home news blogs forums events research newsletter whitepapers careers


UBM Network Computing
TechWeb
Visit our SOA/Web Services Immersion Center

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






Six Biometric Devices Point The Finger At Security
June 1, 1998

By David Willis with Mike Lee
our customizable newsletter, sends you security alerts, product updates and software patches on the products you use. Sign up now at www.networkcomputing.com /express/
 Every network administrator tries to balance system security against user convenience. Users hate security schemes that get in the way of their work, yet administrators need such procedures to track access and usage. Without clear user identification, you can't have nonrepudiation--the assurance that a user undeniably performed an action. So, users are forced to struggle with elaborate password schemes or hardware tokens to help us track who does what.

However, you can get both security and convenience. With low-cost fingerprint-authentication devices, users can merely put down a digit and forget about passwords. No matter how scatterbrained a user might be, he or she simply can't forget his or her fingers.

To view the Report card.We brought six fingerprint-recognition devices into Network Computing's San Mateo, Calif., Real-World Labę to determine how convenient--and how secure--the latest batch of these devices are.

Out of an ever-growing pack of low-cost readers, we tested American Biometric Corp. (ABC) BioMouse, Biometric Access Corp. (BAC) SecureTouch, Digital Persona U.are.U, Identix's SafeTouch II, National Registry Inc. (NRI) Secure Keyboard Scanner and Sony Fingerprint Identification Unit (FIU). We focused specifically on the devices themselves, because most are not complete systems--yet.

Digital Persona's U.are.U proved to be the best device overall, though it suffers from limited software availability. It combines a very fast and flexible reader with a low false reject rate (see "Biometrics Under Our Thumb," on page 86). We couldn't break into systems protected by U.are.U through fake finger or lifted fingerprint techniques as we could with most of the other devices tested. U.are.U features the simplest installation by virtue of the Universal Serial Bus (USB) interface, which, unfortunately, also limits its deployment in the short run.

If you need to deploy a fingerprint-recognition device now, then the best candidate for you is Sony FIU. Its reader is fast and highly secure, and it supports onboard template storage and encryption. Like U.are.U, the FIU supports one-hand operation, reading the fingerprint image without forcing the user to press a capture key.

Tools or Toys All of these devices offer optical techniques that capture a fingerprint image, using a light source refracted through a prism. Yet there are many physical differences among these units. Those from BAC and Identix are heavy, bulky devices, with complicated optics onboard, while NRI's device uses a custom plastic lens. Sony FIU is relatively small and lightweight, with several custom lenses inside. ABC's product uses lightweight plastics, and Digital Persona's device uses a thin plastic that appears to have embedded microprisms.

We also discovered manufacturers with alternative approaches to expensive optical devices. For example, Who? Vision Systems manufactures a product using a custom electro-optical polymer--a very thin, self-illuminating film--that replaces lenses. The cost to manufacturers per device is under $50. Another company, Veridicom, makes a silicon-based fingerprint sensor. Unfortunately, we were not able to get complete products from these vendors in time for testing.

Only the Digital Persona and Sony devices could detect a fake finger attack by combining optical and proprietary finger-detection methods. ABC offers an enhancement for live finger recognition that uses infrared and pulse detection--for an additional cost. Without this add-on, ABC's BioMouse can be hacked with a fake finger built from an imprint of a user's finger--as can the BAC, Identix and NRI devices.



The Fingerprint-Authentication Device Features charts, in Acrobat format.

For the Side Bar on

Biometrics Under Our Thumb

The Software Battle Has Just Begun


Related Links

S/MIME And OpenPGP Vie For Security Title
March 1, 1998

What Is A Virtual Private Network?,
March 15, 1998

What To Look For In Dial-In Authentication
March 15, 1998

RFP: Security Services
April 1, 1998

Finjan SurfinGate: The Lifeguard Is On Duty
April 15, 1998

PGP Grows Up
April 15, 1998

Smartcards: The Intelligent Way To Security
May 15, 1998

Kerberos and DCE
November, 1997


Company Directory
to browse our data, starting with a particular company.

Network Computing Links
allows you to request additional product information from our advertisers.

Print This Page








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Media Kit  |   Briefing Centers
Other Techweb Sites:   InformationWeek Reports  |  Intelligent Enterprise  |  Light Reading  |  InformationWeek
Techweb  |  Dark Reading  |  Network Computing Germany  |   Byte & Switch  |  bMighty  |  Small Biz Resource  |  InformationWeek Analytics
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights