Navigation Links
HYPR Corp. Addresses Android Vulnerability That Exposes Ecosystem-wide Biometric Security Challenges
Date:8/12/2015

NEW YORK, Aug. 12, 2015 /PRNewswire/ -- New research unveiled at Black Hat 2015 outlines how hackers can attack Android phones to steal users' fingerprints. Information released today by HYPR Corp. identifies the increasing availability of fingerprint scanners on mobile devices, making the security of this data of utmost concern. To secure biometrics on mobile devices, HYPR Corp. recently released a biometric tokenization platform to augment these convenient authentication systems with strong cryptographic security. More information on this biometric authentication platform is available from HYPR (https://www.hypr.com/biometric-authentication/).

Security concerns identified at HYPR Corp., and findings from the research1 revealed at Black Hat, include:

  • A recent report from Market Research estimated that by 2019, more than half of smartphones will include a fingerprint sensor.
  • Most device manufacturers fail to use available protection to safeguard users' most sensitive biometric data in the Android Trust Zone, an environment that is safely isolated from the operating system.
  • Hackers have found a means to steal victims' fingerprint data due to fingerprints being stored as an image file in an open, world readable, folder.

In order to ensure biometric security, HYPR Corp. advises:

  • Leveraging biometric tokenization to enable the safe transmission of a fingerprint image, or template, to the cloud using trusted public key cryptography.
  • Storing fingerprints as a mathematical representation in a trusted environment, a location separate from a device's operating system.
    • As of late, key players, such as biometric sensor suppliers and mobile device manufacturers, have been behind this approach.
  • Deploying secure processors that are specifically designed for the storage of sensitive data, such as biometrics.

By utilizing state of the art biometric encryption protocols, relying parties can validate signatures in various ways while meeting these four guiding principles of biometric tokenization:

  • No third party should be allowed to centralize storage of biometric credentials.
  • Biometric data should remain isolated from the operating system on a user's device.
  • End users should have full control in choosing what biometric authenticators they will utilize.
  • Relying parties should be able to choose between bring-your-own-device (BYOD) or specialized hardware tokens for authentication in a device agnostic manner.

HYPR Corp. has introduced its biometric tokenization platform to address security with a focus on the financial, government and healthcare sectors. A video overview and demonstration of the HYPR SDK is available here: https://youtu.be/gFJj0-Rag-I

George Avetisov, CEO of HYPR Corp. said:
"Biometric authentication provides a much-needed solution to the problem of insecure passwords, but it is not a panacea. As we have seen, when executed poorly, biometric authentication can put sensitive data at risk. That is why enterprises must ensure they have implemented a robust, multifaceted security solution that ensures biometric signatures and user data is stored safely and isn't transmitted across the Internet. This is where biometric tokenization comes into play."

About HYPR
HYPR is a sector agnostic platform enabling secure biometric authentication. From software developers to enterprises and device manufacturers, we're replacing the use of passwords with advanced biometric cryptography. As an end-to-end solution, HYPR is the fundamental framework for securing the Internet-of-Things. Additional information is available at: https://www.hypr.com/

1 YuLong Zhang, Zhaofeng Chen, Hui Xue and Tao Wei, "Fingerprints on Mobile Devices: Abusing and Leaking," FireEye Labs, August 2015. https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Fingerprints-On-Mobile-Devices-Abusing-And-Leaking-wp.pdf

PR Contact:
Jessica M. Pasko
Nadel Phelan, Inc.
+1 831-440-2412
jessica@nadelphelan.com

Logo - http://photos.prnewswire.com/prnh/20150409/197571LOGO

 


'/>"/>
SOURCE HYPR Corp.
Copyright©2015 PR Newswire.
All rights reserved

Related biology news :

1. HYPR Corp. Launches Industry First Biometric Tokenization Platform
2. HYPR Corp. Expands Biometric Authentication Team with Enterprise All Stars
3. Government Ready Biometric Security Approaching as HYPR Corp. Files FIPS 140-2 Level 3 Validation for Its Proprietary Biometric Token
4. HYPR Corp. Biometric Security Integration Kit Shields Applications and Devices Across the Internet of Things
5. HYPR Corp. Joins the FIDO Alliance
6. Pitt Engineering develops strategic alliance with Lubrizol Corp.
7. Vapor Corp. Unveils E-Cigarette Industrys First Biometric Technology
8. Digital Wallet Choices; PayPal, Google Wallet, Apple Passbook - and Now Wocket Smart Wallet : Who Addresses Issues of Security?
9. New book addresses consequences of drought in arid regions
10. Zynx Health Adds Android Device Support to ZynxCarebook Solution
11. DigitalPersona Announces U.are.U Software Development Kit (SDK) for Android Applications
Post Your Comments:
*Name:
*Comment:
*Email:
(Date:5/16/2017)... , May 16, 2017  Veratad Technologies, LLC ( ... online age and identity verification solutions, announced today they ... Conference 2017, May 15 thru May 17, 2017, in ... and International Trade Center. Identity impacts ... and in today,s quickly evolving digital world, defining identity ...
(Date:5/6/2017)... SINGAPORE , May 5, 2017 ... has just announced a new breakthrough in biometric ... that exploits quantum mechanical properties to perform ... new smart semiconductor material created by Ram Group ... across finance, entertainment, transportation, supply chains and security. ...
(Date:4/19/2017)... 2017 The global military biometrics ... marked by the presence of several large global players. ... five major players - 3M Cogent, NEC Corporation, M2SYS ... nearly 61% of the global military biometric market in ... global military biometrics market boast global presence, which has ...
Breaking Biology News(10 mins):
(Date:8/15/2017)... Wisconsin (PRWEB) , ... August 15, 2017 , ... ... a new family of 6” modular downlights designed to stay tightly sealed and ... including areas where damp and wet location listings just aren't enough, such as: ...
(Date:8/15/2017)... ... August 15, 2017 , ... ... by various biotic and abiotic factors. During this educational webinar, participants will learn ... as well as gain a better understanding of how genomics is important for ...
(Date:8/14/2017)... ... August 14, 2017 , ... Every year, ... researchers in the antibody community have recently come together to address this antibody ... the laboratory. , The team at Thermo Fisher Scientific ...
(Date:8/14/2017)... ... , ... The Conference Forum has confirmed the one-day agenda for ... 6, 2017 at the Marriott Copley Place in Boston, MA. , Returning as program ... Strategy, Pfizer Innovative Research Lab, Pfizer, who leads 19 industry speakers in discussing how ...
Breaking Biology Technology: