Showing posts with label fingerprint spoof. Show all posts
Showing posts with label fingerprint spoof. Show all posts

Wednesday, 9 September 2015

The Top 10 Features for a Modern Authentication Solution

Back in 2009 I wrote an analyst report for Goode Intelligence on the mobile phone as an authentication device. It predicted that the mobile phone would become the prime user authenticator and enable people to securely access digital services delivered across a wide range of endpoints; used as an out-of-band authenticator for web services and as a seamless authentication tool for mobile apps. 

Roll forward to 2015 and these predictions have proved to be pretty accurate. The smartphone has become the remote control of our digital lives with user authentication being one of the main go-to buttons on our remote controls. All of the major authentication platforms are transitioning away from delivering strong authentication through sole-purpose hardware. Traditional stronger authentication technology, such as the smartcard and OTP token is largely being replaced by smart and agile forms of mobile-based authentication solutions some of which (Apple's Touch ID biometric authentication technology) is being embedded into mass-market consumer technology. It has never been as easy to deploy strong mobile-based authentication. But which authentication and identity management solution should an organization choose and how should they measure them?

In the years that I have been covering the authentication industry I have worked with my colleagues, both at Goode Intelligence and through our many consultancy engagements, to develop a checklist of where an authentication solution needs to excel in order to be market leading. 

The result of this work has been the recently launched Product Evaluation service that provides an independent analysis of information security products and services, including authentication and identity management solutions. We define that a modern authentication solution should have the following ten features to be successful in meeting the latest demands. These ten features are listed below.


We have used this criteria as part of a product evaluation of the Encap Security Smarter Authentication Platform in a recently published free-to-download report. The evaluation concludes that Encap's mobile-based authentication platform meets the requirements of a modern authentication platform and Goode Intelligence has awarded the product a ‘Highly Commended’ rating (Goode Intelligence’s top rating for Authentication and IAM). 



This rating has been awarded as the Smarter Authentication Platform is a highly customizable, adaptive and risk-based platform that meets the needs of highly-scalable connected digital services. It has the ability to be quickly integrated and rolled out to millions of end-users and is available for all smart mobile devices. 

Organizations can apply the same measurement criteria when evaluating authentication and identity management solutions for their own use and Goode Intelligence shall be publishing further product evaluation reports in the coming months to assist organizations in choosing the most appropriate technology for their use.






Wednesday, 16 April 2014

The Samsung Galaxy S5 fingerprint sensor has been spoofed - what can be done to prevent it

With the recent news that researchers from SR Labs in Germany have successfully fooled (spoofed) the Samsung Galaxy S5's integrated fingerprint sensor; allowing unauthorised access to the device and the ability to make payments using the PayPal app, there are questions as to how secure fingerprint biometrics are for authentication. These questions are justified. 

An authentication solution can be convenient but it must also be secure.  

A fingerprint biometric can be more convenient than using a PIN or password especially on a mobile phone. By touching or swiping a finger over a sensor a person can quickly unlock a device, gain access to an account or make a payment. However, if the sensor can be easily fooled than the solution is fundamentally flawed. 

The key point in my last sentence was "easily fooled". Attacks on fingerprint biometric systems are relatively difficult to carry out. As Marc Rogers from Lookout Mobile Security pointed out in his blog from last year -  "Why I hacked Apple's Touch ID and still think its awesome" - an attacker needs access to the device and then use a lot of kit to physically create the fake fingerprint. As Rogers stated this can be "tricky" and probably not within the reach of your average street thief. However, with the right equipment and a little ingenuity it can be done. 

So what can be done to ensure we benefit from the convenience of biometric authentication on mobile devices but also have a level of assurance that the solution is difficult to spoof and attack? 

One solution is to improve the anti-spoofing solutions within the biometric system. NexID Biometrics develops spoof mitigation and liveness detection solutions including its Mobile Live Finger Detection (LFD) software. The company claims that the solution can help ensure that the fingerprint system is not spoofed and states that authentication accuracy is as high as 94-97 percent. 

I spoke with NexID Biometrics' COO, Mark Cornett, to get his views on this and he said; "While Apple validated the convenience of fingerprint authentication on mobile devices, the spoof of the iPhone 5S should have sent a signal to other device manufacturers that while providing users with convenient authentication, the current level of security is vulnerable to spoofing. The layers of security for unlocking mobile devices and their applications needs to be stronger to properly meet the needs of users, and facilitators of mobile commerce and BYOD policies. Now that the two largest distributors of mobile devices in the world have had their solutions spoofed, they will hopefully add liveness detection solutions to mitigate this vulnerability and thereby instil confidence in the use of mobile device fingerprint authentication."

As well as anti-spoofing and liveness detection solutions there are other tools that can be deployed to improve the security of these emerging authentication solutions. This include combining biometric authentication with other factors as part of a multi-factor authentication solution - especially useful for step-up verification where a highly level of user assurance is required. 

I am a big fan of behavioural, or gesture, biometrics where the device learns about how a specific user engages with their mobile device to create a profile that can be used as part of a risk-based authentication solution. By combining behavioural biometrics with fingerprint authentication a greater level of trust in who is actually using the device can be created. And when an unauthorised user attempts to spoof the system by using a gummy bear or wood glue mould then the authentication service can request for another level of authentication to ensure that it is the valid owner of the phone and service. The link between the end user authentication client and cloud-based risk-based (anti-fraud) solutions, especially in financial services, cannot be underestimated. 

There are ways in which you can improve the security of mobile-based biometric authentication solutions and deter the type of spoofing attack that has been witnessed with the Samsung Galaxy S5 - I have just touched the surface in what is possible. 

However, an enhancement to the security of the biometric solution should not come at the expense of convenience and usability. 

Mobile device manufacturers and service providers are turning to biometrics because they can enhance the usability of the authentication experience - this must not be altered.