SlideShare a Scribd company logo
1 of 24
Download to read offline
Design and Implementation of the Veridium Authenticator:
A Biometric WSO2 Federated Authenticator
John Callahan, CTO
© 2018 Veridium IP Ltd. All Rights Reserved 1
OUR APPROACH
Single-Step Multi-Factor Biometric Authentication
PHONE
What You Have
PIN CODE
What You Know
BIOMETRICS
What You Are
© 2018 Veridium IP Ltd. All Rights Reserved 2
OUTLINE
© 2018 Veridium IP Ltd. All Rights Reserved 3
• Products
VeridiumID
VeridiumAD
4Fingers TouchlessID
• Biometric Authentication
Push notification
QR-code mode
• Configuration
Not covered:
• Conditional MFA via XACML (in WSO IS 5.6+)
• Use with WSO2 API Manager (OAuth2 use cases)
PRODUCTS
Platform Enterprise Plugin Biometrics
© 2018 Veridium IP Ltd. All Rights Reserved 4
VERIDIUMID
© 2018 Veridium IP Ltd. All Rights Reserved 5
Authenticate • Authorize • Access
Extensible Platform
IEEE 2410-2017
Biometric Open Protocol Standard (BOPS)
2410-2017 configuration options
Storage
Matching
Mobile Server
Mobile
✅
(FIDO UAF compliant)
✅
Server ✅ ✅
Shares
(both mobile and server) ✅ ✅
Proprietary and Confidential 7
• VeridiumAD (VAD) is an enterprise plugin that extends VeridiumID (VID)
to Microsoft Active Directory (AD) environments
• VAD can replace passwords for companies using AD and for companies
using Citrix StoreFront and AD
• VAD can replace software or hardware tokens as a second-factor for
enterprises using AD with NetScaler or other VPNs using RADIUS
• Offline login is supported
• VAD is verified as Citrix Ready
VERIDIUMAD
© 2018 Veridium IP Ltd. All Rights Reserved 8
• False rejection rate (FRR) is as low as 2% at a
false acceptance rate (FAR) of 0.1%
• 4 Fingers is one of the most secure biometrics
available
• More secure than Face, Touch ID, or Voice
4 Fingers is reliable in
any environment
4 FINGERS TOUCHLESSID
© 2018 Veridium IP Ltd. All Rights Reserved 9
Integration
© 2018 Veridium IP Ltd. All Rights Reserved 10
PUSH NOTIFICATION MODE
© 2018 Veridium IP Ltd. All Rights Reserved 11
PUSH NOTIFICATION MODE
© 2018 Veridium IP Ltd. All Rights Reserved 12
Proprietary and Confidential 13
© 2018 Veridium IP Ltd. All Rights Reserved 14
QR-CODE MODE
© 2018 Veridium IP Ltd. All Rights Reserved 15
© 2018 Veridium IP Ltd. All Rights Reserved 16
INTEGRATED DEMO
© 2018 Veridium IP Ltd. All Rights Reserved 17
© 2018 Veridium IP Ltd. All Rights Reserved 18
CONFIGURATION
© 2018 Veridium IP Ltd. All Rights Reserved 19
© 2018 Veridium IP Ltd. All Rights Reserved 20
© 2018 Veridium IP Ltd. All Rights Reserved 21
© 2018 Veridium IP Ltd. All Rights Reserved 22
© 2018 Veridium IP Ltd. All Rights Reserved 23
SELECTED AWARDS & RECOGNITION
Winner of the DFS Tech Biometrics
Challenge, Sponsored by the Bill &
Melinda Gates Foundation
ABA 2018 Stevie Silver Winner -
Most Innovative Tech Company of
the Year - Up to 100 Employees
2017 Winner of Innovative Tech of
the Year (Security)
Cyber Defense Magazine 2018
Infosec Awards Best Product –
Multi-Factor Authentication
Fast Company World Changing
Ideas 2018 Finalist
Selected Vendor – Biometric
Authentication Methods in
six 2017 Hype Cycles
Entrepreneurial Company of the
Year - Biometric Authentication
Solutions Industry
KNOW Identity Awards 2018 Finalist
Greatest Social Impact Through
Identity & CEO of the Year
InfoSecurity Products Guide Global
Excellence Awards 2018 Bronze
Winner: Authentication
Sovrin Stewart – Veridium iBeta Independent Accuracy Report
2017 CRN Emerging Vendor in
Security
Certified to match against Peru's
national fingerprint database
© 2018 Veridium IP Ltd. All Rights Reserved
CRADA with NIST Contactless
Fingerprint Capture program (SP
500-305)
Member of the Decentralized
Identity Foundation (DIF) .
C
O
M
IN
G
SO
O
N

