SlideShare a Scribd company logo
Design and Implementation of the Veridium Authenticator:
A Biometric WSO2 Federated Authenticator
John Callahan, CTO
© 2018 Veridium IP Ltd. All Rights Reserved 1
OUR APPROACH
Single-Step Multi-Factor Biometric Authentication
PHONE
What You Have
PIN CODE
What You Know
BIOMETRICS
What You Are
© 2018 Veridium IP Ltd. All Rights Reserved 2
OUTLINE
© 2018 Veridium IP Ltd. All Rights Reserved 3
• Products
VeridiumID
VeridiumAD
4Fingers TouchlessID
• Biometric Authentication
Push notification
QR-code mode
• Configuration
Not covered:
• Conditional MFA via XACML (in WSO IS 5.6+)
• Use with WSO2 API Manager (OAuth2 use cases)
PRODUCTS
Platform Enterprise Plugin Biometrics
© 2018 Veridium IP Ltd. All Rights Reserved 4
VERIDIUMID
© 2018 Veridium IP Ltd. All Rights Reserved 5
Authenticate • Authorize • Access
Extensible Platform
IEEE 2410-2017
Biometric Open Protocol Standard (BOPS)
2410-2017 configuration options
Storage
Matching
Mobile Server
Mobile
✅
(FIDO UAF compliant)
✅
Server ✅ ✅
Shares
(both mobile and server) ✅ ✅
Proprietary and Confidential 7
• VeridiumAD (VAD) is an enterprise plugin that extends VeridiumID (VID)
to Microsoft Active Directory (AD) environments
• VAD can replace passwords for companies using AD and for companies
using Citrix StoreFront and AD
• VAD can replace software or hardware tokens as a second-factor for
enterprises using AD with NetScaler or other VPNs using RADIUS
• Offline login is supported
• VAD is verified as Citrix Ready
VERIDIUMAD
© 2018 Veridium IP Ltd. All Rights Reserved 8
• False rejection rate (FRR) is as low as 2% at a
false acceptance rate (FAR) of 0.1%
• 4 Fingers is one of the most secure biometrics
available
• More secure than Face, Touch ID, or Voice
4 Fingers is reliable in
any environment
4 FINGERS TOUCHLESSID
© 2018 Veridium IP Ltd. All Rights Reserved 9
Integration
© 2018 Veridium IP Ltd. All Rights Reserved 10
PUSH NOTIFICATION MODE
© 2018 Veridium IP Ltd. All Rights Reserved 11
PUSH NOTIFICATION MODE
© 2018 Veridium IP Ltd. All Rights Reserved 12
Proprietary and Confidential 13
© 2018 Veridium IP Ltd. All Rights Reserved 14
QR-CODE MODE
© 2018 Veridium IP Ltd. All Rights Reserved 15
© 2018 Veridium IP Ltd. All Rights Reserved 16
INTEGRATED DEMO
© 2018 Veridium IP Ltd. All Rights Reserved 17
© 2018 Veridium IP Ltd. All Rights Reserved 18
CONFIGURATION
© 2018 Veridium IP Ltd. All Rights Reserved 19
© 2018 Veridium IP Ltd. All Rights Reserved 20
© 2018 Veridium IP Ltd. All Rights Reserved 21
© 2018 Veridium IP Ltd. All Rights Reserved 22
© 2018 Veridium IP Ltd. All Rights Reserved 23
SELECTED AWARDS & RECOGNITION
Winner of the DFS Tech Biometrics
Challenge, Sponsored by the Bill &
Melinda Gates Foundation
ABA 2018 Stevie Silver Winner -
Most Innovative Tech Company of
the Year - Up to 100 Employees
2017 Winner of Innovative Tech of
the Year (Security)
Cyber Defense Magazine 2018
Infosec Awards Best Product –
Multi-Factor Authentication
Fast Company World Changing
Ideas 2018 Finalist
Selected Vendor – Biometric
Authentication Methods in
six 2017 Hype Cycles
Entrepreneurial Company of the
Year - Biometric Authentication
Solutions Industry
KNOW Identity Awards 2018 Finalist
Greatest Social Impact Through
Identity & CEO of the Year
InfoSecurity Products Guide Global
Excellence Awards 2018 Bronze
Winner: Authentication
Sovrin Stewart – Veridium iBeta Independent Accuracy Report
2017 CRN Emerging Vendor in
Security
Certified to match against Peru's
national fingerprint database
© 2018 Veridium IP Ltd. All Rights Reserved
CRADA with NIST Contactless
Fingerprint Capture program (SP
500-305)
Member of the Decentralized
Identity Foundation (DIF) .
C
O
M
IN
G
SO
O
N

