I was fortunate to be out in Washington DC last week (8-11 September) speaking at an RSA Global Summit on the future of authentication and presenting my research on mobile and wearable biometric authentication.
The Summit coincided with Apple's latest product launch on the 9th September and I was able to catch up with the announcements during a couple of breaks - unfortunately not aided by Apple's live streaming debacle that was at times verging on the ridiculous. (I particularly enjoyed the Chinese commentary and some severe editing that left out much of what Cook was saying. I got the applause but not the reason for the applause - perhaps that was Apple's corporate comms team in charge of editing?)
As well as a number of new hardware launches including bigger bolder iPhones and a watch....(will it support biometrics for authentication?). We saw Apple make a push into payments with 'Apple Pay'; using the Touch ID fingerprint system to provide authentication for payments (both online and physical). I have been watching Apple create the building blocks for this payment solution over the last couple years - Passcode, iBeacon, Passbook, Touch ID, Secure Enclave and finally NFC. Nice to see the finished solution.
As I said in a couple of interviews with the press last week, what Apple has done is not revolutionary; what it has successfully done is to cement a number of emerging technologies into a usable solution. This is backed by strategic partnerships with the world's largest retail payment providers and links over 800 million global iTunes users to a mobile payments solution. And from a biometric authentication point of view, with Touch ID, it offers quite possibly the best user experience and the highest penetration of available mobile devices - a frictionless payment tool in a sleek piece of metal and glass. It will be interesting to see how it links other features such as loyalty, social and coupons to the payment app to make it any more appealing than using a plastic card - the value is not in the payment transaction per se.
By also opening up the Touch ID environment to third parties (Touch ID API) it allows other service providers (including financial services providers) to take advantage of this frictionless authentication solution. We have already seen announcements from MINT and Simple bank that they are utilising Touch ID for their mobile banking apps plus a proof of concept from Nok Nok Labs with a FIDO Ready solution. I expect that we will see many more announcements as the devices start to get in the hands of consumers (there is apparently pent-up demand for the latest iPhone from 4S and 5 users wanting to upgrade).
It is quite possible that the trend of Bring Your Own Identity (BYOI) may be accelerated as a result of Apple's Touch ID solution. All a service provider need do is to build an app that uses the Touch ID API and that's my authentication sorted - right?
Talking of FIDO, this year has also seen the world's two largest Internet payment companies, PayPal and Alipay adopt FIDO standards (through Nok Nok Lab's S3 Authentication Suite) to leverage mobile-based fingerprint sensors to provide the prime authentication solution for mobile payments (where the device obviously supports it).
Payments is definitely driving consumer biometrics.
So what about the enterprise? Are they ready to embrace BYOI and adopt authentication solutions for their employees and business partners? I think the answer is a guarded yes but it may take some time.
My time spent at the RSA Global Summit last week in DC was very informative in listening to the thoughts and opinions of enterprise users. Consumer is definitely driving innovation in authentication and this is taking its time to trickle down into the enterprise. In the main, they have BYOI and consumer-based mobile biometric authentication technology on their radar but also need some assurances that the trust, privacy and security models (there is obvious overlap between these three) employed by mobile device OEMs (including Apple, Samsung and Huawei) is good enough to meet security policy and industry regulation.
FIDO can help; by creating a user authentication standard fit for a modern connected world, ratified by some of the world's leading technology companies and service providers, organisations and end users can have a higher level of assurance that trust, privacy and security demands are met. FIDO has real positives in the 'first mile' of authentication but also needs connections to subsequent miles of the authentication and authorisation journey.
Enterprise users in particular demand comprehensive and integrated authentication solutions that combine convenient user authentication (probably on a mobile or wearable device) with other associated risk and security solutions including single sign on/federation, risk based authentication and risk management, business aware authorisation that is context aware and threat intelligence/threat analytics, That's potentially a lot of integration work!
Please free to leave a comment on this blog - I am always interested in receiving feedback and openly discussing this fascinating topic.
Thank you, Alan.
