Showing posts with label Apple iPhone 5S. Show all posts
Showing posts with label Apple iPhone 5S. Show all posts

Thursday, 5 June 2014

Touch ID - The Cornerstone of Apple's Authentication Framework

This is an extract from an upcoming Goode Intelligence Analyst Report entitled "Mobile & Wearable Biometrics for Authentication Applications"

Apple caught much of the analyst and biometric community by surprise with the announcement that it was to open up its Touch ID fingerprint biometric environment to third-parties using an API at its annual developer conference, WWDC2014, on 1 June 2014.

Apple announced that once iOS 8 launches (possibly September or October 2014) third party developers will be able to access the Touch ID environment and leverage the benefits of mobile fingerprint biometrics.

During the presentation given by Apple's SVP Craig Federighi, Apple referenced Touch ID being used to authenticate into a personal financial application called Mint.

Apple’s Touch ID Local Authentication Framework (LocalAuthentication.framework) will enable third-party app developers to make use of Touch ID and benefit from its convenient personal authentication features.

Touch ID has been a great success for Apple; Apple also announced some stats for its Passcode phone unlock feature at WWDC. 83 percent of users were turning on the Passcode phone lock feature compared with 49 percent of general iOS users. That equates to millions more iOS devices being protected against unauthorised access and a great deterrent to theft.

Apple has been steadily building up its product and software portfolio to offer a wide range of connected services and it appears that they intend to use Touch ID as the foundation for identity verification on the Apple ecosystem.

I believe that Touch ID will be used to authenticate in the following scenarios (some of these are available now and some are predictions):
  • To replace the PIN for Passcode (device unlock)
  • To provide authentication for Apple ID (iTunes purchases)
  • To verify identity for an Apple payments product (both for online and physical store purchases)
  • To provide authentication for Apple’s CarPlay in-car service
  • To verify identity for Apple’s mobile healthcare solution “Healthkit”
  • To provide authentication for Apple’s connected home solution “Homekit"
    • This includes  the ‘Secure Pairing’ feature where only authorised users can unlock a home door or change the temperature of a room via a smart thermostat
Apple’s vision is to merge the logical and physical worlds using an iDevice (iPhone, iPad or even iWatch) as the smart controller with Touch ID providing convenient biometric authentication for this uber connected world. 

Wednesday, 16 April 2014

The Samsung Galaxy S5 fingerprint sensor has been spoofed - what can be done to prevent it

With the recent news that researchers from SR Labs in Germany have successfully fooled (spoofed) the Samsung Galaxy S5's integrated fingerprint sensor; allowing unauthorised access to the device and the ability to make payments using the PayPal app, there are questions as to how secure fingerprint biometrics are for authentication. These questions are justified. 

An authentication solution can be convenient but it must also be secure.  

A fingerprint biometric can be more convenient than using a PIN or password especially on a mobile phone. By touching or swiping a finger over a sensor a person can quickly unlock a device, gain access to an account or make a payment. However, if the sensor can be easily fooled than the solution is fundamentally flawed. 

The key point in my last sentence was "easily fooled". Attacks on fingerprint biometric systems are relatively difficult to carry out. As Marc Rogers from Lookout Mobile Security pointed out in his blog from last year -  "Why I hacked Apple's Touch ID and still think its awesome" - an attacker needs access to the device and then use a lot of kit to physically create the fake fingerprint. As Rogers stated this can be "tricky" and probably not within the reach of your average street thief. However, with the right equipment and a little ingenuity it can be done. 

So what can be done to ensure we benefit from the convenience of biometric authentication on mobile devices but also have a level of assurance that the solution is difficult to spoof and attack? 

One solution is to improve the anti-spoofing solutions within the biometric system. NexID Biometrics develops spoof mitigation and liveness detection solutions including its Mobile Live Finger Detection (LFD) software. The company claims that the solution can help ensure that the fingerprint system is not spoofed and states that authentication accuracy is as high as 94-97 percent. 

