Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts

Thursday, 1 June 2017

Five Considerations for Selecting a Consumer Authentication Vendor

In today's mobile-first world, consumer authentication is driven by the need of having a smooth user experience. Of course, it has to be secure and tick all of the boxes for privacy and regulation but when I talk with clients, both authentication vendors and service providers, they all say that the number one priority is having a great user experience (UX). If the authentication user experience fails then customers will simply walk away and go somewhere else or choose an alternative payment method.

I was recently asked to create a white paper for RSA and EyeVerify on key considerations for selecting a consumer authentication vendor. I identified five key considerations:

  1. Consumer choice
  2. Convenience
  3. Demonstrable fraud reduction
  4. Meeting a 'mobile first' strategy'
  5. Regulation compliance
These five considerations are powerful criteria for organizations when assessing authentication solutions and vendors.

Consumers must be given a choice of convenient, easy to use authentication services. The availability of a wide range of device-based authentication technologies including multiple biometric solutions supports this requirement. Convenience and consumer choice can also be combined in a well-designed consumer authentication solution. The combination of risk based authentication (RBA) and mobile biometric authentication services (MBAS) can meet this criteria. Risk based authentication can meet a good percentage of normal authentication scenarios and mobile biometrics can be applied to authentication scenarios that require further ‘proof’ of true identity; a combination of frictionless and friction-light authentication.

Service providers are increasingly pressured to support legacy service channels including physical (bank branch and retail store) and telephony at the same time as evolving their offering to work across a wide range of new technology, first web, now mobile and moving swiftly into the Internet of Things (IoT). When choosing an agile technology partner that can support multiple delivery channels, omnichannel support, an organization must ensure that they choose an authentication solution that can operate across a wide range of these channels. The mobile first strategy can allow organizations to design and deploy effective authentication services that meet this consideration.

Fraud is rising in all sectors. A consumer authentication vendor must be able to demonstrate fraud reduction as a result of deploying the chosen authentication solution – measurable and tangible fraud reduction benefits.

Around the world, regulatory powers are adapting existing regulation or introducing new ones to ensure that consumers are protected when using the latest digital services. A trusted technology partner must be able to demonstrate:
  1. It can help organizations address the latest federal and industry regulations; and
  2. It actively participates in influencing regulatory bodies to ensure that convenience and ease of use are not sacrificed at the expense of over rigid security requirements.

Getting the balance between security and convenience is an essential ingredient in supporting flexible digital service delivery.

To read the white paper in full, you can download it from the Goode Intelligence website here.

Thank you - Alan

Thursday, 14 July 2016

Will Brexit affect PSD2's Strong Customer Authentication Requirements?

There is no doubting that Brexit is having a profound affect on the UK and ripples of disruption have been felt around the world as result of the UK's decision to leave the EU.

I have written extensively on EU and EC legislation and its impact on a number of cyber security matters including mobile security, identity, authentication and biometrics. 

Recent researchhas investigated the impact of PSD2  on security; in particular the impact on how payment service providers (PSPs) manage customer authentication. 

To summarise the main objectives of PSD2:

  • Contribute more to a more integrated and efficient European Payments market
  • Improve the level playing field for payment service providers (PSPs), including new players
  • Make payments safer and more secure
  • Protect consumers
  • Encourage lower prices for payments

The European Parliament adopted PSD2 in October 2015 and EU member states have two years in which to implement the new procedures. The EC states that there is a different date of application for the new security measures, including Strong Customer Authentication (SCA) and standards for secure communication. This is subject to the adoption of the regulatory technical standards which are being developed by the European Banking Authority (EBA) and adopted by the EC. It is anticipated that the new security measures shall apply 18 months after the adoption of the standards by the EC.

PSD2 provides rules for payment security and customer authentication, concentrating on protecting consumers when paying on the internet. 

PSD2 applies to all payment service providers (PSPs) operating in the EU, including banks, payment institutions or third party providers (TPPs) and relates to all electronic means of payment.
The EC defines SCA as a process that “validates the identity of the user of a payment service or of the payment transaction”.

SCA is based on the use of two or more elements:
  1. Knowledge - something only the user knows, e.g. a password or a PIN
  2. Possession - something only the user possesses, e.g. a card or an authentication code (OTP) generating device
  3. Inherence - something the user is, e.g. a biometric authenticator such as fingerprint, voice or eye-print
PSD2 states that these elements have to be independent of each, meaning that if one element is breached or compromised then this does not compromise the “reliability” of the others. The design of the authentication solution must also protect the confidentiality of the authentication data or identity credentials. 
As the UK has voted to exit the EU, will this mean that UK banks and PSPs will not be bound to comply with these regulations (and in fact other EU legislation)? This is a difficult question to answer as the exact nature of the UK's exit and what will exactly be negotiated as the UK triggers Article 50 is still very much up in the air. What I think will happen is this:
  • UK banks and PSPs that have functions in the EU will have to comply with PSD2 - it also makes competitive sense to support PSD2
  • PSD2's authentication requirements are pretty-much the basic requirements for supporting strong customer authentication and it makes common sense to support them especially some of the risk-based authentication services that enable lower-risk payment transactions to be exempt from strong customer authentication
  • Some UK retail banks are owned by European organisations who will want to have a common strategy for customer authentication that supports PSD2
As the UK's ex Prime Minister, Harold Wilson said in the 1960s "A week is a long time in politics" and I am sure that there will much debate over the coming months and years about the relevance of EU legislation to the EU. If you are a UK bank and have started projects to ensure compliance to PSD2 then I am pretty sure that these will not be halted as a result of Brexit.
Please let me know your thoughts my commenting on this blog. Thank you and remember in the global economy no nation is an island!

