Small Business Resources, Business Advice and Forms from AllBusiness.com

Who Are You?

By Cieslak, David
Publication: California CPA
Date: Sunday, May 1 2005
HEADNOTE

AUTHENTICATION TECHNOLOGIES ENSURE USERS ARE WHO THEY CLAIM TO BE

Today, more than ever, protecting your electronic identity is a top priority. In addition to normal security precautions, such as using antivirus

software and keeping system patches up to date, computer users must be on guard against phishing scams and other high-tech methods used by identity thieves, who seek to coax you into surrendering your personal information.

So, how can you combat this problem and better protect your vital information?

Meet authentication technologies.

Authentication technologies are not new. In fact, a number of products and strategies have been around since the early days of computing.

However, a heightened awareness and increased affordability of these technologies is pushing them to the forefront.

In simplest terms, authentication technologies ensure that individuals are who they claim to be. The technologies fall under three broad categories: something you know, something you have and something you are.

Passwords, tokens, public key infrastructure and biometrics are all examples of authentication technologies that can help verify identity and control access to resources-and each falls within one of these three broad classifications.

PASSWORDS

Passwords are the least expensive and most common type of authentication technology and are based on "something you know."

Passwords require users to remember a string of characters and enter this information when prompted to gain access to a desired resource. Unfortunately, passwords also are one of the weakest forms of authentication technology and users themselves are typically at the root of this weakness.

Often, users share passwords, making them a poor means of individual identification. Or, passwords are left blank, not changed for long periods of time, re-used across multiple accounts or overly simplistic, leaving your password vulnerable to hacking via freely available tools.

IMAGE PHOTOGRAPH 1

While passwords should continue to play a role in user authentication, they should not be overly relied upon because of their inherent limitations.

TOKENS

Under the "something you have" category, token-based authentication technologies-such as magnetic strips (credit cards), smart cards, SecurID cards or USB keys-hold longer, harder-to-break "secrets" that are more difficult to hack or reproduce.

The weakness with authentication technologies is that tokens afford little protection if they are lost or stolen.

And similar to passwords, simple possession of these objects often serves as the only means to distinguish the owner.

The effectiveness of tokens can be significantly enhanced, however, by combining their use with "something you know." For example, requiring the use of a PIN code or password along with the possession of the physical token.

PUBLIC KEY INFRASTRUCTURE

PKI refers to a system where digital certificates are used to verify user identity for e-mail messages and e-commerce transactions, and also is an example of "something you have."

Digital certificates often are issued by an independent certificate authority that then acts as a third-party reference regarding the owner's identity. These certificates are attached to e-mail messages or referenced by a web browser during an e-commerce transaction as a means of identification.

When applications encounter these certificates, the origin can be verified by inquiring with the issuing certificate authority to ensure the identity of the sender or website owner.

Digital certificates also provide a means for users to exchange encrypted information using a combination of a private key (owned by the sender) and public key (freely shared with recipients) to encrypt and decrypt message text.

PKI uses highly secure encryption standards and third-party verification to help ensure information integrity and end-user identity, but as yet, has only seen limited adoption in the marketplace.

BIOMETRICS

The final category of authentication technology is based on "something you are" and uses biometrics to examine physical characteristics to differentiate individuals.

Some of the more common biometric technologies include:

Fingerprint Recognition-Fingerprint identification systems take a digital scan of an individual's fingertip(s) and record their unique physical characteristics. Data is then either stored as an image or encoded as a character string.

To prevent fooling the system, some fingerprint ID systems also measure blood flow to the finger so that "fake" fingers can't be used.

Of all the biometric technologies, fingerprint recognition is becoming the most commonplace and is being incorporated into a number of new devices coming to market, from PDAs and thumb drives to mice and keyboards. These devices actually require users to swipe their finger prior to unlocking these devices.

In addition, a number of vendors sell external USB-based devices that can be plugged into any desktop or laptop computer to inexpensively ($50 to $100) add fingertip biometric authentication capabilities.

Fingerprints also are being used with a number of other devices including time clocks, cell phones, door locks and safes.

Iris Recognition-Iris-scan systems analyze and map numerous points of the iris. Eyeglasses, contact lenses and eye surgery do not change the characteristics of the iris, so this method is very reliable, even as a person ages.

Iris recognition systems often vary the light during the scanning process to verify that the pupil dilates, so that a fake eye can't be used to fool the system.