I spoke with NexID Biometrics' COO, Mark Cornett, to get his views on this and he said; "While Apple validated the convenience of fingerprint authentication on mobile devices, the spoof of the iPhone 5S should have sent a signal to other device manufacturers that while providing users with convenient authentication, the current level of security is vulnerable to spoofing. The layers of security for unlocking mobile devices and their applications needs to be stronger to properly meet the needs of users, and facilitators of mobile commerce and BYOD policies. Now that the two largest distributors of mobile devices in the world have had their solutions spoofed, they will hopefully add liveness detection solutions to mitigate this vulnerability and thereby instil confidence in the use of mobile device fingerprint authentication."

As well as anti-spoofing and liveness detection solutions there are other tools that can be deployed to improve the security of these emerging authentication solutions. This include combining biometric authentication with other factors as part of a multi-factor authentication solution - especially useful for step-up verification where a highly level of user assurance is required. 

I am a big fan of behavioural, or gesture, biometrics where the device learns about how a specific user engages with their mobile device to create a profile that can be used as part of a risk-based authentication solution. By combining behavioural biometrics with fingerprint authentication a greater level of trust in who is actually using the device can be created. And when an unauthorised user attempts to spoof the system by using a gummy bear or wood glue mould then the authentication service can request for another level of authentication to ensure that it is the valid owner of the phone and service. The link between the end user authentication client and cloud-based risk-based (anti-fraud) solutions, especially in financial services, cannot be underestimated. 

There are ways in which you can improve the security of mobile-based biometric authentication solutions and deter the type of spoofing attack that has been witnessed with the Samsung Galaxy S5 - I have just touched the surface in what is possible. 

However, an enhancement to the security of the biometric solution should not come at the expense of convenience and usability. 

Mobile device manufacturers and service providers are turning to biometrics because they can enhance the usability of the authentication experience - this must not be altered.

Tuesday, 21 January 2014

From Swipe to Touch to Invisible Touch - The Evolution of Fingerprint Sensors in Smart Mobile Devices

From Swipe to Touch to Invisible Touch - The Evolution of Fingerprint Sensors in Smart Mobile Devices


Readers of a certain age will possibly remember Genesis, the English prog-rock band that featured first Peter Gabriel and then Phil Collins on vocals. In the 1980s they released a rather poor 13th album called ‘Invisible Touch’. Little did they know that we would use that title in a rather obscure pun in an article on the evolution of fingerprint sensors in smart mobile devices (SMD) – the album cover is rather relevant though! And if you hear ‘Invisible Touch’ wafting over the speakers at a product launch at MWC 2014 – you know where they got their idea from.


This blog explores the evolution of fingerprint sensors designed for consumer electronic devices including smart mobile devices; from swipe to touch to ‘invisible touch'. This blog first appeared in the January 2014 edition of the Goode Intelligence Market Intelligence publication; "Fingerprint Biometrics Market Intelligence" (published 28 January 2014). 

Smartphone OEMs rush to embed fingerprint sensors

Despite the intense media attention that accompanied Apple’s launch of Touch ID embedded fingerprint sensors on mobile phones have been around since 1998. Ever since Siemens developed its prototype device back in 1998 there has been steady stream of handsets being biometric-enabled.

Fingerprint sensors are becoming a common-feature of flagship smartphones with an increasing number of mobile device OEMs joining Apple in launching high-end devices during the latter part of 2013. This included HTC, Fujitsu and Pantech. So far, all these Android-based devices have used swipe fingerprint sensors, sourced from either Fingerprint Cards (FPC) or Validity Sensors. For these android devices, the sensor is being located on the rear of the smartphone (see image of HTC One max below).

HTC One max (with Validity swipe sensor located underneath rear camera)

















Apple Touch ID - leader for smartphone touch sensor

Apple is so far the only mobile device OEM to have launched a device with an embedded Touch Capacitive sensor (shown below). The sensor uses capacitive touch technology to take a high resolution (500 pixels per inch or ppi) from small sections of a fingerprint (from the subepidermal layers of the skin).














Source: Apple

There are advantages in using a touch sensor over a swipe sensor on a mobile device:
  • The user experience is usually superior
  • Greater accuracy;  there appears to be fewer failures as the finger is better positioned for touch. For swipe, the finger has to be swiped accurately over the sensor to ensure that the fingerprint is read correctly. On some smartphone implementations, especially on larger devices (phablets), the location of the sensor on the rear of the device makes this difficult when holding the device with one hand 
  • The sensor can be built into a hard button on the front of the mobile device, e.g. home/power button

Non-Apple smartphones - first swipe then touch


Goode Intelligence believes that for the first quarter of 2014 a number of Tier 1 mobile device OEMs will launch flagship models that incorporate a swipe sensor. This will include further HTC models and releases from LG, Lenovo and Samsung (Samsung may want to launch with a touch sensor to match the user experience of Apple’s Touch ID).

