Breakthrough in biometric token replay

August 2003 Access Control & Identity Management

The RAU-Standard Bank Academy for Information Technology recently achieved a breakthrough in the replay of biometric tokens. One of the major problems of sending any biometric token over a network, and specifically a public network like the Internet, is that if the token is intercepted (sniffed), it can be replayed even if the token had been encrypted.

This possibility of replaying such a token, of course gives rise to serious risks, because the user cannot replace the token or choose a new one - the specific biometric token is uniquely linked to the user. If a user's right thumb biometric token is compromised he cannot choose another right thumb - the token is permanently compromised.

To date it was not possible to recognise a replayed biometric token as such. This is one of the main reasons why biometric tokens (fingerprints, iris prints, retinal prints, palm prints, etc) are not yet used as widely as the technology of biometrics deserves. The Academy's system, known as BioVault, aims to solve this inherent problem. A recent product demonstration showed how a biometric token, in this case a fingerprint, was sent over a network, and compromised by being intercepted (sniffed) during transmission without the knowledge of the user.

The intercepted biometric token was then replayed. When this sniffed token was replayed with BioVault switched off, the replayed (masquerading) token was accepted as an original. When BioVault was switched on, the replayed (sniffed) token was immediately rejected as a replay.

The RAU has taken out a provisional patent on the underlying algorithm used in BioVault. At least two advanced post graduate projects are presently active to thoroughly test the characteristics of BioVault, and then to expand its use.

For more information contact Prof Basie von Solms, RAU, 011 489 2843, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Defending against SIM swap fraud
Access Control & Identity Management
Mobile networks must not be complacent about SIM swap fraud, and they need to prioritise the protection of customers, according to Gur Geva, Founder and CEO of iiDENTIFii.

Read more...
Access Selection Guide 2024
Access Control & Identity Management
The Access Selection Guide 2024 includes a range of devices geared specifically for the access control and identity management market.

Read more...
Biometrics Selection Guide 2024
Access Control & Identity Management
The Biometrics Selection Guide 2024 incorporates a number of hardware and software biometric identification systems aimed at the access and identity management market of today.

Read more...
Smart intercoms for Sky House Projects
Nology Access Control & Identity Management Residential Estate (Industry)
DNAKE’s easy and smart intercom solution has everything in place for modern residential buildings. Hence, the developer selected DNAKE video intercoms to round out upmarket apartment complexes, supported by the mobile app.

Read more...
Authentic identity
HID Global Access Control & Identity Management
As the world has become global and digital, traditional means for confirming authentic identity, and understanding what is real and what is fake have become impractical.

Read more...
Research labs secured with STid Mobile ID
Access Control & Identity Management
When NTT opened its research centre in Silicon Valley, it was looking for a high-security expert capable of protecting the company’s sensitive data. STid readers and mobile ID solutions formed part of the solution.

Read more...
Is voice biometrics in banking secure enough?
Access Control & Identity Management AI & Data Analytics
As incidents of banking fraud grow exponentially and become increasingly sophisticated, it is time to question whether voice banking is a safe option for consumers.

Read more...
Unlocking efficiency and convenience
OPTEX Access Control & Identity Management Transport (Industry)
The OVS-02GT vehicle detection sensor is the newest member of Optex’s vehicle sensor range, also known as ‘virtual loop’, and offers reliable motion detection of cars, trucks, vans, and other motorised vehicles using microwave technology.

Read more...
Protecting our most vulnerable
NEC XON Access Control & Identity Management Products & Solutions
In a nation grappling with the distressing rise in child kidnappings, the need for innovative solutions to protect our infants has never been more critical. South Africa finds itself in the throes of a child abduction pandemic.

Read more...
Understanding the power of digital identity
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
The way we perceive business flourishing is undergoing a paradigm shift, as digital identity and consumer consent redefine the dynamics of transactions, says Shanaaz Trethewey.

Read more...