Tomorrow's Transactions » identity authentication technology government http://tomorrowstransactions.com Thought leadership from Consult Hyperion Wed, 10 Sep 2014 20:33:30 +0000 en-US hourly 1 http://wordpress.org/?v=4.0 Travel advisory http://tomorrowstransactions.com/2010/03/travel-advisory/ http://tomorrowstransactions.com/2010/03/travel-advisory/#respond Tue, 02 Mar 2010 20:27:38 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/03/travel-advisory/ As has been discussed many times before, the current e-passport is a complement to the physical passport: that's why it's a chip inside the passport, not a chip instead of a passport BAC locks the passport so that you have to physically read the passport MRTD in order to read the data from the chip (this is not strictly true, by the way, because the MRTD data isn't random, but that's a detail). ... Note, incidentally, that while the UK is outside the Schengen area, the UK biometric resident permit is an EAC-compliant contactless product (don't be fooled by the contact plate on it) and the UK version of the UK National ID card -- there are two: the non-UK citizens version and the UK citizens version, because national ID cards are travel cards in the EU so the non-UK citizen version doesn't have -- is also an EAC-compliant travel document.

The post Travel advisory appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] When we think about electronic identity, we tend to think in terms of the identity structures that we are familiar with from the physical world, so we talk about passports and borders. But the current system of passports, visas and border controls doesn’t work terribly well — see the discussions ad infinitum about the recent Dubai death squad’s comedy disguises and simple faked passports — so I’m not sure it’s much of a basis for exploration. Why do I say this? Well, because I’ve been to a few presentations about the various systems involved recently and have been trying to understand some of the dynamics to help our customers develop some longer-term strategies around identity.

One of the problems is that there is so much going on. Start with moving on from SIS. The SIS2 (Schengen Information System 2) will store biometrics to prevent visa fraud. After a three year transitional period, SIS2 must check with the new Visa Information System (VIS). VIS will require fingerprints and these will be matched via AFIS (so that if, say, a Moroccan person applies for visas in both French and German consulates then this will be known). The fingerprints are currently kept for five years. The Central VIS will connect via a new secure network (S-TESTA) to the national VIS systems and these national systems are connected in turn to the national consulates overseas. Are you with me so far?

What’s the point? Well, it’s so that when a non-EU person applies for a visa in Schengen country, the details will be passed up to the central system and then they will be checked when the passport is presented at Schengen border control. The purpose of all this is to defeat a common immigration fraud, which is that a bona-fide Chinese businessman (say) gets a visa to come to a Schengen country, and gives it to someone else. That person enters Schengen and then sends the passport and visa back to China by DHL. The next Chinese person enters Schengen, and then posts it back again… Will SIS2 fix this? Surely the problem will shift to the feeder documents. It’s impossible to imagine that an EU consulate somewhere can accurately verify and validate passports from 196 countries, but let’s put that to one side for a moment. There are plenty of people who think that SIS will end up causing more problems than it is solving.

The number of computers with access to the Schengen Information System has doubled to 500,000 thanks to the extension of the EU.

[From Half a million PCs can access Schengen's 'secure' database • The Register]

Since half a million PCs around Europe can access the system, that means that to all intents and purposes everything on the system is public.

Statewatch, a group that monitors civil liberties in Europe, said it was aware of a case in Belgium where personal information extracted from the system by an official was sold to an organised criminal gang.

[From 500,000 EU computers can access private British data | Technology | The Observer]

There’s another system coming online as well, the Euro Border Surveillance System, or Eurosur. This aims to reduce illegal migrants entering EU by sea, particularly aimed at Mediterranean). Good luck on that one. Spain has had some positive results from using satellite tracking (positive in the sense that the immigrants go to Italy instead) but I’m sure Eurosur will help further.

Then there’s the new e-passport. As has been discussed many times before, the current e-passport is a complement to the physical passport: that’s why it’s a chip inside the passport, not a chip instead of a passport. Almost everywhere you go in the world, the chip is not used, but in the future it may be. There’s security, naturally. The e-passports have Basic Access Control (BAC), which we’ve also discussed before. BAC locks the passport so that you have to physically read the passport MRZ in order to read the data from the chip (this is not strictly true, by the way, because the MRZ data isn’t random, but that’s a detail). Extended Access Control (EAC) is the next step: for one thing, it stops people from cloning the chips. But it adds additional functionality as well so, from 28th June 2009, member states have been required to issue EAC e-passports only.

Back to the difference between the chip and the book. If the e-passport is going to store data that isn’t on the passport (eg, your fingerprints) then these must be encrypted so that they can only be read by authorised authorities. An EAC passport will therefore only give up data to readers that it can authorise through the use of asymmetric cryptography (the reader must present a certificate signed by a recognised authority) and the passport can then encrypt and sign its own data. There’s something called Active Authentication as well, so the e-passport contains a key pair: the secret private key and the not secret public key (which appears in Data Group 14, DG14, in the data).

