Showing posts with label biometrics. Show all posts
Showing posts with label biometrics. Show all posts

Tuesday, June 19, 2012

Beyond Passwords Or: How I Learned To Stop Hating And Worked Without Forced Authentication


“Everyone knows there is a problem with passwords.  What I would like to do is I’d like to move us to a world where you sit down at a console, identify yourself, and you just start working.  The authentication happens in the background – invisible to you – while you continue doing your work without interruptions.”  - Mr. Richard Guidorizzi, DARPA Program Manager, Beyond Passwords

The current standard method for validating a user’s identity for authentication on an information system requires humans to do something that is inherently unnatural: create, remember, and manage long, complex passwords.

Moreover, as long as the session remains active, typical systems incorporate no mechanisms to verify that the user originally authenticated is the user still in control of the keyboard.

Thus unauthorized individuals may improperly obtain extended access to information system resources if a password is compromised or if a user does not exercise adequate vigilance after initially authenticating at the console.

The Active Authentication program seeks to address this problem by developing novel ways of validating the identity of the person at the console that focus on the unique aspects of the individual through the use of software based biometrics.  Biometrics are defined as the characteristics used to uniquely recognize humans based on one or more intrinsic physical or behavioral traits.

This program focuses on the behavioral traits that can be observed through how we interact with the world.  Just as when you touch something your finger you leave behind a fingerprint, when you interact with technology you do so in a pattern based on how your mind processes information, leaving behind a “cognitive fingerprint.”


The first phase of the program will focus on researching biometrics that do not require the installation of additional hardware sensors, rather the program will look for research on biometrics that can be captured through the technology we already use looking for aspects of this “cognitive fingerprint.”

These could include, for example, how the user handles the mouse and how the user crafts written language in an e-mail or document.  A heavy emphasis will be placed on validating any potential new biometrics with empirical tests to ensure they would be effective in large scale deployments.

The later phases of the program will focus on developing a solution that integrates any available biometrics using a new authentication platform suitable for deployment on a standard a Department of Defense desktop or laptop.

The combinatorial approach of using multiple modalities for continuous user identification and authentication is expected to deliver a system that is accurate, robust, and transparent to the user’s normal computing experience.  The authentication platform will be developed with open Application Programming Interfaces (APIs) to allow the integration of other software or hardware biometrics available in the future from other sources.

Information for this article and video provided by DARPA

Tuesday, June 14, 2011

Biometric Sharing Initiative: Making the World Safer

Known or suspected terrorists. Transnational criminals. Both threaten not only U.S. security but the security of nations around the world.

One way to help reduce this threat is for nations to share fingerprints and other kinds of biometric information on terrorist-related subjects and international criminals who’ve had previous brushes with law enforcement. Here in the U.S., the FBI’s Criminal Justice Information Services Division—through its Foreign Biometric Exchange program— serves as the centralized collection point for foreign fingerprint records and other biometric data.

Actually, the Bureau has been exchanging fingerprints internationally for nearly 80 years (see previous story), primarily in criminal matters. But after the terrorist attacks of 9/11/01, the U.S. Attorney General specifically directed the FBI to obtain and maintain fingerprints and other biometrics for known and suspected terrorists processed by foreign law enforcement agencies. We then expanded the initiative to include international criminals, who, like terrorists, routinely cross national borders to commit their crimes and often use aliases.

The Foreign Biometric Exchange program is coordinated by CJIS’s Global Initiatives Unit. Says Gary Wheeler, who heads up the unit, “Our mission is two-fold—in addition to collecting and analyzing the data we receive, we also offer assistance to nations who want to develop their own automated biometric systems that meet international standards.” To accomplish both tasks, unit personnel work with our International Operations Division at FBI headquarters, our legal attaché officers overseas, and sometimes INTERPOL and other U.S. federal agencies. 

How it all works
If a nation is interested in participating, we first assess its fingerprint capabilities through surveys and on-site visits. Then we determine what, if any, assistance we can provide in terms of equipment—like mobile fingerprint devices—and training in areas like basic fingerprinting and identification, crime scene preservation, and latent print collection.

