Blogginlägg -

Identity data capture and validation is key

This week I had the pleasure of visiting NORSIS event IDentitet 2016 in Oslo. Very well structured the event started with presentations around the capturing and validation of identity data which is fundamental for the trust in eIDs (and of course other types of credentials). Many good points around the difficulties in validating physical identity documents that are later used to issue digital identities, points that also validated with real life examples in the next sessions around Identity Theft. 

In the identity theft session we got to hear Marthe Lunde, a victim of identity theft, speak about her experiences from several aspects and how easy it is to perform an overtake of some ones identity due to lack to good controls and secure distribution and use of identity information, in Marthe Lunde’s case it resulted in a number of purchases for a significant amount and over 200 hours work for Marthe to reclaim her identity and eliminate the damage the criminal caused. I especially noted the inability from the society and the merchants to help Marthe, in the end she has not caused this, she is a victim of weak controls and processes and of course criminal activities.

The later sessions went over to the digital identity side but with links back to the earlier session with a clear message that we need a secure capturing and validation of the initial identity data and if we then link that to a secure digital identity which can present the initial data in the digital channel we can raise the protection of users and reduce identity theft significantly. There is obviously so many great services we can build on an improved system that combines a secure identity capturing and validation with a convenient eIDs in order to establish a trusted identity that can work across borders as well. But to establish the trust it is necessary to address the complete chain not just the indiviudal parts.

Per Hägerö

Read more about NORSIS here 

Ämnen

  • Datasäkerhet

Regioner

  • Dalarna

Kontakter

Relaterat innehåll

  • Sex teman driver identitetshantering under 2016

    För neXus, internationellt ledande leverantör av säkerhetslösningar och -tjänster, är identiteshantering det centrala temat i sammanhang med IT-säkerhet under 2016. Ansvariga för detta är trender så som den fortsatta flexibiliseringen av arbetslivet, nya typer av kundkommunikation och det växande antalet cyberangrepp.

  • Ny CFO till neXus

    Magnus Karlsson tillträder som CFO i Nexus den 22 februari 2016 och blir därmed ny medlem i koncernledningen. Magnus efterträder Björn Johansson som efter nio år i Nexus beslutat sig för att söka nya utmaningar utanför koncernen.

  • Ale kommun stärker säkerhet för anställda

    Ale kommun har upphandlat en lösning för tillverkning och administration av tjänstekort som gäller för alla anställda. Kommunledningen ställde krav på att alla anställda skall ha en säker identifikation som också kan användas för säker inloggning samt för passage, print-on-demand etc.

  • neXus stärker i Mellanöstern

    neXus har ingått ett distributionsavtal med Shifra, en distributör i Dubai, vilket gör det möjligt för Shifra att sälja neXus PKI-plattformar i Mellanösternregionen.

  • Carolen Ytander ny CMO för neXus

    neXus stärker sin företagsledning ytterligare och rekryterar Carolen Ytander som ansvarig för marknad, kommunikation och strategisk HR. Carolen kommer närmast från Vattenfall där hon haft flera olika chefsroller, däribland som nordisk marknadschef.

  • Identitetshantering för banker

    Den 12 februari 2016 publicerade den tyska finanstidningen gi geldinstitute en artikel om vikten av Identity Management, identitetshantering, för banker.

  • Happy Data Privacy Day!

    January 28th is the Data Privacy Day, a date that is currently observed in United States, Canada and 47 European countries.

  • Explosion in IoT reveals risk of massive black market

    In a recent report Gartner predicts that by 2020 over 50% of new major business process and system will incorporate some element of the Internet of Things. From a security perspective this growth will be challenge from many perspectives.

  • WebCrypto, Invisible Token and Hybrid Access Gateway

    After following the development of WebCrypto for more then three years it is awesome to see how it now slowly becomes implemented by the larger browsers. You can test your browser here.

  • The SCIM standards just grew up to become RFC's

    Integrity and simplicity for both users and IT-departments just took a huge step forward on the Internet. The SCIM specifications, System for Cross-Domain Identity Management, are now published as publications by the Internet Engineering Taskforce (IETF) as RFC7643 and RFC7644. At neXus we are super proud because we have been playing a key part of the specifications.

  • Server Name Indication and Hybrid Access Gateway

    SNI is an extension to TLS that has been around for a while, since 2003, but is becoming more and more important as installations become multi tenant with customers from completely different organizations.

  • Identities without borders

    ​Imagine using your Swedish electronic signature for applying for a building permit for your summer home in Spain? It can soon turn into reality as the new EU regulation eIDAS is being introduced across Europe, enabling national electronic signatures to work across borders in the union.

  • Securing banking solutions

    How can neXus help securing banking solutions for authentication, verification and signatures for the next generation of banking services? Meeting and attracting new customers in a disruptive banking market thru new mobile channels is a big challenge!