emerging biometric applications

36
Emerging Biometric Applications Expectations and Reality (in 25 minutes or less!)

Upload: shanae

Post on 08-Jan-2016

40 views

Category:

Documents


2 download

DESCRIPTION

Emerging Biometric Applications. Expectations and Reality (in 25 minutes or less!). An Emerging Technology. What are Biometrics?. The term biometrics refers to a science involving the standard analysis of biological characteristics. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Emerging Biometric Applications

Emerging BiometricApplications

Expectations and Reality(in 25 minutes or less!)

Page 2: Emerging Biometric Applications

An Emerging Technology

Page 3: Emerging Biometric Applications

What are Biometrics?

The term biometrics refers to a science involving the standard analysis of biological

characteristics.

A biometric is a unique, measurable characteristic or trait of a human being for automatically recognising or

verifying identity.

Page 4: Emerging Biometric Applications

Who are you?

No, who are you, really???

Page 5: Emerging Biometric Applications

Authentication Methods in Network & Internet Security

Something you areBiometrics Positive identificationNever lost or stolen

Something you knowPasswordsPINsMother’s maiden name

Something you haveATM cardSmart cardDigital certificate

Page 6: Emerging Biometric Applications

BiometricsInnate

IrisRetinaEarFingerprintPalm / handFace (visual & heat)Skin detail / veinsDNA / Blood / Saliva / anti-bodiesHeart rhythmFootprintLips

BehavioralGait

Signature

Typing style

MixedVoice

Body odour

Page 7: Emerging Biometric Applications

Why Biometrics?

“Biometric identification (e.g., fingerprints, face and voice) will emerge as the only way to truly authenticate an individual, which will become increasingly important as security

and privacy concerns grow.”

- Gartner Group 26th April 2000

Page 8: Emerging Biometric Applications

How do Biometrics Work?Enrolment: Add a biometric identifier to a database

Fingerprint, Voice, Facial or Iris

Verification: Match against an enrolled record

Presentbiometric

Capture Process Store

Presentbiometric

Capture Process

Compare

Match

IDENTIFIED

No Match

DENIED

Page 9: Emerging Biometric Applications

Fingerprint Image Identification

Page 10: Emerging Biometric Applications

Randomness

Page 11: Emerging Biometric Applications

Accuracy v. Affordability v. Acceptability

0

1

2

3

4

Accuracy >>

Aff

ord

ab

ility

>>

Courtesy, Veridicom Corp.

Page 12: Emerging Biometric Applications

Benefits for the Consumer

Page 13: Emerging Biometric Applications

Benefits of Biometrics

Biometrics link a particular event to a particular individual, not just to a password or token, which may be used by someone

other than the authorized user

Page 14: Emerging Biometric Applications

Business Scenarios

The password problem

Remote access

Who is using our fee-based web-site?

Challenge-response tokens

Too many physical-access devices

Protecting the single-sign-on vault

Page 15: Emerging Biometric Applications

The Password Problem

They’re either too easy or they’re written down somewhere!

Users forget them!

Help Desk has to sort out the mess!

Page 16: Emerging Biometric Applications

The Password Problem

Write it Down

47 28 8 16

% of respondents

Never Occasionally Often Always

Source: CCH

Page 17: Emerging Biometric Applications

The Password Problem

Resets per Year

4 62 29 5

% of respondents

Zero 1-2 3-6 > 6

Source: CCH

Page 18: Emerging Biometric Applications

The Password Problem

Identifiable costsLost productivityFlow-on productivity lossesSupport teamManagement and infrastructure

US research - $340 per incident*

Anecdotal – some incidents over $AU10,000

*BioNetrix Corp - www.bionetrix.com/inserts.pdf

Page 19: Emerging Biometric Applications

Choosing Technologies and Partners

Page 20: Emerging Biometric Applications

Privacy Concerns and Ethics

Criminal stigma3rd party use of data

Sold or given for other than intended purposeProvided to law enforcementUnauthorized access

Identity theft“Tracking” of actions through biometricsReligious objections - “Mark of the Beast”

Page 21: Emerging Biometric Applications

Australian Privacy Act

NPP 4 – Data Security

An organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access, modification or disclosure.

Page 22: Emerging Biometric Applications

Privacy Policy Recommendations

5 basic principlesNotice – disclose ALL data captured

Access –anyone can view their stored data

Correction Mechanism

Informed Consent – no 3rd-party involvement

Reliability & Safeguarding

Page 23: Emerging Biometric Applications

Who would use Biometrics

Strong identification and authentication

Medium – high data security

Non-repudiation (I didn’t do it!)

Page 24: Emerging Biometric Applications

Who would use Biometrics

The last metre

Fee-for-service web sites

e-Commerce transaction verification

Page 25: Emerging Biometric Applications

Selecting Biometric Technologies

User / environment considerations

Technology factors

Page 26: Emerging Biometric Applications

Technology ComparisonIris Face Finger Signature Voice

Accuracy Very HighMedium High High Medium

Ease of Use Medium Medium High High High

Barrier toAttack

Very High Medium High Medium Medium

UserAcceptability

Medium Medium Medium Very High High

Long TermStability

High Medium High Medium Medium

Interference ColouredContacts

Lighting Aging,Glasses,Hair

DrynessDirt,Age,Race

ChangingSignatures

Noise,Colds,Weather

Page 27: Emerging Biometric Applications

Accuracy

False rejection rateMeasures how often an authorized user, who should be recognized by the system, is not recognized.I am not recognised as me!

False acceptance rateMeasures how often a non-authorized user, who should not be recognized by the system, is falsely recognized.You are pretending to be me!

Page 28: Emerging Biometric Applications

Matching vs. Non-Matching Prints

Non-matchingprints

Matchingprints

MatchingThreshold

False non-matches False matches

d

Page 29: Emerging Biometric Applications

Selecting a Biometric Solution

Who can help?

Page 30: Emerging Biometric Applications

Your Vendor / Consultant

Existing relationship

Ability to integrate biometrics into existing platform

Ability to draw on other experience

Page 31: Emerging Biometric Applications

Australian Biometric Testing Organisation

Recently incorporatedImpartial testerEducation sourceGovernment & industry funded

www.biomet.org/[email protected]

“Introduction to Biometrics” 1-day course August 30th

Page 32: Emerging Biometric Applications

What problem are we solving?

If biometrics is the answer, what’s the question?

Page 33: Emerging Biometric Applications

Evaluation Strategy

Define the requirements

Testing & trialing

Management buy-in

Internal champion (not the IT Manager)

Page 34: Emerging Biometric Applications

Who is using it?

Connecticut Dept Social Welfare

Health Application

ABN-AMRO

Page 35: Emerging Biometric Applications

What are some of the products?

Page 36: Emerging Biometric Applications

Give Passwords the Finger!