Unfortunately, shifting to EAC adds complexity because there are now two trust chains: the data trust chain (so that the readers can verify the passport data) and the terminal trust chain (so that the passport can verify the reader data). You can imagine that co-ordinating both of these chains across the globe has turned out to be something of a problem: every reader has to have every valid certificate from every country in it. The Brussels Interoperability Group (BIG) is responsible for harmonising the e-passport specification throughout the EU and has also been responsible for the certificate policies, protection profiles, conformance tests and interoperability tests. At ID World, Bob Carter from IPS said that the most difficult job was trying to work out how to exchange certificates between countries and he is, of course, right. One thing that is not yet in place is the protection profile from readers (a lesson from chip and PIN deployment in the UK: there’s no point having secure chips and wholly insecure readers).

It would be nice to be able to set a date when we might move to a wholly e-passport world, but to get there we have to get rid of visa stickers. There’s a name for this too: ESTA (Electronic System for Travel Authorisation). If this could be achieved, then there is no need to have manned border control, since introducing people into the loop could not improve the system in any way. This is a very appealing prospect to governments, but I think there is a real concern here: if a criminal is able to get a legitimate visa certificates, smart card, e-stamp or whatever else and is never questioned by a human security official, then once they are inside the perimeter they can operate with impunity.

Look, passports are a very special case of an identity document. Because of international obligations, we can’t just do what we want with them. Fair enough. But should they be at the heart of electronic identity for the 21st century? Should we be designing ID cards that are an electronic emulation of this existing system?

Without going into too much details, I believe the objective is to mimic the modern identity that revolves around photo IDs (passport, driving license, student card etc) in our online identity transactions.

[From Bringing identity home : Media Influencer]

There’s something else being mimiced here. Why the discourse on BAC/EAC? Well, the UK version of the UK National ID card — there are two: the non-UK citizens version and the UK citizens version, because national ID cards are travel cards in the EU so the non-UK citizen version doesn’t have the travel version — is also an EAC-compliant travel document. It has a contact plate on it, a contact plate which is not connected to anything (technically, there is no answer-to-reset, or ATR, via the contact interface). As I’ve mentioned before, this is a “Potemkin” plate, purely for show, intended to impress political masters, but actually useless. It has only contactless functionality, and the only contactless functionality is has is the e-passport. That’s all it is.

Potemkin Card.png

Surely it would have saved a lot of money to have just printed a picture of a shiny gold contact plate on the back of the card somewhere? Hence my suggestion to some policy wonks (I’m sure they won’t be offended by the description, since that what they called themselves) that when the incoming administration scraps the ID card scheme — but finds itself unable to scrap the systems, because systems integrators have contracts that will cost a fortune to terminate — they stop calling these “ID cards” and start calling then “Passport Plus’ (the non-UK citizen version without the travel functionality — so, in other words, with no functionality at all — can be called “Passport Minus”). That way, everyone’s happy, except for taxpayers.

Passports are a travel document: let’s leave them to that physical world and stop using them as a paradigm for identity management in the online world.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Travel advisory appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/03/travel-advisory/feed/ 0
Trans-mission http://tomorrowstransactions.com/2009/12/trans-mission/ http://tomorrowstransactions.com/2009/12/trans-mission/#respond Thu, 03 Dec 2009 22:22:19 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2009/12/trans-mission/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post Trans-mission appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Should people be allowed to have “anonymous” prepaid mobile phones (well, SIMs) or not? It’s a simple question, but a complicated subject. And it’s worth exploring because it helps us to have a real, focused discussion about practical privacy and security issues. The subject came up because of one of the current hot topics in the UK, which is the government’s proposed “crackdown” (although “crackup” might be a better description) on the authorised copying of copyright material. Once the government has disconnected most broadband users in Britain through the “three accusations and you’re out” policy, many desperate internet addicts will be driven to using mobile connections to continue online banking, reading about “I’m a celebrity get me out of here” behind the Murdoch paywall and playing World of Warcraft. At which point, the mobile operators will come under pressure to start disconnecting people as well. But as the always spot-on mobile industry analyst and Forum friend Dean Bubley notes

“On one hand, the government’s trying to encourage internet connectivity — bridging the digital divide — but a lot of people in lower socioeconomic groups are on prepay, and the vast majority are anonymous,” Bubley said

[From Mobile industry 'cannot identify pirates' - ZDNet.co.uk]

So the mobile operator won’t be able to turn over the name and address of the supposed copyright pyrate. When the letter from Apple Corporation arrives at Vodafone asking them to turn over the name and address of the person who downloaded “Love Me Do”, Vodafone won’t be able to tell them (so presumably Vodafone will then be found in contempt of court or something and their internet access will be turned off).

So what to do? Well, one approach (followed in many countries) is simply to force all prepaid phones to be registered with the authorities. In the UK, the government might use its splendid new national identity register, for example, to ensure that all prepaid phones have a passport or national identity card connected to them them. And, as in Spain, take immediate action against those terrorists, money launderers, child pornographers and criminals who refuse to do so.

Spanish mobile operators last night cut off an estimated three to four million pre-pay mobile phones whose owners had not followed government instructions to register their devices.

[From Spain cuts off 3m pre-pay mobiles • The Register]

I can see exactly why law enforcement and government agencies object so strongly to anonymous mobile phones (although they still allow people to post letters anonymously) but I think they are wrong to react in this way. The truth is, the criminals will just use other peoples’ phones and will be even harder to track and trace than they were before.

