To advertise, contact
Nathalie Akl
+971 4 2108520
nathalie.akl@itp.com
بالعربية
Where am I? Home /


BREAKING NEWS :

Is Biometrics the next big thing?

By Karel Rode on Monday, April 07, 2008


For many of us that have to prove some detail of who we are to a computer, a username and password is about as bearable as it can get.

Now we also have a slew of vendors that want us to rather replace this fact of some detail that we know (and hopefully remember) with something we physically are - a biometric component like a fingerprint, retina scan or voice print.

This all sounds like super spy or sci-fi stuff, but the reality is that these controls have reached a level of maturity that will make many of them enterprise-ready and cost-effective to deploy.

Still, there are some details to consider within the process of deploying a biometric solution. The fact is within a manual labour environment we will not be able to acquire a reasonable thumbprint all of the time, so a hand geometry scanner could be a more suitable solution. Moreover, the placement of such a device will be key to its ongoing success. Having a thumbprint reader at a high traffic area, for example in front of a lift shaft, may not be ideal, so the design of such solutions within the physical access control arena requires specialised resources.

In the logical access space, we now see many portable computing devices that ship with built-in thumbprint biometric readers. I have seen many of them utilised as a BIOS lock, where the machine will not boot successfully without presenting the correct thumbprint scan.
Story continues below
advertisement



Funny business

The level of comedy that could be associated with this outside of enterprise deployments is very high, with standalone users sometimes locked out of their own machines with little or no access recourse.

The fact is, in regard to larger deployments, we want users to strongly authenticate, we also want ease of use and we demand improved systems security. These are sadly all counterpoints to each other and business has to live within a fine balance. Moreover, having access to the ‘system' is not where the concerns stop.

Users that are properly authenticated also need access to various resources. These endpoints and applications should only be exposed to those users properly authorised to access these resources.

Therefore knowing who has access to systems is an important start, but ensuring that only authorised users can use these systems is a different matter. It is in this area where separation of duties and 'super user' access comes into the discussion.

High Expectations

The fact is, in regard to larger deployments, we want users to strongly authenticate, we also want ease of use and we demand improved systems security.

I have seen many instances of strong user authentication, most often with two-factor tokens, biometrics or digital certificates, where users gain access to systems from a remote location, and once they are logged into the enterprise they perform the functions as an administrator or root user, with no or very little auditing of their actions. This leaves the user exposed as 'plausible deniability' comes into play.

So I am of the opinion that IT systems secured with biometrics may have a business value proposition, if it is first clearly defined what the resources are that need to be protected. As an example: I use a strong credential to protect access to my machine, but by mounting the hard drive in another computer or by making use of a Linux boot disk, I can gain access to the core local data that is not encrypted.

At this phase I see it 'as a game' over that which you probably value the most in the form of data, confidential e-mail and more that could be available to an untrustworthy third-party.

This then brings us back to the strategy of defence in depth. Use the appropriate measure to protect that what is valuable. Do it in a way that will be meaningful and convenient to the user with the maximum payoff from an IT security point of view to the business.

Karel Rode is security solutions strategist at CA


User Comments (2 comments)

Voice Biometrics are convenient and secure
Posted by David Standig, Yardley, PA, USA on 6 May 2008 at 17:43 UAE time


Using voice biometric authentication gives the layer of security and convenience. There are companies providing Voice Verification services (e.g. VoiceVerified) which give the convenience and security so there is no counterpoint.
Hand Geometry verses Fingerprint
Posted by Jim Kerr on 7 April 2008 at 18:32 UAE time


"The fact is within a manual labour environment we will not be able to acquire a reasonable thumbprint all of the time, so a hand geometry scanner could be a more suitable solution."

Hand geometry solutions can be cost prohibitive and most modern fingerprint biometric solutions are not limited to only one appendage.
All posts are sent to the administrator for review and are published only after approval. ITP.net reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic.
Name *
( Remmber Me )
Email *
(Your email address will not be published)
City
Country
Subject *
Comment *
Security Code * Code
 


Please click post only once - your comment will not be published immediately.

Related Comment

Virtual machines need the same security and management considerations as real servers  

Related Feature

Part of the process

CIOs are facing an uphill struggle. More and more demands are being made of IT departments. Budgets are ever-tightening.... 

Related Feature

International Vendors

 


Competitions

Win this overclocked beast!

Ends On Saturday, 15 November 2008

If you’re looking to up your rig’s graphics grunt this is the competition for you, as our good friends at Asus have donated one of their excellent EN8800 GT TOP graphics cards for giveaway.


Advertising Features


Latest Products
Nero Burning Rom 8

Software | Applications | September 2008

The latest version of Nero's Burning ROM software is more functional than ever before.

RATING


Acer Aspire 6920g

Hardware | Notebooks | September 2008

Aspires to be a desktop replacement and largely succeeds.

RATING


BenQ DC X800

Hardware | Digital Imaging | September 2008

BenQ's DC X800 has the looks but does this snapper really have the 'X' factor?

RATING


Sony Cybershot DSC-H50

Hardware | Digital Imaging | September 2008

It's got the range for distant shots but do you have the ability to keep still?

RATING


Technology Jobs
Information Technology Manager
Location: Dubai, UAE
Account (Sales) Executive
Location: Dubai, UAE
IT Manager
Location: Dubai, UAE
System Analyst
Location: Dubai, UAE

For editorial enquiries contact
Mark Sutton
mark.sutton
@itp.com
To advertise, contact
Ahmad Bashour
+971 4 210 8549
or ahmad.bashour
@itp.com


Arabian Computer News Channel Middle East Channel Middle East - Arabic Charged CommsMEA Network Middle East Windows Middle East Windows Middle East - Arabic ALL ITP TITLES