Good morning, happy Friday everyone. Thank you very much. It's great to be here in Berlin today. Thank you for being here. My name is Fabian. I'm CEO and co-founder of Keyless, the pioneer and leader in privacy preserving biometric authentication. So today I'd like to talk about an important topic, securing user identity across the entire digital life cycle, from the initial enrollment throughout ongoing authentication, in the most simple, secure and privacy preserving way. Unfortunately, the way we authenticate users today is fundamentally broken.
We're all reading about staggering numbers in account takeovers, continued data breaches and hacks, dissatisfied users or escalating support costs. If I'd ask you, when was the last time you had to reset your password? Or you struggled receiving that SMS OTP to complete the MFA challenge? Maybe you live in Germany and you're still waiting for that activation code that your bank should have sent with a letter to your home address so you can recover access to your account. I imagine many of us can relate. Now this is even becoming more complex. It's no longer just about stealing your password.
It's also about swapping your face or cloning your voice. AI generated fraud is becoming one of the biggest threats to businesses today. Deep fakes, voice cloning, synthetic identities, these are no longer sci-fi concepts. They're real, scalable and dangerous. One of these numbers should scare you. 40 billion dollars. That's the number of fraud losses that Deloitte projects AI generated fraud to deliver by 2027. And banks are already seeing this pain.
I imagine many of you have heard about the story of a Hong Kong financial institution last year that was defrauded for 25 million dollars because scammers created a completely fake meeting with fake people with deepfake technology to trick an employee to wire out that large sum of money. And organizations are seeing this challenge in today's world. More than half of crypto firms today have already encountered deepfake fraud. At the same time, 60 percent of organizations report that they're dissatisfied with their own account recovery methods.
So account recovery or device activation or reactivation remains one of the weakest links in the authentication chain across the life cycle. And all of this isn't a surprise because we're relying on fragile tools. Passwords that are reused, SMS OTPs that are phishable, hard tokens that we share or lose, and call centers that one are expensive but two are frustrating for all of us. Now we believe biometric authentication has the potential to solve that gap but when implemented correctly. Today we can classify biometric authentication systems in two categories.
The device native or local biometric approach where both enrollment and face matching has happened locally on the device. And the server side or centralized biometric approach where enrollment and authentication happens remotely on a server. Each of these approaches has their advantages and disadvantages that I'd like to look at now. Starting with a local or device native approach, it's great because there is no biometric data that ever leaves the device.
So it provides that security and the privacy of the user being in control of their own sensitive personal information, their biometric data, because it's stored on their own device. The huge disadvantage here though is that we're not really authenticating the individual. The remote service we are authenticating into doesn't know who the person behind the device is. I imagine many of you when you've upgraded your phone or you lost your device you realized that you had to re-enroll your face on the new device that you're using.
Now this can be achieved with a server side or centralized biometric approach where that authentication process doesn't happen on the device but remotely on a server where that template is stored. So we provide that strong link of the real person behind the device and essentially the person that we're authenticating into the remote service. So we verify the user's identity. However that comes at the great expense of having to store all the sensitive personal information in a central database. So from a security risk or compliance perspective we're running in severe issues.
Now what if we could combine the interoperability and the usability benefits of the server side biometric approach with the security and privacy benefits of the device native or local biometric approach. This is what we've done at Keyless and we call this paradigm zero knowledge biometric authentication. Now we've been working with Gartner in this case for a few years to create a new category which Gartner calls decentralized biometric authentication.
They loosely define it as a category where no single party has full control over the biometric information achieving or with the aim of achieving a better balance of usability security and privacy through the use of so-called privacy enhancing technology or a fancy word for cryptography. Now the Keyless approach to this decentralized model is not just a system where no single party has full control over the biometric data but it's a system where no biometric data is stored at all.
So what happens technically is when the user looks into the camera of their device that we capture the biometric features we transform them locally on the user's device through a one-way cryptographic function using a multi-party computation scheme into a cryptographic quantity that cannot be reversed but that also cannot be linked to the individual. So neither us as the service provider the organization would run and host this on-premise or the user themselves have access to the information.
There's no biometric data or no signing key that is stored anywhere neither on the user's device nor anywhere on the server. The other characteristic of the system is that it provides an inherent multi-factor security. We've verified both the user's device that is cryptographically tied to the account at the point of registration or enrollment distinct and independent of performing passive liveness and server-side face matching.
So we're combining two factors with one look into the camera but to the user it looks and feels like face ID and it does so across any end-user device the only requirement being a 720 pixel capable camera. Now part of every authentication every good biometric method is obviously ensuring that the user is a real human not a deepfake video injection attack or someone with a mask.
So as part of every authentication we provide passive liveness detection which passive meaning being completely passive there is no user action required, no looking left right, smiling, blinking, no nodding, no moving back or forth, no colors, no flashlights, really an experience that face ID delivers with the superior senses that the iPhones have which is overlaid with additional signals, behavioral elements, so we measure micro movements, the accelerated gyroscope to assure that it is a real human not a video or a deepfake.
Now as part of the face matching one of the things you may look at when evaluating biometric vendors is the FIDO benchmark for the component certification around biometrics which sets thresholds for false reject rates and false accept rates at three percent at an equal error rate of 0.01 percent and assesses the presentation attack detection against the ISO 3107-3 requirements or the equivalent ibeta level one or two which we have as well.
In addition you may want to look at the NIST rankings, biometric vendors can submit their algorithms to NIST which benchmarks these algorithms, we rank among the top 50 in the one-to-one category, top 11 in the one-to-many category, notable to mention that many of these algorithms are not commercially used come from countries like China or Russia so from labs but that is an open public source you may want to look into.
Another source obviously being here in Europe is ADAS and the component certification, the module certification for the assurance level highest which is another thing you may want to look at and obviously customer references, banks and we've been meeting regulators and operate in some European countries with a possibility of not requiring explicit user consent because there is no biometric data that we store.
Now talking about securing the entire life cycle of the user, biometric authentication or authentication in general is really more than passwordless login which is often talked about, it starts with the initial enrollment obviously covers login procedures but then goes across the life cycle for use cases such as securing high risk events, think of changing address information, adding a phone number to your account or changing your card data, securing payments or signing transactions against the open banking or strong customer authentication requirements which mandate multi-factor authentication and dynamic linking to sign that transaction for the audit trail of the bank and then the account recovery or device activation use cases which often involve the call center, involve the user having to physically show up in a branch or complete new KYC or IDV flow from the start.
Now talking about these enrollment options there are also multiple ways we can enroll a user and we can distinguish between active enrollment processes and a passive enrollment process which is very elegant that I'd like to touch upon in more detail in a second. On the active enrollment side obviously when talking about biometrics there's a new way of using the digital ID card, extracting the self-image through the NFC chip and basically assuring or verifying the user identity that way which is one of the active options.
The other option is just a live capture of the face similar how you add your face onto your phone where you look into the camera, the template is created, in our case that cryptographic key material which is then stored server-side for ongoing authentication.
The passive option which we call IDV bridge to bridge IDV identity verification and ongoing authentication is a model where we're able to tap into existing selfie images that an organization may have on file from digital onboarding processes the result files of the KYC where we could crop the image and enroll these existing selfies in the background through this IDV bridge component and generate that cryptographic key material that we then authenticate completely passively or silently in the background.
So if you've went through a digital onboarding process with an organization and that organization would use Keyless for ongoing authentication you wouldn't be required to register yourself into Keyless but we can do that in the background by leveraging the selfie that already exists in file and through that bridge both IDV and ongoing authentication. In today's world and that is what drives those challenges we see especially in the consumer side is that these domains are completely siloed.
We go through a robust IDV process, we create the identity and establish a very strong binding between the real world person and the digital twin or the account that is created but then when we authenticate into that account we use credentials such as username password and SMS OTPs which basically yeah drive the challenge we have.
Now what we're able to do with this IDV bridge component is tie these together in a very seamless and convenient way leveraging those existing selfies and running this component on premise where those selfies reside so no biometric data ever leaves the perimeter of the organization and then ongoing authentication doesn't introduce any risk from a PII perspective in authenticating the user or verifying continuously assuring the user's identity no matter what device or channel they're coming from.
In addition to the consumer cases I've talked about we also offer a solution around workforce authentication certainly the plain vanilla use cases for passwordless login or authenticating the remote employee when accessing sensitive pieces of information or systems but one very interesting use case we're finding is the ability to authenticate multiple employees on a shared device.
Think of frontline workers, kiosks, point of sale where there may not be the need or the possibility of using a companion device to authenticate that person android zebra devices in shops or a kiosk or tablet at the store whether the employee is able to look into the camera of that device and authenticate into the IDP or any connected application in a convenient way assuring that it is that very person who is authenticating. So now I'd like to show a few example of these use cases on both the consumer and the workforce side to give you a feel of how that looks like in practice.
Now starting with the device activation or reactivation journey on the consumer side with a large bank or the largest bank in Italy we're having a user who has a new device and wants to recover access to the account and tie this device to his or her account in this case her account so comes in downloads the app clicks on link my device puts in their personal code so any unique identifier puts in their pin this is optional if the user forgets the pin they can recover the pin with keyless now keyless comes into play where the user looks into the camera we perform the liveness check we extract the biometric features locally transform them into that cryptographic quantity that is matched against the cryptographic quantity that is associated to that personal code on the server side in this case it is the right user that matches we generate that device key pair the state on the device to cryptographically tie the device to the account the user is again in their account and every authentication going forward will be an inherent multi-factor authentication another use case a login use case in this case a large bitcoin wallet out of Switzerland many other European countries use keyless among other use cases for the login so this is me a few weeks back in the office I click on the login or the biometric icon I look into the camera and I'm authenticated with two factors this isn't sped up this is real use you should all get an account it's a great company but you look into the camera we verify the device in the background so there's a cryptographic proof against the device key zero-knowledge proof against that key to assure possession independent of passive liveness and server-side face matching and I'm logged in those of you who work in the financial context with instant payments especially the need to authenticate payments in a strong way and assure that it was actually the user having carried out that transaction non-disputes mule accounts huge challenge we're seeing so unlike today where especially in Germany many of us use a second token app that we actually need to switch to in some cases even log into copy paste the pin code switch back to the banking app paste that in to send 30 euros you could just look into the camera we verify the device in the background we authenticate the user ensure their identity through the biometrics generate that dynamic link the unique authentication code to sign that transaction and we know it was the genuine account holder who made that transaction or not anyone else now jumping on to the workforce side with one example IDP we have present here at the show as well is the login into a shared device or an account with that IDP from a user so the user comes onto a terminal a tablet a company device puts in their username so the employee email address in this case the password looks into the camera of that very device so it doesn't require a companion device we perform the liveness check and the user is authenticated so we know it is that very employee who's authenticating but the employee doesn't have to have their companion device so it's one look into the camera but a shared device where multiple employees can authenticate into the same machine now summing up there might be anyone who hasn't heard of keyless so far in this case you dodged the team we're the pioneer and the leader in privacy preserving biometrics we're a European company headquartered in London with offices in Rome presence in Singapore we predominantly work with enterprises in the regulated field but also elsewhere and partner with essentially any relevant companies in the broader identity and fraud ecosystem and yeah be very happy to have a conversation with you so if you're interested in modernizing your authentication flows we'd be very happy of building a future of authentication where there's nothing to remember where there's nothing to steal and you are the key so thank you very much for attention wish you a great day ahead thanks very much Fabian for being on time well actually slightly ahead of time so we have some questions from the audience so is it I assume that means your system also available on-prem or only on the keyless cloud both so could be on-prem and hybrid models or SAS and public cloud okay good next question is is the liveness detection result generated entirely locally or is it part of a multi-party protocol the liveness happens locally because we don't want any biometric data to leave the device so both the transformation of the user's facial features and liveness happens locally on the user's device what leaves the device is no longer biometric data and that is confirmed by European regulators but yeah so short answer yes locally on the device okay that's great and then we how do you how do you educate consumers about the privacy aspect with passkeys we've seen consumers being concerned that companies will get their biometric data actually passkeys have a real challenge around adoption and there's a huge confusion between biometric authentication and passkeys being biometrics face id to unlock the phone biometrics to unlock the passkey and then sync passkeys have a whole other security issue when you look at the entire system what we are finding is that the great thing with face id or apple and google is that face recognition is the dominant means for biometric authentication and there's some users who would ask what happens with the biometric data but then it comes down to educating the consumers but we've seen great adoption in the solution so far with banks across europe and other regions quick technical question is do you integrate with intra id auth we do okay that's good and perhaps a fun a fun question to end on what about twins they ask it's an interesting challenge with twins there is a challenge with any biometric system i think what makes us different is that the twin in order to basically circumvent the biometric pipeline and the passive liveness detection would also need to be in possession of the same device of their twin which makes it harder in practice um there's certainly a theoretical chance that a twin might be able to authenticate into the twins account with any biometric system so i'm not going to say we're the ones who stop it um but we'll make it harder than others okay everyone please give it up for fabian evelyn