You can download the Goode Intelligence White Paper "The impact of PSD2 on authentication and security" from here.

Thursday, 7 July 2016

The Future of Mobile Security

Mobility is the new normal for enterprise users. With forecasts from the GSMA predicting that 80 percent of adults on earth will have a smart phone by 2020 these always connected and always on devices are the most popular personal computer in history.

The use of smart mobile devices (smart phones and tablets running mobile platforms such as Apple iOS and Google Android) in the enterprise is rising rapidly each year. Figures from Citrix indicate that the number of smart mobile devices (SMD) managed in the enterprise increased by 72 percent from 2014 to 2015.

What is surprising, however, is that the enterprise is not fully embracing mobile. Whether it is an employee-owned Android smart phone or a company-issued and controlled iPhone productivity-enhancing enterprise services are still relatively scarce within the enterprise. Outside of email and calendar applications there are relatively few examples of enterprise mobile apps. This differs from the current situation with consumer adoption of mobile where it dominates social, financial services, commerce and entertainment.

So why is? In the latest white paper from Goode Intelligence, the issues facing the enterprise in delivering services to mobile is explored. The report discovers that a mixture of technology constraints, security concerns, compliance to regulation and privacy law are having an impact of restricting mobile enterprise services.

Enterprises do face a challenge in enabling productivity enhancing applications to be available through smart mobile devices but there are ways in which they can combine the convenience of mobility and strong security mechanisms that meet company security policy and comply with regulation. In covering mobile security since 2007 I have learnt that next generation mobile security solutions should have these characteristics:
  • They should focus on users
  • Support agile multi-factor authentication (MFA) with a choice of authenticator to match the context 
  • Be able to provide mobile-based single-sign-on (SSO)
  • Must protect the data, both at rest and during transmission
  • Be available in a simple to use and unified security offering
I believe that there are very few solutions that offer a unified solution that supports these characteristics and this is why we have seen limited adoption of full-throttled enterprise services for mobile. Often, an organisation will have to mix and match technology solutions to support this vision and this can be expensive and time-consuming. A solution that combines the functionality and features of a next generation mobile security solution is the Sign&go Mobility Center from Ilex International

This product provides an integrated security solution to solve the enterprise mobility conundrum; mixing convenience and mobile security in a unified product and provides:
  • Strong Multi-Factor Authentication supporting one, two or three factors
  • Mobile SSO
  • Data Protection in a secure container
Without the combination of these features, organisations will remain limited in what productivity-enhancing mobility solutions they can deliver. 



Wednesday, 9 September 2015

The Top 10 Features for a Modern Authentication Solution

Back in 2009 I wrote an analyst report for Goode Intelligence on the mobile phone as an authentication device. It predicted that the mobile phone would become the prime user authenticator and enable people to securely access digital services delivered across a wide range of endpoints; used as an out-of-band authenticator for web services and as a seamless authentication tool for mobile apps. 

Roll forward to 2015 and these predictions have proved to be pretty accurate. The smartphone has become the remote control of our digital lives with user authentication being one of the main go-to buttons on our remote controls. All of the major authentication platforms are transitioning away from delivering strong authentication through sole-purpose hardware. Traditional stronger authentication technology, such as the smartcard and OTP token is largely being replaced by smart and agile forms of mobile-based authentication solutions some of which (Apple's Touch ID biometric authentication technology) is being embedded into mass-market consumer technology. It has never been as easy to deploy strong mobile-based authentication. But which authentication and identity management solution should an organization choose and how should they measure them?

In the years that I have been covering the authentication industry I have worked with my colleagues, both at Goode Intelligence and through our many consultancy engagements, to develop a checklist of where an authentication solution needs to excel in order to be market leading. 

The result of this work has been the recently launched Product Evaluation service that provides an independent analysis of information security products and services, including authentication and identity management solutions. We define that a modern authentication solution should have the following ten features to be successful in meeting the latest demands. These ten features are listed below.


We have used this criteria as part of a product evaluation of the Encap Security Smarter Authentication Platform in a recently published free-to-download report. The evaluation concludes that Encap's mobile-based authentication platform meets the requirements of a modern authentication platform and Goode Intelligence has awarded the product a ‘Highly Commended’ rating (Goode Intelligence’s top rating for Authentication and IAM). 



This rating has been awarded as the Smarter Authentication Platform is a highly customizable, adaptive and risk-based platform that meets the needs of highly-scalable connected digital services. It has the ability to be quickly integrated and rolled out to millions of end-users and is available for all smart mobile devices. 

Organizations can apply the same measurement criteria when evaluating authentication and identity management solutions for their own use and Goode Intelligence shall be publishing further product evaluation reports in the coming months to assist organizations in choosing the most appropriate technology for their use.






Thursday, 2 July 2015

A guide for banks in choosing the most appropriate biometric system

Banks are racing ahead in deploying biometric systems in an attempt to control rising levels of financial fraud and to reduce friction on inconvenient forms of authentication and fraud management. 

There are many different competing biometric modalities that banks can implement but what criteria do (or should) they use to ensure that the biometric system is appropriate.

Through Goode Intelligence, I have been involved in a number of consultancy engagements with banks and suppliers to assist them in assessing and choosing the most appropriate biometric system to meet their requirements.

Based on this experience, and engagements with a wide range of biometric and authentication technology companies, we have devised an assessment methodology that banks and systems integrators can use to ensure that the most appropriate biometric system is chosen. 

The Goode Intelligence Banking Biometric System Assessment (BBSA) tool is based on four interlocking parts, biometric performance, usability, regulation and security. It is also applicable to other highly regulated industries including healthcare, government, telecommunications and utilities. 


