written extensively on EU and EC legislation and its impact on a number of cyber security matters including mobile security, identity, authentication and biometrics. 

Recent researchhas investigated the impact of PSD2  on security; in particular the impact on how payment service providers (PSPs) manage customer authentication. 

To summarise the main objectives of PSD2:

  • Contribute more to a more integrated and efficient European Payments market
  • Improve the level playing field for payment service providers (PSPs), including new players
  • Make payments safer and more secure
  • Protect consumers
  • Encourage lower prices for payments

The European Parliament adopted PSD2 in October 2015 and EU member states have two years in which to implement the new procedures. The EC states that there is a different date of application for the new security measures, including Strong Customer Authentication (SCA) and standards for secure communication. This is subject to the adoption of the regulatory technical standards which are being developed by the European Banking Authority (EBA) and adopted by the EC. It is anticipated that the new security measures shall apply 18 months after the adoption of the standards by the EC.

PSD2 provides rules for payment security and customer authentication, concentrating on protecting consumers when paying on the internet. 

PSD2 applies to all payment service providers (PSPs) operating in the EU, including banks, payment institutions or third party providers (TPPs) and relates to all electronic means of payment.
The EC defines SCA as a process that “validates the identity of the user of a payment service or of the payment transaction”.

SCA is based on the use of two or more elements:
  1. Knowledge - something only the user knows, e.g. a password or a PIN
  2. Possession - something only the user possesses, e.g. a card or an authentication code (OTP) generating device
  3. Inherence - something the user is, e.g. a biometric authenticator such as fingerprint, voice or eye-print
PSD2 states that these elements have to be independent of each, meaning that if one element is breached or compromised then this does not compromise the “reliability” of the others. The design of the authentication solution must also protect the confidentiality of the authentication data or identity credentials. 
As the UK has voted to exit the EU, will this mean that UK banks and PSPs will not be bound to comply with these regulations (and in fact other EU legislation)? This is a difficult question to answer as the exact nature of the UK's exit and what will exactly be negotiated as the UK triggers Article 50 is still very much up in the air. What I think will happen is this:
  • UK banks and PSPs that have functions in the EU will have to comply with PSD2 - it also makes competitive sense to support PSD2
  • PSD2's authentication requirements are pretty-much the basic requirements for supporting strong customer authentication and it makes common sense to support them especially some of the risk-based authentication services that enable lower-risk payment transactions to be exempt from strong customer authentication
  • Some UK retail banks are owned by European organisations who will want to have a common strategy for customer authentication that supports PSD2
As the UK's ex Prime Minister, Harold Wilson said in the 1960s "A week is a long time in politics" and I am sure that there will much debate over the coming months and years about the relevance of EU legislation to the EU. If you are a UK bank and have started projects to ensure compliance to PSD2 then I am pretty sure that these will not be halted as a result of Brexit.
Please let me know your thoughts my commenting on this blog. Thank you and remember in the global economy no nation is an island!

You can download the Goode Intelligence White Paper "The impact of PSD2 on authentication and security" from here.

Thursday, 7 July 2016

The Future of Mobile Security

Mobility is the new normal for enterprise users. With forecasts from the GSMA predicting that 80 percent of adults on earth will have a smart phone by 2020 these always connected and always on devices are the most popular personal computer in history.

The use of smart mobile devices (smart phones and tablets running mobile platforms such as Apple iOS and Google Android) in the enterprise is rising rapidly each year. Figures from Citrix indicate that the number of smart mobile devices (SMD) managed in the enterprise increased by 72 percent from 2014 to 2015.

What is surprising, however, is that the enterprise is not fully embracing mobile. Whether it is an employee-owned Android smart phone or a company-issued and controlled iPhone productivity-enhancing enterprise services are still relatively scarce within the enterprise. Outside of email and calendar applications there are relatively few examples of enterprise mobile apps. This differs from the current situation with consumer adoption of mobile where it dominates social, financial services, commerce and entertainment.

So why is? In the latest white paper from Goode Intelligence, the issues facing the enterprise in delivering services to mobile is explored. The report discovers that a mixture of technology constraints, security concerns, compliance to regulation and privacy law are having an impact of restricting mobile enterprise services.

Enterprises do face a challenge in enabling productivity enhancing applications to be available through smart mobile devices but there are ways in which they can combine the convenience of mobility and strong security mechanisms that meet company security policy and comply with regulation. In covering mobile security since 2007 I have learnt that next generation mobile security solutions should have these characteristics:
  • They should focus on users
  • Support agile multi-factor authentication (MFA) with a choice of authenticator to match the context 
  • Be able to provide mobile-based single-sign-on (SSO)
  • Must protect the data, both at rest and during transmission
  • Be available in a simple to use and unified security offering
I believe that there are very few solutions that offer a unified solution that supports these characteristics and this is why we have seen limited adoption of full-throttled enterprise services for mobile. Often, an organisation will have to mix and match technology solutions to support this vision and this can be expensive and time-consuming. A solution that combines the functionality and features of a next generation mobile security solution is the Sign&go Mobility Center from Ilex International. 

