Breakthrough in biometric token replay

August 2003 Access Control & Identity Management

The RAU-Standard Bank Academy for Information Technology recently achieved a breakthrough in the replay of biometric tokens. One of the major problems of sending any biometric token over a network, and specifically a public network like the Internet, is that if the token is intercepted (sniffed), it can be replayed even if the token had been encrypted.

This possibility of replaying such a token, of course gives rise to serious risks, because the user cannot replace the token or choose a new one - the specific biometric token is uniquely linked to the user. If a user's right thumb biometric token is compromised he cannot choose another right thumb - the token is permanently compromised.

To date it was not possible to recognise a replayed biometric token as such. This is one of the main reasons why biometric tokens (fingerprints, iris prints, retinal prints, palm prints, etc) are not yet used as widely as the technology of biometrics deserves. The Academy's system, known as BioVault, aims to solve this inherent problem. A recent product demonstration showed how a biometric token, in this case a fingerprint, was sent over a network, and compromised by being intercepted (sniffed) during transmission without the knowledge of the user.

The intercepted biometric token was then replayed. When this sniffed token was replayed with BioVault switched off, the replayed (masquerading) token was accepted as an original. When BioVault was switched on, the replayed (sniffed) token was immediately rejected as a replay.

The RAU has taken out a provisional patent on the underlying algorithm used in BioVault. At least two advanced post graduate projects are presently active to thoroughly test the characteristics of BioVault, and then to expand its use.

For more information contact Prof Basie von Solms, RAU, 011 489 2843, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The future of security: intelligent automation
Access Control & Identity Management AI & Data Analytics IoT & Automation
As the security landscape evolves, businesses are no longer looking for stand-alone solutions, they want connected, intelligent systems that automate, streamline, and protect.

Read more...
Smart automation is changing security
SA Technologies IntelliGuard Access Control & Identity Management
Security has come a long way from manual check-ins, logbooks, and standalone surveillance cameras. With the rise of intelligent automation, security is now faster, smarter, and more connected than ever.

Read more...
The future of security in South Africa
ATG Digital Access Control & Identity Management
Security technology is evolving rapidly, but is local innovation keeping pace? Some global players recognise the potential of South African products for international markets, but can our manufacturers and service providers thrive without external support?

Read more...
Integration enhances estate access control
Access Control & Identity Management
With one-third of residential burglaries starting at the front door, the continued seamless integration of Glovent’s estate management platform with Impro access control software is welcome news for estates.

Read more...
T&A in South Africa’s retail sector
ERS Biometrics Access Control & Identity Management
Using existing systems, ERSBio provides a practical and more cost-effective way for businesses to manage operations, reduce payroll mistakes, and enhance overall efficiency through innovative T&A processes.

Read more...
Navigating the complexities of privileged access management
Editor's Choice Access Control & Identity Management
Privileged Access Management and Identity Access Management are critical pillars of modern cybersecurity, designed to secure access to sensitive resources, enforce principles like least privilege, and implement just-in-time access controls.

Read more...
Paxton opens second experience centre
Paxton News & Events Access Control & Identity Management
Security technology manufacturer, Paxton, has opened a new experience centre in Cape Town on 12 February in partnership with its exclusive distributors, Reditron and Regal Security.

Read more...
DoorBell with built-in AI
Ajax Systems Access Control & Identity Management Products & Solutions Smart Home Automation
Ajax Systems has announced the release of Ajax DoorBell, which features built-in AI, an IR sensor, and app control, seamlessly integrating into the Ajax ecosystem to ensure efficiency and security confidence.

Read more...
Physical security evolving beyond security teams
ATG Digital Access Control & Identity Management
The landscape of physical security is undergoing a major shift. Traditionally, selecting access control and visitor management solutions fell squarely on the shoulders of security professionals, but today includes legal, IT, technical operations and more.

Read more...
A passwordless future?
Access Control & Identity Management
The digital landscape is evolving rapidly, and with it comes the urgent need for more secure authentication methods. Passwords, once the cornerstone of online security, are now easy targets for cybercriminals.

Read more...