Retina Recognition-Retinal scanning systems shine a light into the eye and looks at the pattern of blood vessels on the retina. Retina recognition systems are among the most accurate of all biometric technologies and are virtually impossible to fool. This technology is used routinely in high-risk applications-and also is relatively expensive.

Face Recognition-Facial recognition measures and analyzes the physical attributes of a person's face, including its overall structure and shape, and distances between the eyes, nose, mouth and jaw edges. Facial recognition systems can accurately verify the identify of a person standing a few feet away in a matter of seconds.

Other biometric technologies include hand recognition, voice recognition, skin surface pattern identification, typing pattern recognition and signature dynamics.

Of the three types of authentication technology, biometrics are considered the most secure since physical characteristics are unique to each individual and can't be easily spoofed. Similar to the other types of authentication, the reliability of biometrics can be further strengthened by combining several forms of biometric recognition, known as multiple biometric, or by requiring users to enter a PIN code to uniquely identify a user-combining "something you are" with "something you know."

SAFEGUARDING USERS

As users increasingly rely on electronic means of conducting business and exchanging information, the need for authenticating user identity and ensuring reliability will grow. Authenticating technologies will continue to evolve and play a greater role in helping safeguard users.

AUTHOR_AFFILIATION

BY DAVID CIESLAK, CPA, CITP

AUTHOR_AFFILIATION

David Cieslak, CPA, CITP, GSEC is a principal with Information Technology Group, Inc. in Simi Valley. You can reach him at dcieslask@itguse.com.

In addition, make sure to read these articles:

  • Will the e-mortgage ever arrive?
  • REMEMBER WHEN THE FAX MACHINE WAS REVOLUTIONARY TO THE MORTGAGE INDUSTRY? Suddenly transferring documents in the loan process was faster and less costly. It took ......
  • Rapattoni Adds PingFederate Single Sign-on to Its Internet-Based Services.
  • Federated Identity Management to Power One Time Log On for Realtor Associations and Multiple Listing Services DENVER -- Ping Identity Corporation today announced that Rapattoni ......
  • Calendar.
  • Calendar Topic Time Mar. 4 Grand Opening for The Piedmont 10:00 a.m. Saving, Investing and 6:30 a.m. Retirement Planning Networking Breakfast 7:30 a.m. 5 Credit ......
  • Break Free
  • HEADNOTE A USER'S GUIDE TO WIRELESS TECHNOLOGY TODAY-AND TOMORROW It's no secret that wireless technology continues to change the way we access information and conduct ......
  • Cut the cord: going wireless opens a whole new way of doing things.
  • The wireless revolution continues to change the way individuals and businesses work, access information and communicate. As the technology becomes more affordable and gains broader ......
  • Let me in: data sharing between applications is closer than you think.
  • A lucky few work with only one or two computer applications a day. Everyone else must navigate a variety of programs and often enter the ......
  • Firm news.
  • San Ramon-based Armanino McKenna LLP acquired the health care audit and review practice of San Francisco-based Clare, Chapman, Storey & Bowen LLP. Dan Bowen, a ......
  • 26th annual 2005 New York CPA, business & technology show & conference.
  • July 25-26, 2005, Mon-Tues, Hilton New York Hotel, NY 1335 Ave Americas at West 54th St, Midtown Manhattan Sponsored by the Foundation for Accounting Education ......
  • Simi Valley.
  • A Summer Concert Tribute to Elvis will occur on July 21 from 6 to 8 p.m. at Rancho Sinai Community Park. This free event will ......
  • Information security: time to take care of business.
  • With so much written about information security over the past several years, most professionals are now aware of the importance of security when using a ......
  • Information Security: Move Beyond Simple Awareness To Specific Action
  • Given all the publicity surrounding information security in recent years, and the airtime and ink spent detailing its importance as well as documenting high-profile security ......
  • Break free: a user's guide to wireless technology today--and tomorrow.
  • It's no secret that wireless technology continues to change the way we access information and conduct business. Consider the following: * 95 percent of all ......
  • AICPA TECH 2005 In Las Vegas
  • The AICPA's TECH Conference, the largest gathering of CPA technologists in the country, is celebrating its 25th anniversary in 2005 and will run June 26-29....
  • Simi Valley.
  • Library: Nov. 4 marked the 15th anniversary of the opening of the Ronald Reagan Presidential Library and Museum. The facility high above Ventura County traces ......
  • member milestones
  • interaction: 44% of U.S. senior finance execs said their CFO interacts with the board of directors significantly more than two years ago. - Booz Allen ......

Computer Security: What Is Phishing?
Interview with network security expert Matt Sarrel of the Sarrel Group.