More Related Content

What's hot

Best Practices for Productizing APIs with API Management and Automated Testing
Best Practices for Productizing APIs with API Management and Automated TestingBest Practices for Productizing APIs with API Management and Automated Testing
Best Practices for Productizing APIs with API Management and Automated Testing
WSO2
 
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
WSO2
 

What's hot (20)

Open Banking and PSD2: Are your APIs ready for external testing?
Open Banking and PSD2: Are your APIs ready for external testing?Open Banking and PSD2: Are your APIs ready for external testing?
Open Banking and PSD2: Are your APIs ready for external testing?
 
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
 
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
 
APIdays Paris 2019 - Zero Downtime in API Management by Waldemar Rosenfeld, A...
APIdays Paris 2019 - Zero Downtime in API Management by Waldemar Rosenfeld, A...APIdays Paris 2019 - Zero Downtime in API Management by Waldemar Rosenfeld, A...
APIdays Paris 2019 - Zero Downtime in API Management by Waldemar Rosenfeld, A...
 
Best Practices for Productizing APIs with API Management and Automated Testing
Best Practices for Productizing APIs with API Management and Automated TestingBest Practices for Productizing APIs with API Management and Automated Testing
Best Practices for Productizing APIs with API Management and Automated Testing
 
[WSO2 Summit EMEA 2020] Fintech Ecosystems & Consumer Experiences: The Next G...
[WSO2 Summit EMEA 2020] Fintech Ecosystems & Consumer Experiences: The Next G...[WSO2 Summit EMEA 2020] Fintech Ecosystems & Consumer Experiences: The Next G...
[WSO2 Summit EMEA 2020] Fintech Ecosystems & Consumer Experiences: The Next G...
 
[WSO2 Summit APAC 2020] Unified Endpoint Management APIs for Enterprise Devices
[WSO2 Summit APAC 2020] Unified Endpoint Management APIs for Enterprise Devices[WSO2 Summit APAC 2020] Unified Endpoint Management APIs for Enterprise Devices
[WSO2 Summit APAC 2020] Unified Endpoint Management APIs for Enterprise Devices
 
[WSO2 Summit Americas 2020 ] Fintech Ecosystems & Consumer Experiences: The N...
[WSO2 Summit Americas 2020 ] Fintech Ecosystems & Consumer Experiences: The N...[WSO2 Summit Americas 2020 ] Fintech Ecosystems & Consumer Experiences: The N...
[WSO2 Summit Americas 2020 ] Fintech Ecosystems & Consumer Experiences: The N...
 
apidays LIVE London 2021 - Presenting the Kubernetes Browser by Daria Muehlet...
apidays LIVE London 2021 - Presenting the Kubernetes Browser by Daria Muehlet...apidays LIVE London 2021 - Presenting the Kubernetes Browser by Daria Muehlet...
apidays LIVE London 2021 - Presenting the Kubernetes Browser by Daria Muehlet...
 
Invansys Technologies
Invansys TechnologiesInvansys Technologies
Invansys Technologies
 
What's New With WSO2 Open Banking
What's New With WSO2 Open BankingWhat's New With WSO2 Open Banking
What's New With WSO2 Open Banking
 
apidays LIVE Singapore 2021 - A cloud-native approach to open banking in acti...
apidays LIVE Singapore 2021 - A cloud-native approach to open banking in acti...apidays LIVE Singapore 2021 - A cloud-native approach to open banking in acti...
apidays LIVE Singapore 2021 - A cloud-native approach to open banking in acti...
 
API-first Integration for Microservices
API-first Integration for MicroservicesAPI-first Integration for Microservices
API-first Integration for Microservices
 
[WSO2 Summit APAC 2020] Automating an Integrated API Supply Chain Using a Clo...
[WSO2 Summit APAC 2020] Automating an Integrated API Supply Chain Using a Clo...[WSO2 Summit APAC 2020] Automating an Integrated API Supply Chain Using a Clo...
[WSO2 Summit APAC 2020] Automating an Integrated API Supply Chain Using a Clo...
 
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
 
apidays LIVE London 2021 - Banking APIs Evolution by Hector Arias, BBVA
apidays LIVE London 2021 - Banking APIs Evolution by Hector Arias, BBVAapidays LIVE London 2021 - Banking APIs Evolution by Hector Arias, BBVA
apidays LIVE London 2021 - Banking APIs Evolution by Hector Arias, BBVA
 
An Entry Point to Impactful Open Banking Architecture
An Entry Point to Impactful Open Banking ArchitectureAn Entry Point to Impactful Open Banking Architecture
An Entry Point to Impactful Open Banking Architecture
 
[WSO2Con EU 2018] Simplifying Digital Transformation with an "API Aware" Mindset
[WSO2Con EU 2018] Simplifying Digital Transformation with an "API Aware" Mindset[WSO2Con EU 2018] Simplifying Digital Transformation with an "API Aware" Mindset
[WSO2Con EU 2018] Simplifying Digital Transformation with an "API Aware" Mindset
 
API-Centric Hybrid Integration Platform for Microservices or ESB Style Archit...
API-Centric Hybrid Integration Platform for Microservices or ESB Style Archit...API-Centric Hybrid Integration Platform for Microservices or ESB Style Archit...
API-Centric Hybrid Integration Platform for Microservices or ESB Style Archit...
 
apidays LIVE Australia 2021 - Quantum Duality of “API as a business and a tec...
apidays LIVE Australia 2021 - Quantum Duality of “API as a business and a tec...apidays LIVE Australia 2021 - Quantum Duality of “API as a business and a tec...
apidays LIVE Australia 2021 - Quantum Duality of “API as a business and a tec...
 

Similar to [WSO2Con USA 2018] Design and Implementation of the Veridium Authenticator: A Biometric WSO2 Federated Authenticator

Similar to [WSO2Con USA 2018] Design and Implementation of the Veridium Authenticator: A Biometric WSO2 Federated Authenticator (20)

The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
 
Eliminating Passwords with Biometrics for Identity Access Management Webinar
Eliminating Passwords with Biometrics for Identity Access Management WebinarEliminating Passwords with Biometrics for Identity Access Management Webinar
Eliminating Passwords with Biometrics for Identity Access Management Webinar
 
Introduction to the FIDO Alliance: Vision & Status
Introduction to the FIDO Alliance: Vision & StatusIntroduction to the FIDO Alliance: Vision & Status
Introduction to the FIDO Alliance: Vision & Status
 
FIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical Overview
 
FIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical Overview
 
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance
FIDO & PSD2 – Achieving Strong Customer Authentication ComplianceFIDO & PSD2 – Achieving Strong Customer Authentication Compliance
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance
 
2016-Mar-03 Leppitsch in Auckland meetup
2016-Mar-03 Leppitsch in Auckland meetup2016-Mar-03 Leppitsch in Auckland meetup
2016-Mar-03 Leppitsch in Auckland meetup
 
Indigo vision company overview 2018
Indigo vision company overview 2018Indigo vision company overview 2018
Indigo vision company overview 2018
 
Managing Identity without Boundaries
Managing Identity without BoundariesManaging Identity without Boundaries
Managing Identity without Boundaries
 
FIDO Masterclass
FIDO MasterclassFIDO Masterclass
FIDO Masterclass
 
Beyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer AuthenticationBeyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer Authentication
 
Webinar: Securing IoT with FIDO Authentication
Webinar: Securing IoT with FIDO AuthenticationWebinar: Securing IoT with FIDO Authentication
Webinar: Securing IoT with FIDO Authentication
 
Deploying FIDO Authentication - Business Considerations
Deploying FIDO Authentication  - Business ConsiderationsDeploying FIDO Authentication  - Business Considerations
Deploying FIDO Authentication - Business Considerations
 
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
FIDO Authentication in Korea: Early Adoption & Rapid InnovationFIDO Authentication in Korea: Early Adoption & Rapid Innovation
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
 
Using FIDO Authenticator for IoT Devices
Using FIDO Authenticator for IoT DevicesUsing FIDO Authenticator for IoT Devices
Using FIDO Authenticator for IoT Devices
 
FIDO2 and Microsoft
FIDO2 and MicrosoftFIDO2 and Microsoft
FIDO2 and Microsoft
 
Identiverse - Microservices Security
Identiverse - Microservices SecurityIdentiverse - Microservices Security
Identiverse - Microservices Security
 
[WSO2 Summit EMEA 2020] Unified Endpoint Management APIs for Enterprise Devices
[WSO2 Summit EMEA 2020] Unified Endpoint Management APIs for Enterprise Devices[WSO2 Summit EMEA 2020] Unified Endpoint Management APIs for Enterprise Devices
[WSO2 Summit EMEA 2020] Unified Endpoint Management APIs for Enterprise Devices
 
Technical Principles of FIDO Authentication
Technical Principles of FIDO AuthenticationTechnical Principles of FIDO Authentication
Technical Principles of FIDO Authentication
 
Technical Principles of FIDO Authentication
Technical Principles of FIDO AuthenticationTechnical Principles of FIDO Authentication
Technical Principles of FIDO Authentication
 

More from WSO2

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Fueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected ProductsFueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected Products
WSO2
 
A Reference Methodology for Agile Digital Businesses
 A Reference Methodology for Agile Digital Businesses A Reference Methodology for Agile Digital Businesses
A Reference Methodology for Agile Digital Businesses
WSO2
 

More from WSO2 (20)

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Accelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessAccelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with Platformless
 
How to Create a Service in Choreo
How to Create a Service in ChoreoHow to Create a Service in Choreo
How to Create a Service in Choreo
 
Ballerina Tech Talk - May 2023
Ballerina Tech Talk - May 2023Ballerina Tech Talk - May 2023
Ballerina Tech Talk - May 2023
 
Platform Strategy to Deliver Digital Experiences on Azure
Platform Strategy to Deliver Digital Experiences on AzurePlatform Strategy to Deliver Digital Experiences on Azure
Platform Strategy to Deliver Digital Experiences on Azure
 
GartnerITSymSessionSlides.pdf
GartnerITSymSessionSlides.pdfGartnerITSymSessionSlides.pdf
GartnerITSymSessionSlides.pdf
 
[Webinar] How to Create an API in Minutes
[Webinar] How to Create an API in Minutes[Webinar] How to Create an API in Minutes
[Webinar] How to Create an API in Minutes
 
Modernizing the Student Journey with Ethos Identity
Modernizing the Student Journey with Ethos IdentityModernizing the Student Journey with Ethos Identity
Modernizing the Student Journey with Ethos Identity
 
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
 
CIO Summit Berlin 2022.pptx.pdf
CIO Summit Berlin 2022.pptx.pdfCIO Summit Berlin 2022.pptx.pdf
CIO Summit Berlin 2022.pptx.pdf
 
Delivering New Digital Experiences Fast - Introducing Choreo
Delivering New Digital Experiences Fast - Introducing ChoreoDelivering New Digital Experiences Fast - Introducing Choreo
Delivering New Digital Experiences Fast - Introducing Choreo
 
Fueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected ProductsFueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected Products
 
A Reference Methodology for Agile Digital Businesses
 A Reference Methodology for Agile Digital Businesses A Reference Methodology for Agile Digital Businesses
A Reference Methodology for Agile Digital Businesses
 
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
 
Lessons from the pandemic - From a single use case to true transformation
 Lessons from the pandemic - From a single use case to true transformation Lessons from the pandemic - From a single use case to true transformation
Lessons from the pandemic - From a single use case to true transformation
 
Adding Liveliness to Banking Experiences
Adding Liveliness to Banking ExperiencesAdding Liveliness to Banking Experiences
Adding Liveliness to Banking Experiences
 
Building a Future-ready Bank
Building a Future-ready BankBuilding a Future-ready Bank
Building a Future-ready Bank
 
WSO2 API Manager Community Call - November 2021
WSO2 API Manager Community Call - November 2021WSO2 API Manager Community Call - November 2021
WSO2 API Manager Community Call - November 2021
 
[API World ] - Managing Asynchronous APIs
[API World ] - Managing Asynchronous APIs[API World ] - Managing Asynchronous APIs
[API World ] - Managing Asynchronous APIs
 
[API World 2021 ] - Understanding Cloud Native Deployment
[API World 2021 ] - Understanding Cloud Native Deployment[API World 2021 ] - Understanding Cloud Native Deployment
[API World 2021 ] - Understanding Cloud Native Deployment
 

Recently uploaded

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Recently uploaded (20)

Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 

[WSO2Con USA 2018] Design and Implementation of the Veridium Authenticator: A Biometric WSO2 Federated Authenticator

  • 1. Design and Implementation of the Veridium Authenticator: A Biometric WSO2 Federated Authenticator John Callahan, CTO © 2018 Veridium IP Ltd. All Rights Reserved 1
  • 2. OUR APPROACH Single-Step Multi-Factor Biometric Authentication PHONE What You Have PIN CODE What You Know BIOMETRICS What You Are © 2018 Veridium IP Ltd. All Rights Reserved 2
  • 3. OUTLINE © 2018 Veridium IP Ltd. All Rights Reserved 3 • Products VeridiumID VeridiumAD 4Fingers TouchlessID • Biometric Authentication Push notification QR-code mode • Configuration Not covered: • Conditional MFA via XACML (in WSO IS 5.6+) • Use with WSO2 API Manager (OAuth2 use cases)
  • 4. PRODUCTS Platform Enterprise Plugin Biometrics © 2018 Veridium IP Ltd. All Rights Reserved 4
  • 5. VERIDIUMID © 2018 Veridium IP Ltd. All Rights Reserved 5 Authenticate • Authorize • Access Extensible Platform
  • 6. IEEE 2410-2017 Biometric Open Protocol Standard (BOPS)
  • 7. 2410-2017 configuration options Storage Matching Mobile Server Mobile ✅ (FIDO UAF compliant) ✅ Server ✅ ✅ Shares (both mobile and server) ✅ ✅ Proprietary and Confidential 7
  • 8. • VeridiumAD (VAD) is an enterprise plugin that extends VeridiumID (VID) to Microsoft Active Directory (AD) environments • VAD can replace passwords for companies using AD and for companies using Citrix StoreFront and AD • VAD can replace software or hardware tokens as a second-factor for enterprises using AD with NetScaler or other VPNs using RADIUS • Offline login is supported • VAD is verified as Citrix Ready VERIDIUMAD © 2018 Veridium IP Ltd. All Rights Reserved 8
  • 9. • False rejection rate (FRR) is as low as 2% at a false acceptance rate (FAR) of 0.1% • 4 Fingers is one of the most secure biometrics available • More secure than Face, Touch ID, or Voice 4 Fingers is reliable in any environment 4 FINGERS TOUCHLESSID © 2018 Veridium IP Ltd. All Rights Reserved 9
  • 10. Integration © 2018 Veridium IP Ltd. All Rights Reserved 10
  • 11. PUSH NOTIFICATION MODE © 2018 Veridium IP Ltd. All Rights Reserved 11
  • 12. PUSH NOTIFICATION MODE © 2018 Veridium IP Ltd. All Rights Reserved 12
  • 14. © 2018 Veridium IP Ltd. All Rights Reserved 14
  • 15. QR-CODE MODE © 2018 Veridium IP Ltd. All Rights Reserved 15
  • 16. © 2018 Veridium IP Ltd. All Rights Reserved 16
  • 17. INTEGRATED DEMO © 2018 Veridium IP Ltd. All Rights Reserved 17
  • 18. © 2018 Veridium IP Ltd. All Rights Reserved 18
  • 19. CONFIGURATION © 2018 Veridium IP Ltd. All Rights Reserved 19
  • 20. © 2018 Veridium IP Ltd. All Rights Reserved 20
  • 21. © 2018 Veridium IP Ltd. All Rights Reserved 21
  • 22. © 2018 Veridium IP Ltd. All Rights Reserved 22
  • 23. © 2018 Veridium IP Ltd. All Rights Reserved 23
  • 24. SELECTED AWARDS & RECOGNITION Winner of the DFS Tech Biometrics Challenge, Sponsored by the Bill & Melinda Gates Foundation ABA 2018 Stevie Silver Winner - Most Innovative Tech Company of the Year - Up to 100 Employees 2017 Winner of Innovative Tech of the Year (Security) Cyber Defense Magazine 2018 Infosec Awards Best Product – Multi-Factor Authentication Fast Company World Changing Ideas 2018 Finalist Selected Vendor – Biometric Authentication Methods in six 2017 Hype Cycles Entrepreneurial Company of the Year - Biometric Authentication Solutions Industry KNOW Identity Awards 2018 Finalist Greatest Social Impact Through Identity & CEO of the Year InfoSecurity Products Guide Global Excellence Awards 2018 Bronze Winner: Authentication Sovrin Stewart – Veridium iBeta Independent Accuracy Report 2017 CRN Emerging Vendor in Security Certified to match against Peru's national fingerprint database © 2018 Veridium IP Ltd. All Rights Reserved CRADA with NIST Contactless Fingerprint Capture program (SP 500-305) Member of the Decentralized Identity Foundation (DIF) . C O M IN G SO O N