...[K]ey [smartcard] benefits, including the ability to electronically exchange beneficiary medical information and electronically convey beneficiary identity and insurance information to providers, would do little or nothing to deter fraud, experts said.Note: GAO = Government Accountability Office
Adding certain layers of protection to smart cards like biometric biometric information or a picture ID could help to deter fraud, the GAO said.
Showing posts with label tokens. Show all posts
Showing posts with label tokens. Show all posts
Tuesday, April 28, 2015
US GAO: To reduce fraud, MediCare smatrcards need biometrics
Smart cards would do little to curtail Medicare fraud: GAO (McKnight's)
Wednesday, August 27, 2014
3-D Printed Bump Keys
It appears a token technology that we've relied on to secure our possessions and domiciles for centuries has been hacked by clever men with 3-D printers and rubber mallets.
These 3-D Printed Skeleton Keys Can Pick High-Security Locks in Seconds (Wired)
The article at the link also has this very informative gif a showing how a bump key works in a lock.
According to the logic employed by some critics of biometric technologies, this means locks opened using metal keys are useless now. I, for one, however, will not be contracting with any security guard services today. A fingerprint front door unlocker would be cool, though.
These 3-D Printed Skeleton Keys Can Pick High-Security Locks in Seconds (Wired)
One of the hairier unintended consequences of cheap 3-D printing is that any troublemaker can duplicate a key without setting foot in a hardware store. But clever lockpickers like Jos Weyers and Christian Holler already are taking that DIY key-making trick a step further: They can 3-D print a slice of plastic or metal that opens even high-security locks in seconds, without even seeing the original key.
The article at the link also has this very informative gif a showing how a bump key works in a lock.
![]() |
Source: Wired
|
According to the logic employed by some critics of biometric technologies, this means locks opened using metal keys are useless now. I, for one, however, will not be contracting with any security guard services today. A fingerprint front door unlocker would be cool, though.
Tuesday, February 26, 2013
Which technology will revolutionize hotel room keys?
Hotels are already equipping their doors for the future — Examining technologies that can bring "non-stop check-in" to hotels at Hospitality Net.
The contenders:
Author Keith Gruen breaks down the pros and cons.
The contenders:
- Smartphone with app
- Traditional mobile telephone
- Universally programmable key (includes certain advanced house, office or car keys)
- PIN code
- 2-D barcode
- Fingers, hands or eyes (guests tend not to leave these items at home)
Author Keith Gruen breaks down the pros and cons.
Wednesday, December 12, 2012
Mobile biometrics
Mobile Biometrics: The Next Phase of Enterprise Authentication? (Network Computing)
Smartphones and tablets have the potential to become powerful platforms for enterprise authentication. By combining biometric capabilities such as a fingerprint reader or voice recognition software with mobile devices that users carry with them all the time, enterprises may be able to roll out two-factor authentication as part of an identity and access management (IAM) infrastructure.See also: Mobile Devices and Biometric Modalities
Friday, April 27, 2012
Well that makes more sense...
...Japanese "cardless" ATM's also use two pieces of additional information.
Scan Hand for ATM Cash, No Card Required (Discovery)
This post goes into some more detail about the impracticality of single factor biometric cash machines: Polish bank claims Europe's first biometric cash point.
Scan Hand for ATM Cash, No Card Required (Discovery)
First, Ogaki Kyoritsu Bank (Japanese site) customers will register their biometric information at a branch, according to Gizmag's Darren Quick. Then they'll be able to go to one of the new ATMs and get cash simply by scanning a hand and then typing in their birthdate and a four-digit PIN. [Emphasis added]Here's a recent article on the subject: Japanese biometric ATM reads your palm, tells fortune.
This post goes into some more detail about the impracticality of single factor biometric cash machines: Polish bank claims Europe's first biometric cash point.
Monday, February 20, 2012
Mobile Devices and Biometric Modalities
Smartphones and tablets combine the most powerful attributes of the networked computer and the cell phone, extending the web into every nook and cranny of the globe.
In one awesomely tiny package they facilitate data collection, storage and access to data stored elsewhere.
As a platform for near field communication (NFC) and SMS One-time passwords, mobile devices are also increasingly being used to deliver identity management applications by using a person's known possession of the device as a way of verifying their identity. In access control lingo, mobile devices are being used as tokens.
Using mobile devices is a dream come true for businesses that rely upon tokens: Your customer already owns it; If they lose it, they will be aware of the loss very quickly and they will replace it at their own expense; People are disinclined to lend their phone/credential to someone else; Etc.
Now to the question of securing the device itself and biometric modalities.
Fingerprints are currently the most frequently used biometric for overtly identifying cooperative, habituated individuals. They have a lot of things going for them. Fingerprints are well-understood scientifically, durable, reliable, and fingerprint ID management techniques have been shown to deliver high return on investment in many applications.
These are some of the reasons I lamented Motorola's announcement that it was leaving the fingerprint sensor out of the Atrix 2. The decision makes sense, though. The fingerprint sensor wouldn't be widely used until developers had written software using it, but including the sensor would drive up the cost of each unit for a thinly-used feature. The innovation chicken-and-egg problem is a real one and Motorola seems to have made the judgement that they weren't gaining enough of an advantage in the highly-competitive mobile device market by including it.
But that hasn't meant the end of mobile device biometrics. Just as businesses that issue tokens have been able to take advantage of the fact that their users are already carrying the necessary technology around with them, biometric identity management application developers are doing the same.
Mobile devices already contain the hardware required to deliver two biometric modalities: a camera for facial recognition and a microphone for voice. These modalities present challenges not usually associated with fingerprint biometrics — in the case of facial recognition challenges include lighting and the well-publicized photograph hack; for voice, background noise can be a problem — but they offer the advantage that the hardware is "free" and never going to be yanked out of mobile devices. That's quite an advantage, and it points to why face and voice biometrics are the front-runners for handset biometrics.
Nice and tidy, eh?
So, what to make of today's news that Fujitsu is set to compete more aggressively in the global handset market?
Fujitsu Aims for European Mobile Phone Market (Financial Times)
In one awesomely tiny package they facilitate data collection, storage and access to data stored elsewhere.
As a platform for near field communication (NFC) and SMS One-time passwords, mobile devices are also increasingly being used to deliver identity management applications by using a person's known possession of the device as a way of verifying their identity. In access control lingo, mobile devices are being used as tokens.
Using mobile devices is a dream come true for businesses that rely upon tokens: Your customer already owns it; If they lose it, they will be aware of the loss very quickly and they will replace it at their own expense; People are disinclined to lend their phone/credential to someone else; Etc.
Now to the question of securing the device itself and biometric modalities.
Fingerprints are currently the most frequently used biometric for overtly identifying cooperative, habituated individuals. They have a lot of things going for them. Fingerprints are well-understood scientifically, durable, reliable, and fingerprint ID management techniques have been shown to deliver high return on investment in many applications.
These are some of the reasons I lamented Motorola's announcement that it was leaving the fingerprint sensor out of the Atrix 2. The decision makes sense, though. The fingerprint sensor wouldn't be widely used until developers had written software using it, but including the sensor would drive up the cost of each unit for a thinly-used feature. The innovation chicken-and-egg problem is a real one and Motorola seems to have made the judgement that they weren't gaining enough of an advantage in the highly-competitive mobile device market by including it.
But that hasn't meant the end of mobile device biometrics. Just as businesses that issue tokens have been able to take advantage of the fact that their users are already carrying the necessary technology around with them, biometric identity management application developers are doing the same.
Mobile devices already contain the hardware required to deliver two biometric modalities: a camera for facial recognition and a microphone for voice. These modalities present challenges not usually associated with fingerprint biometrics — in the case of facial recognition challenges include lighting and the well-publicized photograph hack; for voice, background noise can be a problem — but they offer the advantage that the hardware is "free" and never going to be yanked out of mobile devices. That's quite an advantage, and it points to why face and voice biometrics are the front-runners for handset biometrics.
Nice and tidy, eh?
So, what to make of today's news that Fujitsu is set to compete more aggressively in the global handset market?
Fujitsu Aims for European Mobile Phone Market (Financial Times)
Fujitsu’s smartphones will certainly feature electronic money technology – enabling owners to use NFC, the mobile payment system – and biometric recognition to make their use as mobile wallets more secure.Fujitsu, more than any other handset manufacturer, is deeply involved in biometric sensor hardware (finger, palm) that doesn't currently reside on stock mobile platforms. So stay tuned.
Tuesday, November 15, 2011
Mobile Computing: Will Biometrics Replace Tokens?
Some ideas about how logical access control will evolve as mobile computing hits the government sector...
Are mobile devices already making PIV cards obsolete? (Government Computer News)
Are mobile devices already making PIV cards obsolete? (Government Computer News)
How will cards be accommodated on smart phones and other handheld devices?
Some industry observers think they won’t be; that the time of the PIV [ed: Personal Identity Verification] card has passed before it has been fully adopted.
“I think they will move away from the hardware requirements,” said Susan Zeleniak, group president of Verizon Federal. She predicted that authentication and authorization will be done via onboard biometric applications in handheld devices.
Thursday, May 13, 2010
Polish bank claims Europe's first biometric cash point
From The Independent (UK)
Could it be? Are token-less ATM machines now in use in Europe?
From day one, cash machines have required a token and a PIN. The token, a plastic card, identifies you to the banking network and the PIN confirms that the card is being used by someone who knows the account holder's password.
When the card is introduced into the machine, the banking network already knows the correct PIN that goes with the card. The computer network has only to answer one simple question: Does the PIN that goes with the card match the PIN that was just entered into the machine? If the answer is yes, the transaction is executed and the ATM user gets her cash.