The methodology provides guidance to banks in assessing biometric systems and exactly how a bank weights the assessment criteria is dependent on their own set of circumstances such as budget, security policy, bank channel, regulatory environment and risk and privacy models.

There will obviously be other technical and non-technical assessment criteria that a bank will use including integration, scalability and support models etc. 

Biometric Performance: The assessment of the biometric performance and accuracy of a banking biometric system includes measurement of False Reject Rates (FRR), False Acceptance Rates (FAR) and Failure to Enrol Rates (FER). The accuracy of a banking biometric system is expressed as an Equal Error Rate (ERR). It is important to be pragmatic when assessing biometric systems using these standard biometric performance measurements as 'lab conditions' may not match those experienced by a banks' customers when they are using the technology. It is important for a bank to ensure that they can continuously measure the performance of a live  biometric system and banks must ensure that their suppliers can meet this requirement.

Usability: Today’s app-driven world means that getting usability right across a wide-range of devices is essential. What might be an appropriate biometric modality in terms of usability at an ATM might not be appropriate when a bank customer is authenticating themselves via a mobile app or via an Interactive Voice Response (IVR) solution. A pilot or proof-of-concept (POC) provides an opportunity for banks to evaluate a biometric system and different biometric modalities. Financial institutions should build usability measurement into these pilots and POCs and to gather feedback from users in reference to how easy the biometric systems are to use. Regional differences also play an important part in the usability choices of a bank; a biometric system that is suitable for one region may be inappropriate for others.

Security: When evaluating a biometric system for banking, banks should ask whether the system is secure and able to meet internal and external (regulatory) security requirements. Biometric systems must adhere to security policy and regulation and biometric data, including templates, should be securely captured, encrypted and stored. 

Regulation: Banking (industry) regulation is the fourth main component of the assessment of a biometric system for bank use. Biometric systems in banking is currently controlled by a mixture of data protection and privacy regulation, such as the EU’s Data Protection legislation, technology-based guidelines including the US’s FFIEC guidance on the use of authentication in an internet environment, and specific financial services regulation including the EU’s Payment Services Directive II (EU PSD II). 

We have published more information on our banking biometric system assessment methodology / tool in our recently published report; Biometrics for Banking; Market & Technology Analysis, Adoption Strategies and Forecasts 2015-2020. Goode Intelligence's biometric advisory and consultancy service aims to assist organisations in choosing the most appropriate biometric systems - contact us for more information. 

Friday, 17 April 2015

Biometrics for Banking Gets Going

I was talking with a senior manager responsible for authentication strategy at a leading retail bank recently about their views on biometrics for user authentication and whether they were thinking of adopting it. I remember a similar conversation with the same person in 2013 and remember them declaring that biometrics was simply not a possible solution for them; a combination of hardware and software OTP tokens was still the favoured solution. 

Moving forward two years and there has been quite a turn-around in their perception of biometrics for providing authentication to bank customers when accessing digital banking services. Biometrics is definitely on the agenda for them and they have a number of live and pilot projects that are leveraging biometrics on mobile devices including the support of Apple Touch ID for mobile app authentication. 

So what has changed in two years for them? 

I think the fundamental reason is the need for convenient privacy-aware authentication across a number of banking channels with the emergence of mobile as the prime banking channel (not forgetting the start of a wearable banking strategy). A hardware OTP token works well enough when a bank customer is accessing banking services from a desktop computer at home but simply does not cut it when that same customer is using their mobile phone or calling up their bank using a telephone-based service. These 1980s two-factor authentication technologies are also susceptible to Man-in-the-Middle (MitM) and Phishing/Malware attacks.

This has led banking security professionals to look for alternatives that meet the needs to strongly authenticate across a wide range of existing banking channels. The explosion of FinTech-led financial services has also meant that challenger banks are looking at other innovative ways that customers can interact with their banks; biometric authentication gives them the potential to offer their customers a usable and secure method to protect their financial assets when accessing financial services from a range of endpoints.

The use of integrated fingerprint sensors is just one method of providing convenient banking user authentication and will continue to grow as more devices become available. However, I believe that the solutions will evolve and increasingly incorporate other authentication factors and biometric modalities to provide strong security and convenience. For instance, by combining face and voice in a multi-modal biometric authentication solution that can work across a range of banking channels. USAA's recent deployment of Daon's IdentityX multi-modal mobile authentication platform is a great example of this. 

Depending on the context of the transaction/interaction then you can either use a single modality - voice in an IVR interaction - or a combination of modalities - face and voice for mobile or desktop banking services. The combination of context and security risk will dictate the most-appropriate modality or factor to use.

There has also been a lot of debate as to the choice of biometric architecture that a bank should adopt; device-centric, where the biometric data never leaves the device, or server-centric, where the user enrols their biometric and then is stored by the financial institution. For verification; the matching is performed on the device for the device-centric model and against a stored template within a network database (Cloud) for the server-centric model. I think that both models have their merits. I believe that the decision to adopt one over the other (and there will be scenarios where a mixture of both will be adopted) will be driven by a combination of privacy/trust requirements and specific business drivers (some of which will be moulded by culture decisions, i.e. availability of national biometric database). 

For on-device biometric authentication services, I believe that the best approach that meets privacy and trust requirements is to utilise embedded security within mobile devices; Secure Enclave for iOS and TrustZone in ARM-based devices. A great example of this is voice biometric specialist AGNITiO's KIVOX Mobile solution that leverages TrustZone embedded hardware security using a FIDO-Ready implementation developed by Nok Nok Labs. In this model, the bank customer would enrol their biometric voice print on their smart mobile device and then be able to access mobile banking services securely using their voice for authentication. AGNITiO also support the server-centric and IVR-based models ticking the boxes to support multi-channel banking. 

