Reflections on RSA Conference: Vendors Stepping Up to Challenges of Strong Authentication for Mobile Users

In spite of pre-conference concern surrounding the roles information security (Infosec) technology providers like RSA play in the scheme(s) of government surveillance programs, the RSA Conference drew close to 30,000 people to (in the carefully chosen words of the conference organizers “Share. Learn. Secure.” It certainly was a learning experience for me: one that started with a panel of CISOs (Chief Information Security Officers) discussing the challenges of balancing the appropriate level of security to mobile devices, apps or content without greatly inconveniencing mobile users or busting the budgets allocated for technology that must now protect enterprise information and facilities from physical entry, denial of service attacks, advanced persistent threats, malware and all forms of unwanted access. As a strong proponent of biometrics-based authentication, especially the use of voiceprints for mobile access, I was gratified to observe that the infrastructure, protocols and business processes are coming together to make simple, secure and trusted mobile access more accessible to business enterprises. Two development and marketing initiatives drove home this point. The most dramatic was the high-profile progress that the FIDO Alliance was able to demonstrate when comparing this year’s RSA to last year’s. It’s hard to believe that FIDO (Fast ID Online) was just making its debut to the world in February 2013. Its founding members included voiceprint specialist Agnitio, semiconductor manufacturer Infineon Technologies, computer maker Lenovo, security software infrastructure provider Nok Nok Labs, PayPal, and sensor maker Validity. Barely a year later, at RSA Conference 2014, FIDO Alliance held an awareness raising event in which it could brag nearly 100 members, including a Board of Directors that includes representatives from Google, MasterCard, Discover Card, Bank of America, Microsoft, PayPal and RSA. It could showcase real world implementations of its “simpler, stronger, authentication.” Even more importantly, when it hits the century mark, most of the new alliance participants will be regarding the two FIDO frameworks (UAF or “Universal Auth Framework” and U2F for “Universal Second Factor”) as de facto, industry-initiated standards for either replacing or augmenting “username/password” as the predominant authentication method for mobile devices as well as computers. The magic words involve members’ agreement to “share technology and collaborate to deliver open specifications for universal strong authentication.” They have made great strides. While walking the exhibit hall, it was pretty clear that Identity and Access Management (IAM) represents a small percentage of the floor space. Those linking biometrics to IAM are fewer still. Yet the need for a simple way to secure mobile devices, apps and content is causing both the security and IT community to look more closely at their alternatives. I was particularly impressed by the technology provided by Mocana, which positions itself as living at the “intersection of security, mobility and the Internet of Things.” That’s a bold statement, but its core new offering is the Mocana Atlas(TM) Extended Enterprise Engine. As the product managers described it to me, it sounds like a core, missing piece to the security dilemma that BYOD (Bring Your Own Device) has introduced to the enterprise IT ecosystem. Mocana’s approach secures individual mobile applications in a way that is indifferent to the mobile platform in use or the nature of the app itself. Enterprises install a highly-scalable, purpose-built security appliance on their networks and it establishes a protected link between enterprise systems and databases and the apps running on mobile devices. To prevent the establishment of yet another security system, the protection is established on a “per app” basis. The apps themselves are developed separately from the security infrastructure. As the marketware explains: this approach to Mobile App Protection “injects new security into existing third-party, hybrid and in-house enterprise app binaries… no coding or security expertise required.” This “decoupling” of apps for app security overcomes all sorts of fragmentation and shortens the time it takes to launch new mobile apps in the enterprise. Perhaps most important from a mobile authentication point of view, it supports the existing auth mechanism which, ideally, could be set up with a “Single Sign On” approach for all the MAP protected apps. The enterprise can use the token of its choice, including voice biometrics.