This product provides an integrated security solution to solve the enterprise mobility conundrum; mixing convenience and mobile security in a unified product and provides:
  • Strong Multi-Factor Authentication supporting one, two or three factors
  • Mobile SSO
  • Data Protection in a secure container
Without the combination of these features, organisations will remain limited in what productivity-enhancing mobility solutions they can deliver. 



Friday, 26 February 2016

Biometrics Takes Centre Stage at MWC 2016

This is my fourth year of being a judge for  the GSMA's annual Global Mobile Awards (Mobile Identity and Mobile Security category) and each year I am seeing an increase in the number of entries that are using biometrics to protect smart mobile devices and the services that are being accessed from them.

One of this year's nominees (finalists) was Hoyos Labs who were nominated for their 1U mobile biometric authentication product. Hoyos Labs is one of a growing list of companies that are showcasing their biometric solutions at Mobile World Congress (MWC) as mobile has been a major catalyst for the rapid growth in biometric technology and its adoption by millions of consumers.

Alongside Virtual Reality (VR) technology (did you see that crazy image of Mark Zuckerberg entering the auditorium with all those people plugged into VR units?), wearables was one of the big themes of this year's MWC. We have had limited adoption of biometrics on wearables for security purposes and one consortium of technology companies wants to change that by providing a solution that offers hardware OEMs a platform for building biometric authentication in a range of wearable devices. Gemalto, Fingerprint Cards, Precise Biometrics and STMicroelectronics have partnered to introduce an end-to-end security framework for the use of fingerprint biometrics on wearable devices. The partnership will demonstrate a solution that embeds a fingerprint sensor from Fingerprint Cards, fingerprint software from Precise Biometrics and secure NFC and low-power mircocontrollers from STMicroelectronics. Gemalto is providing the UpTeq eSE , secure hardware where the user's credentials are stored, and the match-on-card application that validates the fingerprint.

The financial services market has been the fastest growing area of biometric adoption with our (Goode Intelligence) forecasts of over 120 million users in 2015. On the back of HSBCs decision to roll-out voice and fingerprint multi-modal mobile biometric authentication to its UK customers in 2016, MWC 2016 witnessed a flurry of announcements for this sector. 

MasterCard is another financial services company that is planning to roll-out multi-modal mobile-based biometric authentication with the decision to deploy fingerprint and facial-recognition technology in around 14 countries. MasterCard's 'selfie pay' solution was piloted in the Netherlands in 2015 and proved to be so successful that it will be available to millions of payment customers around the globe. The aim is to offer this solution to replace MasterCard's 'SecureCode' online payment verification solution. This is an ideal solution and solves a real problem; how do you verify those transactions that need additional user verification and also make it convenient. How many people currently abandon the payment process when the SecureCode window pops up and asks you to enter your 2nd, 5th and 7th letter of your SecureCode? Touching a finger against a sensor or taking a selfie on your smartphone is miles better and should play an important role in reducing Card-Not-Present (CNP) fraud, making it easy to prove you are who you say you are. 

Visa, not wanting to be outdone by its main card scheme competitor, also made announcements on biometrics at MWC including a tie-up with Morpho. Morpho has many years of experience in the high-end biometric market (identity and law enforcement) and wants to apply this experience to the consumer market. This includes the use of the MorphoWave four-finger scanner at the physical point of sale. MorphoWave can scan and match four fingerprints in under one second without any sensor contact and involves a customer waving their hands through the scanner. 

This is just a selection of the activity that is happening with the convergence of mobile, wearables and biometrics at the moment. If you are a company that is involved in this exciting area of technology then please reach out to me - either through this blog or via the enquiry email address at Goode Intelligence; enquiry at goode intelligence dot com.

Thank you. 










Monday, 19 October 2015

Innovation in Biometrics Enables Alternative Payment Methods

Payments have been the major driving force for the wide-scale adoption of biometrics in the consumer market. Today, millions of customers (Goode Intelligence forecast 350 million plus during 2015) are using biometrics on a daily basis around the world to provide secure convenient user authentication and transaction authorisation and this theme is set to continue with a forecast of over three billion users by 2020. 

Biometrics for payments is increasingly a vital part of a payment service providers’ toolkit in the never-ending task of reducing financial fraud and ensuring that their customers can conveniently prove their identity and authorise transactions.

The adoption of biometrics for payments is also leading to wide-scale disruption in the payment industry, enabling alternative methods for consumers to pay for goods and services in a variety of payment scenarios. This is not simple replacing one authentication mechanism with another; the finger replacing the PIN. Biometrics is allowing alternative payment methods to be introduced, some of which are being supplied by non-traditional payment service providers. 

HYPR Corp has developed a biometric security protocol that provides digital payment platforms, including Bitcoin, with a solution to secure access to their digital payment assets.

One of the core security concerns around Bitcoin and other digital currency platforms is that unlike with credit cards, transactions are irreversible.

HYPR was founded to solve the core fraud problem by providing a definitive answer to the question of “Am I who I say I am?” 

HYPR answers the question of “Am I who I say I am?” through a three-factor authentication protocol that creates a biometric authentication bridge between the user and their mobile wallet. The cryptographic algorithm that HYPR uses is the same as the digital signature algorithm that the Bitcoin protocol uses. Because of this similarity, future iterations of the HYPR biometric security platform could be used to biometrically validate Bitcoin transactions.

Another company looking to secure Bitcoin transactions is Nymi with their heartbeat-enabled wearable band. The Nymi band can be used to store a users Bitcoin in a native biometric wallet with the private key tied to a unique ECG biometric signature. I recently demoed the capabilities of the Nymi band at a presentation I gave on the future of biometrics for wearables at the Biometrics 2015 conference in London. I even use the Nymi band to log me into my office computer and have been impressed at how natural it feels to allow me access to my computer. 

It is also enabling new ways in which consumers can use traditional payment methods, even cash (still the preferred payment type for many people). Hoyos Labs has developed a smartphone-based biometric authentication solution that aims to reduce the increasing amount of fraud at the ATM, negating the problem of bank card skimming. Their 1U ATM product is a software platform that allows bank customers to access their accounts via ATMs using biometrics on smartphones. There is no need for cards or for the customer to enter in a PIN at the ATM as the entire authentication occurs on the customer’s smartphone.

The Hoyos Labs solution is compatible with existing ATM platforms and does not need any hardware to be installed on the ATMs.

These are just three examples of how the latest biometric solutions are protecting payments and enabling alternative ways in which we can pay for a wide range of goods and services in a variety of payment scenarios; from Bitcoin to the humble bank note

I explore many more examples of biometric payments, including the rise of the mobile wallet, in an analyst report recently published by Goode Intelligence; "Biometrics for Payments; Payment Security Gets Personal". 
 



Thursday, 2 July 2015

A guide for banks in choosing the most appropriate biometric system

Banks are racing ahead in deploying biometric systems in an attempt to control rising levels of financial fraud and to reduce friction on inconvenient forms of authentication and fraud management. 

There are many different competing biometric modalities that banks can implement but what criteria do (or should) they use to ensure that the biometric system is appropriate.

Through Goode Intelligence, I have been involved in a number of consultancy engagements with banks and suppliers to assist them in assessing and choosing the most appropriate biometric system to meet their requirements.

Based on this experience, and engagements with a wide range of biometric and authentication technology companies, we have devised an assessment methodology that banks and systems integrators can use to ensure that the most appropriate biometric system is chosen. 

The Goode Intelligence Banking Biometric System Assessment (BBSA) tool is based on four interlocking parts, biometric performance, usability, regulation and security. It is also applicable to other highly regulated industries including healthcare, government, telecommunications and utilities. 


The methodology provides guidance to banks in assessing biometric systems and exactly how a bank weights the assessment criteria is dependent on their own set of circumstances such as budget, security policy, bank channel, regulatory environment and risk and privacy models.

There will obviously be other technical and non-technical assessment criteria that a bank will use including integration, scalability and support models etc. 

Biometric Performance: The assessment of the biometric performance and accuracy of a banking biometric system includes measurement of False Reject Rates (FRR), False Acceptance Rates (FAR) and Failure to Enrol Rates (FER). The accuracy of a banking biometric system is expressed as an Equal Error Rate (ERR). It is important to be pragmatic when assessing biometric systems using these standard biometric performance measurements as 'lab conditions' may not match those experienced by a banks' customers when they are using the technology. It is important for a bank to ensure that they can continuously measure the performance of a live  biometric system and banks must ensure that their suppliers can meet this requirement.

Usability: Today’s app-driven world means that getting usability right across a wide-range of devices is essential. What might be an appropriate biometric modality in terms of usability at an ATM might not be appropriate when a bank customer is authenticating themselves via a mobile app or via an Interactive Voice Response (IVR) solution. A pilot or proof-of-concept (POC) provides an opportunity for banks to evaluate a biometric system and different biometric modalities. Financial institutions should build usability measurement into these pilots and POCs and to gather feedback from users in reference to how easy the biometric systems are to use. Regional differences also play an important part in the usability choices of a bank; a biometric system that is suitable for one region may be inappropriate for others.

Security: When evaluating a biometric system for banking, banks should ask whether the system is secure and able to meet internal and external (regulatory) security requirements. Biometric systems must adhere to security policy and regulation and biometric data, including templates, should be securely captured, encrypted and stored. 

