...[C]ontactless palm vein recognition technology is nothing new and was first demonstrated back in 2002 and is widely used. It works by extracting feature data from biometric data. With previous technologies, confidential data was encrypted with this feature data, but when decrypting, the feature data extracted from biometric data would usually be matched with the encrypted data. This does not present a problem when used in a personal device, such as a laptop or smartphone, but when used via an open network such as in the cloud, a more secure decryption technology is necessary to prevent leaks of biometric data.The article discusses encryption within biometric templates using Fujitsu's palm vein technology, but the idea would seem to be applicable across biometric modalities.
Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts
Thursday, November 5, 2015
Biometrics + Cryptography
Keeping your passwords safely in the palm of your hand (electropages)
Wednesday, April 15, 2015
True cybersecurity requires a conceptual shift
The user knows nothing: Rethinking cybersecurity
This position — that the adversary knows your system as well as you do, if not better, as soon as it is stood up — while extreme, led to the creation of large number factorization, the basis for all modern encryption, from PGP to RSA tokens. Under these encryption schemes, as long as the key is kept private, someone can know everything about how the security system works and still not be able to crack it.Coincidentally, our CTO and I were having a conversation along these lines just yesterday. It's a thrill a minute at SecurLinx!
To get to a place of true cybersecurity, another stark innovation in thinking is needed. What is needed is an Inverse Shannon's Maxim: the user knows nothing.
Thursday, November 10, 2011
Protecting Biometrics on ID Documents
Spotlight on Entrust, its CEO and how they fit in to secure ID.
Putting a face and a fingerprint to a name (Daily Herald, Provo, UT)
Putting a face and a fingerprint to a name (Daily Herald, Provo, UT)
"We put a digital signature into the chip or the magnetic strip," Conner said in his Dallas headquarters office. "We encrypt and digitally sign all of the personal information that you provide so that it can't be tampered with."
The same is true for more than half of the passports issued by governments around the world.
Passports in six European countries and Malaysia have added biometric photos and fingerprints embedded by Entrust to foil counterfeiters. Saudi Arabia, Qatar and the United Arab Emirates use its encryption for their national identity cards, some with biometrics.
But the piece de resistance is an all-in-one smart card developed for Interpol so that its law enforcers can move seamlessly from one country to the next, get inside any of its worldwide facilities and securely hook up at even the most insecure public Internet kiosk or cafe.
Monday, October 24, 2011
Biometrics, Mobile Computing & Encryption
Are Biometrics the most Important Portable Feature? (ghacks.net)
When making decisions about security, individuals must determine the type of event they wish to secure themselves against. The more extreme the event, the more extreme the security precautions. More extreme security precautions are more costly: they're more expensive and they impose additional delays even upon the "good guys".
TPM architecture as described in the article is no different. It imposes manufacturing costs, slows down the computer's operation and is more subject to hardware failure. The market forces in mobile computing are telling manufacturers "make 'em cheaper and faster", not "make 'em more secure."
I predict, however, that the market segment represented by the article's author will grow.
My argument is that, certainly on laptops, ultraportables and netbooks, but also and perhaps to a slightly lesser extent, tablets, smartphones and even desktops, TPM chips should now be everywhere and encryption should be simple and intuitive if not completely automatic and seamless (as it is on some new high-end hard disks). The amount of data we all have and carry around with us now is incredibly valuable, not just to us but also to others. With the prices of TPM chips at an all-time low, I really can’t see why we’re not seeing ubiquity here in the way they are implemented.This article makes interesting and compelling points about mobile device security and how to radically increase the security of the data stored on mobile devices. This is a real issue and it's only going to become more pressing as more data is stored on more mobile devices.
When making decisions about security, individuals must determine the type of event they wish to secure themselves against. The more extreme the event, the more extreme the security precautions. More extreme security precautions are more costly: they're more expensive and they impose additional delays even upon the "good guys".
TPM architecture as described in the article is no different. It imposes manufacturing costs, slows down the computer's operation and is more subject to hardware failure. The market forces in mobile computing are telling manufacturers "make 'em cheaper and faster", not "make 'em more secure."
I predict, however, that the market segment represented by the article's author will grow.
Subscribe to:
Posts (Atom)