Stable IT2 is a key for accessing digital wallets, password managers, or single sign-on systems that includes all the benefits of passkeys while introducing an additional layer of authentication through “biometric binding” to boost security.
Through its Stable IT2 offering, T Stamp Inc (NASDAQ:IDAI, EURONEXT:AIID), doing business as Trust Stamp, offers enterprises the ability to enhance security and authentication.
In a new whitepaper, Trust Stamp’s team, led by chief science officer Dr. Norman Poh, explains how this advanced, privacy-focused solution can address the shortcomings of existing methods like passkeys to ensure only authorized users can access applications, accounts, and wallets. Below are excerpts from the white paper.
Stable IT2s: enhancement beyond passkeys
Passkeys represent a modern authentication method wherein a user's secret key is stored locally on their device, typically in a Trusted Execution Environment (TEE). They are a step forward in digital security, offering a more secure alternative to traditional passwords. When users need to sync their secret key across devices, it is transmitted to and held securely in the cloud. This approach, while innovative and typically better than passwords and one-time passcodes, is imperfect and still relies on possession-based authentication. Moreover, the centralized storage of passkeys leads to additional security risks.
Security risks posed by passkeys
While passkeys offer substantial security benefits, Trust Stamp's Stable IT2 technology provides a more advanced and secure solution in several key areas:
- Compromise of a device containing passkeys: With passkeys, the user's secret key must be stored on the device within the TEE. Although this is generally secure, it poses risks if the device is physically compromised. For example, if someone steals a phone containing a passkey and has the pin to the device.
- Cloud sync and security risks: Syncing passkeys involves transmitting the secret key to the cloud. This process can raise concerns about entrusting all your secrets to one cloud provider, especially when multiple keys are involved.
- Vulnerability to hacking: In the event that a device with passkeys is hacked, and if the attacker gains access to the cloud service, they could obtain all the stored passkeys, posing a significant security breach.
Trust Stamp’s Stable IT2 solution
Trust Stamp’s Stable IT2 is a biometric cryptosystem designed to secure cryptographic keys and other important secrets. The Stable IT2 secures a renewable and cancellable cryptographic secret using a facial image.
It revolutionizes data security in biometric systems by eliminating the need to store biometric data. With this technology, a face is authenticated, not by comparing it to a stored biometric, but because only the right face can regenerate the cryptographic key. Therefore, users can secure digital assets by safeguarding the key, which can only be regenerated using the right face.
Stable IT2 use cases
Stable IT2 has wide applications across many target markets, but financial institutions, digital wallet providers, and identity and access management vendors are ideal users of this solution. Use cases include:
- Augmenting passkeys: While passkeys offer convenience, their reliance on either physical device storage or cloud syncing poses significant security risks. Stable IT2 provides a more secure solution by protecting stored passkeys using biometrically derived keys. This incorporates biometric verification, ensuring enhanced security and integrity even in compromised scenarios.
- Biometric multi-factor authentication (MFA): The Stable IT2 introduces a biometric MFA system that significantly enhances security. This triple-factored solution integrates a password, device possession, and a biometric factor which provides a robust defence against phishing, SIM-swapping, and credential-stuffing attacks.
- Digital wallet: The Stable IT2 from Trust Stamp presents an innovative solution in mobile and digital wallets, where verifying the actual ownership of digital credentials is a persistent challenge. In the current landscape, digital identity is generally linked to the physical possession of a device. This approach implies that whoever presents a digital credential on a device is its rightful owner.
- For issuers: Stable IT2 can be utilized to securely authenticate cardholders using biometrics, ensuring a seamless and robust verification process that enhances security while maintaining user convenience. Enhancing customer authentication by leveraging device biometrics on both mobile and web platforms, providing a seamless and secure alternative to one-time passcode or even passkeys.
- For merchants: Stable IT2 facilitates a streamlined authentication process, allowing merchants to authenticate consumers fully. The Stable IT2 creates a seamless authentication journey for customers, ensuring their digital payments are fast, secure, and convenient. It utilizes cryptographic authentication to drastically reduce fraud risks and meet the requirements of Strong Customer Authentication (SCA) in regulated markets.
- Enhanced know-your-customer (KYC): The Stable IT2, securely generated during enrollment, is a cryptographic anchor for KYC purposes. It ensures a trusted link between the user and the service provider, enabling secure identity verification. This stable key can facilitate seamless KYC processes, whether through traditional methods like one-time access tokens or modern cryptographic protocols, ensuring compliance and enhancing user trust in online transactions.
Atlanta-based Trust Stamp is a global provider of AI-powered identity services for use in multiple sectors, including banking and finance, regulatory compliance, government, real estate, communications, and humanitarian services.