Regulation: Banking (industry) regulation is the fourth main component of the assessment of a biometric system for bank use. Biometric systems in banking is currently controlled by a mixture of data protection and privacy regulation, such as the EU’s Data Protection legislation, technology-based guidelines including the US’s FFIEC guidance on the use of authentication in an internet environment, and specific financial services regulation including the EU’s Payment Services Directive II (EU PSD II). 

We have published more information on our banking biometric system assessment methodology / tool in our recently published report; Biometrics for Banking; Market & Technology Analysis, Adoption Strategies and Forecasts 2015-2020. Goode Intelligence's biometric advisory and consultancy service aims to assist organisations in choosing the most appropriate biometric systems - contact us for more information. 

Friday, 17 April 2015

Biometrics for Banking Gets Going

I was talking with a senior manager responsible for authentication strategy at a leading retail bank recently about their views on biometrics for user authentication and whether they were thinking of adopting it. I remember a similar conversation with the same person in 2013 and remember them declaring that biometrics was simply not a possible solution for them; a combination of hardware and software OTP tokens was still the favoured solution. 

Moving forward two years and there has been quite a turn-around in their perception of biometrics for providing authentication to bank customers when accessing digital banking services. Biometrics is definitely on the agenda for them and they have a number of live and pilot projects that are leveraging biometrics on mobile devices including the support of Apple Touch ID for mobile app authentication. 

So what has changed in two years for them? 

I think the fundamental reason is the need for convenient privacy-aware authentication across a number of banking channels with the emergence of mobile as the prime banking channel (not forgetting the start of a wearable banking strategy). A hardware OTP token works well enough when a bank customer is accessing banking services from a desktop computer at home but simply does not cut it when that same customer is using their mobile phone or calling up their bank using a telephone-based service. These 1980s two-factor authentication technologies are also susceptible to Man-in-the-Middle (MitM) and Phishing/Malware attacks.

This has led banking security professionals to look for alternatives that meet the needs to strongly authenticate across a wide range of existing banking channels. The explosion of FinTech-led financial services has also meant that challenger banks are looking at other innovative ways that customers can interact with their banks; biometric authentication gives them the potential to offer their customers a usable and secure method to protect their financial assets when accessing financial services from a range of endpoints.

The use of integrated fingerprint sensors is just one method of providing convenient banking user authentication and will continue to grow as more devices become available. However, I believe that the solutions will evolve and increasingly incorporate other authentication factors and biometric modalities to provide strong security and convenience. For instance, by combining face and voice in a multi-modal biometric authentication solution that can work across a range of banking channels. USAA's recent deployment of Daon's IdentityX multi-modal mobile authentication platform is a great example of this. 

Depending on the context of the transaction/interaction then you can either use a single modality - voice in an IVR interaction - or a combination of modalities - face and voice for mobile or desktop banking services. The combination of context and security risk will dictate the most-appropriate modality or factor to use.

There has also been a lot of debate as to the choice of biometric architecture that a bank should adopt; device-centric, where the biometric data never leaves the device, or server-centric, where the user enrols their biometric and then is stored by the financial institution. For verification; the matching is performed on the device for the device-centric model and against a stored template within a network database (Cloud) for the server-centric model. I think that both models have their merits. I believe that the decision to adopt one over the other (and there will be scenarios where a mixture of both will be adopted) will be driven by a combination of privacy/trust requirements and specific business drivers (some of which will be moulded by culture decisions, i.e. availability of national biometric database). 

For on-device biometric authentication services, I believe that the best approach that meets privacy and trust requirements is to utilise embedded security within mobile devices; Secure Enclave for iOS and TrustZone in ARM-based devices. A great example of this is voice biometric specialist AGNITiO's KIVOX Mobile solution that leverages TrustZone embedded hardware security using a FIDO-Ready implementation developed by Nok Nok Labs. In this model, the bank customer would enrol their biometric voice print on their smart mobile device and then be able to access mobile banking services securely using their voice for authentication. AGNITiO also support the server-centric and IVR-based models ticking the boxes to support multi-channel banking. 

Apple's Touch ID has certainly changed the perceptions of the decision makers in banking security, allowing biometrics to be a serious contender in providing authentication for banking services. There is also a role that biometrics could play in reducing the amount of fraud that is occurring for Apple Pay. There seems to be no problem with Apple's biometric authentication services itself, rather a problem with the card activation (provisioning) process that allows fraudsters to enrol stolen credit cards into Apple Pay and then cash out by purchasing thousands of Dollars worth of Apple kit in-store. Biometrics could close this loophole by allowing the card issuer to validate a legitimate card and its owner using an enrolled voice biometric. Tied in with the card issuer's fraud management system, a customer who was attempting to enrol a credit card into Apple Pay would receive an automated voice call that could verify the legitimacy of the card holder by verifying an enrolled biometric voice print. I don't feel that it would add much friction to the process and have the positive result of reducing this type of credit card fraud. 