Once we begin receiving data from a global partner—either in batches or on a case-by-case basis—we run their fingerprints (both known and unknown) against our Integrated Automated Fingerprint Identification System (IAFIS). Currently, IAFIS contains records of approximately 67 million criminal subjects, including known or suspected terrorists, military detainees, and international criminals.

If there’s a match in IAFIS, we notify the submitting nation. If there’s no match, a new IAFIS record can be created and included in future searches requested by international, national, and perhaps most importantly, local law enforcement officers who are our first line of defense against threats to public safety.

Since 2002, the Global Initiatives Unit has developed relationships with more than 50 countries and has received over 450,000 biometric records that have been added to IAFIS.

Success Story: Mexico
Earlier this year, CJIS provided fingerprints belonging to more than 200 FBI fugitives with violent criminal histories for comparison against the Mexico fingerprint system; in return, Mexico provided nearly 100 prints relating to high-ranking drug cartel members and prison escapees to be run against the FBI’s IAFIS.

The results? Of the records provided by the FBI to Mexico, nearly 20 percent of the fugitives had previously been arrested in Mexico, while more than a quarter of the records Mexico provided to the FBI revealed existing U.S. records.

And in the past couple of years—while working specific cases involving fingerprint exchanges—we’ve returned to Mexico dangerous fugitives who fled to the U.S., including two men wanted separately for child murders, one wanted for rape and murder, and five escapees from a Mexican prison.

Wednesday, April 20, 2011

7 additional Missouri counties to benefit from ICE program to enhance identification and removal of aliens convicted of a crime

JEFFERSON CITY, Mo. - U.S. Immigration and Customs Enforcement (ICE) on Tuesday began using the Secure Communities program in the following seven Missouri counties: Douglas, Howell, Laclede, Oregon, Ozark, Pulaski and Texas. Secure Communities helps federal immigration officials identify criminal aliens in state prisons and local jails by running their fingerprints against federal immigration databases when they are booked into the system.

"Secure Communities enhances public safety by enabling ICE to identify and remove criminal aliens more efficiently and effectively from the United States," said Secure Communities Acting Assistant Director Marc Rapp. "As we expand ICE's use of biometric information sharing nationwide, we are helping to keep communities safe and ensuring the integrity of our immigration system."

With the expansion of Secure Communities to these seven counties, ICE is using this capability in 35 Missouri jurisdictions. Across the country, ICE is using this capability in 1,211 jurisdictions in 41 states. Since ICE began using this enhanced information-sharing capability in October 2008, Secure Communities has resulted in removing more than 72,000 criminal aliens - more than 26,000 of whom were convicted of violent crimes, such as murder, rape, kidnapping and the sexual abuse of children. ICE continues to work with its law enforcement partners across the country to responsibly and effectively implement Secure Communities and plans to reach complete nationwide deployment by 2013.

Prior to the implementation of Secure Communities, fingerprints taken of individuals charged with a crime and booked into state or local custody were checked for criminal history information against the Department of Justice's (DOJ) criminal history records. Once Secure Communities is activated in a jurisdiction, the fingerprints that jurisdiction submits to DOJ's biometric system to check for criminal history records are also automatically sent to DHS' biometric system to check against its immigration law enforcement records. When a match is discovered, ICE evaluates the specific case to determine the individual's immigration status and takes appropriate enforcement action. ICE prioritizes removing criminal aliens convicted of the most serious crimes such as major drug offenses, murder, rape and kidnapping. ICE also gives high priority to other threats to public safety, such as aliens with known gang affiliations, drunk driving arrests, or fugitives, or those who frequently try to game the immigration system.

The biometric systems are maintained by DHS's US-VISIT program and the FBI's Criminal Justice Information Services (CJIS).

"US-VISIT is proud to support ICE by providing comprehensive, reliable information to assist in the smart and effective enforcement of our immigration laws," said US-VISIT Director Robert Mocny. "By enhancing the interoperability of DHS's and the FBI's biometric systems, we are helping federal, state and local government better protect our communities and our nation."

"Under this federal information-sharing initiative, ICE will be utilizing FBI system enhancements that allow improved information sharing at the state and local law enforcement level based on positive identification of incarcerated criminal aliens," said Daniel D. Roberts, assistant director of the FBI's Criminal Justice Information Services Division. "Additionally, ICE and the FBI are working together to take advantage of the strong relationships already forged between the FBI and state and local law enforcement necessary to assist ICE in achieving its goals."

For more information about Secure Communities, visit www.ice.gov/secure_communities/.

Tuesday, April 27, 2010

Defense Media CTO: Wither Biometrics?

Craig Kaucher is the Chief Technology and Information Officer at Defense Media Activity.

April 27, 2010 - Over the past decade, approaches to securing enterprise information systems have evolved from the secure bastion, through defense in depth, to include today the concepts of continuous monitoring and operations. Through this all, many newer, more powerful technologies have emerged and been integrated into various portions of the enterprise information assurance architecture. One particular aspect of information assurance, the password, which is often seen as one of the greatest vulnerabilities of information systems, still seems to be sticking around in some form or another.

Fortunately at the Department of Defense, the Common Access Card (CAC) has alleviated much of the pain of remembering multiple passwords. Unfortunately, the still-required password, as a backup to the CAC, if nothing else, is longer than ever. Combine that with the near infinite number of passwords that almost anyone uses to access anything from on-line banking to e-commerce sites to subscriptions, and the potential for mistakes or intentional bypassing (i.e., writing them down) becomes quite high.

My own theory is that six characters in a password are about all most people will commit to memory most of the time. With each additional character required in a password, I feel there is an increased chance that people will write down the password. By the time a 16 character (or greater) password requirement is reached, my theory is that most people will write their passwords down somewhere. Again, this isn’t scientific, but just my gut feeling.

So why not do away with passwords, or at least the really big ones? Yes, decreasing the length of passwords makes cracking them mathematically more probable, or at least more quickly possible, but this can, as with the CAC, be offset by other factors or multi-factors at one time.

The password is something you know. The CAC (or any other reliable token) is something you have. What about what you are, or in other words, biometrics?

US Marine Corps Sgt. Michael Weaver uses the Biometric Automated Tool Set, Oct. 2008, to enter an Iraqi man's info. (Photo: US Marine Corps Cpl. Tyler W. Hill)

When I was teaching at the Information Resources Management College at National Defense University, I built an information assurance lab. One of the most popular labs was on biometrics. We did hands-on familiarization with fingerprint, face and voice recognition, and iris scanning technologies, looking at their strengths and weaknesses, and emphasizing their potential role in enterprise information assurance.

Biometrics technology seemed to be taking off rapidly. The Department of Defense formed the Biometrics Management Office, and it seemed like in no time, we’d all be accessing Defense Department networks with biometric technologies at the touch of a finger or a glance in the camera.

So what happened? Well, biometrics are still around at the Department of Defense, and they are used in a big way for verifying identity, not necessarily just of Defense Department personnel. The Biometrics Management Office has become the Biometrics Identity Management Agency, and it continues to be the Defense Department’s primary proponent for biometrics, internally to the department, as well as in national and international efforts to advance the use of the technology and standards.

Biometrics are being used for identification of captured or detained personnel in current theaters of war. Likewise, the Department of Homeland Security now requires biometric (fingerprint) identification of travelers to the U.S. from most countries coming through all major air ports of entry.

But back to information assurance for Defense Department systems and networks. When will we see widespread use of biometrics for this purpose? What’s stopping DoD components, or the Department at large, from using biometrics to enhance information assurance? Is it cost? Complexity? Lack of maturity or trust in the technology? If anyone has or knows of any large-scale projects to implement biometrics on an enterprise level to support information assurance, let Armed With Science know.