Showing posts with label biometrics. Show all posts
Showing posts with label biometrics. Show all posts

Friday, August 8, 2014

Nice introduction to biometrics

Biometrics: New IDs that are uniquely you (Student Science)
Rapidly and accurately identifying people is useful. The police sometimes use biometric technology to ID criminals, disaster victims and missing children. Bank tellers may use biometrics to verify the identity of anyone attempting to withdraw money from an account. Because of the usefulness of biometric technology, governments are starting to include fingerprint and other biometric data in driver’s licenses, ID cards and passports.

Research on biometrics is advancing rapidly. Here we meet researchers behind three teams developing new ways to ID people.

Thursday, July 17, 2014

Wednesday, July 24, 2013

July tweet chat: Steria and their recent survey of European opinions on biometrics

When:
July 25, 2013 11:00 am EDT, 8:00 am PDT, 16:00 pm BST, 17:00 pm (CEST), 23:00 pm (SGT), 0:00 (JST)

Where:
tweetchat.com/room/biometricchat (or Twitter hashtag #biometricchat)

Host:
John at M2SYS

Guest:
Steria Group (Twitter: @Steria) will be discussing the results of a recent European survey on biometric technology they conducted which revealed that although many support the use of biometrics for criminal identification and for use in passports and identity cards, less than half of those surveyed were amenable to using the technology to replace personal identification numbers (PINs) in banking.

Topics:
  • Results of recent European biometric public acceptance survey
  • Convenience vs. security
  • USA vs. European view of how biometrics impacts privacy and civil liberties
  • “Passive” biometrics
  • How vendors can advance public education of biometrics
  • Viability of new biometric modalities
UPDATE and bump:
John has posted the questions for tomorrow's discussion:
  1. How do you explain the dichotomy between public acceptance of biometrics for identity cards or passports and the use of biometrics to replace personal identification numbers (PINs)?
  2. While we see “civil liberties” and “privacy” as one of the obstacles to wider use of biometrics in the US, is that the same thing you are seeing in your European survey?
  3. One of the dynamics that appears to be evident is that while people want to guard their biometric data, if they can get to the head of the line (e.g. Clear Me airport security program) they are willing to give up their biometrics.  Can you comment on how convenience and faster transactions might impact the more pervasive use of biometrics?
  4. Some country’s public sector organizations that have collected biometrics for a specific purpose are making them available for use by the private sector to prevent fraud, assure a person’s identity, etc.  Do you believe this is a trend we will see more of?
  5. How will “passive” biometrics like facial recognition, voice recognition and iris at a distance be accepted since it doesn’t require any specific actions by a person for it to be used?
  6. What strategies can biometric vendors deploy to help advance the public’s understanding of biometric identification that may help it to be more acceptable as a replacement for personal identification (PIN) numbers?
  7. What new or forthcoming biometric modalities (e.g. – heartbeat, thermal imaging, gait, DNA, etc.) do you predict has the best chance to become sustainable in the industry? Are there any specific modalities that you feel the public accepts more readily than others?

What is the BiometricChat:
Janet Fouts, at her blog, describes the format:
Twitter chats, sometimes known as a Twitter party or a tweet chat, happen when a group of people all tweet about the same topic using a specific tag (#) called a hashtag that allows it to be followed on Twitter. The chats are at a specific time and often repeat weekly or bi-weekly or are only at announced times.
There's more really good information at the link for those who might be wondering what this whole tweet chat thing is all about.

This one, the #biometricchat, is a discussion about a different topic of interest in the biometrics landscape each month. It's like an interview you can participate in.



More at the M2SYS blog.


Earlier topics have included:
Privacy
Mobile biometrics
Workforce management
Biometrics in the cloud
Law enforcement
Privacy again
Biometrics for global development
Large-scale deployments
The global biometrics industry
Biometrics markets


Modalities such as iris and voice have also come in for individual attention.

I always enjoy these. Many thanks to John at M2SYS for putting these together.

Monday, October 15, 2012

Playing it down the middle

Biometric ID advance ignites debate over rights (Trib Live)
Long envisioned as an alternative to remembering scores of computer passwords or lugging around keys to cars, homes and businesses, technology that identifies people by their faces or other physical features finally is gaining traction, to the dismay of privacy advocates.
A balanced article on the tension between biometric technology and privacy.