I expect to see a lot of innovation in this space where bank-controlled multi-modal biometrics will compliment integrated mobile biometric solutions that have been deployed by the mobile OEM to enable customers to securely access full-banking services from a wide variety of end points. 




Monday, 2 February 2015

The Impact of Privacy and Data Protection Legislation on Biometric Authentication

As more and more biometric solutions are deployed to mainstream digital services, questions surrounding the privacy and security implications of biometrics are increasingly being asked.

With the growth of biometric technology and its expansion on to consumer digital services, privacy and security concerns are correspondingly growing.

As biometric data is being captured and stored on a wide range of smart mobile devices (SMDs) including Apple’s iPhone and iPad, Samsung Galaxy and Huawei smartphones, or stored in cloud-based biometric databases there are inevitably questions as to how this incredibly personal data of ours is being protected.  

There is much debate about the relative merits of these two trust models; is the device-centric approach that Apple and FIDO employed too restrictive a model? And can I trust the security of a database (cloud-based) biometric solution?

How, and where, is my biometric data being stored? Who has access to it? How well is it protected? When I enrol my fingerprint on my smartphone, is it stored in secure hardware and does it ever leave the security enclave? What legislation and regulation is in place to cover the privacy and security aspects of biometric technology?

These are all valid questions that citizens, service providers, biometric technology vendors, governments and hardware manufacturers need to answer.

Regulation is still playing catch up with the proliferation of biometric authentication and identity systems and in many regions there is little control on how biometric data is captured, stored and accessed. This is an alarming situation.

In a number of regions including the European Union (EU), biometric data is beginning to be considered as personal data and as such, is governed by data protection and privacy legislation.

In the case of the EU, protection of privacy and personal data is covered by the Data Protection Directive of 1995 (officially Directive 95/46/EC). The directive relates to the protection of individuals with regard to the processing of personal data and on the free movement of such data.

In April 2012, the Article 29 Working Party issued an ‘Opinion’ in biometric technologies with particular attention to fingerprints, vein patterns, facial, voice recognition, DNA and signature biometrics.[1] The Opinion aims to provide a framework of recommendations and guidelines for the implementation of data protection rules in biometric applications.

The Opinion has a number of recommendations (legal and technical) related to biometric data. These include suggestions on user consent, contract and the concept of “privacy by design” for biometric systems.

In other regions including Australia, Canada and the USA, there is federal and state data protection legislation that could be applied to biometric data but nothing specific (although there have been attempts to integrate biometric data into general data protection legislation in Australia).

In addition to federal and state data protection legislation there must be specific regulation and guidelines from a sector perspective. The financial services market is one sector that has a decent track record on data protection and identity (including authentication) matters and there are references in the EU’s Payment Services Directive II. The Payment Service Directive II regulates payment services and payment service providers such as banks within the EU and recommends “various due diligence procedures in regard to the safety of personalised security features of payment authentication instruments.”

The new Directive on Payment Services II which might possibly be approved in 2015 suggests that a biometric authentication system is deemed secure and advisable. The Directive recommends the use of `strong user authentication’ which is defined by the European Central Bank (ECB) in its “Recommendations for the security of internet payments” document.[2] The report defines strong user authentication as “a procedure based on the use of two or more of the following elements– categorised as knowledge, ownership and inherence: (i) something only the user knows, e.g. static password, code, personal identification number; (ii) something only the user possesses, e.g. token, smart card, mobile phone; (iii) something the user is, e.g. biometric characteristic, such as a fingerprint".

Fingerprint biometric authentication has been one of the fastest growing authentication technologies ever, offering a convenient method for authenticating users especially on smart mobile devices. It is not the only biometric method that will gain widespread adoption. I am a big fan of behavioral biometrics, especially for financial services as it fits well into existing anti-fraud and risk management solutions that are often used by financial companies. It can also complement existing authentication and biometric authentication solutions in enabling service providers to have a much more accurate mechanism of proving that a particular device or web session is actually being used by the legitimate user; rather than in the hands of a fraudster. 

Behavioral biometrics is based on a behavioral trait of an individual and includes how individuals uniquely interact with a device – be it a smartphone or a laptop accessing a website. Behavioral traits include keystrokes and interactions with a touchscreen.

Goode Intelligence has just published a white paper commissioned by behavioral biometrics specialist, BehavioSec investigating the impact of privacy and data protection legislation on biometric authentication and it is available free to download here.

As always, I welcome your thoughts and opinion on this blog and on the contents of the white paper.







[1] Opinion 3/2012 on developments in biometric technologies, 0072012/EN/WP193, 27/04/2014, Article 29 Data protection Working Party: http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2012/wp193_en.pdf

Thursday, 6 November 2014

Moving from what I carry to what I wear - wearable technology brings biometric authentication closer to us

Biometrics has been creating a tremendous amount of buzz this week at two separate shows, one in Paris - CARTES 2014 - the other in Las Vegas - Money 20/20. Innovative biometric technology vendors such as EyeVerify (Eye Vein) and Agnitio (Voice) have been demonstrating how their respective technologies can bring convenient user authentication to smart mobile devices for a wide range of use cases including banking and payments.

