FB pixel

ID federation and continuous authentication schemes have their fans and challenges

ID federation and continuous authentication schemes have their fans and challenges
 

A panel discussion aimed at U.S. federal agencies regarding digital ID and authentication management this week took looks at federation and continuous authentication. Both options are liked but both have challenges.

One Advanced Technology Research Center panelist, Matt Topper, president of ID and access-management vendor Uberether, reportedly was exciting about the prospect that the National Institute of Standards and Technology will publish guidance on federation itself.

A fan of how federated schemes can provide security, Topper said, standards will enable authentication among agencies as well as between bureaucrats, contractors and citizens, according to reporting by trade publication Nextgov.

The challenge will be sorting out all the credentials that long-term contractors gather.

Like barnacles on ships, businesses who win multiple contracts – and do so on projects over the years – end up with a lot of access rights. Barnacles, however, will not render a ship dead in the water, prey for bad actors or bad weather.

A growing hodgepodge of IAM certifications that are not examined at the end of a project presents a very real threat. The Nextgov article points out that the infamous SolarWinds attack was able to move horizontally through organizations, a tactic that could be made less dangerous through a federated identity approach.

And a thorough understanding of who has what security certification and knowing who owns that certification.

The National Institute of Standards and Technology is planning to publish updated guidance on identity and access management that addresses federation, and the Cybersecurity and Infrastructure Security Agency has guidance coming soon.

Another view on the same event, from trade publication GovCIO, quotes a government IT officials saying continuous authentication as a category is evolving well. Gerald Caron is the chief information officer within the federal Health and Human Service Department’s office of inspector general.

The problem is that it is difficult to deliver continuous authentication, particularly in hybrid workplaces. It is typically carried out with behavioral or physical biometrics.

Caron says derived credentials attached to a mobile device, for instance, are only as good as the schedule on which they are interrogated. The longer a device sits not directly monitored, the more likely that it will be used as a tool to access apps and data it sought by the cybercriminal at the device.

Hardware and software changes can make it so common access or personal ID verification cards can re-authenticate users, but that is going to be a hard sell in constrained budgets and even moreso if it means changing personal equipment.

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

New Incode age estimation tool processes biometrics on-device

Prompted by the introduction of online safety regulations globally, Incode has released an on-device age estimation product. An announcement from…

 

Western Australia privacy commissioner not consulted on police facial recognition trial

The Office of the Information Commissioner of Western Australia (OIC WA) says it was not invited to participate in any…

 

Toppan, Raonsecure pilot cross-border VC interoperability between Japan and Korea

Toppan and Raonsecure have launched a digital identity proof of concept (PoC) pilot that generally aims to build a Japan-Korea…

 

Fragomen and SICPA form JV to join digital identity market with end-to-end platform

A new entrant is joining the digital identity market to provide next-generation solutions for governments, enterprises and individuals. The independent…

 

World Bank outlines practical roadmap for digital wallet trust frameworks

The World Bank has released the second in a series of policy notes focused on digital wallets, this time outlining…

 

IDfy wins privacy challenge as India operationalizes DPDP Act

Identity verification firm IDfy has been declared winner of a competition dubbed “Code for Consent: The DPDP Innovation Challenge,” organized…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events