Logo preloader Xtension

Biometrics and mobile security

The topic of the latest Samsung Knox Meetup (8 November 2018 at Warsaw Spire) was ''Mobile Security''. One of the most important topics was the issue of ''biometrics''. Let's take a closer look at it.
Samsung
Biometricsignature
Knox

Why biometrics?

During the Samsung Knox Meetup event, Paweł Śniecikowski from Samsung presented basic concepts related to biometrics. He explained why biometrics is so useful and what its applications can be. Thanks to biometrics, we do not need additional knowledge (e.g. remembering countless passwords to various devices), there is no need for us to have any cards or additional devices. Biometric methods are based on what/who the user is. This makes them so simple and intuitive to use. A handwritten signature (known as a biometric) stands out from the other methods because of its very high capture rate comparable to that of face biometrics. However, the face, like the fingerprint, is not very resistant to the most common spoof-proof attacks, while the biometric signature is not forgeable and, with appropriate security methods, inextricably linked to the document and therefore impossible to change or "inject". 

 

Another difference between a handwritten signature and other types of biometrics was also pointed out. Unlike biometrics based on physiological traits, in the case of signature biometrics the biometric is not stored on the device. The encrypted biometric goes directly into the document and the key to read it is held offline by a trusted third party. Finally, Paweł Śniecikowski presented the process of verification of a handwritten electronic signature, which at the stage of court proceedings is based on the knowledge of an expert (graphologist). During the presentation also tools supporting the expert in the analysis of signatures were shown. These tools allow the visual comparison of signatures, all their parameters (position in time, speed of signing, pressure) and even the visual reproduction of the signing itself. Thanks to them, the graphologist's task is greatly facilitated.

 

Behavioural biometrics

Biometric methods, are broadly divided into two groups: 

  • based on physiological traits (e.g. fingerprint, iris, DNA)
  • Behavioural (e.g. handwritten signature, the way you walk or type on a keyboard). 

During the second lecture, Mateusz Chrobok of Digital Fingerprints introduced the audience to the world of behavioural biometrics, in particular explaining how to prevent unauthorised use of systems using biometrics based on the way people type on the keyboard. Interestingly, the speaker asserted that behavioural biometrics, unlike physiological biometrics, are not sensitive data.

 

Biometric signature in business

The last presentation of the evening concerned handwritten and qualified electronic signatures in business applications. Artur Miękina from Asseco Data Systems began his presentation with the legal aspects of electronic signatures. He pointed out that the signature itself is not a legal entity - it must always be linked to a specific content. The signed document, on the other hand, is an independent entity, which can produce a specific legal effect and independent evidence in court proceedings. The main part of the presentation concerned the case of application of a combination of two solutions, i.e. handwritten electronic signature and qualified signature.

 

Not so long ago, in order to obtain a qualified signature, a client had to sign a paper declaration at an identity confirmation point. Today, paper is no longer necessary. A PDF document signed on a mobile device is sufficient. The Certum representative signs the document with his own qualified signature, and the client (who has not yet been issued a qualified signature) signs with a handwritten electronic signature on a tablet - i.e. his own unique biometric signature. I would like to mention that I also use such a mix of solutions in my business relations. Let me quote a situation from last week. When signing the acceptance protocol, ordered from a subcontractor, I used a handwritten signature in our signaturiX system, while our partner used a qualified Certum signature. What's more, signaturiX is integrated with Certum's SimplySign qualified signature. This allows any handwritten signature created using our system to be qualifiedly stamped and time-stamped.

 

At the end of the lecture, it was pointed out that paperless is not a product, but a solution that requires a prior audit of business processes. At this point I was reminded of a visit to a financial institution, whose CEO said: "One page of paper-printed contract costs us only 2 cents... paperless has no business case". Such a statement implies a lack of understanding of the true cost of paper. In the whole paperless process, the most costly element is its handling, i.e. the time spent on printing, scanning, archiving, receiving and transporting paper documents. Thanks to solutions created in the spirit of paperless we are able to significantly reduce these costs.

Publication date: 27 November 2018
Author: Marcin Sikorski
Read the next articles
Mobile
Certum
Security
Biometric signature - the future of business
Mobile
Certum
Security
Unrivalled moment.js
Mobile
Certum
Security
signaturiX. Sign on your smartphone!
Let's create a unique project together
Write to us

Xtension Sp z o.o.

ul. Opacka 12

80-338 Gdańsk

 

office@xtension.pl

 

LinkedIn