The financial services industry is increasingly turning to biometric technology to solve a number of problems including how to conveniently authenticate mobile banking and payment customers and how to add strong authentication to previously un-authenticated contactless payments (both card and mobile) at the physical point of sale without adding friction to a currently speedy process. The latter point would enable higher value transactions to be supported when using contactless technology - currently shoppers are restricted to around $20,00 per transaction. Zwipe, a biometric card technology company, is partnering with MasterCard to extend its trial for fingerprint biometric authenticated payments for contactless payments. It also solves the problem of what if I lose a contactless payment or transit card that doesn't authenticate people when they use them.

MasterCard is also partnering with another innovative technology company in Canada, They are teaming with the Royal Bank of Canada (RBC) and Bionym, the company behind the Nymi electrocardiogram (ECG) band, to test  electrocardiogram-authenticated payments by the end of this year. The use of wearable devices for biometric authentication is set to rapidly expand over the next five-to-six years. Not only will you have sole-purpose wearables (like the Nymi), being used for biometric authentication purposes but biometric sensors and software technology will also be integrated into consumer wearable technology to sit alongside health and lifestyle applications. The creation of biometric platforms and freely available APIs will accelerate the integration of biometrics technology into a wide range of wearable technology.

The ability to leverage multiple sensors that are continuously collecting biometric data from us will revolutionize how humans are identified to a wide range of digital services and led to synergies between physical and cyber worlds. From opening up my front door and locking my car to waking up my desktop and authorising a wire transfer (BTW I am not a techno-utopian - I know that it will be extremely difficult to have the one digital identity on the single device that can be asserted across all of my connected devices and assets).

Instead of people typing in a remembered PIN, password or OTP generated by a hardware token, their identity shall be presented to connected devices through a combination of biometric data and behavioural analysis. Instead of presenting a finger to unlock an iPhone or to make a payment using a biometric card, wearable devices allow continuous biometric feedback from its owner - something that could be very powerful and potentially much more difficult to spoof or hack. It also becomes hygiene - I know that it is there and I know that it is keeping my digital and physical assets safe and secure but it is definitely not obtrusive and annoying like remembering where I put my token or unlocking my personal safe to get hold of my bulky black book of passwords (that is getting thicker and tattier by the day).

These trends are happening at an incredible pace and as a result I have decided to update a report I wrote originally published in June 2014. The report, "mobile and wearable biometric authentication market analysis and forecasts 2014-2019" has been updated with revised forecasts for wearable biometrics authentication users and reflects new market activity such as Apple Pay. The report forecasts that by 2019 there will be 604 million users of wearable biometric authentication solutions.

If you want to know more about this research or talk to me about this blog then I would love to hear from you. Contact me through the website www.goodeintelligence.com.

Thanks for reading. Alan




Tuesday, 28 October 2014

The role of the Mobile Network Operator in Authentication Services

In previous posts, I have talked about the need to deliver agile authentication services that are convenient to use and address the needs for proving identity across a wide range of services from a variety of endpoints.

Legacy authentication solutions, especially passwords, are continually proving to be both inconvenient and insecure for both consumers and employees – although the lines between the two are being eroded.

Thankfully, a combination of factors including the development and deployment of open standards,  including OpenID Connect, SAML and FIDO, and the creation of innovative mobile-based  authentication technology, including biometrics, are moving us away from a reliance on legacy authentication solutions. Authentication solutions that allow people to authenticate once with the touch of a finger.

PayPal’s FIDO-enabled biometric authentication solution on Samsung devices and Apple’s Touch ID solution is paving the way for wide-scale adoption of convenient user-centric authentication and getting people used to new methods of proving their identity for digital services.

These services are just the tip of the iceberg in terms of the potential for next generation mobile authentication services and I believe that Mobile Network Operators (MNOs) can play an important role in the new authentication landscape as they logical owners of authentication services in an era where accessing the internet is increasingly being made from mobile devices.

MNOs have long standing relationships with millions of consumers around the world and are considered to be trusted organisations that know how to deliver secure consumer-focused services. 

By owning and managing one of the trusted building blocks of mobile communication, the SIM, MNOs have a part to play in the delivery of authentication services to billions of mobile phone subscribers around the world.

I have just completed a piece of work, commissioned by Nok Nok Labs, that details the important role of Mobile Network Operators in delivering the latest agile authentication solutions. You can download the white paper from the Goode Intelligence website here.

I am also taking part in an online webinar organised by Nok Nok Labs to discuss this research on 4th November 2014 at 16:00 GMT. You can sign up to the webinar here.

Thanks for reading. 