More Related Content

PDF
[WSO2Con USA 2018] CIAM @ IDEXX: Changing the Auth Engine In-flight
PDF
[APIdays INTERFACE 2021] Programming the Cloud through APIs
PDF
[WSO2Con EU 2018] API-driven Integration with WSO2 at Schneider Electric
PDF
[APIdays INTERFACE 2021] Authentication and Authorization Best Practices for ...
PDF
[2021 Somos Summit] - Rethinking Identity Access Management and The Rise of t...
PDF
[WSO2Con EU 2018] The Hybrid Integration Platform: Can You Be in Business Wit...
PDF
Fintech Primitives - Wealth Management - MF Pro - Distributor
PDF
Which ap is which business models_ a real-world guide for banks in sri lanka
[WSO2Con USA 2018] CIAM @ IDEXX: Changing the Auth Engine In-flight
[APIdays INTERFACE 2021] Programming the Cloud through APIs
[WSO2Con EU 2018] API-driven Integration with WSO2 at Schneider Electric
[APIdays INTERFACE 2021] Authentication and Authorization Best Practices for ...
[2021 Somos Summit] - Rethinking Identity Access Management and The Rise of t...
[WSO2Con EU 2018] The Hybrid Integration Platform: Can You Be in Business Wit...
Fintech Primitives - Wealth Management - MF Pro - Distributor
Which ap is which business models_ a real-world guide for banks in sri lanka

What's hot (20)

PDF
Open Banking and PSD2: Are your APIs ready for external testing?
PDF
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
PDF
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
PDF
APIdays Paris 2019 - Zero Downtime in API Management by Waldemar Rosenfeld, A...
PDF
Best Practices for Productizing APIs with API Management and Automated Testing
PDF
[WSO2 Summit EMEA 2020] Fintech Ecosystems & Consumer Experiences: The Next G...
PDF
[WSO2 Summit APAC 2020] Unified Endpoint Management APIs for Enterprise Devices
PDF
[WSO2 Summit Americas 2020 ] Fintech Ecosystems & Consumer Experiences: The N...
PDF
apidays LIVE London 2021 - Presenting the Kubernetes Browser by Daria Muehlet...
PPS
Invansys Technologies
PDF
What's New With WSO2 Open Banking
PDF
apidays LIVE Singapore 2021 - A cloud-native approach to open banking in acti...
PDF
API-first Integration for Microservices
PDF
[WSO2 Summit APAC 2020] Automating an Integrated API Supply Chain Using a Clo...
PDF
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
PDF
apidays LIVE London 2021 - Banking APIs Evolution by Hector Arias, BBVA
PDF
An Entry Point to Impactful Open Banking Architecture
PDF
[WSO2Con EU 2018] Simplifying Digital Transformation with an "API Aware" Mindset
PDF
API-Centric Hybrid Integration Platform for Microservices or ESB Style Archit...
PDF
apidays LIVE Australia 2021 - Quantum Duality of “API as a business and a tec...
Open Banking and PSD2: Are your APIs ready for external testing?
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
APIdays Paris 2019 - Zero Downtime in API Management by Waldemar Rosenfeld, A...
Best Practices for Productizing APIs with API Management and Automated Testing
[WSO2 Summit EMEA 2020] Fintech Ecosystems & Consumer Experiences: The Next G...
[WSO2 Summit APAC 2020] Unified Endpoint Management APIs for Enterprise Devices
[WSO2 Summit Americas 2020 ] Fintech Ecosystems & Consumer Experiences: The N...
apidays LIVE London 2021 - Presenting the Kubernetes Browser by Daria Muehlet...
Invansys Technologies
What's New With WSO2 Open Banking
apidays LIVE Singapore 2021 - A cloud-native approach to open banking in acti...
API-first Integration for Microservices
[WSO2 Summit APAC 2020] Automating an Integrated API Supply Chain Using a Clo...
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
apidays LIVE London 2021 - Banking APIs Evolution by Hector Arias, BBVA
An Entry Point to Impactful Open Banking Architecture
[WSO2Con EU 2018] Simplifying Digital Transformation with an "API Aware" Mindset
API-Centric Hybrid Integration Platform for Microservices or ESB Style Archit...
apidays LIVE Australia 2021 - Quantum Duality of “API as a business and a tec...
Ad

