Beyond Authentication: Rethinking Digital Identity Security

upi biometric

Thumbs up with virtual fingerprint to scan identity and access password. Technology security system to prevent unauthorized data breaches. Strengthen your digital safety and protect your identity.

Fragmented state laws and inconsistent standards have created gaps in identity verification and transactional risk for financial institutions. But even without a consistent standard, there are ways for financial institutions to disrupt malicious activity before it reaches identity systems, applications, or transactions—and before a breach becomes public.

A report from Javelin Strategy & Research, States of Uncertainty: How Cyber-Threat Intel Reduces Digital Transactional Risk, offers guidance on tactics such as dynamic risk profiles to strengthen an organization’s identity verification practices. Without overarching guidance, however, financial institutions are largely left to develop their own approaches.

“The fact that we have all these disparate definitions for digital identity makes it really challenging,” said Tracy Goldberg, Director of Cybersecurity at Javelin Strategy & Research. “We have no definition for digital identity, and until we get that firmed up—not just within the United States but globally—we’re going to face some real challenges.”

Defining Digital Identity

Javelin defines digital identity as a combination of a user’s digital footprint, how they identify themselves, their online behaviors, and the ways they interact with their devices. But when consumers are asked to define digital identity, the responses vary widely. Without a clear definition, it’s difficult for financial institutions to determine what information they should require from consumers and what consumers can reasonably expect to consent to.

“When you’re tracking people’s behaviors, that gets really dicey as far as the privacy controls that are in place,” said Goldberg. “We’re all required now to accept cookies, which are a tracking mechanism that’s used to monitor our online behaviors or the way we interact with certain websites. But there’s only so far we can go with some of that because consumers have to consent.”

The problem is even more pronounced at the governmental level. A definition of digital identity that meets verification requirements in one state may not translate well to another. A federal standard could eliminate much of this confusion and provide greater consistency when federal banking regulators evaluate the authentication and identity verification measures banks have in place.

Issues of Sharing Information

Many industries have established organizations for sharing this type of information. In addition to the Financial Services Information Sharing and Analysis Center (FS-ISAC), there are, for example, healthcare and airline ISACs. Within these industries, some information sharing occurs, but there is generally no mandate to participate.

Many financial institutions are reluctant to disclose that they’ve been breached or experienced a significant identity compromise. Beyond the potential PR damage, they may also be concerned about regulatory fines. If institutions felt more comfortable sharing what they were seeing from an IP perspective—or alerting others to malicious sites targeting their account holders—it could benefit the broader financial industry.

Information-sharing measures such as STIX and TAXII allow organizations to anonymize data so it can’t be traced back to a specific bank. But these protocols are highly technical, and many banks don’t fully understand how to use them. As a result, they have struggled to gain widespread adoption.

Working in the Content Delivery Network

One way to address the problem is to move further upstream and verify the authenticity of an identity before it reaches the identity verification stage. Much of the malicious activity occurs at the content delivery network layer, where banks can look for malicious infrastructure, credential-stuffing campaigns, or illicit proxy use. Preventing that activity upstream could alleviate many of the challenges that occur further down the line without requiring consumers to provide additional information.

The content delivery network layer is an intermediary tier in internet architecture, consisting of geographically distributed edge servers that cache and serve content closer to end users. Content delivery networks can also help protect against malicious traffic, including DDoS attacks. These attacks typically require a launching pad, often involving compromised devices or servers that are used to generate large volumes of traffic and overwhelm targeted websites.

“The problem is that this is not an environment that existing identity verification platforms and systems work in,” Goldberg said. “It’s going to require a mindset change. And there really aren’t the players that work in the identity proofing space today. They’re operating primarily from a behavioral biometrics standpoint: voice, retina scan, fingerprint scanning. This would be much further upstream and is going to require working with a cybersecurity vendor versus an identity proofing provider.”

Looking for Help

A complicating factor is that many smaller institutions are beholden to the platform providers they work with, such as Jack Henry, Fiserv, or FIS, and therefore have to rely largely on the capabilities those providers offer. Larger institutions face a similar challenge, but their architectures tend to involve long-term relationships with multiple vendors, with new capabilities added to existing infrastructure rather than replacing it.

A more holistic approach to identity, however, may be key to solving the problem.

“It’s a cultural challenge, it’s an infrastructural challenge, and it’s a mindset challenge because we have to think about identity in a much more dynamic way that gets outside of this thought that identity has to be verified with the individual,” said Goldberg. “We have to take the individual out of it, because we can’t reliably verify an individual in a digital environment today without bringing in some of these other signals.”

Companies like Akamai that monitor web traffic are expanding into content delivery and security. If they identify suspicious traffic or determine that malicious sites are being used to compromise identities, they can alert financial institutions and recommend stronger authentication for a particular user or transaction.

Ultimately, the key is information sharing.

“Until there is some regulation and mandates around sharing threat intelligence, I don’t know that there’s going to be a lot of impetus on the side of the financial institutions,” said Goldberg. “But there is promise on the side of the vendors, who are gathering some of this intelligence across all the clients, whether it’s banks or retailers that they’re working with. You could have a vendor that’s seeing certain things attacking a handful of their clients, and they could share that with other clients in an anonymous way. That could be a way that intel could get shared.”

Exit mobile version