Apple's Touch ID has certainly changed the perceptions of the decision makers in banking security, allowing biometrics to be a serious contender in providing authentication for banking services. There is also a role that biometrics could play in reducing the amount of fraud that is occurring for Apple Pay. There seems to be no problem with Apple's biometric authentication services itself, rather a problem with the card activation (provisioning) process that allows fraudsters to enrol stolen credit cards into Apple Pay and then cash out by purchasing thousands of Dollars worth of Apple kit in-store. Biometrics could close this loophole by allowing the card issuer to validate a legitimate card and its owner using an enrolled voice biometric. Tied in with the card issuer's fraud management system, a customer who was attempting to enrol a credit card into Apple Pay would receive an automated voice call that could verify the legitimacy of the card holder by verifying an enrolled biometric voice print. I don't feel that it would add much friction to the process and have the positive result of reducing this type of credit card fraud. 

I expect to see a lot of innovation in this space where bank-controlled multi-modal biometrics will compliment integrated mobile biometric solutions that have been deployed by the mobile OEM to enable customers to securely access full-banking services from a wide variety of end points. 




Tuesday, 28 October 2014

The role of the Mobile Network Operator in Authentication Services

In previous posts, I have talked about the need to deliver agile authentication services that are convenient to use and address the needs for proving identity across a wide range of services from a variety of endpoints.

Legacy authentication solutions, especially passwords, are continually proving to be both inconvenient and insecure for both consumers and employees – although the lines between the two are being eroded.

Thankfully, a combination of factors including the development and deployment of open standards,  including OpenID Connect, SAML and FIDO, and the creation of innovative mobile-based  authentication technology, including biometrics, are moving us away from a reliance on legacy authentication solutions. Authentication solutions that allow people to authenticate once with the touch of a finger.

PayPal’s FIDO-enabled biometric authentication solution on Samsung devices and Apple’s Touch ID solution is paving the way for wide-scale adoption of convenient user-centric authentication and getting people used to new methods of proving their identity for digital services.

These services are just the tip of the iceberg in terms of the potential for next generation mobile authentication services and I believe that Mobile Network Operators (MNOs) can play an important role in the new authentication landscape as they logical owners of authentication services in an era where accessing the internet is increasingly being made from mobile devices.

MNOs have long standing relationships with millions of consumers around the world and are considered to be trusted organisations that know how to deliver secure consumer-focused services. 

By owning and managing one of the trusted building blocks of mobile communication, the SIM, MNOs have a part to play in the delivery of authentication services to billions of mobile phone subscribers around the world.

I have just completed a piece of work, commissioned by Nok Nok Labs, that details the important role of Mobile Network Operators in delivering the latest agile authentication solutions. You can download the white paper from the Goode Intelligence website here.

I am also taking part in an online webinar organised by Nok Nok Labs to discuss this research on 4th November 2014 at 16:00 GMT. You can sign up to the webinar here.

Thanks for reading. 

Thursday, 5 June 2014

Touch ID - The Cornerstone of Apple's Authentication Framework

This is an extract from an upcoming Goode Intelligence Analyst Report entitled "Mobile & Wearable Biometrics for Authentication Applications"

Apple caught much of the analyst and biometric community by surprise with the announcement that it was to open up its Touch ID fingerprint biometric environment to third-parties using an API at its annual developer conference, WWDC2014, on 1 June 2014.

Apple announced that once iOS 8 launches (possibly September or October 2014) third party developers will be able to access the Touch ID environment and leverage the benefits of mobile fingerprint biometrics.

During the presentation given by Apple's SVP Craig Federighi, Apple referenced Touch ID being used to authenticate into a personal financial application called Mint.

Apple’s Touch ID Local Authentication Framework (LocalAuthentication.framework) will enable third-party app developers to make use of Touch ID and benefit from its convenient personal authentication features.

Touch ID has been a great success for Apple; Apple also announced some stats for its Passcode phone unlock feature at WWDC. 83 percent of users were turning on the Passcode phone lock feature compared with 49 percent of general iOS users. That equates to millions more iOS devices being protected against unauthorised access and a great deterrent to theft.

Apple has been steadily building up its product and software portfolio to offer a wide range of connected services and it appears that they intend to use Touch ID as the foundation for identity verification on the Apple ecosystem.

I believe that Touch ID will be used to authenticate in the following scenarios (some of these are available now and some are predictions):
  • To replace the PIN for Passcode (device unlock)
  • To provide authentication for Apple ID (iTunes purchases)
  • To verify identity for an Apple payments product (both for online and physical store purchases)
  • To provide authentication for Apple’s CarPlay in-car service
  • To verify identity for Apple’s mobile healthcare solution “Healthkit”
  • To provide authentication for Apple’s connected home solution “Homekit"
    • This includes  the ‘Secure Pairing’ feature where only authorised users can unlock a home door or change the temperature of a room via a smart thermostat
Apple’s vision is to merge the logical and physical worlds using an iDevice (iPhone, iPad or even iWatch) as the smart controller with Touch ID providing convenient biometric authentication for this uber connected world. 

Tuesday, 11 March 2014

Improving the first mile of authentication – how the FIDO Alliance and Nok Nok Labs are helping to create the building blocks of trusted identity

There has been a lot of media attention attracted by the FIDO Alliance, an organisation that is attempting to change the nature of online authentication through standards and I have been following the developments with interest.

FIDO has had a successful start to its history with some of the largest names in technology, PayPal, Google, Microsoft, Synaptics (Validity Sensors), Lenovo, RSA and MasterCard to name a few, playing a role in developing the standards that were recently made public.

A number of the FIDO members have already showcased FIDO Ready™ devices at this year’s trade shows including CES, MWC and RSA Conference 2014. Solutions from AGNITiO, GO-Trust, Infineon, Fingerprint Cards, Yubico, Synaptics (Validity Sensors) and Nok Nok Labs have all been shown to demonstrate how FIDO can be implemented at the endpoint.

And with Samsung announcing its new flagship S5 smartphone at MWC 2014 with an integrated fingerprint sensor linked to PayPal’s FIDO Ready™ mobile payments app we will soon see how the FIDO standards operate in the real world.

Samsung is also planning to open up the fingerprint sensor to third parties using its new Pass API and there is a possibility that the FIDO components will be available for developers to build mobile-based multi-factor authentication enabled applications; a very promising move.

I expect to see more clients and devices being launched throughout 2014 that are FIDO Ready™. These FIDO enabled devices will run a Multifactor Authentication Client (MFAC) that supports FIDO’s Universal Authentication Framework Protocol (UAF) and interfaces with a FIDO server.

Currently, Nok Nok Labs is the only provider of both the FIDO Ready™ client and server components with its S3 Authentication Suite.

The device OEM (could be a smartphone, a tablet or a Windows PC) would pre-install the MFAC and then a service provider, the Relying Party, (could be a financial services provider or a mobile network operator running it on an Authentication as a Service basis) would run the MFAS.

The MFAS has the capability of interfacing with policy and risk engines (including Risk Based Authentication) and also federated identity providers to link the client identity with multiple online services – brokering identity using strong mobile based MFA.

Over the past five years, we have witnessed a lot of development in the ‘last mile’ of authentication and identity assurance; standards such as SAML and OpenID have introduced a framework in which user identities can be shared amongst online services.

The FIDO Alliance and Nok Nok Labs are attempting to standardise the ‘first mile’ of authentication – an event at the beginning of the authentication process proving that an authorised person is allowed access to a digital service or to authorise a transaction.

These are early days for FIDO and Nok Nok Labs but I firmly believe that they are establishing the building blocks for agile omni-channel authentication and identity verification that will have an important part to play in improving the levels of trust in an open connected world.

Tuesday, 21 January 2014

From Swipe to Touch to Invisible Touch - The Evolution of Fingerprint Sensors in Smart Mobile Devices

From Swipe to Touch to Invisible Touch - The Evolution of Fingerprint Sensors in Smart Mobile Devices


Readers of a certain age will possibly remember Genesis, the English prog-rock band that featured first Peter Gabriel and then Phil Collins on vocals. In the 1980s they released a rather poor 13th album called ‘Invisible Touch’. Little did they know that we would use that title in a rather obscure pun in an article on the evolution of fingerprint sensors in smart mobile devices (SMD) – the album cover is rather relevant though! And if you hear ‘Invisible Touch’ wafting over the speakers at a product launch at MWC 2014 – you know where they got their idea from.


This blog explores the evolution of fingerprint sensors designed for consumer electronic devices including smart mobile devices; from swipe to touch to ‘invisible touch'. This blog first appeared in the January 2014 edition of the Goode Intelligence Market Intelligence publication; "Fingerprint Biometrics Market Intelligence" (published 28 January 2014). 

Smartphone OEMs rush to embed fingerprint sensors

Despite the intense media attention that accompanied Apple’s launch of Touch ID embedded fingerprint sensors on mobile phones have been around since 1998. Ever since Siemens developed its prototype device back in 1998 there has been steady stream of handsets being biometric-enabled.

Fingerprint sensors are becoming a common-feature of flagship smartphones with an increasing number of mobile device OEMs joining Apple in launching high-end devices during the latter part of 2013. This included HTC, Fujitsu and Pantech. So far, all these Android-based devices have used swipe fingerprint sensors, sourced from either Fingerprint Cards (FPC) or Validity Sensors. For these android devices, the sensor is being located on the rear of the smartphone (see image of HTC One max below).

HTC One max (with Validity swipe sensor located underneath rear camera)

















Apple Touch ID - leader for smartphone touch sensor

Apple is so far the only mobile device OEM to have launched a device with an embedded Touch Capacitive sensor (shown below). The sensor uses capacitive touch technology to take a high resolution (500 pixels per inch or ppi) from small sections of a fingerprint (from the subepidermal layers of the skin).














Source: Apple

There are advantages in using a touch sensor over a swipe sensor on a mobile device:
  • The user experience is usually superior
  • Greater accuracy;  there appears to be fewer failures as the finger is better positioned for touch. For swipe, the finger has to be swiped accurately over the sensor to ensure that the fingerprint is read correctly. On some smartphone implementations, especially on larger devices (phablets), the location of the sensor on the rear of the device makes this difficult when holding the device with one hand 
  • The sensor can be built into a hard button on the front of the mobile device, e.g. home/power button

Non-Apple smartphones - first swipe then touch


Goode Intelligence believes that for the first quarter of 2014 a number of Tier 1 mobile device OEMs will launch flagship models that incorporate a swipe sensor. This will include further HTC models and releases from LG, Lenovo and Samsung (Samsung may want to launch with a touch sensor to match the user experience of Apple’s Touch ID).

The three remaining fingerprint sensor manufacturers who can supply to the mobile device industry, Fingerprint Cards, Idex and Validity Sensors (part of Synaptics) are all in the process of commercialising their versions of the mobile-ready touch sensor.