Similar to [WSO2Con USA 2018] Design and Implementation of the Veridium Authenticator: A Biometric WSO2 Federated Authenticator (19)

PDF
Eliminating Passwords with Biometrics for Identity Access Management Webinar
PDF
The Password Is Dead: An Argument for Multifactor Biometric Authentication
PDF
Secure Mobile Banking
PDF
The 10 most trusted authentication solution providers of 2021
PDF
Identity as a Services in a Mobile World - David Harding CTO IWSinc
PDF
Top Biometric Identifiers: Risks & Rewards
PDF
Identiy Authentication White Paper
PDF
The State of FIDO
PDF
Biometric Trends for 2017 Webinar
PDF
#MFSummit2016 Secure: Mind the gap strengthening the information security model
PDF
Identive | Press Release | Identive Introduces TouchSecure® OpenAccess Wall M...
PDF
The State of FIDO
PDF
What Is Biometric Authentication? A Complete Overview | Enterprise Wired
PPTX
Financial services 20150503
PPTX
FIDO Alliance Vision and Updates
PDF
2018 12-07 tokyo-seminar Brett McDowell
PDF
Linas Eriksonas, Market for mobile biometrics
PPTX
FIDO Masterclass
PPTX
Introduction to the FIDO Alliance: Vision & Status
Eliminating Passwords with Biometrics for Identity Access Management Webinar
The Password Is Dead: An Argument for Multifactor Biometric Authentication
Secure Mobile Banking
The 10 most trusted authentication solution providers of 2021
Identity as a Services in a Mobile World - David Harding CTO IWSinc
Top Biometric Identifiers: Risks & Rewards
Identiy Authentication White Paper
The State of FIDO
Biometric Trends for 2017 Webinar
#MFSummit2016 Secure: Mind the gap strengthening the information security model
Identive | Press Release | Identive Introduces TouchSecure® OpenAccess Wall M...
The State of FIDO
What Is Biometric Authentication? A Complete Overview | Enterprise Wired
Financial services 20150503
FIDO Alliance Vision and Updates
2018 12-07 tokyo-seminar Brett McDowell
Linas Eriksonas, Market for mobile biometrics
FIDO Masterclass
Introduction to the FIDO Alliance: Vision & Status
Ad

More from WSO2 (20)

PDF
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
PDF
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
PDF
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
PDF
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
PDF
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
PDF
Platformless Modernization with Choreo.pdf
PDF
Application Modernization with Choreo for the BFSI Sector
PDF
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
PDF
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
PPTX
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
PPTX
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
PPTX
WSO2Con 2025 - Building Secure Customer Experience Apps
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
PPTX
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
PPTX
WSO2Con 2025 - Architecting Cloud-Native Applications
PDF
Mastering Intelligent Digital Experiences with Platformless Modernization
PDF
Accelerate Enterprise Software Engineering with Platformless
PDF
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
Platformless Modernization with Choreo.pdf
Application Modernization with Choreo for the BFSI Sector
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - Architecting Cloud-Native Applications
Mastering Intelligent Digital Experiences with Platformless Modernization
Accelerate Enterprise Software Engineering with Platformless
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation

Recently uploaded (20)

PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Approach and Philosophy of On baking technology
PPT
Teaching material agriculture food technology
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
A Presentation on Artificial Intelligence
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PPTX
MYSQL Presentation for SQL database connectivity
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Cloud computing and distributed systems.
PPTX
Programs and apps: productivity, graphics, security and other tools
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Unlocking AI with Model Context Protocol (MCP)
Approach and Philosophy of On baking technology
Teaching material agriculture food technology
Per capita expenditure prediction using model stacking based on satellite ima...
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
A Presentation on Artificial Intelligence
MIND Revenue Release Quarter 2 2025 Press Release
Chapter 3 Spatial Domain Image Processing.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
NewMind AI Weekly Chronicles - August'25-Week II
MYSQL Presentation for SQL database connectivity
The Rise and Fall of 3GPP – Time for a Sabbatical?
Machine learning based COVID-19 study performance prediction
Cloud computing and distributed systems.
Programs and apps: productivity, graphics, security and other tools
The AUB Centre for AI in Media Proposal.docx
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx

[WSO2Con USA 2018] Design and Implementation of the Veridium Authenticator: A Biometric WSO2 Federated Authenticator