Friday, 19 September 2014

Payments drives consumer biometrics and the push for enterprise

I was fortunate to be out in Washington DC last week (8-11 September) speaking at an RSA Global Summit on the future of authentication and presenting my research on mobile and wearable biometric authentication.

The Summit coincided with Apple's latest product launch on the 9th September and I was able to catch up with the announcements during a couple of breaks - unfortunately not aided by Apple's live streaming debacle that was at times verging on the ridiculous. (I particularly enjoyed the Chinese commentary and some severe editing that left out much of what Cook was saying. I got the applause but not the reason for the applause - perhaps that was Apple's corporate comms team in charge of editing?)

As well as a number of new hardware launches including bigger bolder iPhones and a watch....(will it support biometrics for authentication?). We saw Apple make a push into payments with 'Apple Pay'; using the Touch ID fingerprint system to provide authentication for payments (both online and physical). I have been watching Apple create the building blocks for this payment solution over the last couple years - Passcode, iBeacon, Passbook, Touch ID, Secure Enclave and finally NFC. Nice to see the finished solution.

As I said in a couple of interviews with the press last week, what Apple has done is not revolutionary; what it has successfully done is to cement a number of emerging technologies into a usable solution. This is backed by strategic partnerships with the world's largest retail payment  providers and links over 800 million global iTunes users to a mobile payments solution. And from a biometric authentication point of view, with Touch ID, it offers quite possibly the best user experience and the highest penetration of available mobile devices - a frictionless payment tool in a sleek piece of metal and glass. It will be interesting to see how it links other features such as loyalty, social and coupons to the payment app to make it any more appealing than using a plastic card - the value is not in the payment transaction per se.

By also opening up the Touch ID environment to third parties (Touch ID API) it allows other service providers (including financial services providers) to take advantage of this frictionless authentication solution. We have already seen announcements from MINT and Simple bank that they are utilising Touch ID for their mobile banking apps plus a proof of concept from Nok Nok Labs with a FIDO Ready solution. I expect that we will see many more announcements as the devices start to get in the hands of consumers (there is apparently pent-up demand for the latest iPhone from 4S and 5 users wanting to upgrade).

It is quite possible that the trend of Bring Your Own Identity (BYOI) may be accelerated as a result of Apple's Touch ID solution. All a service provider need do is to build an app that uses the Touch ID API and that's my authentication sorted - right?

Talking of FIDO, this year has also seen the world's two largest Internet payment companies, PayPal and Alipay adopt FIDO standards (through Nok Nok Lab's S3 Authentication Suite) to leverage mobile-based fingerprint sensors to provide the prime authentication solution for mobile payments (where the device obviously supports it).

Payments is definitely driving consumer biometrics.

So what about the enterprise? Are they ready to embrace BYOI and adopt authentication solutions for their employees and business partners? I think the answer is a guarded yes but it may take some time.

My time spent at the RSA Global Summit last week in DC was very informative in listening to the thoughts and opinions of enterprise users. Consumer is definitely driving innovation in authentication and this is taking its time to trickle down into the enterprise. In the main, they have BYOI and consumer-based mobile biometric authentication technology on their radar but also need some assurances that the trust, privacy and security models (there is obvious overlap between these three) employed by mobile device OEMs (including Apple, Samsung and Huawei) is good enough to meet security policy and industry regulation.

FIDO can help; by creating a user authentication standard fit for a modern connected world, ratified by some of the world's leading technology companies and service providers, organisations and end users can have a higher level of assurance that trust, privacy and security demands are met. FIDO has real positives in the 'first mile' of authentication but also needs connections to subsequent miles of the authentication and authorisation journey.

Enterprise users in particular demand comprehensive and integrated authentication solutions that combine convenient user authentication (probably on a mobile or wearable device) with other associated risk and security solutions including single sign on/federation, risk based authentication and risk management, business aware authorisation that is context aware and threat intelligence/threat analytics, That's potentially a lot of integration work!

Please free to leave a comment on this blog - I am always interested in receiving feedback and openly discussing this fascinating topic.

Thank you, Alan.




Thursday, 5 June 2014

Touch ID - The Cornerstone of Apple's Authentication Framework

This is an extract from an upcoming Goode Intelligence Analyst Report entitled "Mobile & Wearable Biometrics for Authentication Applications"

Apple caught much of the analyst and biometric community by surprise with the announcement that it was to open up its Touch ID fingerprint biometric environment to third-parties using an API at its annual developer conference, WWDC2014, on 1 June 2014.

Apple announced that once iOS 8 launches (possibly September or October 2014) third party developers will be able to access the Touch ID environment and leverage the benefits of mobile fingerprint biometrics.

During the presentation given by Apple's SVP Craig Federighi, Apple referenced Touch ID being used to authenticate into a personal financial application called Mint.