Fingerprint Cards is probably in a more advanced state of commercialisation and has gone on record to say that their touch sensor (FPC1020) has been sold to a “Tier 1 OEM” for a “flagship smartphone with a targeted launch date in the summer of 2014”[1]

Idex and Validity will follow FPC in launching their own touch sensors during 2014 and GI expects to see them appear in smart mobile devices and other consumer electronic devices.

Next generation consumer fingerprint sensors - Invisible Touch

The third stage to the evolution of mobile device-based fingerprint sensors is driven by the need for greater user convenience combined with a trend to remove physical buttons from smart mobile devices. Partly as a result of the reduction of the bezel-size and driven by the trend for larger touch screen sizes.

The elimination of physical buttons creates a problem for component suppliers including fingerprint sensor manufacturers as it removes an obvious place to position the sensor. It also provides them with an opportunity for new markets for their products.

The positioning of the fingerprint sensor underneath, or within the touch screen, is the next stage in the evolution of consumer fingerprint biometrics and enables mobile device OEMs to remove physical buttons. It also ensures that the convenience of identification, touching a finger on the front of a mobile device, is maintained.

GI believes that all of the fingerprint sensor manufacturers currently operating in the consumer and mobile space are well advanced in their research and development efforts to make this a reality:
  • Idex released this video after demonstrating a proof-of-concept device that placed the fingerprint sensor within the touch screen display
  • Validity Sensors is now part of Synaptics who are one of the world’s largest suppliers of touchscreen technology. Synaptics are also developing fingerprint sensors built into the touchpads that are embedded into laptops and notebooks
  • FPC has demoed demoed touch sensor capabilities with Windows for integration into Windows 8 (8.1) products and also works with CrucialTec, manufacturer of the optical TrackPad (OTP)
This includes Apple and the resources that were integrated as a result of the AuthenTec acquisition.

Invisible Touch’ is not only suitable for smart mobile devices; any consumer electronic device that uses a screen has the potential to integrate a touch fingerprint under or within the screen. This could include smart TVs, single-use gaming handhelds, tablets, touchscreen monitors, hybrid notebooks and touchscreens integrated into domestic appliances and smart house control technology. Whether anybody would want to authenticate using their fingerprint for their fridge is debatable (although perhaps if you wanted to stop a young child from turning on an oven or keeping your teenager out of your wine cooler?).

This is a potentially huge market and is part of the wider Consumerisation of biometrics that will revolutionise how we interact with technology.

This opportunity will be explored in an upcoming analyst report published by Goode Intelligence; "Emerging Markets for Fingerprint Biometrics".




[1] FPC wins first 1020 touch sensor DW from Global Tier 1 OEM for their flagship smartphone. 20 December 2013: http://www.fingerprints.com/blog/2013/12/20/fpc-wins-first-1020-touch-sensor-dw-from-global-tier-1-oem-for-their-flagship-smartphone/



Thursday, 26 September 2013

The Changing Face of User Authentication and the Road to Bring Your Own Identity

I recently presented on an Infosecurity Magazine webinar entitled “How to Make Access to your Sensitive Data More Secure - The Easy Way”.  During my presentation I explored how user authentication is adapting to meet the changes created by a number of linked transformational trends that include cloud computing, mobility and the Consumerisation of IT.

The presentation focused on one of Goode Intelligence’s specialist areas, mobile-based authentication (both the phone as an authenticator and mobile authentication when an IT service is accessed from the mobile device). It also touched on other areas of Identity and Access Management (IAM) and the development of these corresponding areas is vital to the successful transformation of user authentication services (both mobile and non-mobile). It is imperative that we meet the security challenges of the next generation of IT services – to defend the borderless enterprise.

We are increasingly accessing a huge wealth of digital information, both inside and outside of the enterprise network, from a myriad of devices. In this new world of IT, traditional authentication solutions, both single-factor (passwords) and two-factor (smart cards and OTP tokens), have become clumsy, inconvenient and less secure. Password management is a headache; in the main we either write down strong passcodes or alternatively re-use passwords that we can easily remember (there are password management tools that exist).  Alternatively, when traditional two-factor authentication is used then this is often not designed for cloud, mobile or BYOD. Authentication solutions designed for traditional, behind firewall, enterprise systems are increasingly not effective for new, agile, IT services.

So what are the alternatives? How do we match convenience and security and ensure identity is successfully proven across a wide variety of different devices (enterprise-issued and employee-owned) accessing many services located on-premise, hybrid and wholly in the cloud?

I believe that we are close in achieving the goal of supporting a much more agile and mobile world of IT service provision with strong, convenient, authentication. We know what the problem is and we have many of the building blocks to make this a reality. These building blocks include Risk-based authentication (RBA), federated identity, multi-factor authentication and user choice.

Match risk with appropriate security – combining user intelligence with business context
At Goode Intelligence, we are seeing increasing demand for more intelligent forms of authentication where the choice of authentication method used is real-time risk driven. The financial services sector has been an early adopter of RBA technology as it has a history of measuring (managing) risk.

RBA matches the most appropriate authentication method to the assessed risk. To be successful in this you must first know who the user is and what they plan to do.

User intelligence can be gathered from a number of inputs and the mobile device can play an important part in this process. When combined with more active forms of authentication, by learning the unique characteristics of its owner; where they are usually located (geo-location), the days and times that they are normally active and even how they hold and touch the device (behavioural analysis).

An accurate risk score can be calculated by combining user intelligence with business context. What is the user trying to achieve - Is it a high-value financial transaction to an unknown recipient or attempting to access the latest sales data? Based on this risk score the authentication engine can then choose the most appropriate authentication method to prove identity. A one-time-password (OTP) generated by the authentication engine and sent to the user’s registered mobile device via SMS may be sufficient or alternatively the authentication level may be ‘stepped-up’ to a stronger factor – a biometric or even a separate hardware device.