Showing posts with label BYOI. Show all posts
Showing posts with label BYOI. Show all posts
Friday, 19 September 2014
Wednesday, 6 November 2013
Bring Your Own Finger - The Consumerisation of Biometrics on Mobile Devices
Firstly, let me apologise for jumping on the BYO bandwagon. I did grimace a bit when writing it but in a way it is rather apt. Biometrics are always with you and you do bring them with you; to the shops, to work, when travelling.....
That's what makes them a very attractive proposition for identification purposes. With the ever-growing list of super-long passwords that we are required to use for an increasingly long list of digital services, the search for an agile method for securely identifying people has been the Holy Grail for some time. Link that with the move towards accessing digital services on mobile devices and you have a situation that creates a perfect environment for easy-to-use, convenient, authentication and identity verification services.
Without even considering the rush by mobile manufacturers to embed fingerprint sensors into their latest smart mobile devices, mobile devices have many sensors that can be leveraged for biometric identification purposes. Cameras (front and rear with the support to capture HD video, high quality microphones, accelerometers for behavioural biometrics etc.
In my latest report for Goode Intelligence, "Mobile Biometric Security - Market Forecast Report 2013-2018", I have revised the forecasts from the original report, published in June 2011, to take into consideration the rapidly changing landscape. My research into this sector has discovered that in the last two years the following factors has created an environment that will create a market that is worth US$8.3 billion by 2018:
The Consumerisation of Biometrics: Apple has changed everything and has again disrupted a market and rebranded biometrics as a convenient method of communicating with consumer technology. Previously, Biometrics has largely been associated with high-end security; border control, national ID solutions and for providing access control for high-security buildings. This has all changed with the Apple iPhone 5s and Touch ID
Convenient mobile device protection: Existing
mobile device authentication is cumbersome and inconvenient. This means that many devices are left with no
protection. Replacing a PIN or Passcode with an easy-to-use biometric can
reduce this burden
That's what makes them a very attractive proposition for identification purposes. With the ever-growing list of super-long passwords that we are required to use for an increasingly long list of digital services, the search for an agile method for securely identifying people has been the Holy Grail for some time. Link that with the move towards accessing digital services on mobile devices and you have a situation that creates a perfect environment for easy-to-use, convenient, authentication and identity verification services.
Without even considering the rush by mobile manufacturers to embed fingerprint sensors into their latest smart mobile devices, mobile devices have many sensors that can be leveraged for biometric identification purposes. Cameras (front and rear with the support to capture HD video, high quality microphones, accelerometers for behavioural biometrics etc.
In my latest report for Goode Intelligence, "Mobile Biometric Security - Market Forecast Report 2013-2018", I have revised the forecasts from the original report, published in June 2011, to take into consideration the rapidly changing landscape. My research into this sector has discovered that in the last two years the following factors has created an environment that will create a market that is worth US$8.3 billion by 2018:
The Consumerisation of Biometrics: Apple has changed everything and has again disrupted a market and rebranded biometrics as a convenient method of communicating with consumer technology. Previously, Biometrics has largely been associated with high-end security; border control, national ID solutions and for providing access control for high-security buildings. This has all changed with the Apple iPhone 5s and Touch ID
Mobile Commerce: Mobile devices have become the prime method of carrying out digital
commerce yet identity verification and payment authorisation has not yet been
updated to match this form factor. Biometrics can offer a convenient and secure
method to prove identity and to authorise payments
As part of a multi-factor authentication solution: Most of the major authentication vendors support, or
have plans to support, biometrics in their authentication products. This will be
supported by authentication standards initiatives such as the FIDO Alliance
that will enable biometrics to be easily utilised, when available, on mobile
devices
Mobile devices are getting more secure: Apple’s Touch ID fingerprint solution makes use of a ‘secure vault’ to
ensure that the fingerprint templates are stored in a secure area of the
hardware. It is thought that Apple is leveraging ARM’s TrustZone, a hardware-security
environment for secure storage and trusted execution. Security services are
being built into all mobile platforms to counteract malware and to protect
sensitive information and transactions. Complimentary services such as Mobile
Device Management (MDM), Secure Containers and Mobile Application Management
(MAM) create a trusted platform to support biometric security on consumer
mobile devices
Labels:
alan goode,
Apple iPhone,
Apple iPhone 5S,
authentec,
biometric,
biometrics,
BYOI,
fingerprint,
fingerprint sensor,
goode intelligence,
ios,
mobile authentication,
smart mobile identity,
Touch ID
Thursday, 26 September 2013
The Changing Face of User Authentication and the Road to Bring Your Own Identity
I recently presented on an Infosecurity Magazine
webinar entitled “How to Make Access to your Sensitive Data More Secure - The Easy Way”.
During my presentation I explored how user
authentication is adapting to meet the changes created by a number of linked transformational
trends that include cloud computing, mobility and the Consumerisation of IT.
The presentation focused on one of Goode Intelligence’s specialist areas, mobile-based authentication (both the phone as an
authenticator and mobile authentication when an IT service is accessed from the
mobile device). It also touched on other areas of Identity and Access Management
(IAM) and the development of these corresponding areas is vital to the
successful transformation of user authentication services (both mobile and
non-mobile). It is imperative that we meet the security challenges of the next
generation of IT services – to defend the borderless enterprise.
We are increasingly accessing a huge wealth of digital
information, both inside and outside of the enterprise network, from a myriad
of devices. In this new world of IT, traditional authentication solutions, both
single-factor (passwords) and two-factor (smart cards and OTP tokens), have
become clumsy, inconvenient and less secure. Password management is a headache;
in the main we either write down strong passcodes or alternatively re-use
passwords that we can easily remember (there are password management tools that
exist). Alternatively, when traditional two-factor
authentication is used then this is often not designed for cloud, mobile or
BYOD. Authentication solutions designed for traditional, behind firewall,
enterprise systems are increasingly not effective for new, agile, IT services.
So what are the alternatives? How do we match convenience
and security and ensure identity is successfully proven across a wide variety
of different devices (enterprise-issued and employee-owned) accessing many
services located on-premise, hybrid and wholly in the cloud?
I believe that we are close in achieving the goal of
supporting a much more agile and mobile world of IT service provision with
strong, convenient, authentication. We know what the problem is and we have
many of the building blocks to make this a reality. These building blocks
include Risk-based authentication (RBA), federated identity, multi-factor
authentication and user choice.
Match risk with
appropriate security – combining user intelligence with business context
At Goode Intelligence, we are seeing increasing demand for
more intelligent forms of authentication where the choice of authentication
method used is real-time risk driven. The financial services sector has been an
early adopter of RBA technology as it has a history of measuring (managing) risk.
RBA matches the most appropriate
authentication method to the assessed risk. To be successful in this you must
first know who the user is and what they plan to do.
User intelligence can be gathered from a number of inputs
and the mobile device can play an important part in this process. When combined
with more active forms of authentication, by learning the unique
characteristics of its owner; where they are usually located (geo-location),
the days and times that they are normally active and even how they hold and
touch the device (behavioural analysis).
An accurate risk score can be calculated by combining user
intelligence with business context. What is the user trying to achieve - Is it
a high-value financial transaction to an unknown recipient or attempting to
access the latest sales data? Based on this risk score the authentication
engine can then choose the most appropriate authentication method to prove
identity. A one-time-password (OTP) generated by the authentication engine and
sent to the user’s registered mobile device via SMS may be sufficient or
alternatively the authentication level may be ‘stepped-up’ to a stronger factor
– a biometric or even a separate hardware device.
Federated Identity –
the road to single sign on and a more frictionless experience
For both enterprise and consumer users the prospect of
having to uniquely identify themselves to multiple applications and web
services is an onerous task. This is probably why for mobile devices the
auto-authenticate option is widely deployed – thumbs up for convenience, thumbs
down for security.
Organisations are increasingly turning their attentions to
Identity federation, sometimes referred to as Single Sign-On (SSO), as
one way to solve this problem. Identity federation allows for a standards-based
way to share identity amongst multiple organisation and applications. Standards
include the Security Assertion Markup Language (SAML), the OpenID
protocol and WS-Federation.
The benefit to the user is that they only need to
authenticate once to access a number of different organisations and
applications. Using techniques such as SAML-insertion identity is then shared
transparently with other applications. The user is authenticated once and then
other application providers can verify the authenticity of the provided
federated identity.
Multi-Factor
Authentication/Identity Verification and context
Two-factor authentication (2FA) is so last year!
Over the last 24 months we have seen virtually all of the
major internet players, Google, Twitter, LinkedIn, Microsoft and Facebook
deploy some form of 2FA (mainly mobile OTP-based). Microsoft was so enamoured
at mobile phone-based 2FA that it acquired a vendor, PhoneFactor. The option to
use 2FA in these networks I usually optional so it is difficult to gauge how
popular these services are outside the InfoSec geek community.
In terms of trends in the authentication market there is a
definite movement towards supporting multiple factors (MFA), sometimes referred
to as infinite factors. This is not necessarily the third factor –
often associated with what you are, biometrics. MFA is about allowing a choice
of factors and then matching them against context.
I feel that the combination of MFA and contextual awareness
is one of the most exciting areas of authentication at the moment and we expect
it to be a standard feature of premium authentication solutions. Many of the
authentication vendors, including RSA, Entrust and SecurEnvoy, have already
increased their portfolio of factors that can be deployed for use with their
authentication engines and I believe that the number of factors, and user
choice, will increase in the next 12 months. Factors include both traditional –
hardware/software tokens and smart cards – and emerging – mobile, biometrics,
image-based and behavioural.
The power of having multiple factors at your disposal is
multiplied when you add contextual analysis. This is where mobile devices
really come into their own as authenticators. Smart mobile devices have so many
in-built sensors that have the capability to capture important information
about the context of how and where these devices are being used. Geo-location
through a combination of GPS and cellular-network positioning (even more
accurate with LTE/4G services), ambient noise levels captured through the
microphone (important in voice biometrics), user identification through the
camera and embedded fingerprint sensors (Even before Apple’s iPhone 5S and Touch
ID there were over 20 million smartphones shipped with fingerprint sensors).
All of this contextual information can be captured and then passed onto
services that support risk-based and intelligence-based authentication. A
relatively accurate identity scoring can be calculated on a continuous basis
and then fed into the authentication service providing a method of identifying
whether the authorised owner of the device is initiating a service and then
calculating whether additional authentication is required. This is sometimes
referred to as step-up verification (although step-up verification is also a
part of non- mobile authentication and RBA services).
User choice – The
road to Bring Your Own Identity (BYOI)?
We have bring your own device/platform/software…. Is it time
for bring your own identity? Let the user choose what is the most convenient
and secure way to protect their digital assets? People decide how best to
protect their property and automobile cars why not let them choose how they
should protect their digital lives?
I feel that we are already seeing evidence of this with
Internet passports, e.g. Facebook ID and Google Authenticator, that allow
registered users to authenticate to other services that support authentication
from the passport provider. For instance, if I choose to I can use my Facebook
ID to authenticate into my Spotify streaming music service.
The big question is whether this will expand to services
that are more sensitive, i.e. have more risk. Will my bank allow me to use my
Google Authenticator to login to its internet bank service and then transfer
funds out of the account? Does the bank trust credential s issued by a social
network? Possibly not funds transfer but what about a balance enquiry? Step-up
verification could be used for when I want to transact or to request an
increase to my overdraft limit.
Alternatively what if a universal digital ID was issued by a
government and managed by a trusted authentication service provider? I wouldn’t
discount it but we are at the early stages of BYOI and perhaps initiatives such
as the FIDO Alliance, Open Identity
and the GSMA’s Mobile Identity Programme may help provide the plumbing
and the initiatives to support it.
Alan Goode September 2013
Subscribe to:
Posts (Atom)