Apple’s Touch ID Local Authentication Framework (LocalAuthentication.framework) will enable third-party app developers to make use of Touch ID and benefit from its convenient personal authentication features.

Touch ID has been a great success for Apple; Apple also announced some stats for its Passcode phone unlock feature at WWDC. 83 percent of users were turning on the Passcode phone lock feature compared with 49 percent of general iOS users. That equates to millions more iOS devices being protected against unauthorised access and a great deterrent to theft.

Apple has been steadily building up its product and software portfolio to offer a wide range of connected services and it appears that they intend to use Touch ID as the foundation for identity verification on the Apple ecosystem.

I believe that Touch ID will be used to authenticate in the following scenarios (some of these are available now and some are predictions):
  • To replace the PIN for Passcode (device unlock)
  • To provide authentication for Apple ID (iTunes purchases)
  • To verify identity for an Apple payments product (both for online and physical store purchases)
  • To provide authentication for Apple’s CarPlay in-car service
  • To verify identity for Apple’s mobile healthcare solution “Healthkit”
  • To provide authentication for Apple’s connected home solution “Homekit"
    • This includes  the ‘Secure Pairing’ feature where only authorised users can unlock a home door or change the temperature of a room via a smart thermostat
Apple’s vision is to merge the logical and physical worlds using an iDevice (iPhone, iPad or even iWatch) as the smart controller with Touch ID providing convenient biometric authentication for this uber connected world. 

Wednesday, 16 April 2014

The Samsung Galaxy S5 fingerprint sensor has been spoofed - what can be done to prevent it

With the recent news that researchers from SR Labs in Germany have successfully fooled (spoofed) the Samsung Galaxy S5's integrated fingerprint sensor; allowing unauthorised access to the device and the ability to make payments using the PayPal app, there are questions as to how secure fingerprint biometrics are for authentication. These questions are justified. 

An authentication solution can be convenient but it must also be secure.  

A fingerprint biometric can be more convenient than using a PIN or password especially on a mobile phone. By touching or swiping a finger over a sensor a person can quickly unlock a device, gain access to an account or make a payment. However, if the sensor can be easily fooled than the solution is fundamentally flawed. 

The key point in my last sentence was "easily fooled". Attacks on fingerprint biometric systems are relatively difficult to carry out. As Marc Rogers from Lookout Mobile Security pointed out in his blog from last year -  "Why I hacked Apple's Touch ID and still think its awesome" - an attacker needs access to the device and then use a lot of kit to physically create the fake fingerprint. As Rogers stated this can be "tricky" and probably not within the reach of your average street thief. However, with the right equipment and a little ingenuity it can be done. 

So what can be done to ensure we benefit from the convenience of biometric authentication on mobile devices but also have a level of assurance that the solution is difficult to spoof and attack? 

One solution is to improve the anti-spoofing solutions within the biometric system. NexID Biometrics develops spoof mitigation and liveness detection solutions including its Mobile Live Finger Detection (LFD) software. The company claims that the solution can help ensure that the fingerprint system is not spoofed and states that authentication accuracy is as high as 94-97 percent. 

I spoke with NexID Biometrics' COO, Mark Cornett, to get his views on this and he said; "While Apple validated the convenience of fingerprint authentication on mobile devices, the spoof of the iPhone 5S should have sent a signal to other device manufacturers that while providing users with convenient authentication, the current level of security is vulnerable to spoofing. The layers of security for unlocking mobile devices and their applications needs to be stronger to properly meet the needs of users, and facilitators of mobile commerce and BYOD policies. Now that the two largest distributors of mobile devices in the world have had their solutions spoofed, they will hopefully add liveness detection solutions to mitigate this vulnerability and thereby instil confidence in the use of mobile device fingerprint authentication."

As well as anti-spoofing and liveness detection solutions there are other tools that can be deployed to improve the security of these emerging authentication solutions. This include combining biometric authentication with other factors as part of a multi-factor authentication solution - especially useful for step-up verification where a highly level of user assurance is required. 

I am a big fan of behavioural, or gesture, biometrics where the device learns about how a specific user engages with their mobile device to create a profile that can be used as part of a risk-based authentication solution. By combining behavioural biometrics with fingerprint authentication a greater level of trust in who is actually using the device can be created. And when an unauthorised user attempts to spoof the system by using a gummy bear or wood glue mould then the authentication service can request for another level of authentication to ensure that it is the valid owner of the phone and service. The link between the end user authentication client and cloud-based risk-based (anti-fraud) solutions, especially in financial services, cannot be underestimated. 

There are ways in which you can improve the security of mobile-based biometric authentication solutions and deter the type of spoofing attack that has been witnessed with the Samsung Galaxy S5 - I have just touched the surface in what is possible. 

However, an enhancement to the security of the biometric solution should not come at the expense of convenience and usability. 

Mobile device manufacturers and service providers are turning to biometrics because they can enhance the usability of the authentication experience - this must not be altered.