  • 1. Design and Implementation of the Veridium Authenticator: A Biometric WSO2 Federated Authenticator John Callahan, CTO © 2018 Veridium IP Ltd. All Rights Reserved 1
  • 2. OUR APPROACH Single-Step Multi-Factor Biometric Authentication PHONE What You Have PIN CODE What You Know BIOMETRICS What You Are © 2018 Veridium IP Ltd. All Rights Reserved 2
  • 3. OUTLINE © 2018 Veridium IP Ltd. All Rights Reserved 3 • Products VeridiumID VeridiumAD 4Fingers TouchlessID • Biometric Authentication Push notification QR-code mode • Configuration Not covered: • Conditional MFA via XACML (in WSO IS 5.6+) • Use with WSO2 API Manager (OAuth2 use cases)
  • 4. PRODUCTS Platform Enterprise Plugin Biometrics © 2018 Veridium IP Ltd. All Rights Reserved 4
  • 5. VERIDIUMID © 2018 Veridium IP Ltd. All Rights Reserved 5 Authenticate • Authorize • Access Extensible Platform
  • 6. IEEE 2410-2017 Biometric Open Protocol Standard (BOPS)
  • 7. 2410-2017 configuration options Storage Matching Mobile Server Mobile ✅ (FIDO UAF compliant) ✅ Server ✅ ✅ Shares (both mobile and server) ✅ ✅ Proprietary and Confidential 7
  • 8. • VeridiumAD (VAD) is an enterprise plugin that extends VeridiumID (VID) to Microsoft Active Directory (AD) environments • VAD can replace passwords for companies using AD and for companies using Citrix StoreFront and AD • VAD can replace software or hardware tokens as a second-factor for enterprises using AD with NetScaler or other VPNs using RADIUS • Offline login is supported • VAD is verified as Citrix Ready VERIDIUMAD © 2018 Veridium IP Ltd. All Rights Reserved 8
  • 9. • False rejection rate (FRR) is as low as 2% at a false acceptance rate (FAR) of 0.1% • 4 Fingers is one of the most secure biometrics available • More secure than Face, Touch ID, or Voice 4 Fingers is reliable in any environment 4 FINGERS TOUCHLESSID © 2018 Veridium IP Ltd. All Rights Reserved 9
  • 10. Integration © 2018 Veridium IP Ltd. All Rights Reserved 10
  • 11. PUSH NOTIFICATION MODE © 2018 Veridium IP Ltd. All Rights Reserved 11
  • 12. PUSH NOTIFICATION MODE © 2018 Veridium IP Ltd. All Rights Reserved 12
  • 14. © 2018 Veridium IP Ltd. All Rights Reserved 14
  • 15. QR-CODE MODE © 2018 Veridium IP Ltd. All Rights Reserved 15
  • 16. © 2018 Veridium IP Ltd. All Rights Reserved 16
  • 17. INTEGRATED DEMO © 2018 Veridium IP Ltd. All Rights Reserved 17
  • 18. © 2018 Veridium IP Ltd. All Rights Reserved 18
  • 19. CONFIGURATION © 2018 Veridium IP Ltd. All Rights Reserved 19
  • 20. © 2018 Veridium IP Ltd. All Rights Reserved 20
  • 21. © 2018 Veridium IP Ltd. All Rights Reserved 21
  • 22. © 2018 Veridium IP Ltd. All Rights Reserved 22
  • 23. © 2018 Veridium IP Ltd. All Rights Reserved 23
  • 24. SELECTED AWARDS & RECOGNITION Winner of the DFS Tech Biometrics Challenge, Sponsored by the Bill & Melinda Gates Foundation ABA 2018 Stevie Silver Winner - Most Innovative Tech Company of the Year - Up to 100 Employees 2017 Winner of Innovative Tech of the Year (Security) Cyber Defense Magazine 2018 Infosec Awards Best Product – Multi-Factor Authentication Fast Company World Changing Ideas 2018 Finalist Selected Vendor – Biometric Authentication Methods in six 2017 Hype Cycles Entrepreneurial Company of the Year - Biometric Authentication Solutions Industry KNOW Identity Awards 2018 Finalist Greatest Social Impact Through Identity & CEO of the Year InfoSecurity Products Guide Global Excellence Awards 2018 Bronze Winner: Authentication Sovrin Stewart – Veridium iBeta Independent Accuracy Report 2017 CRN Emerging Vendor in Security Certified to match against Peru's national fingerprint database © 2018 Veridium IP Ltd. All Rights Reserved CRADA with NIST Contactless Fingerprint Capture program (SP 500-305) Member of the Decentralized Identity Foundation (DIF) . C O M IN G SO O N