If anyone has any doubt biometrics is coming to the consumer world, they may have missed Apple's recent run of acquisitions around fingerprint and facial recognition technologies. Topped with Apple's Siri voice recognition facility and gyroscope/accelerometer facilities in mobile devices, a biometrics user profile on consumer mobiles can be captured within a reasonable timeframe. The longer term question is, how will government biometrics benefit from the consumer experience of biometrics on their mobile devices?
The threat of malware and phishing is engulfing the web. It is expected to be an even greater threat in the mobile context, as battery power limitations and the lack of screen real estate of handsets tie the hands of anti-virus methods and user messaging methods, and people’s continuous handset connectivity makes them more vulnerable to abuse. This paper argues that biometric methods, such as fingerprinting methods, could address a large part of this towering threat but only if properly architected. We describe an architecture that is practically attainable and which would address the problem in a meaningful way, and argue that this is a promising direction – both in terms of security and usability. Keywords-authentication; biometrics; fraud; malware.
L'invention porte sur un systeme pour une utilisation avec un gestionnaire de services de confiance (TSM) et un dispositif mobile ayant des donnees d'identification uniques d'abonne, lequel systeme comprend : un serveur qui valide une application par rapport aux donnees d'identification uniques du dispositif mobile et fournit l'application validee au dispositif mobile; et un element securise (SE) agissant en tant que client, dans lequel le SE est present dans le dispositif mobile en tant que client. L'application validee provenant du serveur est installee dans le SE; et le SE execute l'application validee pour effectuer un processus de service, qui permet des fonctions de paiement sur le dispositif mobile, comprenant : la fourniture d'une communication securisee entre le mobile et le serveur; l'approvisionnement securise d'un instrument de paiement sur le mobile, avec authentification et verification fournies par le serveur; et la liaison de l'instrument de paiement et de l'application validee au mobile pour fournir une gestion d'identifiant forte pour une protection d'utilisateur amelioree et une securite et une integrite de systeme ameliorees.