May 20, 2008 11:30 AM PDT

Fujitsu gives biometrics a hand

For years, biometric finger scanners have been used in ATMs and at the cash register. But there are problems with finger scanners. Researchers have demonstrated how a flat photograph or molded fingertip can easily fool these devices into giving a false approval. And while face recognition is improving, especially 3D facial mapping, these devices aren't yet in wide use today.

Fujitsu PalmSecure is another option. Already in use in hospitals and government offices, the device reads the hand's vein pattern using near-infrared light. On this week's Security Bites podcast, I spoke with Joel Hagberg, vice president of marketing and business development at Fujitsu Computer Products of America, about the technology.

Below is a transcript of part of my interview. The entire podcast can be heard here.

Hagberg: Fujitsu has worked in biometrics for many years with fingerprint sensors and scanners--both in the manufacturing and the marketing of those technologies. We work with the corporate clients and government clients of Fujitsu Limited, and there has been an interest in moving the level of security up and beyond what fingerprints were able to provide. When you look at the fingerprint sensors and fingerprint biometrics, there is a strong opportunity to utilize those for a range of handheld or low-cost devices where individual usage carries a lot of security threat. It's not a major concern as is maybe other types of computer systems or physical sites and locations where fingerprints can easily be compromised. If you look at the range of university professors looking to spoof different types of biometrics, they are able to take fingerprint records and etch a fingerprint into a piece of latex and then the sensors or touch pads, you know, read air gaps. Having someone that has built an artificial finger is able to easily compromise most fingerprint sensors in the market. Our customers are looking at ways to overcome that potential threat with a higher level of biometric authentication.

Q: What is that method that you came up with?

Hagberg: Fujitsu looked at a range of products and determined that vascular authentication--reading vein patterns and specifically in the Palm--is best. Our product is called PalmSecure, and what it does it takes a snapshot of blood moving through your vein. Looking into it from three-letter agencies and the government which are very high in security, department of defense applications, this says something. They call it Liveness Detection, which means you have a live body with biometric authentication. Many other biometric authentications can be fooled without live bodies or without live body parts. Fingerprint and iris scans are examples. You'll see in many modern-day movies or television shows like 24, where people use body parts to overcome and bypass biometric security. With our product you're looking at moving the deoxidized hemoglobin that's moving through the vein pattern. You have a near-infrared signal that comes up from a sensor; it reflects off of the hand. The blue blood that's moving without oxygen through your hand actually absorbs the light and what's emitted back is the pattern, the vein pattern. It absorbs that light that's emitted from the sensor.

Q: Ultimately, though, this is still an image, is it not?

Hagberg: Yes, that's correct, it's an image. But it's the image of moving blood, not of a static pattern. So there are many of professors in the universities in Japan who have been making a practice of trying to spoof biometrics, and they've been unsuccessful here. They've broken every other biometric except for our vascular vein PalmSecure Product.

Q: But with all biometric devices there is a variance factor. The scan that I do today isn't going to be exactly the scan that I do tomorrow, is that correct?

Hagberg: Well, I think with anything you take it from kind of a multiple snapshot scan of the pattern in your hand. Fujitsu's research into this over the last 10 years--of working with the product and in general--has shown that there is no variance in your vein pattern without catastrophic injury--meaning losing part of you hand. If you have a cut on the external surface of your hand or other damage externally, it doesn't affect the blood flow through the vein pattern. Your muscle or structure of your hand is developed from childhood and continues as you move to adulthood. Those veins have settled into place. So the vein pattern signature that you see when you register stays the same. The vein pattern from number of years ago when I registered is no different than when I walk through the facility today to get into our building.

Q: I guess what I was after--I know with certain retina scans you have to fix your eye on a certain dot and then it takes a only scan of a particular region. So you're looking at the entire hand--you're not looking at a subpart of the palm?

Hagberg: Correct. That's one of the differences. We looked at iris scan. We looked at facial recognition software and other types of voice recognition software in our thoughts about moving to a higher level modality of biometrics. We determined the iris scan--just from a peer use standpoint, as you highlighted--you're constantly concerned about the pattern or the particular area in the iris you're looking at but you have a use concern. I met with some very high-level executives within IT departments of the U.S. security agencies in the last month and I asked them how many of them were comfortable having their iris scanned everyday. Not one hand went up. So, that's what we found in research in Japan. With both government and corporate employees, they wondered what happens to your eye when it's scanned everyday for the next five years. Even though you'll say it's harmless, they don't feel comfortable about it. The other thing that we also uncovered in our focus groups and customer discussions was contact. When you look at fingerprint or you look at any other even iris you're either touching a pad with a fingerprint or you're leaning against something, a pad for an iris, to position your eye correctly. Say the person in front of you is sweating, they're leaning against this pad or touch that pad or they're leaving SARS or avian flu, you know, on that device for you to touch and your eye is one of the most sensitive areas in terms of the transmission of disease; so are your hands. Touching things with your hands or getting close to touching things with your eyes is a concern for transmission of disease. Having a contact-less product like ours where you are holding your hand above the device has satisfied that hygiene and kind of transference of potential contagious disease concerns that we uncovered in our research. We've addressed it where I think iris and fingerprints still have a long way to go to address those concerns.

Recent posts from Defense in Depth
Column: Raising Cain at Black Hat
Black Hat 2008: Notes from the field
Column: Finally, ID fraud protection that works
Column: Will you be ditching your antivirus app anytime soon?
A real simple answer to password protection
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.