Consider the most prosaic of examples. Where I live, in a deprived part of Europe called “Surrey”, a window in the house opposite to ours was smashed by a gang of feral youths. Sadly, we didn’t see this happen so we unable to assist the local constabulary. But suppose I had seen it happen? I have, currently, four prepaid mobile phones about my person (they are used for various demos and experiments for work) so I would have just picked up one of these phones and called the police with the details of the incident and a description of the yobs.

But now suppose that my prepaid phones were now connected to me through the national identity register? Now there’s no chance that I will pick up one of them and report the crime, because I’d be worried that my name and address would get (via the police or the database) to the gang in question.

This may be a silly example, but from battered women to corporate whistleblowers there are plenty of good reasons for allowing anonymity. We need this to be part of the infrastructure.

All this does prove, though, that there is a legitimate place for digital anonymity, and I hope that any identity management system required by the US government and others will allow anonymity and not prevent it.

[From Tech and Law: Technology, domestic violence, anonymity]

Note the important qualification here: there is a legitimate place for “digital anonymity”. I would go further than that and say that without digital anonymity, we are creating the wrong kind of infrastructure for a successful and prosperous society. Now, your web site may choose to allow or decline access by digitally known, pseudonymous or anonymous identities. If you are a web site discussing Iranian democracy, you may well insist on the latter. If you are government department, you may insisit on the former. The infrastructure must cope with both.

The example of prepaid mobile phones may well be one of those cases where the simple, “common-sense” response is just plain wrong. Here’s what I mean. Suppose that I am a terrorist. The police tap my mobile phone and hear that I am discussing blowing up Parliament (not an entirely unlikely contingency if I happen to be listening to Radio 4’s Today programme at the time). Now, because my mobile phone is anonmyous.

Now take the other case: mobile phones are not anonymous. So I will simply kill someone and steal their phone, or I will pay some witless dupe to get a phone for me. You won’t stop me from getting the phone, although you will cause me to commit more crimes. Or I’ll just carrying on using the phone but call a redirection box, or use a code when I’m speaking, or whatever.

There are circumstances where forms of anonymity are social goods, and I think I will make it one of my missions for 2010 to try and help to spread the word on this: anonymity isn’t a bad thing. On the contrary, sometimes it is desperately important. But why is it so hard to spread this meme? I wonder if it might be because the digital model of anonymity has at its core an active concept of privacy: you don’t remain anonymous by being ignored but by actively being anonymous, if you see what I mean.

Digital immigrants tend to think about privacy as the ability to conceal information from others. Digital natives instead share information within certain contexts, and with granular privacy controls on that information.

[From Is Online Privacy a Generational Issue? | GeekDad | Wired.com]

I’m involved in some customers meetings looking at new proposition in the identity field over the next few days and these will give me an opportunity to think through these issues in a more commercial context, so I will be bck posting on this key topic again soon.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Trans-mission appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2009/12/trans-mission/feed/ 0
Air side http://tomorrowstransactions.com/2009/11/air-side/ http://tomorrowstransactions.com/2009/11/air-side/#respond Mon, 09 Nov 2009 18:20:04 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2009/11/air-side/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post Air side appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] The whole business of air travel is a laboratory for experimenting at the boundary between public and private identities, where national and international agreements interact with corporate alliances, outsourcing and value chains to produce a complex environment that needs and benefits from change. Speaking as a frequent traveller, and happy near-weekly user of Heathrow’s Terminal 5, it seems to me that air travel has got considerably quicker, more efficient and simpler in the last couple of years. I print my boarding pass out at home, jump in a cab or on the train, nip through T5 to the lounge and then on to the plane — the only hold-up in the whole process is the queue for security on the way out (sometimes this can be 10-15 minutes even at T5) and the queue for passport control on the way in.

However, the need to print a physical boarding pass, even using 2D barcodes rather than a magnetic stripe, and the lack of an efficient bag drop system means that despite the universal electronic ticket for air travel, more than two-thirds of passengers still went to a check-in desk. Where to look for the next improvement? Well, I’m sure like most people I think that the key technology that will change this is the mobile phone. If the mobile phone allows you to check in and obtain a boarding pass, and a kiosk at the airport allows you to self-tag (clearly there are some security issues around this) then the flow through airports would increase significantly and the costs would reduce accordingly.

In fact I saw a presentation for one of the companies that supplies infrastructure to airports recently an they were talking about their experiences with the mBCBP (mobile bar code boarding pass) — they said that “we only care about Blackberry, iPhone and high-end smartphones”, which means we can assume big, clear screens — but still the current 2D barcode solutions don’t carry enough data for the airlines to store more than three legs plus frequent-flier and other data.

So why am I looking at this space? One of the biggest players in the industry, IER, is advocating the “pass & fly” sticker solution and I saw them present on the Air New Zealand and Air France case studies which, I have to say, was rather impressive.

As we have discussed repeatedly over at the Digital Money Forum, there are many organisations who can see the consumer pull for contactless solutions and the consumer excitement around these contactless solutions when linked to the mobile phone. The mobile industry (by which I mean the combination of handset manufacturers and operators) has messed around to the point where they have driven people to seek alternative solutions and stickers are emerging as the favourite. Less functional than NFC, for sure. Bypassing the handset manufacturer and the operator, absolutely.

I see that yet another step in this direction was taken last week when Twinlinx (who make an NFC sticker with a Bluetooth interface) announced they are working closely with Inside (the founder of Twinlinx came from Inside):

INSIDE Contactless, a leading provider of advanced, open-standard contactless and near field communication (NFC) chip technologies, and TWINLINX, an innovative market entrant providing NFC technology platforms and applications, today revealed they are working together on the integration of INSIDE`s secure components in the TWINLINX MyMax NFC sticker, and are cooperating to gain type approval from major bank card brands.

[From INSIDE and TWINLINX Team On MyMax NFC Sticker | Reuters]

To be honest, I’m unconvinced about the “fancy sticker” approach. I think simple stickers, which do not connect with the phone at all, are adequate to get new businesses off of the ground in preparation for NFC in the handset, whereas the cost and complexity of loading software into connected stickers, while adding obvious functionality, may well outweigh the short term gains. But I may be wrong. In any case, the market is evolving, and the nexus of contactless interface and mobile phone must remain central to the ID management roadmap.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Air side appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2009/11/air-side/feed/ 0
Another model that the UK could try http://tomorrowstransactions.com/2009/10/another-model-that-the-uk-could-try/ http://tomorrowstransactions.com/2009/10/another-model-that-the-uk-could-try/#comments Tue, 13 Oct 2009 18:18:16 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2009/10/another-model-that-the-uk-could-try/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post Another model that the UK could try appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] I’m going provide a case study on the use of multi-application smart cards with EMV “chip and PIN” software on them that I think contains some useful nuggets for us in the UK to ponder over, because the case study is about combining payment (EMV) and digital signature (PKI) applications on the same card.

Identity folks will have to understand a little about the payment folks’ EMV standard to understand the dynamics. There are actually three flavours of EMV, the international card scheme standard for chip transactions. These are Static Data Authentication (SDA), Dynamic Data Authentication (DDA) and Combined Data and Application Cryptogram (CDA). Most of the cards out on the streets in the UK are SDA cards without enciphered PIN (the PIN is not encrypted from the PIN pad into the card).

SDA cards are cheapest, which is why our banks issue them, but they can be cloned and used in terminals that are offline, so they are a security risk. DDA cards are not vulnerable in this way, but they are more expensive, both because the cards are more sophisticated — they have a cryptographic co-processor to handle asymmetric cryptography and take longer to “personalise” — but UK banks will have to replace SDA with DDA by end of 2010 (indeed, Consult Hyperion work with banks to help them to migrate in a cost-effective way). CDA cards cost the same as DDA, but still need to be planned for.

For technical reasons, CDA cards are more secure than DDA cards. Why? Because CDA protects against the “wedge attack”. It is possible to insert a device that would let a genuine DDA card generate a legitimate digital signature but then intercept the request for an application cryptogram and return a bogus one for a different amount to the terminal. The terminal would carry on regardless. This is not possible with CDA since both the DDA signature and cryptogram are delivered by the card at the same time.

OK, so all this is well-known, but why does it matter to the digital ID world? Well, if a bank goes to the expense of issuing DDA or CDA cards, then the presence of re-usable cryptographic software and the cryptographic co-processor mean that it is a minimum of cost and complexity for the card to carry an additional PKI application as well as the EMV application. Almost all of the PKI application’s “guts” are already on the card because they are used by the EMV application. What’s more, the card can generate its own key pairs (which is very good for security) and then, provided you have the infrastructure, third parties can sign the card’s public key(s) to create a wide variety of public key certificates to deliver interesting services. The card can store these certificates if it has enough memory or store pointers to the certificates online somewhere if it doesn’t.

Here’s a real example.

Brazil is one of those markets that we need to pay attention to. They’ve had an ambitious national PKI programme running for a while and are committed to online services and e-government. It’s also growth market for payments, a potential battleground between bank-led and mobile-led money transfer, a laboratory for agent-based banking and a major influence on the rest of Latin America as well as being a huge market in its own right. So I’m always curious to see how things are developing there.

Banrisul is the largest bank in the south of Brazil, with over 3m customers, 3000 ATMs and 100,000 POS terminals. A few years ago, they decided to migrate their payment cards to EMV (the terminals in Brazil have mostly been upgraded already — the last couple of times I’ve been there I used my UK chip and PIN cards without a problem) and, unlike a great many other banks, they decided to do it properly. They decided to issue CDA cards with enciphered offline PIN. So then they began to look around for other applications that they could put on the same card to make it better, deliver new services, reduce churn or whatever might help with the business case.

Meanwhile, back in 2001, the government of Brazil started developing a national PKI (ICP in Portugese) and had created a national CA together with the legal infrastructure needed to make it all work. About 2m national certificates have already been issued (in total, I mean, not to Banrisul customers) and these are mainly used filing tax returns (about 20m so far).

Brazil has entered the 21st century making clear choices with regard to some core technological matters and reflecting these choices in an objective political framework… The choices were for an authentication technologies framework based on a national public key infrastructure in which the public and the private intertwine…

[From Three Cheers for João-de-Barro at Marcelo Thompson]

The states began to develop their own CAs and RAs (AC and AR in Portugese) — there are now more than 1,000 CAs — so Banrisul decided to make a PKI application that worked with the national PKI. They put a PKI application with a bank certificate on each card they send out. The customers can then go to a bank branch and use this certificate to obtain a state government certificate (the bank’s branches are all RAs) and then use this to obtain a national certificate.

