FB pixel

EyeVerify CEO proposes payment grade for the biometrics industry

 

In a recent blog post, EyeVerify CEO and founder Toby Rush proposes that the biometrics industry needs to define standards around Payment Grade biometrics to determine the strength of a given biometric solution.

“Payment grade is an effort to help financial institutions gain confidence and move towards biometrics faster,” Rush writes. “As they begin to engage the biometric world, many financial institutions don’t have the bandwidth, depth or resources to thoroughly investigate how every biometric technology works.”

Rush explains that this lack of resources causes to a sense of uncertainty among financial companies because there is no consistent set of requirements for a biometric solution.

A Payment Grade would provide a set of industry-defined standards that measure biometric requirements, which will instill greater confidence in financial institutions and other industry players and help them to transition to biometrics faster, said Rush.

Rush outlines what he considers the three primary cornerstones that the payment industry needs to consider when assessing different biometric solutions: accuracy, liveness and privacy.

In terms of accuracy in biometric authentication for mobile payments, Rush explains that there is no definite consensus on what is considered “good enough”.

However, establishing a Payment Grade accuracy requirement would ultimately help banks and other payment players eliminate an extra layer of uncertainty.

Rush proposes a 1 in 50,000 False Accept Rate (FAR) as a requirement since Apple and several large OEMs have previously stated this FAR as a requirement for biometrics in their own devices or applications.

The liveness cornerstone, which prevents spoofing, is more difficult to standardize as there are currently no metrics for liveness or standards for how to assess it, writes Rush.

Liveness needs to be specific to each of the three primary sensors for mobile biometrics — the microphone (voice), the camera (face and eye), and the fingerprint sensor.

Rush proposes that a series of tests should be set up with users to determine how successful the technology is at blocking specific threats, such as whether it is possible for the solution to authenticate using an image of a face or a voice recording found online.

In terms of the privacy cornerstone, Rush said three essential questions must be answered: “Is the biometric revocable, do you store it locally or on the server, and if you do store it on the device – do you ever unencrypt the template, and do you have a method to calculate a high entropy key?”

Rush concludes by stressing the need for an equivalent to the VeriSign logo in the early days of ecommerce, which would serve as a trustworthy indicator for financial institutions in assessing biometric technologies.

To create such a Payment Grade mark, key industry stakeholders (banks, payment networks and device manufacturers) could develop specifics for standards, which could then be validated through various tests by third party groups, said Rush.

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

NIST sees biometrics developers closing in on operational morph detection

Biometrics developers are getting better at detecting face morphs, even if facial recognition algorithms aren’t. Day 2 of the EAB’s…

 

Big talk on imminent UK social media law as consultation closes

UK Prime Minister Keir Starmer is promising to act “very, very quickly” to put legal age restrictions on social media…

 

Regula warns most organizations don’t know what bots are doing, or why

The latest report from Regula underlines the discrepancy between what’s happening to companies in the AI age, and how seriously…

 

UK digital ID consultation advances to 120-member People’s Panel

The UK’s digital ecosystem is still digesting the government’s public consultation on digital ID, and what can and should be…

 

Signicat adds Austria ID as Europe prepares for EUDI Wallet transition

Signicat has added Austria’s electronic ID system to its unified platform for national eIDs and EU Digital Identity (EUDI) wallets,…

 

Injection attack detection critical to digital security yet often misunderstood

The most influential factor in the tech market is pace. When a new technology appears, it inevitably kicks off a…

Comments

12 Replies to “EyeVerify CEO proposes payment grade for the biometrics industry”

  1. Toby, I applaud your initiative. I would appreciate the opportunity to dialog with you on several aspects of this approach if you wish.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events