Biometric Authentication as a Service is an innovative approach for strong authentication in web environments based on the Software as a Service model. However, both the adoption of SaaS systems and biometric technologies negatively correlate with perceived privacy and data protection risks. We specify a list of evaluation criteria for BioAaaS systems from a data protection point of view including elements specific to both biometrics and SaaS. We further apply these criteria on a prototypical implementation of a SaaS-compliant biometric authentication service based on keystroke dynamics for enterprise deployment. The assessment shows that for the most part the prototype conforms to technical data protection requirements. At the organizational level the selection and control of a trust-worthy provider and the conclusion of the service agreement remain.
Biometrische Systeme kommen derzeit immer häufiger in den verschiedensten Bereichen zum Einsatz. Diesbezüglich herrscht jedoch eine Vielzahl besonders datenschutzrechtlicher Bedenken vor. Der nachfolgende Artikel identifiziert zunächst die zentralen datenschutzrechtlich relevanten Anforderungen, welche an das Design und den Betrieb biometrischer Lösungen zu stellen sind. Anschließend erfolgt eine konkrete Evaluation textgebundener biometrischer Systeme zur Nutzerauthentifizierung.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.