Tuesday, August 21, 2012

Of course, Biometrics are not evil.

Mike Elgan's recent article, Are biometric ID tools evil?, is really, really dumb (I almost said evil). It's either that or bordering on libelous so, I'll give it the benefit of the doubt, even though the piece doesn't extend the same courtesy to those of us working on biometric identity management technologies.

But maybe he didn't mean it. The title, after all, is a question, right? We'll read on.

It doesn't take much longer for the author to remove all doubt, as he rapidly moves from the rhetorical title to the "How often do you beat your wife?" formulation of the question:
How evil is biometric ID?
Followed by...
So we find ourselves in a strange position in which some religious conservatives and some secular liberal privacy advocates both agree that biometric identification is evil.
...
On the other, you have a large number of people who consider biometrics an unparalleled evil, and they will refuse to participate.
...
Who's right and who's wrong? Is biometric technology the answer to our security problems? Or is it just plain evil? [all emphasis mine]
Evil? Really? Not "a bad idea", "misguided", or "dangerous" — evil? 

Last I checked evil means "profoundly immoral and malevolent" and because most people gave up imputing moral qualities to inanimate objects sometime around the Bronze Age, the whole piece is either a really bad joke lacking a punchline or a shot at people — the people at every level of biometric development, from academia to enterprise — working to apply a new technology to the human challenges of identity management.

And why the fixation on "evil"?

Maybe "creepy" seemed too Jan Brady (and way played-out) and moral hyperbole is the new new thing.

Maybe it's a reference to what is perhaps the least ambitious corporate motto of all time: "Don't be evil."

One thing, however, is certain: someone really needs a thesaurus.


inconceivable_means_02
You keep using that word.

Thursday, August 16, 2012

Gartner Hype Cycle 2012

Gartner's 2012 Hype Cycle for Emerging Technologies Identifies "Tipping Point" Technologies That Will Unlock Long-Awaited Technology Scenarios (Gartner)

Biometrics feature prominently is several of the technology groups Grtner presents. Whether you're an old hand or hearing of the Hype Cycle for the first time, you'll want to click through and check it out.



Source: Gartner




The Peak of Inflated Expectations was frustrating. The Trough of Disillusionment was a grind. Now is the fun part.

Tuesday, August 14, 2012

Is Apple taking biometrics mainstream? Part 2

Apple's AuthenTec Buy Validates Biometrics, Valid Tech Says (IT Jungle)
Whatever Apple's plans are, the $356 million it's put on the table has already helped to "validate" biometric authentication as a whole, Faust says. "Biometric is absolutely the way to do authentication, because nothing else makes any sense," he says.
Part 1

Thursday, May 3, 2012

UK Political Process Yields Biometric Guidelines

Protection of Freedoms Act comes into force and lays out new laws on DNA retention and surveillance cameras (Out Law)

The new law touches upon CCTV, surveillance, fingerprints, DNA, schools, law enforcement, national security and sets guidelines for the proper handling of biometric information for different combinations of the above.

A new technology is never either entirely good or entirely bad, though by helping people to accomplish more with less effort, successful technologies will, by making the people who adopt them more productive, do more good than harm.

The UK's new law seems to strike a balance that attempts to allow people to capture the productivity gains offered by biometric technologies while mitigating the potential for the abridgment of individual rights either through abuse or unforeseen circumstances. This is as it should be.

The passage of the Protection of Freedoms Act is an important "Biometrics in Society" event and the Out Law article linked above does an excellent job of conveying its breadth.

Monday, April 30, 2012

National Level Biometric Deployment Trees & Forest

Though it's not my intention, I know it can seem like "All India, All the Time" around here. That's because India has set for itself the most ambitious ID management in human history, and therefore, India is providing more real world examples of the challenges inherent in very large scale biometric deployments than anywhere else. But India isn't necessarily unique in terms of the problems it is attempting to address with biometrics. All the BRICS (Brazil, Russia, India, China, South Africa), for example, face very similar challenges.

Forest and trees:
The information upon which blogs rely (the news articles below) provide great descriptions of individual trees. The four articles from the Indian press below can be seen as individual trees. The four sections in bold below the articles describe the species to which each different tree belongs.

The biometrics forest is made up of these, and more, species.

