Alternative Technologies : Biometrics Thursday, October 5, 2000 Mik Emmerechts email@example.com
What you’re not being told about PKI • Security is only as strong as its weakest component • Are digital certificates really authenticating the user? • NO • Who is using your key? How do you protect it? • How secure is your hard drive? • If stored on a smart card, how attack-resistant is the card? • Why does this matter? • Non-repudiation • If your signing key has been certified by an approved Certificate Authority, then you are legally responsible for whatever that private key does
what you ARE (voice, face, fingerprint) what you KNOW (PINs, passwords) what you HAVE (keys, cards, tokens) What’s the solution ? • Extend authentication beyond the device/knowledge to include to user BIOMETRICS = The science of verifying an individual’s identity by means of personal characteristics such as voice, face and fingerprints.
How does biometric authentication work ? • Enrollment Process • Happens 1 time • Voice, face and/or fingerprint capture • Unique features (BioData) are extracted and stored on database or smart card for future reference • Verification Process • Happens every time • Live data is compared to reference BioData • User is accepted or rejected
How will digital certificates and biometrics be used ? • Rather than substituting traditional authentication means, biometrics will be complementary • Biometrics will unlock the digital certificate after positive biometric authentication PKI Digital Certificates Biometrics Tokens Smart Cards Passwords/Cards
What are the costs? • Approximately 3000 people every day contact credit card bureaus to report identity theft • Identity theft results in billions of dollars of fraud each year, and the numbers are climbing • The cost of resetting passwords is $150/user/year (based on help desk costs) • Can you afford not to explore the biometric authentication alternative?
Conclusion • Biometrics enhances security and privacy by extending authentication beyond the digital certificate to include the user • Biometric technology is … • Here today • Highly effective in protecting privacy • Convenient to the user • Affordable • 1-888-KEYWARE • www.keyware.com