The bank also decided to give out free smart card readers. They are simple, cheap USB readers to work with a browser plug-in. When customers make online transactions using their smart cards, they get higher transaction limits. Customers are therefore using the same card, same reader and same PIN to log on to their bank and to buy stuff: a straightforward way to have more security.

Next year, the bank expects to issue another 1.5m cards and upgrade some customers’ from the simple USB card readers to readers with secure built-in keypads and displays for even higher security. Meanwhile, some of the banks here have not even started to roll out the already dated EMV-based 2FA (Visa’s DPA and Microsoft’s CAP).

Most significantly, [hackers] are now undeterred by systems that create temporary passwords, such as RSA’s SecurID system, which involves a small gadget that displays a six-digit number that changes every minute based on a complex formula. If you computer is infected, the Trojan zaps your temporary password back to the waiting hacker who immediately uses it to log onto your account.

[From How Hackers Snatch Real-Time Security ID Numbers - Bits Blog - NYTimes.com]

There’s no doubt in my mind that end-to-end hardware-based encryption and authentication is mopre secure, more flexible and more effective than the always intended to be a stopgap “token authentication”, but what does this have to do with the UK? The UK is in the throes of developing a national identity management system but it has an architecture centred on the ID card and the ID register. But there are two other obvious secure computing platforms that should form part of the infrastructure: bank-issued EMV cards and mobile operator-issued SIM cards (EMV cards and SIM cards are actually the same chips but with different application software). And the use case for the public is using the card, not using digital certificates, which really should be the heart of the transactional components.

Why should we consider this architecture? Well, the government here is very muddled about national identity infrastructure. The current system jumbles about passports and identity cards and delivers few compelling use cases. The next administration will certainly want to alter the cost-benefit equation in some way. Suppose that the vision for national identity focused on the certificate rather than the card or biographical details? Then, as a user of the scheme, I might have a certificate on my purpose-built national identity card (so that’s a minority of the population taken care of), I might have a certificate on my bank card (so that’s the overwhelming majority of the population taken care of) and I might have a certificate in my mobile phone (so that’s 99.9% of the population taken care of).

The Spanish Ministry of Industry, Tourism and Commerce will distribute around 500,000 electronic ID information packs across the country… The information packages will contain an electronic ID card reader, an installation CD and the software for service use on computers, as well as information manuals.

[From 'Spain govt offers 500,000 electronic ID information packs']

The government could give out free smart card readers (as they do in Spain) or leave it to the banks to distribute them. In practice, I think the example set by a modern country such as Turkey is most attractive: I log in to the government with some ID number, the government sends a message to my mobile phone (over-the-air or via NFC in the future), the PKI in my SIM decodes the challenge and signs the response, and I’m connected. Securely and simply. And if other service providers want me to log in in the same way, they can issue their own certificates as well.

There’s another point to be made here, too: why not just use PKI-based identity management and forget about EMV for remote transactions? It’s a good point, but it’s a topic for another day, such as November 4th, when I’ll be chairing at ID WORLD — see you there!

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Another model that the UK could try appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2009/10/another-model-that-the-uk-could-try/feed/ 1
There’s always mistales http://tomorrowstransactions.com/2009/03/theres-always-mistales/ http://tomorrowstransactions.com/2009/03/theres-always-mistales/#comments Wed, 18 Mar 2009 11:14:38 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2009/03/theres-always-mistales/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post There’s always mistales appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Well, this is interesting. One of my mobile phone operators (I currently have three: my iPhone, my dongle and my son’s phone) has sent me someone else’s bill. I now have someone’s name, address (why it came through our door I have no idea: the address isn’t even in the same town, let alone the same street), mobile number and an itemised bill. I’m sure I could get up to some mischief with this. I don’t want to pick on mobile operators in particular, but I do want to point out that this sort of thing will always happen. In a bizarre way, we’ve come to expect them. It’s even vaguely comforting to read about the usual colossal cock-ups with computers, because it reassures you that all is right with the world…

Zamora said the pump at the By-Pass Deli and Conoco service station at Stevens Drive and the Highway 240 Richland bypass registered only $26 for the fuel. But somehow the transaction was recorded on his debit card as totaling $81,400,836,908… After learning that afternoon by e-mail that his debit card was maxed out (no kidding! ed.) he called customer service… “Somebody from a foreign country who spoke in broken English argued with me for 10 to 15 minutes,” Zamora said. ” ‘Did you get the gas?’ he asked. Like I had to prove that I didn’t pump $81,400,836,908 in gas!”

[From Local News | How many billion dollars for that tank of gas? | Seattle Times Newspaper]

I am literally astonished that a charge for $81 billion could go through the debit card system at all. Wouldn’t you have thought that the settlement system had some limit minding in it that will trigger if a transaction for more than, oh I don’t know, let’s say A BILLION DOLLARS comes through on a debit PAN? Clearly, whoever built the system never imagined that this could happen, so they never put in any logic to watch out for it.

It’s crazy to build systems on the assumption that nothing will go wrong. Amusingly, in a tragic and depressing kind of way, this was reinforced by the news that public employees have already been snooping around in the proto-national identity register to look up friends, family and presumably other “interesting” people even though it’s not even been built yet. Still, not to worry. So far it’s only 30 local authorities that have noticed a problem.

Staff at 30 local authorities have been responsible for “serious security breaches” in the government database that will form the core of the national ID cards programme. Local authority staff have viewed sensitive personal records on the Customer Information System (CIS) run by the Department for Work and Pensions (DWP), it emerged today. The £72m Customer Information System is an Oracle database being built by Accenture for the Department for Work and Pensions. It will hold a wide variety of data on nearly all UK citizens.

[From ID Cards insider: scheme is "largest , most complex and sensitive undertaking in Government" (Tony Collins's IT Projects Blog)]

Why on earth would anyone have imagined that there would be any other outcome? And by the way, if I was one of these public employees snooping around for the purposes of amusement, I’d have been using someone else’s username and password, so there’s no real chance of catching them.

But should we be so negative all the time? I’m a glass-half-full kind of guy (my finance director is a “why do we buy such big glasses” kind of guy) so I look for comfort: it’s computer catastrophes, government procurement incompetence and management consulting theories that will save us from the dystopian nightmare of being a total surveillance society.

Surveillance in Nineteen Eighty-Four is relentlessly efficient. Nothing is overlooked, nothing is missed. But surveillance in 2009 is incompetent: officials forget to put film in the cameras; they lose the secret data they have gathered, leaving it on trains or in bars; and they frequently never get around to consulting what they do manage to keep hold of:

[From Only incompetence will save us from Orwell's surveillance state - Telegraph]

Joking aside, a sure-fire way to stop personal data from being abused is not to store it in the first place. When it comes to the national identity scheme there is no reason at all to have biographic data stored centrally. The entire purpose of the identity register should be uniqueness: the biometric data is there to ensure that ID numbers are unique and nothing else. Then the identity card can take on new purpose: not to store a subset of the biographic data and make it available to everyone, but to control access to personal data. If it could perform as a National Privacy Card rather than as a National Identity Card, revealing appropriate entitlements in the right context but not given away personal data every where and every time it is used, then it could become integral to what we actually need which is a standard, universal authentication scheme. The is what the ID is card not right now.

But alongside this behemoth, we’ll need another national ID-authentication scheme for use in online commerce and public services. The Home Office won’t like it, because it’ll be as much about concealing identity as revealing it

[From Michael Cross on why ID cards should conceal as well as reveal identity | Technology | The Guardian]

But the Home Office should like it, because they are supposed to be on our side, protecting the citizenry. And they should also like because if companies found it more cost-effective to use the National Privacy Card instead of implementing their own schemes then it would also start to generate some revenue for the public purse.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post There’s always mistales appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2009/03/theres-always-mistales/feed/ 3
Privacy-enhancing anti-technology in Europe http://tomorrowstransactions.com/2009/03/privacy-enhancing-anti-technology-in-europe/ http://tomorrowstransactions.com/2009/03/privacy-enhancing-anti-technology-in-europe/#comments Tue, 03 Mar 2009 09:44:10 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2009/03/privacy-enhancing-anti-technology-in-europe/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post Privacy-enhancing anti-technology in Europe appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] There’s been another rash of stories about fingerprinting and the linking of identity and authentication and I thought I’d take a look at a few of them after my afternoon at the Social Market Foundation. Let’s begin by looking at a mass market use of biometrics…

Under a new law published Monday, Mexico will start a national register of mobile phone users by fingerprinting all customers in an effort to catch criminals who use mobile phone to extort money and negotiate kidnapping ransoms. The new law, which will be in force this April, will give mobile phone companies a year to build the database of their clients – complete with fingerprints and any other personally identifiably information.

[From New Mexico Law to Fingerprint All Mobile Phone Users]

Fingerprint mobile phone users could never happen here, of course. Well, not for a while. But fingerprint mobile providers might…

Vodafone dealership DigitalMobile is the latest employer to introduce fingerprint scanning for staff. DigitalMobile spokesman Will Allan says the scanners have been installed in the company’s 22 stores around the country and most of its 190 staff are using them to clock in and out.

[From Vodafone sales staff asked to scan in - New Zealand's source for technology news on Stuff.co.nz]

This seems pretty reasonable: using biometrics to make life easy more people is a much more convincing business case and, as far as I can see, a much more effective use of the technology than biometrics for security (outside nuclear missile launch codes and that kind of thing).

Actually, the use of biometrics to identity employees (which has long been almost standard in data centres, nuclear weapons factories and so on) sort of thing is already here.

The Co-operative Group is introducing a system to monitor staff working hours using biometric technology. A new workforce management platform will record the work patterns of 55,000 staff through in-store data collection terminals using finger scan verification – a method of scanning various points on the finger but which creates a file that bears no resemblance to a fingerprint.

[From Co-op to monitor staff using finger scanning - 12 Feb 2009 - Computing]

There are some particularly disreputable people who do need to be monitored very closely and perhaps in their case fingerprints might be the most appropriate means of tracking and controlling them. I’m talking about politicians, naturally, and in Italy they are already taking steps to use biometrics to manage them.