The three remaining fingerprint sensor manufacturers who can supply to the mobile device industry, Fingerprint Cards, Idex and Validity Sensors (part of Synaptics) are all in the process of commercialising their versions of the mobile-ready touch sensor.

Fingerprint Cards is probably in a more advanced state of commercialisation and has gone on record to say that their touch sensor (FPC1020) has been sold to a “Tier 1 OEM” for a “flagship smartphone with a targeted launch date in the summer of 2014”[1]

Idex and Validity will follow FPC in launching their own touch sensors during 2014 and GI expects to see them appear in smart mobile devices and other consumer electronic devices.

Next generation consumer fingerprint sensors - Invisible Touch

The third stage to the evolution of mobile device-based fingerprint sensors is driven by the need for greater user convenience combined with a trend to remove physical buttons from smart mobile devices. Partly as a result of the reduction of the bezel-size and driven by the trend for larger touch screen sizes.

The elimination of physical buttons creates a problem for component suppliers including fingerprint sensor manufacturers as it removes an obvious place to position the sensor. It also provides them with an opportunity for new markets for their products.

The positioning of the fingerprint sensor underneath, or within the touch screen, is the next stage in the evolution of consumer fingerprint biometrics and enables mobile device OEMs to remove physical buttons. It also ensures that the convenience of identification, touching a finger on the front of a mobile device, is maintained.

GI believes that all of the fingerprint sensor manufacturers currently operating in the consumer and mobile space are well advanced in their research and development efforts to make this a reality:
  • Idex released this video after demonstrating a proof-of-concept device that placed the fingerprint sensor within the touch screen display
  • Validity Sensors is now part of Synaptics who are one of the world’s largest suppliers of touchscreen technology. Synaptics are also developing fingerprint sensors built into the touchpads that are embedded into laptops and notebooks
  • FPC has demoed demoed touch sensor capabilities with Windows for integration into Windows 8 (8.1) products and also works with CrucialTec, manufacturer of the optical TrackPad (OTP)
This includes Apple and the resources that were integrated as a result of the AuthenTec acquisition.

Invisible Touch’ is not only suitable for smart mobile devices; any consumer electronic device that uses a screen has the potential to integrate a touch fingerprint under or within the screen. This could include smart TVs, single-use gaming handhelds, tablets, touchscreen monitors, hybrid notebooks and touchscreens integrated into domestic appliances and smart house control technology. Whether anybody would want to authenticate using their fingerprint for their fridge is debatable (although perhaps if you wanted to stop a young child from turning on an oven or keeping your teenager out of your wine cooler?).

This is a potentially huge market and is part of the wider Consumerisation of biometrics that will revolutionise how we interact with technology.

This opportunity will be explored in an upcoming analyst report published by Goode Intelligence; "Emerging Markets for Fingerprint Biometrics".




[1] FPC wins first 1020 touch sensor DW from Global Tier 1 OEM for their flagship smartphone. 20 December 2013: http://www.fingerprints.com/blog/2013/12/20/fpc-wins-first-1020-touch-sensor-dw-from-global-tier-1-oem-for-their-flagship-smartphone/



Wednesday, 6 November 2013

Bring Your Own Finger - The Consumerisation of Biometrics on Mobile Devices

Firstly, let me apologise for jumping on the BYO bandwagon. I did grimace a bit when writing it but in a way it is rather apt. Biometrics are always with you and you do bring them with you; to the shops, to work, when travelling.....

That's what makes them a very attractive proposition for identification purposes. With the ever-growing list of super-long passwords that we are required to use for an increasingly long list of digital services, the search for an agile method for securely identifying people has been the Holy Grail for some time. Link that with the move towards accessing digital services on mobile devices and you have a situation that creates a perfect environment for easy-to-use, convenient, authentication and identity verification services.

Without even considering the rush by mobile manufacturers to embed fingerprint sensors into their latest smart mobile devices, mobile devices have many sensors that can be leveraged for biometric identification purposes. Cameras (front and rear with the support to capture HD video, high quality microphones, accelerometers for behavioural biometrics etc.

In my latest report for Goode Intelligence, "Mobile Biometric Security - Market Forecast Report 2013-2018", I have revised the forecasts from the original report, published in June 2011, to take into consideration the rapidly changing landscape. My research into this sector has discovered that in the last two years the following factors has created an environment that will create a market that is worth US$8.3 billion by 2018:

The Consumerisation of Biometrics: Apple has changed everything and has again disrupted a market and rebranded biometrics as a convenient method of communicating with consumer technology. Previously, Biometrics has largely been associated with high-end security; border control, national ID solutions and for providing access control for high-security buildings. This has all changed with the Apple iPhone 5s and Touch ID

Convenient mobile device protection: Existing mobile device authentication is cumbersome and inconvenient.  This means that many devices are left with no protection. Replacing a PIN or Passcode with an easy-to-use biometric can reduce this burden

 Mobile Commerce: Mobile devices have become the prime method of carrying out digital commerce yet identity verification and payment authorisation has not yet been updated to match this form factor. Biometrics can offer a convenient and secure method to prove identity and to authorise payments

As part of a multi-factor authentication solution: Most of the major authentication vendors support, or have plans to support, biometrics in their authentication products. This will be supported by authentication standards initiatives such as the FIDO Alliance that will enable biometrics to be easily utilised, when available, on mobile devices

Mobile devices are getting more secure: Apple’s Touch ID fingerprint solution makes use of a ‘secure vault’ to ensure that the fingerprint templates are stored in a secure area of the hardware. It is thought that Apple is leveraging ARM’s TrustZone, a hardware-security environment for secure storage and trusted execution. Security services are being built into all mobile platforms to counteract malware and to protect sensitive information and transactions. Complimentary services such as Mobile Device Management (MDM), Secure Containers and Mobile Application Management (MAM) create a trusted platform to support biometric security on consumer mobile devices

Wednesday, 11 September 2013

iPhone 5S Touch ID - What Apple announced (how much did I get right)

AT 10am EDT yesterday (10/09/2013) Apple held their latest event to announce two new iPhones (iPhone 5S and iPhone 5C) and the latest version of iOS (iOS 7). The event coincided with my attendance at a school information meeting. I thought it wise not to follow Twitter on how the event was progressing even though I was itching to find out whether the fingerprint sensor had made it to the phone - besides, the school hall has awful mobile reception.

The previous day (09/09/2013) I wrote a blog making predictions on how Apple would utilise the fingerprint sensor. So how did I do?

First, let's take a look at what Apple announced yesterday.

What Apple Announced?

Source: Apple
Along with a faster processor and the next version of iOs (iOS 7) Apple announced the fruits of their AuthenTec acquisition, Touch ID - "a new fingerprint identity sensor". In other words an optical fingerprint sensor embedded underneath the Home button of the iPhone 5S.

In a video released to coincide with the announcement, Apple's chief design guru, Jony Ive, emphasises that Touch ID is more about convenience than security by saying that it "enhances the user's experience" and "is the next step in using your iPhone" as well as "protecting all of the information" held on the phone.

Touch ID will have two functions at lauch:

  1. Unlock the phone (iPhone Passcode replacement)
  2. Authenticate into iTunes (Apple ID Passcode replacement)

How does it work?
Once a user has enrolled (a user can enrol a single or multiple fingers) with Touch ID they can then replace the Passcode to unlock a locked device with the touch of their enrolled finger(s). One of the issues of previous smartphones with embedded fingerprint sensors (including the Atrix 4G) was a lack of other supporting functionality outside of the unlock phone feature. Apple have taken a positive step forwards by also allowing the fingerprint to provide authentication for iTunes payments - replacing the Apple ID password with the fingerprint. Is this the entry point (or pilot) for Apple's fingerprint-authenticated mPayments and will Apple store payments come next?

Technology
As with any embedded fingerprint sensor the service is a combination of hardware and software. The new Home button is made from sapphire crystal that both protects the sensor and acts as a lens to enhance the fingerprint. A steel ring has been inserted surrounding the button that detects the finger and wakes up the sensor (probably saves the battery). The optical sensor takes a high resolution image of the print (taken from the subepidermal surface of the skin to counteract damaged  and ageing epidermi). The captured image is then compared with the stored template that was captured during the enrolment process.

