Safer mobile transactions

Opinion
Jul 5, 20113 mins

Last week (“More on biometrics“) I recommended “biometric recognition as well as using passwords and SMS codes” for more secure mobile banking transactions. Long time reader Patrick O’Kane (he’s chief architect for identity and access management services at Unisys) pointed me to a solution that does just that.

IdentityX, from Reston, Va.’s Daon, claims that using your smartphone, it can enable you to securely establish your identity through a combination of encryption, PIN entry, location-based technology, and biometrics such as voice, face and palm image matching. The company further claims that IdentityX is a fully mobile, private and cost-effective solution that allows you to set the level of security for each type of transaction — thereby tuning the balance of convenience and security.

ANALYSIS: Mobile payments in US: Creative chaos or just chaos?

Is it any good? Well, Daon was recently named the winner in the Cyber Security & Authentication category for the American Technology Awards, which bestows the only “Best Of” awards that recognize all technology products and services for the technology industry. That award was attributed to IdentityX.

So, how does it work?

As described by Daon, IdentityX is comprised of both the IdentityX Server component and the IdentityX Authenticator application on the user’s mobile device. When the user initiates a transaction on the service provider’s website (e.g., transferring money through online banking), a request is made to the IdentityX Server for verification. The IdentityX Server determines which verification methods are required (e.g., some combination of biometrics, passwords and/or GPS location) based on the type of request from the service provider and makes the appropriate request to the IdentityX Authenticator application on the mobile phone. The service provider can set multiple levels of authentications based on the value of the transaction (or other factors, of course).

The IdentityX Authenticator application runs on the user’s mobile device. It is responsible for receiving authentication requests from the server and displaying them in a transaction list for the user to act upon. When the user selects a transaction, the IdentityX Authenticator application presents a GUI to capture whatever authentication credentials are required, whether PIN and/or some form of biometric. Once the user submits their data, the Authenticator sends this information to the server for comparison to the information already on record for that individual.

Depending upon how the IdentityX solution is configured, a successful validation may be directly communicated to the Service Provider, or the IdentityX Server could return a one time use password to the Authenticator for display. The user would then be required to enter this number on the Service Provider’s application to provide proof of a successful IdentityX authentication.

What could be easier, yet very secure? If you need high security for mobile transactions, check out IdentityX.