In the case of the token-less ATM's described in the article linked above, it is less clear what is going on. Unlike the magnetized plastic card, fingerprints and PIN's don't store any account information so their use can't lead directly to a simple yes/no question for the bank software to sort out. So what is happening?
It's probably not the case that the bank customer puts their finger on a sensor and the bank software identifies the proper account from the finger alone to be confirmed later by the PIN. This would require the bank software to answer a yes/no question as many times as it has finger vein-enabled accounts every time someone uses the machine. Example: Does this finger go with account 1? If no, does this finger go with account 2? If no...
I suspect that, in order to dispense with the plastic card, the machine's software designers ask the user to input their PIN first. That would reduce the number of yes/no questions the software must answer in order to confidently establish a user's identity by a factor of 10,000 by allowing the software to search only from among accounts that use the same PIN. Given that there probably aren't very many consumer checking accounts that are finger-vein accessible, the customers of BPS SA aren't likely to notice any increase in the machine's response time over earlier cash machine models.
A system, such as the one described in the article, however, is likely to experience considerable growing pains. First, in order to serve other bank's customers and to reap the considerable fees to be charged in so doing, the machine must still support the old fashioned card-and-PIN model, adding to the costs of the machine by adding an input device to the older model (sensor/card reader/key pad vs. card reader/key pad).
Then, as the number of the bank's customers which use the finger-based method to access their account increases, the number of yes/no questions the software must sort through increases as well, slowing response time.
When my local bank adopts a finger-based system, I can start using the BPS SA machines while in Poland, correct? Not necessarily. If my bank uses the same Hitachi software that BPS SA uses, then things might work out, but if it has chosen another finger-based biometric vendor then things are unlikely to go well unless the banks involve a middleware vendor such as SecurLinx.
Over time and with the giant leaps in computing power implied by Moore's Law, applications like the one described in the linked article will be brought to the market improving the efficiency of the banking industry and improving the lives of people worldwide. Those days, however, are still in the future. The BPS SA case is probably best seen as a proof-of-concept experiment, rather than a full commercial deployment.
The exact same critiques could have been and probably were voiced when John Shepherd Barron, the inventor of the cash machine, first pitched his idea to Barclays way back in 1967. Kudos to BPS SA for blazing the trail.
Could it be? Are token-less ATM machines now in use in Europe?
From day one, cash machines have required a token and a PIN. The token, a plastic card, identifies you to the banking network and the PIN confirms that the card is being used by someone who knows the account holder's password.
When the card is introduced into the machine, the banking network already knows the correct PIN that goes with the card. The computer network has only to answer one simple question: Does the PIN that goes with the card match the PIN that was just entered into the machine? If the answer is yes, the transaction is executed and the ATM user gets her cash.
In the case of the token-less ATM's described in the article linked above, it is less clear what is going on. Unlike the magnetized plastic card, fingerprints and PIN's don't store any account information so their use can't lead directly to a simple yes/no question for the bank software to sort out. So what is happening?
It's probably not the case that the bank customer puts their finger on a sensor and the bank software identifies the proper account from the finger alone to be confirmed later by the PIN. This would require the bank software to answer a yes/no question as many times as it has finger vein-enabled accounts every time someone uses the machine. Example: Does this finger go with account 1? If no, does this finger go with account 2? If no...
I suspect that, in order to dispense with the plastic card, the machine's software designers ask the user to input their PIN first. That would reduce the number of yes/no questions the software must answer in order to confidently establish a user's identity by a factor of 10,000 by allowing the software to search only from among accounts that use the same PIN. Given that there probably aren't very many consumer checking accounts that are finger-vein accessible, the customers of BPS SA aren't likely to notice any increase in the machine's response time over earlier cash machine models.
A system, such as the one described in the article, however, is likely to experience considerable growing pains. First, in order to serve other bank's customers and to reap the considerable fees to be charged in so doing, the machine must still support the old fashioned card-and-PIN model, adding to the costs of the machine by adding an input device to the older model (sensor/card reader/key pad vs. card reader/key pad).
Then, as the number of the bank's customers which use the finger-based method to access their account increases, the number of yes/no questions the software must sort through increases as well, slowing response time.
When my local bank adopts a finger-based system, I can start using the BPS SA machines while in Poland, correct? Not necessarily. If my bank uses the same Hitachi software that BPS SA uses, then things might work out, but if it has chosen another finger-based biometric vendor then things are unlikely to go well unless the banks involve a middleware vendor such as SecurLinx.
Over time and with the giant leaps in computing power implied by Moore's Law, applications like the one described in the linked article will be brought to the market improving the efficiency of the banking industry and improving the lives of people worldwide. Those days, however, are still in the future. The BPS SA case is probably best seen as a proof-of-concept experiment, rather than a full commercial deployment.
The exact same critiques could have been and probably were voiced when John Shepherd Barron, the inventor of the cash machine, first pitched his idea to Barclays way back in 1967. Kudos to BPS SA for blazing the trail.
Subscribe to:
Posts (Atom)