Is it secure?
According to Apple, all fingerprint information is encrypted and stored securely in a 'Secure Enclave' on the new A7 chip. Details of this process have not yet been released but I am guessing that a unique key is used for this encryption. There is also mention on whether the hardware protecting the template is FIPS 140-2 compliant. 

Dan Riccio, SVP, Hardware Engineering, Apple, has stated that the template is "never accessible by other software, never stored on Apple's servers or backed up to the iCloud". Expect to see these these claims coming under the microscopes of security researchers eager to test out this latest piece of security kit.

No security is 100% secure and optical fingerprint sensors are no exception. There have been a number of well-documented replay and relay attacks on sensors that can circumvent the security or the security process that supports the sensor. I am pretty sure that Touch ID will be successfully targeted and we will see the tech and national press quick to highlight the security failings of Apple's flagship iPhone. The question is whether these attacks can be replicated by the average thief  (hundreds of iPhones are stolen on a daily basis). Are we also going to see phone thieves force their users to unlock their devices with their fingerprints or even chop off a finger, as Lookout Mobile Security's Marc Rogers suggests in this interview with the Mirror newspaper. Possibly, but it will be tricky for a violent thief to do this as which finger has the user enrolled? However, if this does happen than it could end up being a PR disaster for Apple.  

It is also interesting to hear Apple emphasise features such as convenience and user convenience, not security or theft deterrence. If Touch ID is accurate and speedy, iPhone unlocks and iTunes transactions will be performed at a faster rate than those performed by password-verification. 

Did I get my predictions right?
Yesterday I predicted that:
  • Apple would release an iPhone with an embedded fingerprint sensor contained in the home button
  • The main uses of the fingerprint sensor would be:
    • To protect the device (phone unlock)
    • Link to iTunes for authentication
    • Enable mobile payments using the iTunes account at Apple stores
  • It wont be opened up to third party developers at launch
4 out of 5 isn't bad and I feel that if there is a positive reception from iPhone 5S users to Touch ID then Apple will look to other services being included in the service and one of these will be mPayments at physical stores. 

I am also confident that we will see this technology embedded within other Apple devices including both the iPad and the iPad mini.

How many iPhone 5S's will Apple sell and what does it mean for the mobile biometric market?
There is a feeling that the lower-priced iPhone 5C will sell more than the Touch-ID equipped 5S but how many units will Apple shift? On its launch last year the iPhone 5 sold more than 5 million units in its first weekend. The last official figures from Apple for Q3 2013 stated that 31.2 million iPhone were sold around the world (that's going to be mixture of 4's, 4S's and 5's).

Based on these figures I am estimating over 20 million iPhone 5S units will be sold around the world by the end of Christmas 2013 - that's a lot of fingerprint sensors. That's more mobile fingerprint sensors than AuthenTec had shipped before being sold to Apple.

Back in 2011 I forecast that there would be 19.4 million mobile devices shipping with embedded fingerprint sensors by 2015. Apple are probably going to blow that forecast in a single quarter.

As a result of this momentous news for the biometrics industry I am going to revise the forecasts from 2011 and publish these in the coming weeks. I feel that Touch ID will have a direct impact on the biometrics industry in general and in particular the mobile biometrics industry. Other mobile phone manufacturers will probably follow-suit with similar solutions, not just fingerprint. Apple also acquired a lot of  fingerprint IP when they purchased AuthenTec. This may well restrict what other mobile device ODMs can do with embedded fingerprint sensors.

One this is for certain, the Apple announcement yesterday will propel biometrics into the mainstream. This knock-on effect will not just be for fingerprint sensors but for many other modalities including voice, facial, eye (iris and retina) and other emerging ones such as heart rhythm and behaviour. Linked to attempts to standardise authentication and identity verification (notably The FIDO Alliance) and the movement of identity services to the cloud will bring about a revolution in how we authenticate and identify ourselves for digital services across multiple endpoints (Remember the smart phone is part of a constantly evolving cycle of technology innovation and we are at the beginning of the start of another one - wearable computing).

It is certainly an exciting time for those of us that work in the security and authentication industries.

Alan Goode - September 11 2013