Officials in Italy’s Chamber of Deputies have begun taking MPs’ fingerprints in preparation for the introduction next month of a new voting system inspired by a similar one in operation in the Mexican parliament. It will allow MPs to vote after entering a smart card containing the details of their identity and fingerprints into an electronic voting terminal.

[From Italian MPs fingerprinted to stop absentee voting - Telegraph]

Should we worry about Big Brother getting hold of individuals biometric data? Perhaps not, as it could be that government IT incompetence ends up as the critical privacy-enhancing technology or, more accurately, a kind of privacy-enhancing anti-technology (PEAT) !!

The original Schengen Information System (SIS) focused on text- only data, such as the traveller’s name and passport number. When the EU took in 10 new members in 2004 and began planning how to take them into Schengen, officials decided that it was the perfect opportunity to create a new SIS, capable of processing not just text information, but ‘biometric’ data such as fingerprints and photos. But the new system quickly ran into problems. SIS II stations set up in individual member states were unable to communicate with the central server in Strasbourg, France, while experts reported that some of the data sent through the system simply disappeared en route.

[From Bugs bite the EU's Big Brother]

So where are we with biometrics on a large scale? All over the place. Without an infrastructure to use biometrics properly, which means as far as I can see some kind of properly organised PKI-based, open standards-based, interoperable scheme, I can’t see where we’re going or how we are going to use biometrics in a positive way to enhance with security or privacy at the European level. Luckily, this is all going to be sorted out (!) at the EEMA eID Interoperability conference in Brussels on 17th/18th March. Look forward to seeing you there.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Privacy-enhancing anti-technology in Europe appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2009/03/privacy-enhancing-anti-technology-in-europe/feed/ 1
At whose fingerprints? http://tomorrowstransactions.com/2009/02/at-whose-fingerprints/ http://tomorrowstransactions.com/2009/02/at-whose-fingerprints/#comments Wed, 25 Feb 2009 18:41:02 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2009/02/at-whose-fingerprints/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post At whose fingerprints? appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] I went to the Social Market Foundation chat about biometrics sponsored by the Identity and Passport Service (IPS). The speakers — Jim Wayman from San Jose State University, Peter Hawks and Hugh Carr Archer (Aurora) from our friends at IAFB, Farzin Deravi from the University of Kent and forum friend Toby Stevens from EPG — got a good discussion going although personally I thought it was a little too short. I was very interested in some of the points being raised from the floor and would have appreciated more time for expert reflection from the panel.

Jim started his talk by referring to the “colourful” history of the future of biometrics, which appealed to my current obsession with paleo-futures at the CSFI, and made a couple of points that I think are worth opening up for discussion here. First of all, he made the key point that biometrics doesn’t solve the problem of identification but once you have identified someone then you can use biometrics to link them to that identity. Biometrics is easy, identification isn’t, and biometrics do not guarantee the validity of non-biometric data in database (this is why I keep promoting the “biometric only” plan from the UK National Identity Register). Secondly, he made me reflect on the difference between schemes where the “users” care about multiple uses or not. So, if I have a season ticket for the London underground, I don’t care about my brother using it on the days that I’m not. But I don’t want him using my credit cards on days that I do not. So why would you need a biometric for a bank card? Good point. I think that the answer is that if we want to use cards for larger transactions then we can’t use PINs because PINs are too easily snaffled, but I’m going to think some more about this and post in the future.

One issue that came up was where the readers for the UK’s ID cards might come from, since there are currently none in service. But this led me to reflect on another of Peter Hawks’ points, which was that chips for fingerprint recognition can now be added to laptops and, you guessed it, mobile phones. Incidentally, Peter was kind enough to point to some of my writing on the synergy between mobile phones and speech biometrics as a nexus for advance in the future, which I greatly appreciated

The idea that a key device for making biometrics useful in the mass market might well be the mobile phone is actually quite widespread and in one particular mode, which is doing one-to-one matches between biometric templates and stored templates in secure devices (let’s call them SIM cards for the time being) in a distributed fashion, a plausible trajectory for enhanced identification and authentication services. Consider, for example, the rather convenient use case of a contactless smart card and a biometric reader: you walk up to a door, put your finger on a scanner, then wave your card over the reader, the door beeps and in you go. Could this work? Yes, and NIST did tests on this a year ago that showed it to be practical.

The NIST tests addressed two outstanding questions associated with match-on-cards. The first was whether the smart cards’ electronic “keys” can keep the wireless data transmissions between the fingerprint reader and the cards secure and execute the match operation all within a time budget of 2.5 seconds. The second question was whether the “match-on-card” operation will produce as few false acceptance and false rejection decisions as traditional match-off-card schemes where more computational power is available. The researchers found that 10 cards with a standard 128-byte-long key and seven cards that use a more secure 256-byte key passed the security and timing test using wireless. On the accuracy side, one team met the criteria set by NIST and two others missed narrowly. The computer scientists plan a new round of tests soon to allow wider participation.

[From Dr. Dobb's | On-card Fingerprint Matching | April 1, 2008]

If we take the same kind of technology and move it into the mobile environment, we can easily imagine using an NFC-equipped mobile phone for both logical and physical access control, and other applications beside. And it’s not only in Japan where this kind of technology is being tried out.

The Kyocera cell phones were used in a mobile payments trial conducted by Cellular South… cell phone users were able to access payment cards using their fingerprints. According to Cellular South, 87% of testers that participated in the trial are interested in using the mobile payment technology once it’s available for commercial use. Other testers found the technology convenient to use and an innovative method for making everyday payments and purchases.

[From Cossacks Breaking News » Companies Test Fingerprint Recognition For Mobile Payments]

There is one big drawback at present. The technology is 99% reliable, which unfortunately is as useful as a contraceptive pill that is 99% reliable (so you only get pregnant once a year). In other words, not quite ready from prime time! This was clearly demonstrated at the recent launch of a new Fujitsu handset for DoCoMo in Japan.

During the 505i launch event on Tuesday, Takeshi Natsuno was on stage to demonstrate the F505i’s capabilities – including the fingerprint reader used to authenticate access to the phone’s address book, mail, picture store, and scheduler. When Natsuno applied his finger onto the reader platen glass (located at the bottom of the phone), **nothing happened!** “OK – we’ll try that later,” he added somewhat sheepishly, after waiting for some 30 seconds..

[From 505i Launch Event: DoCoMo Finger Scanner Boo-Boo with Fujitsu Celly by Wireless Watch Japan]

This, it seems to me, is a common experience with biometric laptops, USB sticks and the like. It works most of the time, but when your boss is standing over you desperate from some document on your laptop, it doesn’t.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post At whose fingerprints? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2009/02/at-whose-fingerprints/feed/ 1
It could never happen here http://tomorrowstransactions.com/2009/01/it-could-never-happen-here/ http://tomorrowstransactions.com/2009/01/it-could-never-happen-here/#comments Thu, 15 Jan 2009 12:43:44 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2009/01/it-could-never-happen-here/ I remember discussing this with someone -- but due to my advancing years, I can't remember who -- a few months ago after reading some of the reputation-realted discussion on the Burton Group blog. The discussion about Personas Need Reputation, Too! was about what a protocol to support reputation might look like. The idea was to enable multiple parties to engage and have the outcome of the engagement (in the form of claims about relationships) communicated.

The post It could never happen here appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Well well. Now here is an interesting story that hasn’t got anything like the attention that it demands:

A South Korean woman barred from entering Japan last year has reportedly passed through its immigration screening system by using tape on her fingers to fool a fingerprint reading machine… A South Korean broker is believed to have supplied her with the tapes and a fake passport, the Yomiuri said, adding that officials believe many more foreigners might have entered Japan using the same technique.

[From Woman fools Japan's airport security fingerprint system]

Now, I wonder if the Japanese ministry of immigration (or whatever) chose that particular system on the basis that it was (according to the vendor) foolproof? That is certainly the perception of biometrics, particularly amongst politicians, but who can say? I suppose the risk analysis they carried out — I’m sure they must have carried out a risk analysis — would have put impersonation as a theoretical probability with a low likelihood and low chance of success. Ooops.

Other elements of this story are fascinating. The biometric system ( which cost four billion Yen) was installed in 30 airports in 2007 to improve security and prevent terrorists — or at least terrorists that you already know well enough to have their fingerprints — from entering into Japan. It work like the EU’s system for detecting multiple asylum applications, by reading the index fingerprints of visitors and cross-checking them with an online database. Pretty secure, and only the most dedicated, well-funded and intelligent international terrorist masterminds would present a realistic threat to the integrity of the scheme. So who was the criminal terrorist genius who got through? Well, in this particular case, the woman was deported in July 2007 for illegally staying in Japan after she worked as a bar hostess. That’s right: a bar hostess. She was barred from re-entering Japan for five years, but was caught in the country a year later. Clearly, her risk analysis around identity and authentication was different from the governments: it made economic sense for her to buy a way round the system just to work as a hostess, much less to bring down the government etc.

This goes back to the question that we were discussing before, about whether biometrics — in of themselves — make things better or worse. If people (the Home Secretary, for example) are convinced that biometrics are perfect, then they adjust their thinking to reconstitute issues in terms of problems that biometrics can solve. Of course, if I were to advance that perspective to government, I would be told “ah well, our system is better / newer / designed by the military”. And, indeed, we are trialling a different system at the moment

The system at Manchester Airport can be used by adult biometric passport holders from the UK and Europe. It works by scanning passengers’ faces and comparing them to the photographs digitally stored on their passports.

[From BBC NEWS | UK | Passengers test new face scanners]

Interestingly, a similar system was introduced into Japan — I kid you not — to stop children from buying cigarettes from machines. In that case, the gasping tots were able to defeat the bimetric security system using a very sophisticated and unimaginably devious mechanism…

The face-recognition machines rely on cameras that scan the purchaser’s face for wrinkles, sagging skin and other signs of age. Facial characteristics are compared with a database of more than 100,000 people, and if the purchaser is thought to be well over 20 years old (the legal age), the sale is approved. If the purchaser looks too young, they are asked to prove their age by inserting a driver’s license. According to Fujitaka, the machines are 90% accurate.

[From Magazine photos fool age-verification cameras ::: Pink Tentacle]

Yes, that’s right. The kids held up pictures from magazines. Doh!

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post It could never happen here appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2009/01/it-could-never-happen-here/feed/ 2