Examples:
I. Can Technology Fix India? (Dawn.com)
The dreams of modern India rarely make it to Rayagada. The Indians of these eastern forests forage for sago leaves and wild mango to survive. Barely a third can sign their names. Most live without electricity. Many have joined a Maoist insurgency fighting to overthrow the system.

Now, modernity is creeping in. Smart cards, fingerprint scanners and biometric identity software are transforming Rayagada into a laboratory to test a thesis with deep implications for the future of India: Can technology fix a nation?
Please click through to look at the pictures (and don't miss the comments).

As readers of this blog know, the short answer to the headline question is: No. Technology cannot fix India. ID management is about people. Biometrics can help (immensely!) with identity management challenges, but they cannot manage anything all by themselves.

II. Aadhaar card fraud exposes registration process errors (Times of India)
"The fraud proves that in a 100% Aadhaar-enrolled city like Hyderabad, 30,000 cards have been registered in a part of the city by exploiting those loopholes.
If:
♦ The Hyderabad population is 4,010,238
♦ The fraud number is 30,000 (article)
♦ 100% of Hyderabad is enrolled (article)

Then the rate of fraud is 0.0074 — less than 1%.

III. Identification of slum residents suspended (The Hindu)
The Chennai Corporation has suspended biometric identification of thousands of slum residents along 16 canals in the city, following stiff opposition from AIADMK councillors. The civic body had begun biometric identification of residents on slums near the Mambalam canal a few weeks ago, in order to issue smart cards, but AIADMK councillors opposed it, alleging that the list prepared by the previous DMK-led council had failed to include many actual beneficiaries. Once the biometric cards were issued, the residents of these slums were to be resettled.
I'm not even sure exactly what this is about but I have no doubt it's of significant local importance (I think it's about accounting for people who reside in areas we in the West would describe as "not Zoned Residential" so that they might be humanely resettled or legitimized as residents — such as when squatters are given title to their abodes).

IV. Persons Throng Aadhar Enrolment (Deccan Herald)


These four specifics are open to a more general interpretation.

I. The scale of the problems better ID management can help address
In the simplest terms, biometrics can really help people reduce the amount and severity of human suffering in their midst. What nobler aim can there be? Biometric Identity Management is about people.

II. Perfect is the enemy of Good
The proper metric for measuring biometric deployments is Return on Investment, not perfection. If half of the funds devoted to a current welfare program are stolen and a proposed biometric ID management system will be defrauded 10% of the time, what should you do?

III. Biometric technology is extremely flexible
Biometrics give talented and imaginative managers a tool that can be applied more problems than any one person can possibly comprehend.

IV: People want it.



Many (but obviously not all) of the posts here fall into one of the four categories above. India just happens to be providing a whole lot of examples.

Thursday, April 26, 2012

Uniqueness That Can't Be Duplicated

UIDAI: Banking on biometrics to give you a unique identity (Economic Times)
An overview of biometrics history and the rationale for applying it to India.

Friday, April 20, 2012

A Gimlet-Eyed View of the Biometrics Market

Biometrics more accurate, but uptake 'disappointing' (ZDNet Asia)
Ovum's senior analyst of IT solutions had a more scathing assessment of the overall biometrics industry. Andrew Kellett pointed out that while the biometrics market is mature and been around for some time, its development from a security and product usage perspective has been "disappointing".

Elaborating, he said while voice, facial recognition, and iris scanning can now be considered as mature technologies alongside fingerprint identification, adoption rate remains steady, rather than dynamic, and below industry expectation. Fingerprint readers, which can be used as a standalone device or incorporated within laptops, for one, continue to see slow uptake, he noted.
Read the whole thing.

Thursday, April 19, 2012

The findBIOMETRICS Newsletter is Out






findBIOMETRICS comes at the biometrics industry primarily through a focus on products and companies. They've been a great resource for a long time.

Wednesday, April 18, 2012

Securing Corporate Data in the Cloud: Biometric Logical and Physical Access Control

How to make information stored in the cloud robustly safe (The Guardian)

Most articles like this mention biometrics only in the context of physical access control at the data center, which is important. You don't hear as much about biometrics for controlling access to data stored in the cloud, though, and that's too bad because biometrics for logical access control could make the cloud a lot safer for businesses and their customers.

At a data center, physical access control prevents this (access to places)...

Image: Copyright Paramount

Logical access control is for this (access to information)...


...and tricking out data centers like Fort Knox, along with other logistical challenges ensures that there are a lot more of the latter than the former.

In networked logical access control solutions, the biometric sensor hardware is a part of the security. In the standard Username/Password regime, the hardware used, the keyboard, offers no additional security. With username/password authentication, a hacker needs only a keyboard to fill in the proper fields and she gains access to the network. If that username/password is a superuser or administrator credential, there's may be some turnover in the CTO function.

Biometric authentication is very different animal because with biometrics, the hardware layer does provide extra security. If the hacker steals a biometric or unencrypted biometric template (a long character string), she can't just type it in even if she finds the place in the programming that handles the template. The template resulting from a verification attempt is like a single use password created during the interaction of a physical object (body part) with certain known sensor.

For organizations using cloud services, requiring biometric authentication to authorize access to any database storing usernames/passwords should dramatically decrease the risk of high profile data breaches or other damaging hacks.

But even if every human account used biometrics for logical access control, some version of username/password verification will be around for a long, long time because username/password is a cheap, well-understood, flexible technology that supports certain access control models that biometrics does not. For one thing, people aren't the only things that claim an identity before accessing IT systems — computers do it, too, and they don't have biometrics.

The challenge that system designers now face is to identify where using Username/Password is too dangerous, and where biometrics can be used to reduce risk to an acceptable level. This requires identifying everything currently authenticated with a username/password and a determining which of these things are more efficiently protected using biometric authentication, then implementing the change. This is far easier said than done.

Requiring biometric verification of all human Administrator logins would be a good start, though. There aren't (or shouldn't be) that many of them. They are tech savvy, so they should be able to adapt to the new security environment quickly. They should have an understanding of why the extra step is worth the effort. It's their responsibility to keep the keys of the kingdom and they're the ones on the hot seat when the CEO is out apologizing to all and sundry following a data breach.

Friday, March 23, 2012

Not Just a Number

Mark Eardley starts with The Prisoner and Jefferson Airplane and concludes with the paragraphs quoted below. The entire piece is must-read material.

There are new horizons for identity and access management (ITWeb - South Africa)
Far from seeing the use of my biometric self as some Orwellian, Big Brother intrusion into the sanctity of my identity – which most people have anyway handed over to a more or less gimmicky variation on the dumber-than-dumb concept of a passcode – I consider it to be an accurate, respectful recognition of who I am and the access privileges and trust that I have earned.

As to those naysayers who seek to undermine the integrity and competency of modern biometrics, I suggest they reflect a little more deeply on the glaringly absurd inadequacies of cards, PINs and passwords – all of which are routinely forgotten, lost, shared and stolen.

Instead of regurgitating a lot of heavily-chewed myths about why biometrics are so flawed, isn't it perhaps time to talk to some of the local vendors that are running biometric-based systems that safely, securely and accurately control physical access for millions, yes millions, of people at thousands of South African companies?

Because these local biometric vendors have created in SA one of the world's largest and most diverse markets for a form of authentication that recognises people for what they are – people.
In the final analysis, identity management is about people. We say this all the time around here because we believe that it can't be said often enough. Recognizing this truth keeps us focused on the fact that if the systems we design don't work for the people who have to use them, they can't help organizations achieve their goals. If they don't work for everyone, they don't work.

Tuesday, January 31, 2012

New Group Formed to Engage Europeans on ID Technology

The European Association for Biometrics Wants to Drive the Use of Technologies Identifying People (MSNBC)
Nouak deems it insufficient to put biometrics on a level with security. In his view, the prime task of biometrics is to increase the comfort of security systems. "Because I have my biometric features with me at all times, there is no need for me to remember any codes, passwords or PINs and to take along keys or cards", says Nouak. "Biometrics can simplify our lives if privacy remains protected and the application corresponds to the required security level."

The non-profit EAB wants to bring together industry, regulators and user groups. For this purpose, it aims at founding a Europe-wide network, which will also discuss its experiences with representatives from politics and business. Moreover, the organization wants to be an independent contact point for interested parties and promote the training of biometrics experts. Joint training and research activities of EAB members are to be one focus of its work. The EAB will have its first appearance on the European stage at the European Biometrics Symposium in Brussels on February 17, 2012.
We wish the European Association for Biometrics much success.

It strikes me that a regional approach to engaging the public, government and business on the subject of biometrics is appropriate.

