FB pixel

Post-quantum identity expands beyond cryptography

Daon introduces a new identity architecture as vendors and governments prepare for quantum computing's impact on digital credentials and biometrics
Categories Biometric R&D  |  Biometrics News
Post-quantum identity expands beyond cryptography
 

As governments and enterprises prepare for practical quantum computing, the focus has largely been on post-quantum cryptography. IBM is targeting 2029 for the launch of a large-scale, fault-tolerant quantum computer. DARPA wants the U.S. government to be able to use one by 2033. Daon argues that securing digital identity will require more than quantum-safe signatures, introducing a new architecture designed to verify the authenticity of identity evidence itself.

The problem in the meantime is that when Q-Day comes, it will allow malicious actors to use post quantum computing to crack the cryptographic protections of data they have already captured in “harvest now, decrypt later” operations.

“The public debate tends to focus on when quantum computers will break today’s cryptography,” says Veridos Director of Innovation Projects Armin Reuter. “But for identity systems, the more pressing question is what happens to documents issued now – passports, national IDs, and trust anchors – whose lifetimes may well extend beyond the point at which the cryptography protecting them ceases to be secure. Such documents often remain valid for many years, so today’s decisions have long-term implications.”

If the cryptography protecting these identity credentials is broken, then criminals can create fraudulent versions that appear to be legitimate.

Industry efforts to prepare for the post-quantum era have so far therefore mostly focussed on post-quantum cryptography (PQC) to protect the signatures that confirm the validity of biometrics and other sensitive data. AuthID recently added PQC support to its biometric digital signature platform, STMicroelectronics introduced a chip with a hardware accelerator for PQC algorithms and Toppan launched smart cards with PQC this week.

Veridos has published a white paper on “The Quantum Risk in Identity Ecosystems” to help organizations understand the risks quantum computing poses to identity systems and help them formulate a plan to migrate to quantum-secure technologies.

Cryptographic evidence cannot be sufficient to prove that biometric evidence is genuine or presented by the person on the other end of the transaction, Daon says in announcing its new technology to protect digital identity systems on the way to Q-Day and beyond.

Daon’s new Quantum Identity architecture

Daon says its Quantum Identity architecture, backed by five U.S. patents, takes a data-plane approach to evaluating the identity evidence entering digital identity systems.

Daon says its architecture complements post-quantum cryptography rather than replacing it. PQC protects keys, signatures and records, while Quantum Identity evaluates whether the biometric and identity evidence entering the system is genuine before trust decisions are made.

The five patented technologies behind Daon’s post-quantum protection system relate to quantum-enhanced biometric morphing detection, quantum identity verification, quantum biometric liveness detection, and quantum injection attack detection and replay resistance. That latter two were issued by the USPTO within the past two months.

“Quantum Identity is not a single algorithm, and it is not simply PQC,” says Daon President and CPO Ralph A. Rodriguez, who is the sole inventor of each of the five patents. “PQC strengthens the cryptographic control plane: keys, signatures, certificates, and protected records. That’s essential, but it secures the messenger, not the message. An identity system also needs confidence that the evidence itself is genuine. Our five issued patents establish that complementary data-plane foundation, detecting manipulation, evaluating high-dimensional fraud signals, and determining whether evidence is live, current, and bound to the transaction taking place rather than injected, cloned, or replayed.”

Daon intends to bring the modular architecture to regulated markets like financial services, the public sector, healthcare, telecommunications and travel to support high-assurance onboarding, account recovery and high-value authorization.

The company has a portfolio of over 320 patents through its Daon Labs.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Meta sued over alleged facial recognition training for smart glasses

Meta Platforms is facing a proposed nationwide class action lawsuit accusing the company of using photographs from Facebook and Instagram…

 

IATA urges EU to extend biometric border flexibility amid EES delays

The International Air Transport Association (IATA) is urging the European Union to extend temporary flexibility measures for its biometric Entry/Exit…

 

Thailand puts verifiable credentials at center of 2027 digital ID strategy

Thailand’s digital development agency is planning big moves for 2027 as it focuses on digital ID and digital transformation. The…

 

Albania gives ALBTrace broader role in digital identity infrastructure

Albania has expanded the mandate of state-owned identity services provider ALBTrace, giving it responsibility for the country’s digital identity infrastructure…

 

BEAC lays foundation for interoperable payments across Central Africa

The Bank of Central African States (BEAC) has rolled out some initiatives lately which suggest a coordinated push aimed at…

 

Procivis expands EUDI footprint as Europe’s wallet deadline approaches

Procivis has added France to a growing list of European digital identity environments where its technology can issue and verify…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events