Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

5/30/2013
04:06 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Startup To Offer 'Human' Authentication

Identify Security Software Inc. will launch next week and preview new technology that eschews passwords and biometrics

A new security startup is building a new authentication model with what it describes as a "human" approach that doesn't use biometrics, passwords or passcodes.

Identify Security Software Inc. -- which will emerge from stealth mode on Monday -- plans to roll out an authentication product in the next nine months or so that uses a camera that recognizes users by their physical presence, physical attributes, thermal image, facial expressions, and authorized activity, in lieu of traditional passwords and other authentication methods. The system verifies that the user is who he or she says he is via the camera and the known information and attributes of the user, and does so multiple times per second.

The identifyME product currently under development is basically a dynamic access control system that watches the user in action and ensures he or she executes only authorized tasks and access. Identify Security Software describes the approach as "person, place and purpose."

"Our aim is human recognition by application," says Andre Limarenko, president and chief operating officer of the Boca Raton, Fla.-based startup. The system works with all types of client machines, including mobile devices, he says.

Unlike biometric technology that still requires software, identifyME relies on the camera's recognition of the user on the other end of the endpoint. The company plans to offer its own highly secure camera for sensitive environments, such as utilities or hospitals, but users can employ their machines' existing cameras as well, which also communicate with the product, for less sensitive operations.

So when an end user sits in front of his machine or grabs his smartphone, the camera records his physical attributes and location. "The moment you walk away, the system sees you're gone, so it shuts" down the session, he says.

If a user falls for a targeted phishing attack or malware hits his machine, the application won't allow activity that doesn't fit with the user's authorized duties, location and other attributes. "We don't stop malware from getting in, but we do stop anyone from entering [from outside] to get" data out of the network, he says.

Limarenko says the camera basically determines the level of security a user has access to. "If you have mission-critical applications for designs, you won't be looking at it on your iPhone. If you want access to it, you go to a secure location where your PC is," he says.

The user data and authorization is handled on a server in the network or in the cloud that stores the facial recognition, thermal sensing, and GPS data on users. "The secret sauce that we bring is the 'glue' that links all those elements together plus a change on the user information repository being in more of a dictionary, less of a database, which doesn't offer backdoors to hackers," according to a description on the company's website.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
J-Lo
50%
50%
J-Lo,
User Rank: Apprentice
6/8/2013 | 6:51:21 PM
re: Startup To Offer 'Human' Authentication
Kelly, how different is this app from face recognition software available in Android smart phones?
Tedlschroeder
50%
50%
Tedlschroeder,
User Rank: Apprentice
6/13/2013 | 6:32:35 PM
re: Startup To Offer 'Human' Authentication
I'd like to know how it solves the problem with the Android face recognition when the light is "wrong". My Android doesn't even see me when the light is too low and when it's super sunny it doesn't have enough contrast to see me either.
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7964
PUBLISHED: 2020-01-24
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
CVE-2020-5224
PUBLISHED: 2020-01-24
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability, the sess...
CVE-2020-7052
PUBLISHED: 2020-01-24
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
CVE-2014-4172
PUBLISHED: 2020-01-24
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service paramet...
CVE-2013-1597
PUBLISHED: 2020-01-24
A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials.