Domain 5 - Identity and Access Management Flashcards
Type 3 Authentication Method
Something you are
- Enrollment in biometric system should take 2 minutes or less
- Throughput of biometric system should take 6-10 seconds or less
FRR
False Reject Rate
Type 1 Error
Type 1 Error
False Reject Rate, FRR
FAR
False Accept Rate
Type 2 Error
Type 2 Error
False Accept Rate, FAR
CER
Crossover Error Rate
- The point where the FRR and FAR are equal
Fingerprint Scans
- Data is called ‘finger print minutiae’
- Includes whorls, ridges, bifurcation
Retina Scan
- Laser scan of the capillaries that feed the retina of the back of the eye
- Laser must actually enter the eye
- PRIVACY CONCERNS
- Exchange of bodily fluid
- Can determine health information (pregnancy, diabetes, etc)
Iris Scan
- Passive biometric control
- Camera takes a picture of the iris, authentication system compares the photo when authenticating
- Works through contact lenses/glasses
- High accuracy
- No exchange of bodily fluids
- Iris pattern is LIFE-LONG and never changes
Hand Geometry (authentication)
- Measures specific points taken on the subject’s hands
- Takes up very little space to store in database (~9 bytes per entry)
Type 1 Authentication Method
Something you know
- Passwords, passphases, etc
Type 2 Authentication Method
Something you have
- Synchronous/asynchronous token
Synchronous Dynamic Token
- Displays dynamic tokens on set time intervals
- Synchronized with a central server
Asynchronous Dynamic Token
- Not synchronized with a central server
- Smart cards, etc…
Centralized Access Control
- One logical access control database
- Can be used to provide SSO
- Centrally provided AAA
- Systems authenticate via third-party auth servers