FIDO Alliance © 2019 - Austin FIDO seminar Jan 20191
FIDO AUTHENTICATION IN THE
SHIFTING EUROPEAN
REGULATORY LANDSCAPE
ALAIN MARTIN
CO-CHAIR FIDO EUROPE WG
VP STRATEGIC PARTNERSHIPS - GEMALTO
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20192
AGENDA
• How FIDO helps with the SCA requirements under PSD2
• Compliance
• The customer journey
• How FIDO helps with GDPR
• The need for strong authentication
• The privacy by design
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20193
FIDO, PSD2 AND THE
CUSTOMER JOURNEY
Open
APIs
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20194
PSD2 IN A FEW WORDS
• New Access to Account mandate  Open APIs
• New Strong Customer Authentication mandate
• New Third Party Provider (TPP) roles :
Open
APIs
Open
APIs
Payment
execution
Open
APIs
Open
APIs
Open
APIs
Gives
consent
Payment Initiation
Service Provider (PISP)
Account Information
Service Provider (AISP)
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20195
THE CUSTOMER JOURNEY
KEY SUCCESS FACTOR FOR THE ROLL OUT OF
PSD2 IN EUROPE
Authentication models have been created
and… much debated by the stakeholders
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20196
AUTHENTICATION MODELS
• Redirection
AISPAISP ASPSP
Authenticate
authentication
AISP AISPASPSP
Authenticate
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20197
AUTHENTICATION MODELS
• Decoupled
• An Out of Band model
PISP
Merchant Merchant
Authenti-
cate
ASPSP
authentication
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20198
POTENTIAL UX ISSUES IN THE REDIRECTION/DECOUPLED MODELS
• In account aggregation use cases
ASPSP C
Sign in with OTP
ASPSP C
Login Go
AISP
ASPSP A
App
AISP
ASPSP B
token
ASPSP C
OTP generator
ASPSP B
Login
Pswd Go
FIDO Alliance © 2019 - Austin FIDO seminar Jan 20199
POTENTIAL UX ISSUES IN THE REDIRECTION MODEL
• In payment initiation use cases
PISP
ASPSP
Login
Merchant
Merchant
Merchant
PISP
Bank 1
Bank 2
Bank 3
Select Bank
Select
account
ASPSP
Approve
transaction
ASPSP
ASPSP
OTP:
123456
Enter OTP:
******
Pswd
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201910
FIDO SIMPLIFIES THE CUSTOMER JOURNEY
PISP
Merchant
ASPSP
Authorise
payment?
ASPSP
Login
Pswd
OTP:
******
ASPSP
Enter OTP:
******
FIDO
Authenticator
PISP
Merchant
Merchant
Merchant
1 step
authentication
3 step
authentication
With FIDO With OTP by SMS
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201911
WHAT THE REGULATOR AND STAKEHOLDERS SAY
• The European Commission
• Added article 32-3 in the RTS on “obstacles”  ASPSP may have to provide
alternatives to Redirection if not properly implemented
• EBA opinion paper (June 2018)
• Redirection not an obstacle per se
• Implementation is key, whichever the model, for a satisfactory user journey
• The Fintechs
• Some happy with redirection, some wanting no friction in the user
experience
• The Berlin Group
• Are working on 2 additional authentication models: Embedded and
Delegated
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201912
ALTERNATIVE AUTHENTICATION MODELS
• Embedded
• Delegated
AISP
authentication
AISPAISP AISP
Authenticate
AISPAISP AISP
Authenticate
authentication
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201913
EMBEDDED MODEL = AUTHENTICATION BY THE BANK
• Not in line with
customer education
• Difference with phishing
attacks
• Similar to Apple Pay
• Requires enrolment
• Requires trust in local
user verification
 the FIDO approach
TPPBank OTP
generator Enter Pswd: ******
Enter OTP: ******
Pswd, OTP
TPP
Authen-
ticate
Bank keys
generated in
device
Challenge/
Response
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201914
DELEGATED MODEL: FIDO/EMVCO COLLABORATION ON
3DSECURE
Merchant
Directory
Service
FIDO
Authentication
3D Secure message
Device
ACS 3
1
2 Authenticator metadata
Risk assessment
Step up
authentication
4
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201915
FIDO COMPLIANCE TO PSD2/RTS ON STRONG CUSTOMER
AUTHENTICATION
• Based on multi-factor authentication
 [RTS] Articles 4, 6, 7, 8
• Protection of the “security elements”
 [RTS] Articles 22, 23, 25
• Separation of execution environments
 [RTS] Article 9
• Support of dynamic linking
 [RTS] Article 5
… a detailed analysis of FIDO compliance is published on https://fidoalliance.org/
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201916
FIDO AND THE GDPR
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201917
GDPR – GENERAL DATA PROTECTION REGULATION
• Applies since 25 May 2018
• Very large fines for infringement: Up to €20,000,000 or 4% total
worldwide turnover
• Data protection
• Consent of data subject
• Data subject rights
• Adequacy, relevance, etc. of data collection
• …
The subject for FIDO
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201918
PROTECTION AGAINST UNAUTHORIZED ACCESS
• Level of security to be appropriate to the risk
FIDO recommendation:
implement strong
authentication to prevent
phishing and hacking
Data subject right
to access, modify,
etc.
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201919
RECENT HEALTHCARE DATA BREACHES
July 2018 – Singapore
“Hackers stole data of PM Lee and 1.5
million patients in 'major cyberattack'
on SingHealth”
October 2018 – USA
“US Center for Medicare & Medicaid Services
says 75,000 individuals' files accessed in
data breach”
July 2018 – USA
“1.4M records breached in UnityPoint Health
phishing attack”
July 2018 – USA
“Patient data exposed for months
after phishing attack on Sunspire”
August 2018 - USA
“3 phishing hacks breach 20,000
Catawba Valley patient records”
20
SPECIAL CATEGORIES OF DATA
• Processing of this data prohibited,
unless allowed in specific cases
• If allowed, requires
• Explicit consent
• Suitable safeguards to protect personal
data
• Data protection impact assessment
• Assessment of the measures, safeguards
and mechanisms envisaged for
mitigating risk and ensuring the
protection of personal data
Special
Categories
of data
Political opinions
Racial or ethnic
origin
Healthcare
Sexual life
Religious
beliefs
Biometric data
FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019
21
USER CONSENT
• Data subject must give consent to processing of his/her personal data
• For special categories: explicit consent
FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019
FIDO recommendation:
Strong authentication is a good practice to properly
identify the data subject providing consent
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201922
THE CONTROLLER SHOULD BE ABLE TO DEMONSTRATE
THIS CONSENT
• FIDO authenticators are capable of signing
transaction data
• Server message can include consent information
• Signed response is a non forgeable proof
• Can be used in case of dispute
Do you agree to
providing your
health data to
ABCHealth ?
Authenticate to
confirm
23
EXEMPTION
• GDPR does not apply to the processing of personal data by a natural
person in the course of a purely personal or household activity
• Biometrics on smartphone can be exempted
• e.g. French Data Protection Authority (CNIL) exemption IF ON DEVICE STORAGE
AND MATCHING
• If remote storage and matching, there must be an impact assessment
FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201924
FIDO’S USE OF BIOMETRICS
• With FIDO, biometrics can only be stored and matched on a consumer’s
device
• FIDO prohibit biometrics from being stored or matched in servers
 No Data Protection Impact Assessment for the use of biometric data
25
DATA PROTECTION BY DESIGN PRINCIPLE
• Proactive
• Embedded from the start in design
• For authentication solutions, this would mean, by design:
Protection of user authentication credentials and biometric data
Protection against phishing or MITM attacks
FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201926
FIDO EMBRACES PROTECTION/PRIVACY-BY-DESIGN
Based on
public key
cryptography
No server-side
shared secrets
Keys
generated
and stored
on device
Verification of
web origin
/channel id
Biometrics, if used,
never leave device
No link-ability
between services or
accounts
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201927
IN SUMMARY
In light of the heavy fines and ever increasing attacks from hackers
 Service providers should consider replacing passwords with
stronger means of authentication
Password
Data protection
measures
FIDO Alliance © 2019 - Austin FIDO seminar Jan 201928
RESOURCES:
PSD2
HTTPS://FIDOALLIANCE.ORG/HOW_FIDO_MEETS_THE_RTS_REQUIREMENTS/
HTTPS://FIDOALLIANCE.ORG/.../FIDO-PSD2_CUSTOMER_JOURNEY_WHITE_PAPER.PDF
GDPR
HTTPS://FIDOALLIANCE.ORG/.../FIDO_AUTHENTICATION_AND_GDPR_WHITE_PAPER_
MAY2018-1.PDF
HTTPS://FIDOALLIANCE.ORG/EVENT/WEBINAR-FIDO-AUTHENTICATION-GDPR/

More Related Content

PDF
FIDO & Mobile Connect
PDF
Javelin Research's State of Strong Authentication 2019 Report Webinar
PDF
Deployment Snapshot from Japan: NTT DOCOMO, Yahoo! Japan
PDF
Lifecycle Consideration for Security Key Deployments
PDF
European Regulation And The Need For Strong Customer Authentication
PDF
Strong Customer Authentication & Biometrics
PPTX
The State of Strong Authentication
PPTX
FIDO Alliance Vision and Updates
FIDO & Mobile Connect
Javelin Research's State of Strong Authentication 2019 Report Webinar
Deployment Snapshot from Japan: NTT DOCOMO, Yahoo! Japan
Lifecycle Consideration for Security Key Deployments
European Regulation And The Need For Strong Customer Authentication
Strong Customer Authentication & Biometrics
The State of Strong Authentication
FIDO Alliance Vision and Updates

What's hot (20)

PDF
Beyond Passwords: FIDO and the Future of User Authentication
PDF
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance
PDF
FIDO Support for the GDPR
PDF
Integrating FIDO & Federation Protocols
PDF
FIDO and the Future of User Authentication
PDF
Technical Principles of FIDO Authentication
PDF
Beyond Passwords: FIDO & the Future of Consumer Authentication
PDF
Current Trends Related to Mobile Network Operators & FIDO SCA Adoption
PPTX
FIDO Masterclass
PPTX
Fido Technical Overview
PDF
Biometrics for Payment Authentication
PPTX
FIDO Alliance Webinar: Catch Up WIth FIDO
PDF
FIDO UAF Adoption in Hong Kong
PPTX
A First Step to a World without Passwords
PDF
FIDO Authentication in a Mobile Network
PPTX
Introduction to FIDO's Identity Verification & Binding Initiative
PDF
FIDO Authentication and GDPR
PDF
FIDO and Adaptive Authentication
PPTX
Introduction to FIDO: A New Model for Authentication
PDF
Digital Identity In Government
Beyond Passwords: FIDO and the Future of User Authentication
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance
FIDO Support for the GDPR
Integrating FIDO & Federation Protocols
FIDO and the Future of User Authentication
Technical Principles of FIDO Authentication
Beyond Passwords: FIDO & the Future of Consumer Authentication
Current Trends Related to Mobile Network Operators & FIDO SCA Adoption
FIDO Masterclass
Fido Technical Overview
Biometrics for Payment Authentication
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO UAF Adoption in Hong Kong
A First Step to a World without Passwords
FIDO Authentication in a Mobile Network
Introduction to FIDO's Identity Verification & Binding Initiative
FIDO Authentication and GDPR
FIDO and Adaptive Authentication
Introduction to FIDO: A New Model for Authentication
Digital Identity In Government
Ad

Similar to FIDO Authentication in the Shifting Regulatory Landscape (20)

PDF
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
PDF
Beyond Passwords: FIDO and the Future of User Authentication
PDF
GDPR(一般データ保護規則)とFIDO標準について
PPTX
FIDO and Government: How Policymakers and Regulators are Thinking About Auth...
PPTX
2019 FIDO Seoul Seminar - Moving Beyond Passwords
PDF
2019 FIDO Tokyo Seminar - Welcome Keynote Andrew Shikiar
PDF
FIDO Authentication in Europe the Momentum and Opportunities
PDF
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
PDF
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...
PDF
Deployment Case Study: Login.gov & FIDO2
PDF
apidays New York 2022 - Discussing the significance of API standardization, D...
PDF
Introduction to FIDO Authentication
PDF
Introduction to FIDO Biometric Authentication
PPTX
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
PPTX
Yet another cybersecurity framework for Financial Services
PDF
201201 b innopay presentation hft
PDF
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
PDF
The Value of FIDO Alliance Membership
PPTX
FIDO Webinar – A New Model for Online Authentication: Implications for Policy...
PPTX
Introduction to FIDO Alliance
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
Beyond Passwords: FIDO and the Future of User Authentication
GDPR(一般データ保護規則)とFIDO標準について
FIDO and Government: How Policymakers and Regulators are Thinking About Auth...
2019 FIDO Seoul Seminar - Moving Beyond Passwords
2019 FIDO Tokyo Seminar - Welcome Keynote Andrew Shikiar
FIDO Authentication in Europe the Momentum and Opportunities
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...
Deployment Case Study: Login.gov & FIDO2
apidays New York 2022 - Discussing the significance of API standardization, D...
Introduction to FIDO Authentication
Introduction to FIDO Biometric Authentication
FIDO Authentication in Korea: Early Adoption & Rapid Innovation
Yet another cybersecurity framework for Financial Services
201201 b innopay presentation hft
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
The Value of FIDO Alliance Membership
FIDO Webinar – A New Model for Online Authentication: Implications for Policy...
Introduction to FIDO Alliance
Ad

More from FIDO Alliance (20)

PPTX
Securing Account Lifecycles in the Age of Deepfakes.pptx
PPTX
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
PPTX
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
PPTX
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
PPTX
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
PPTX
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
PPTX
FIDO Alliance Seminar State of Passkeys.pptx
PPTX
FIDO Munich Seminar: FIDO Tech Principles.pptx
PPTX
FIDO Munich Seminar: Securing Smart Car.pptx
PPTX
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
PPTX
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
PPTX
FIDO Munich Seminar Workforce Authentication Case Study.pptx
PPTX
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
PPTX
FIDO Munich Seminar FIDO Automotive Apps.pptx
PPTX
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
PPTX
FIDO Munich Seminar Introduction to FIDO.pptx
PPTX
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
PPTX
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
PPTX
UX Webinar Series: Aligning Authentication Experiences with Business Goals
PDF
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
Securing Account Lifecycles in the Age of Deepfakes.pptx
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Munich Seminar: FIDO Tech Principles.pptx
FIDO Munich Seminar: Securing Smart Car.pptx
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
FIDO Munich Seminar Workforce Authentication Case Study.pptx
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
FIDO Munich Seminar FIDO Automotive Apps.pptx
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
FIDO Munich Seminar Introduction to FIDO.pptx
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
UX Webinar Series: Aligning Authentication Experiences with Business Goals
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf

Recently uploaded (20)

PDF
Divorce Attorney Chicago – Guiding You Through Every Step
PPTX
A-BREIF-SUMMARY-OF-THE-FIRST-VOYAGE-AROUND-THE-WORLD-BY-MAGELLAN-BY-ANTONIO-P...
PDF
Common Estate Planning Mistakes to Avoid in Wisconsin
PDF
UNIT- 5 & 6_Industrial Relations PPT.pdf
DOCX
Political Science Election Part One.docx
PDF
UNIT-4 Partnership Act_1932.pdf (Applicable for India)
PDF
Case Digest_ G.R. No. 45081 - Angara vs. Electoral Commission.pdf
PPTX
The-Specific-Relief-AmendmentAct2018.pptx
PPTX
Unit 2: LOCAL SELF GOVERNANCE AND VILLAGES
PDF
Dangers In The Oil Field: Helping Injured Workers Hold Oil And Gas Companies ...
PDF
Case Digest_ G.R. No. 46076 - People vs. Rosenthal.pdf
PDF
UNIT-4 - Limited Liability Partnership_2008.pdf
PPTX
white collar crime .pptx power function and punishment
PDF
UNIT-3-COMPANIES ACT-2013.pdf (Applicable for India)
PDF
Brown and Beige Vintage Classic Illustration Paper Project History Presenta_2...
PPTX
ADR-Lecture-ten-1 North South University
PDF
Legal Strategics for Startup Success Contracts.pdf
PDF
UNIT-7_ IPR_Final PPT.pdf (Applicable for India)
PPTX
Cyber Bullying & harassment on social media.pptx
PDF
Principles and Concepts Applicable on Election Law.pdf
Divorce Attorney Chicago – Guiding You Through Every Step
A-BREIF-SUMMARY-OF-THE-FIRST-VOYAGE-AROUND-THE-WORLD-BY-MAGELLAN-BY-ANTONIO-P...
Common Estate Planning Mistakes to Avoid in Wisconsin
UNIT- 5 & 6_Industrial Relations PPT.pdf
Political Science Election Part One.docx
UNIT-4 Partnership Act_1932.pdf (Applicable for India)
Case Digest_ G.R. No. 45081 - Angara vs. Electoral Commission.pdf
The-Specific-Relief-AmendmentAct2018.pptx
Unit 2: LOCAL SELF GOVERNANCE AND VILLAGES
Dangers In The Oil Field: Helping Injured Workers Hold Oil And Gas Companies ...
Case Digest_ G.R. No. 46076 - People vs. Rosenthal.pdf
UNIT-4 - Limited Liability Partnership_2008.pdf
white collar crime .pptx power function and punishment
UNIT-3-COMPANIES ACT-2013.pdf (Applicable for India)
Brown and Beige Vintage Classic Illustration Paper Project History Presenta_2...
ADR-Lecture-ten-1 North South University
Legal Strategics for Startup Success Contracts.pdf
UNIT-7_ IPR_Final PPT.pdf (Applicable for India)
Cyber Bullying & harassment on social media.pptx
Principles and Concepts Applicable on Election Law.pdf

FIDO Authentication in the Shifting Regulatory Landscape

  • 1. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20191 FIDO AUTHENTICATION IN THE SHIFTING EUROPEAN REGULATORY LANDSCAPE ALAIN MARTIN CO-CHAIR FIDO EUROPE WG VP STRATEGIC PARTNERSHIPS - GEMALTO
  • 2. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20192 AGENDA • How FIDO helps with the SCA requirements under PSD2 • Compliance • The customer journey • How FIDO helps with GDPR • The need for strong authentication • The privacy by design
  • 3. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20193 FIDO, PSD2 AND THE CUSTOMER JOURNEY
  • 4. Open APIs FIDO Alliance © 2019 - Austin FIDO seminar Jan 20194 PSD2 IN A FEW WORDS • New Access to Account mandate  Open APIs • New Strong Customer Authentication mandate • New Third Party Provider (TPP) roles : Open APIs Open APIs Payment execution Open APIs Open APIs Open APIs Gives consent Payment Initiation Service Provider (PISP) Account Information Service Provider (AISP)
  • 5. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20195 THE CUSTOMER JOURNEY KEY SUCCESS FACTOR FOR THE ROLL OUT OF PSD2 IN EUROPE Authentication models have been created and… much debated by the stakeholders
  • 6. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20196 AUTHENTICATION MODELS • Redirection AISPAISP ASPSP Authenticate authentication AISP AISPASPSP Authenticate
  • 7. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20197 AUTHENTICATION MODELS • Decoupled • An Out of Band model PISP Merchant Merchant Authenti- cate ASPSP authentication
  • 8. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20198 POTENTIAL UX ISSUES IN THE REDIRECTION/DECOUPLED MODELS • In account aggregation use cases ASPSP C Sign in with OTP ASPSP C Login Go AISP ASPSP A App AISP ASPSP B token ASPSP C OTP generator ASPSP B Login Pswd Go
  • 9. FIDO Alliance © 2019 - Austin FIDO seminar Jan 20199 POTENTIAL UX ISSUES IN THE REDIRECTION MODEL • In payment initiation use cases PISP ASPSP Login Merchant Merchant Merchant PISP Bank 1 Bank 2 Bank 3 Select Bank Select account ASPSP Approve transaction ASPSP ASPSP OTP: 123456 Enter OTP: ****** Pswd
  • 10. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201910 FIDO SIMPLIFIES THE CUSTOMER JOURNEY PISP Merchant ASPSP Authorise payment? ASPSP Login Pswd OTP: ****** ASPSP Enter OTP: ****** FIDO Authenticator PISP Merchant Merchant Merchant 1 step authentication 3 step authentication With FIDO With OTP by SMS
  • 11. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201911 WHAT THE REGULATOR AND STAKEHOLDERS SAY • The European Commission • Added article 32-3 in the RTS on “obstacles”  ASPSP may have to provide alternatives to Redirection if not properly implemented • EBA opinion paper (June 2018) • Redirection not an obstacle per se • Implementation is key, whichever the model, for a satisfactory user journey • The Fintechs • Some happy with redirection, some wanting no friction in the user experience • The Berlin Group • Are working on 2 additional authentication models: Embedded and Delegated
  • 12. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201912 ALTERNATIVE AUTHENTICATION MODELS • Embedded • Delegated AISP authentication AISPAISP AISP Authenticate AISPAISP AISP Authenticate authentication
  • 13. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201913 EMBEDDED MODEL = AUTHENTICATION BY THE BANK • Not in line with customer education • Difference with phishing attacks • Similar to Apple Pay • Requires enrolment • Requires trust in local user verification  the FIDO approach TPPBank OTP generator Enter Pswd: ****** Enter OTP: ****** Pswd, OTP TPP Authen- ticate Bank keys generated in device Challenge/ Response
  • 14. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201914 DELEGATED MODEL: FIDO/EMVCO COLLABORATION ON 3DSECURE Merchant Directory Service FIDO Authentication 3D Secure message Device ACS 3 1 2 Authenticator metadata Risk assessment Step up authentication 4
  • 15. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201915 FIDO COMPLIANCE TO PSD2/RTS ON STRONG CUSTOMER AUTHENTICATION • Based on multi-factor authentication  [RTS] Articles 4, 6, 7, 8 • Protection of the “security elements”  [RTS] Articles 22, 23, 25 • Separation of execution environments  [RTS] Article 9 • Support of dynamic linking  [RTS] Article 5 … a detailed analysis of FIDO compliance is published on https://fidoalliance.org/
  • 16. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201916 FIDO AND THE GDPR
  • 17. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201917 GDPR – GENERAL DATA PROTECTION REGULATION • Applies since 25 May 2018 • Very large fines for infringement: Up to €20,000,000 or 4% total worldwide turnover • Data protection • Consent of data subject • Data subject rights • Adequacy, relevance, etc. of data collection • … The subject for FIDO
  • 18. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201918 PROTECTION AGAINST UNAUTHORIZED ACCESS • Level of security to be appropriate to the risk FIDO recommendation: implement strong authentication to prevent phishing and hacking Data subject right to access, modify, etc.
  • 19. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201919 RECENT HEALTHCARE DATA BREACHES July 2018 – Singapore “Hackers stole data of PM Lee and 1.5 million patients in 'major cyberattack' on SingHealth” October 2018 – USA “US Center for Medicare & Medicaid Services says 75,000 individuals' files accessed in data breach” July 2018 – USA “1.4M records breached in UnityPoint Health phishing attack” July 2018 – USA “Patient data exposed for months after phishing attack on Sunspire” August 2018 - USA “3 phishing hacks breach 20,000 Catawba Valley patient records”
  • 20. 20 SPECIAL CATEGORIES OF DATA • Processing of this data prohibited, unless allowed in specific cases • If allowed, requires • Explicit consent • Suitable safeguards to protect personal data • Data protection impact assessment • Assessment of the measures, safeguards and mechanisms envisaged for mitigating risk and ensuring the protection of personal data Special Categories of data Political opinions Racial or ethnic origin Healthcare Sexual life Religious beliefs Biometric data FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019
  • 21. 21 USER CONSENT • Data subject must give consent to processing of his/her personal data • For special categories: explicit consent FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019 FIDO recommendation: Strong authentication is a good practice to properly identify the data subject providing consent
  • 22. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201922 THE CONTROLLER SHOULD BE ABLE TO DEMONSTRATE THIS CONSENT • FIDO authenticators are capable of signing transaction data • Server message can include consent information • Signed response is a non forgeable proof • Can be used in case of dispute Do you agree to providing your health data to ABCHealth ? Authenticate to confirm
  • 23. 23 EXEMPTION • GDPR does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity • Biometrics on smartphone can be exempted • e.g. French Data Protection Authority (CNIL) exemption IF ON DEVICE STORAGE AND MATCHING • If remote storage and matching, there must be an impact assessment FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019
  • 24. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201924 FIDO’S USE OF BIOMETRICS • With FIDO, biometrics can only be stored and matched on a consumer’s device • FIDO prohibit biometrics from being stored or matched in servers  No Data Protection Impact Assessment for the use of biometric data
  • 25. 25 DATA PROTECTION BY DESIGN PRINCIPLE • Proactive • Embedded from the start in design • For authentication solutions, this would mean, by design: Protection of user authentication credentials and biometric data Protection against phishing or MITM attacks FIDO Alliance © 2019 - Austin FIDO seminar Jan 2019
  • 26. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201926 FIDO EMBRACES PROTECTION/PRIVACY-BY-DESIGN Based on public key cryptography No server-side shared secrets Keys generated and stored on device Verification of web origin /channel id Biometrics, if used, never leave device No link-ability between services or accounts
  • 27. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201927 IN SUMMARY In light of the heavy fines and ever increasing attacks from hackers  Service providers should consider replacing passwords with stronger means of authentication Password Data protection measures
  • 28. FIDO Alliance © 2019 - Austin FIDO seminar Jan 201928 RESOURCES: PSD2 HTTPS://FIDOALLIANCE.ORG/HOW_FIDO_MEETS_THE_RTS_REQUIREMENTS/ HTTPS://FIDOALLIANCE.ORG/.../FIDO-PSD2_CUSTOMER_JOURNEY_WHITE_PAPER.PDF GDPR HTTPS://FIDOALLIANCE.ORG/.../FIDO_AUTHENTICATION_AND_GDPR_WHITE_PAPER_ MAY2018-1.PDF HTTPS://FIDOALLIANCE.ORG/EVENT/WEBINAR-FIDO-AUTHENTICATION-GDPR/