
Evaluating multi-factor authentication solutions requires a look at three critical areas – the security and scalability of the technology, hurdles to user adoption, and the total cost (including internal costs) to deploy and support the system. Below is an analysis of typical biometric authentication systems and PhoneFactor’s phone-based authentication solution with biometric voiceprint capabilities.
Because of the cost and complexity of most biometric systems, use of biometric authentication is generally limited to ultra high security applications (e.g. the defense industry). Historically, biometric systems have been a mixed bag when it comes to availability, compatibility, and security. Training is a significant issue and logistics are perhaps more difficult than with any other two-factor solution.
Deployment involves collecting the biometric data to compare against, which can be a daunting task for users and IT departments. In addition, most biometric authentication solutions rely on fingerprint readers, retinal scanners, or other biometric devices, which are attached to the pc or laptop. The cost and IT resources required to purchase, deploy, and maintain biometric readers creates an often insurmountable challenge.
In addition to being expensive and time consuming to deploy and maintain, both the login credentials and the biometric data are being collected and transmitted through a single channel, making it vulnerable to emerging threats, such as man-in-the-middle attacks. As the sophistication of attacks continues to increase, Out-of-Band authentication, which utilizes a separate channel for the additional authentication factors, is becoming widely recognized as a best practice for multi-factor authentication.
| Technology |
|
| User Adoption |
|
| Cost |
|
By leveraging an existing voice channel, PhoneFactor simultaneously verifies something you have, your telephone, and something you are, your voiceprint, for the second and third factors of authentication. With PhoneFactor, users simply login with their username and password – just like they do today. Instantly the user’s phone rings. They answer and speak their passphrase to complete their login. As such, it works with any phone, anywhere in the world. With no devices, such as biometric readers, to deploy, and an automated enrollment process for end users, PhoneFactor can be rapidly deployed to large numbers of users.
By combining out-of-band biometric authentication with real-time fraud alerts, PhoneFactor offers the strongest level of security on the market today. The PhoneFactor platform relies exclusively on the telephone network for the additional factors of authentication which ensures protection against keystroke loggers and man-in-the-middle attacks. PhoneFactor can be used to verify specific high-risk transactions, so even if the user’s authenticated session has been hijacked, their transactions are protected. Not only does PhoneFactor prevent unauthorized logins and transactions, it notifies you instantly if a user’s credentials have been compromised and an attack is in progress. Other forms of biometric authentication are simply not capable of alerting you to an attack.
PhoneFactor requires very little effort to implement and virtually no ongoing support. PhoneFactor offers instant integration with all leading business systems and synchronizes with AD and LDAP Servers for centralized user management. Easy, automated enrollment and self-service options are available through the phone and web, which helps to significantly minimize overhead. It is easy to use, requiring no end user training.
| Technology |
|
| User Adoption |
|
| Cost |
|
PhoneFactor’s phone-based authentication service with biometric voice authentication offers a greater level of security and a better user experience than other biometric authentication solutions. Learn more about PhoneFactor’s Biometric Authentication, try the PhoneFactor Demo or Download the Free Version.