Federated Identity – the road to single sign on and a more frictionless experience
For both enterprise and consumer users the prospect of having to uniquely identify themselves to multiple applications and web services is an onerous task. This is probably why for mobile devices the auto-authenticate option is widely deployed – thumbs up for convenience, thumbs down for security.

Organisations are increasingly turning their attentions to Identity federation, sometimes referred to as Single Sign-On (SSO), as one way to solve this problem. Identity federation allows for a standards-based way to share identity amongst multiple organisation and applications. Standards include the Security Assertion Markup Language (SAML), the OpenID protocol and WS-Federation.

The benefit to the user is that they only need to authenticate once to access a number of different organisations and applications. Using techniques such as SAML-insertion identity is then shared transparently with other applications. The user is authenticated once and then other application providers can verify the authenticity of the provided federated identity.

Multi-Factor Authentication/Identity Verification and context
Two-factor authentication (2FA) is so last year!

Over the last 24 months we have seen virtually all of the major internet players, Google, Twitter, LinkedIn, Microsoft and Facebook deploy some form of 2FA (mainly mobile OTP-based). Microsoft was so enamoured at mobile phone-based 2FA that it acquired a vendor, PhoneFactor. The option to use 2FA in these networks I usually optional so it is difficult to gauge how popular these services are outside the InfoSec geek community. 

In terms of trends in the authentication market there is a definite movement towards supporting multiple factors (MFA), sometimes referred to as infinite factors. This is not necessarily the third factor – often associated with what you are, biometrics. MFA is about allowing a choice of factors and then matching them against context.

I feel that the combination of MFA and contextual awareness is one of the most exciting areas of authentication at the moment and we expect it to be a standard feature of premium authentication solutions. Many of the authentication vendors, including RSA, Entrust and SecurEnvoy, have already increased their portfolio of factors that can be deployed for use with their authentication engines and I believe that the number of factors, and user choice, will increase in the next 12 months. Factors include both traditional – hardware/software tokens and smart cards – and emerging – mobile, biometrics, image-based and behavioural.

The power of having multiple factors at your disposal is multiplied when you add contextual analysis. This is where mobile devices really come into their own as authenticators. Smart mobile devices have so many in-built sensors that have the capability to capture important information about the context of how and where these devices are being used. Geo-location through a combination of GPS and cellular-network positioning (even more accurate with LTE/4G services), ambient noise levels captured through the microphone (important in voice biometrics), user identification through the camera and embedded fingerprint sensors (Even before Apple’s iPhone 5S and Touch ID there were over 20 million smartphones shipped with fingerprint sensors). All of this contextual information can be captured and then passed onto services that support risk-based and intelligence-based authentication. A relatively accurate identity scoring can be calculated on a continuous basis and then fed into the authentication service providing a method of identifying whether the authorised owner of the device is initiating a service and then calculating whether additional authentication is required. This is sometimes referred to as step-up verification (although step-up verification is also a part of non- mobile authentication and RBA services).

User choice – The road to Bring Your Own Identity (BYOI)?
We have bring your own device/platform/software…. Is it time for bring your own identity? Let the user choose what is the most convenient and secure way to protect their digital assets? People decide how best to protect their property and automobile cars why not let them choose how they should protect their digital lives?

I feel that we are already seeing evidence of this with Internet passports, e.g. Facebook ID and Google Authenticator, that allow registered users to authenticate to other services that support authentication from the passport provider. For instance, if I choose to I can use my Facebook ID to authenticate into my Spotify streaming music service. 

The big question is whether this will expand to services that are more sensitive, i.e. have more risk. Will my bank allow me to use my Google Authenticator to login to its internet bank service and then transfer funds out of the account? Does the bank trust credential s issued by a social network? Possibly not funds transfer but what about a balance enquiry? Step-up verification could be used for when I want to transact or to request an increase to my overdraft limit.


Alternatively what if a universal digital ID was issued by a government and managed by a trusted authentication service provider? I wouldn’t discount it but we are at the early stages of BYOI and perhaps initiatives such as the FIDO Alliance, Open Identity and the GSMA’s Mobile Identity Programme may help provide the plumbing and the initiatives to support it. 

Alan Goode September 2013 

Monday, 9 September 2013

iPhone 5S Fingerprint Sensor: What I think Apple will do with it - it's not just about security!

I am writing this blog a day before Apple's September 10 event where it has been widely predicted by journalists and analysts alike that Apple will launch the next generation iPhone with an embedded fingerprint sensor (EFS).

So how will Apple use the fingerprint sensor?

I have been covering this market for many years now (Goode Intelligence published a report in June 2011 investigating the market for mobile biometrics) and spoke with the team at AuthenTec (Fingerprint Sensor manufacturer) before they were acquired by Apple.

I am currently working on a number of projects for Goode Intelligence that cover this market, a report investigating the market for mobile authentication and identity verification  that covers biometrics and a report taking a look at the security of wearable technology and how it can be used for authentication purposes.
As part of this research I have talked to many biometric technology vendors, including fingerprint sensor manufacturers, buoyed by Apple's potential move in this area. All of them indicate that Apple will tomorrow launch an iPhone with a fingerprint sensor. I share this prediction - it may come back to haunt me tomorrow when we see an iPhone with no sensor - perhaps its an iWatch with a fingerprint sensor!

I predict that Apple could make use of the embedded fingerprint sensor (probably an optical EFS) in the following ways:

Protect the device
My last smartphone was an Android-powered Motorola Atrix 4G - I think I may have been one of the few owners in the UK. It was not a bad smartphone, OK it ran a pretty old version of Android but I could live with that because it had an embedded fingerprint sensor integrated into the rear of the phone doubling up as a power button (see below) - sound familiar? What I loved about this phone was the ability to unlock the device by using the fingerprint sensor (supplied by AuthenTec).

After a pretty simple enrolment process I could use a fingerprint swipe to unlock the device and in approximately 90% of occasions it worked first time. I regularly travel into London, commuting on public trains and tubes and by swiping the sensor with an enrolled finger I could avoid any potential passcode shoulder surfing - a real deterrent against theft.

What I didn't like about this phone, and this is a lesson for any ODM thinking of embedding a biometric sensor into a phone, was the lack of a supporting ecosystem. By using the lock feature, I could conveniently protect my phone from unauthorised use but little else. Motorola, and this is the same mistake made by other fingerprint sensor manufacturers who have sold to laptop and netbook OEMs, didn't create the supporting ecosystem (APIs or SDKs) that could be utilised by other stakeholders, such as third-party app developers and service providers. No one, outside of Motorola, could utilise the benefits of the sensor.

Motorola ATRIX 4G

So enough about Motorola, let us turn to Apple. I believe that Apple will launch with a fingerprint-enabled unlock feature on the iPhone 5S users. To protect this device in a similar manner to the Atrix 4G by unlocking the iPhone by use of  an enrolled finger swiping on pressing the iPhone home button. The iPhone 5S stroke - coming to a train near you soon!

eCommerce
The second feature that I feel will be fingerprint-enabled from tomorrow will be the ability to use a fingerprint in iPhone initiated eCommerce transactions. The iPhone as a payment method. Perhaps without needing NFC (for now anyway).

Apple has become not only a successful computer manufacturer but a very important retailer of digital media. Earlier this year (June 2013), Apple CEO, Tim Cook, announced the there were 575 million registered iTunes accounts around the world. Accounts do not equate to unique users but even so we must be talking of half a billion people who are iTunes users and who have registered their credit cards with Apple.

These 575 million iTunes accounts have downloaded a total of 50 billion apps from the app store and paid for billions of dollars of digital content including films, music and books. According to CNNMoney iTunes generated $12.9 billion in 2012. These figures detail the importance of Apple as a very successful retailer, both on-line and physical (There are a reported 413 physical Apple stores located in 14 countries).

Like any successful retailer Apple will suffer from financial fraud and there have been reports of fraud affecting Apple iTunes. By adding the requirement for a second factor (what you are - your fingerprint) in combination of what you have (the iPhone), fraud surrounding iTunes transactions (for iPhone 5S users) could be significantly reduced.

Fingerprints could also be used to protect Apple's wallet service, Passbook. Apple's vision is to have Passbook as a secure wallet service that contains valuable digital files, boarding passes, loyalty cards, event tickets and retail coupons. A convenient and secure method to protect this valuable information would be to fingerprint-enable Passbook.

Passbook may also be turned into a payment tool. I predict that we will see Passbook being used as a mPayment tool with the user's fingerprint being used to unlock the wallet and then to authenticate transactions. Initially I believe that this will be used (think of it as a pilot) in Apple stores. It could work like this. I am browsing in my local Apple store and I would like to purchase a new MacBook Air. I take my iPhone 5S out, open up the Passbook app and authenticate using my fingerprint. I choose the payment feature and this activates the barcode scanner. I scan in the barcode for the Air and press the 'Buy' button. It asks me to verify my identity and I scan my fingerprint (possibly also entering in my Apple ID passcode, although this may be a bit clunky for a physical store). It verifies me as the account holder and then initiates the transaction (checks whether I have the funds and goes through the fraud management system). Happily for me, and for Apple, I pass all the checks and it sends down a receipt to the phone (contained in the protected Passbook). The receipt could contain a barcode that a retail assistant could check before handing over my lovely shiny new gadget. It could work - quick, convenient and pretty secure.

Will it be open?
In conversations I have with technology vendors working in this space I am always asked my opinion on whether Apple will open up the sensor for third-party use (The authentication vendors may be secretly scared of having their business model disrupted by Apple - not the first and definitely not the last). My answer is a qualified no. Apple's history has been to keep its technology within its garden walls and not to open it up. I believe that any low-level authentication SDKs and APIs that directly call the sensor will be shut off from third-party access. It may wish to add some high-level functions to its iOS development library that make use of the sensor for payment and in-app billing features but, at least for the short-term, I would be surprised that they open it up to authentication vendors.

What may happen is a replication of a trend that we are seeing for consumer end-user authentication. The quasi-federated model where a large, trusted, internet service will provide authentication services on behalf of a third-party service provider. For instance, I can choose to authenticate into my Spotify account using my Facebook ID. Facebook have become the broker for my identity (This also includes Google). Apple could offer a similar sort of service using the fingerprint sensor as part of the response to the challenge. Widen its network, gather vital user intelligence and increase its sphere of influence through identity verification services.

To sum up
I know we have been here before (NFC), but I believe that a piece of security kit that has been hidden away in high-security buildings and been collecting dust on laptops around the world will get the Apple magic tomorrow and Apple will make it work. It is being driven by a combination of convenient security and a desire for Apple to benefit from half a billion credit card owners by enabling iPhone initiated payments at physical stores.

This will have a direct impact on the biometric industry and will propel biometrics into the mainstream.

I welcome any feedback from this blog (including typos and factual corrections).


Disclaimer: This is my personal viewpoint and does not reflect those of my employer, Goode Intelligence.