Democracies in Africa and Europe are adopting biometrics for better ID management, but they are doing so in response to a completely different set of stimuli and with very different sets of challenges. Within each region, however, the challenges faced by neighboring countries are remarkably similar.

Thursday, January 19, 2012

Biometrics and Biostatistics Revisited

[UPDATE: An uptick in recent articles like this one made me want to revisit this post. A quote from the article:
Ford showed off a prototype of this future health system, developed by BlueMetal Architects, at CES. The system will be able to capture biometric data from devices such as pacemakers and glucose monitors, and will also be able to accept voice input from the driver [emph. mine].
Maybe the term "biometrics" has a marketing cachet that "biostatistics" lacks; maybe for reasons of economy, journalists prefer to save ink, pixels, space and keystrokes. Whatever the reason, "biometrics" is a term that gets applied to every new application where technology is used to monitor or measure some aspect of the human body, its condition, motion or position. In being used to describe so many different things, "biometrics" has lost a great deal of precision of meaning.

DARPA has come up with another set of applications that some will be tempted to call biometrics (though DARPA doesn't call them that). DARPA is interested in collecting behavior metrics they call “cognitive fingerprints” or “human secrets” in order to develop an identity assurance model that relies on constant monitoring of an individual's unique behaviors while interacting with computer hardware.

Since...

Acta exteriora indicant interiora secreta; External actions indicate internal secrets

...maybe "actametrics" is a decent term for what DARPA's up to.

But you can see why (over)use of the term "biometrics" is so tempting. In this case, “cognitive fingerprint” and "human secret" is even more confusing than overusing "biometrics," and the folks at DARPA are geniuses that probably know their Latin scientific terms very well.

The original post, with minor edits, follows...]


We've danced around this topic a couple of times in the past (see links at the end of this post).

Biometrics and Biostatistics, the difference is subtle.

Biometric = body measure.
Biostatistic = body status, state, or condition.

[I'm no Latin scholar so I don't want to go to the mat for these definitions, but keeping them in mind helps me make sense of things when I read about all the uses for "biometrics" in health care and the health insurance industry. If there are any Latin (language) scholars out there who have interest and insight into this question, I'd love to hear from them.]

Biometrics for identity management concern facts about the physical human body that don't change (or don't change much) over time.

Biostatistics, on the other hand, are useful precisely because they change, sometimes radically over short or long time-frames.


Health care uses both biometrics and biostatistics. Health care providers use biometrics such as fingerprint and iris scanners for patient records management and logical and physical access control. They use biostatistics such as heart rate, weight, and EEG's, etc. for diagnostics, monitoring progress and assessing outcomes.

The Security sector is also seeking ways to use quantitative biostatistics to achieve better outcomes. I added the "quantitative" modifier because in many ways human beings have used non-quantified biostatistics (observations of behavior, for example) for security purposes since, well, forever. For example, we all know what someone means when they say that someone else was "acting suspiciously" or "looked guilty".

The computerized, measurement of biostatistics for security purposes, is at least as old as lie detectors. The novelty described by the article linked below is in bringing lie detectors out of the rigorously controlled laboratory environment and into more chaotic situations.

Face-reading lie detectors to be tested at UK airports (Airport-Technology.com)
The dual cameras in the system observe changes in facial expression and blood flow, with the first camera spotting signs of deceit such as lip-biting, nose-wrinkling, blinking and Freudian slips, and the second thermal imaging camera measuring flushing and blood-flow patterns around the eyes.


See also:
Behavioral Biometrics or Public Lie Detectors?
Mal-intent may be the future of security

Friday, November 4, 2011

West Virginia's Two Senators Tout the State's Biometrics Industry

Biometrics Industry Continues to Advance (WDTV News)
Video at the link.

Senators: Biometrics Industry Key to State’s Economic Future (The State Journal - West Virginia)

Sen. Jay Rockefeller:
"More and more, biometric companies from around the nation — and from all around the globe — are coming to West Virginia to do business," Rockefeller said. "West Virginia is a place where innovation and ingenuity, combined with a workforce that's second-to-none, are fueling economic growth."
Sen. Joe Manchin
"We're one of the best-kept secrets in the industry, but our little state is well-prepared and positioned as a national hub and a leader in the biometrics sector," Manchin said. "The word is definitely getting out—West Virginia is open for business and it's a great place to do business. I am certain that the biometrics industry will continue to look to our state as a partner in future ventures."