We discussed about the importance of safeguarding user biometric data and system data in our last month newsletter. We will continue the discussion about how the security features in AccuFACE could address the concerns.
(3) No external data storage on the device
Some users may consider having an external data storage (SD card or USB drive) on a biometric security device to store user/device data is convenient because external storage could be detached from the device for easy data retrieval. However, this design is considered a serious security breach and you can hardly find professional biometric security system supporting external data storage.
If an external data storage is present on a biometric device, it means anyone (including intruder) can easily detach the data storage and access to the stored data. Even if the data is encrypted, it is possible to decrypt the data as long as the intruder has possession of the data. Therefore, the key is to prevent intruder from reaching or even possessing the data. Hence, professional biometric security systems do not support external data storage such as SD card or USB drive. If user has to access to data on the system, he has
needs to authenticate himself first.
AccuFACE does not support external data storage. To access to data on AccuFACE, user has to authenticate himself through a proper login procedure or even facial authentication. AccuFACE can be programmed to support "event notification" and work with 3rd party central management software. In other words, if someone tries to retrieve data (including user facial template and user access records), AccuFACE can alert the system administrator so that appropriate action could be taken.
(4) Data encryption
Many people expect the data stored on a biometric security system to be encrypted. If the data is not encrypted, intruder who gains access to the data can easily look at the details of the data, find out the vulnerability of the security system, or even reproduce the data for illegal use. While data encryption is important, it is also critical to have encrypted data transmission between the biometric system and computer. An encrypted data transmission ensures data security and integrity.
The data stored on AccuFACE is encrypted. AccuFACE also supports encrypted data transmission (e.g. HTTPS) to meet the high security requirements by many business corporations and government agencies.