Showing posts with label middleware. Show all posts
Showing posts with label middleware. Show all posts

Friday, July 13, 2012

WVU's own Bojan Cukic holds forth on the state of biometric applications.

Tipping Point Unclear For Mass Market Adoption Of Biometrics
Cukic said that most biometric devices currently available are standalone solutions that do not have access to the Internet. Were this to change, Cukic believes the use of biometrics could receive a significant shot in the arm. "I would say that we have good components, but the question remains, who is going to be the developer responsible for offering these systems in which biometrics address some of the authorization and authentication problems that we face today?" he added.
Middleware and the application development it enables will be critical to moving these technologies out of the lab and niche government installations and into positive ROI applications for profit-making entities.
Or (more succinctly...

Wednesday, February 8, 2012

Multifactor Authentication, Middleware and the Online Security Arms Race

Julie Sartain at has an article at techworld.com that describes some of the new threats that have necessitated the adoption of multifactor authentication for online transactions and the variety of technologies available to augment standard username/password authentication, such as:

♦ Risk-based authentication
♦ Phone-based authentication
♦ Versatile authentication platforms
♦ Image-based authentication and, of course,
♦ Biometrics
As everyone in the security business knows, there is no perfect answer. Gartner's Allan points out that "whatever the desirable level of assurance, it has to be balanced against cost (deployments for hundreds of thousands of users are very cost sensitive) and user experience. We know that bank customers may change their banks if new security features such as authentication degrade the user experience: in a survey a couple of years ago, Gartner found that 3% of customers had done so, and a further 12% considered it," adds Allan.
Because there's no perfect answer, the challenge is in how to adopt new technologies that show positive return on investment without tying a mission-critical business process up in something that might not be the optimal solution over the longer term. How do you adopt new technologies in a way that preserves your ability to continue to adopt new technologies?



Our CEO, Barry Hodge, points out via Twitter that the move to multifactor authentication broaches the subject of middleware.

Middleware, as it relates to this discussion, is the software components that will allow the new authentication factor to interact with the existing authentication scheme and broader business processes.

But not all middleware is created equal.

Middleware can be written to facilitate a custom integration, or it can be written as a more flexible software layer that makes future integration decisions and changes less costly. A hardware analogy might be the difference between a soldering iron and a USB port. Both get the job done but involve entirely different levels of commitment.

Well written middleware components, such as those we've developed here at SecurLinx for biometrics, allow flexibility by reducing an enterprise's switching costs and the costs of adopting future techniques and technologies that may offer a significant returns on investment.

Middleware isn't really a glamorous topic — no Tom Cruise movies, severed eyeballs or rubber fingers — but it's incredibly important and becoming more so.

Thursday, May 12, 2011

TWIC Isn't Keeping Ports Secure, GAO Says

Less Secure than state driver's licenses (National Journal)
Despite nine years of fine-tuning and more than $400 million in funding, a government-issued picture ID card used at U.S. ports provides less security than the average state-issued driver's license, a federal auditor told lawmakers Tuesday.
One of the biggest problems with the TWIC system is interoperability. If you own one location where your customers receive a service, it's all fine and good to have a proprietary, un-networked identity management system. If you're trying to control access at facilities scattered across the globe and managed by many different agencies, you have an ID management challenge of a completely different order.

Part of the solution is technical and part is political.

Interoperability is a term that covers a bit of both the technical and political aspects of ID management.

The solution to the TWIC problem is either a top down agreement among all ports to adopt the same ID management protocols and verification system or a strong standards based solution with a robust middleware integration.

SecurLinx can be of much help with the latter.

Thursday, May 13, 2010

Polish bank claims Europe's first biometric cash point

From The Independent (UK)

Could it be? Are token-less ATM machines now in use in Europe?

From day one, cash machines have required a token and a PIN. The token, a plastic card, identifies you to the banking network and the PIN confirms that the card is being used by someone who knows the account holder's password.

When the card is introduced into the machine, the banking network already knows the correct PIN that goes with the card. The computer network has only to answer one simple question: Does the PIN that goes with the card match the PIN that was just entered into the machine? If the answer is yes, the transaction is executed and the ATM user gets her cash.

In the case of the token-less ATM's described in the article linked above, it is less clear what is going on. Unlike the magnetized plastic card, fingerprints and PIN's don't store any account information so their use can't lead directly to a simple yes/no question for the bank software to sort out. So what is happening?

It's probably not the case that the bank customer puts their finger on a sensor and the bank software identifies the proper account from the finger alone to be confirmed later by the PIN. This would require the bank software to answer a yes/no question as many times as it has finger vein-enabled accounts every time someone uses the machine. Example: Does this finger go with account 1? If no, does this finger go with account 2? If no...

I suspect that, in order to dispense with the plastic card, the machine's software designers ask the user to input their PIN first. That would reduce the number of yes/no questions the software must answer in order to confidently establish a user's identity by a factor of 10,000 by allowing the software to search only from among accounts that use the same PIN. Given that there probably aren't very many consumer checking accounts that are finger-vein accessible, the customers of BPS SA aren't likely to notice any increase in the machine's response time over earlier cash machine models.

A system, such as the one described in the article, however, is likely to experience considerable growing pains. First, in order to serve other bank's customers and to reap the considerable fees to be charged in so doing, the machine must still support the old fashioned card-and-PIN model, adding to the costs of the machine by adding an input device to the older model (sensor/card reader/key pad vs. card reader/key pad).

Then, as the number of the bank's customers which use the finger-based method to access their account increases, the number of yes/no questions the software must sort through increases as well, slowing response time.

When my local bank adopts a finger-based system, I can start using the BPS SA machines while in Poland, correct? Not necessarily. If my bank uses the same Hitachi software that BPS SA uses, then things might work out, but if it has chosen another finger-based biometric vendor then things are unlikely to go well unless the banks involve a middleware vendor such as SecurLinx.

Over time and with the giant leaps in computing power implied by Moore's Law, applications like the one described in the linked article will be brought to the market improving the efficiency of the banking industry and improving the lives of people worldwide. Those days, however, are still in the future. The BPS SA case is probably best seen as a proof-of-concept experiment, rather than a full commercial deployment.

The exact same critiques could have been and probably were voiced when John Shepherd Barron, the inventor of the cash machine, first pitched his idea to Barclays way back in 1967. Kudos to BPS SA for blazing the trail.