Hitoshi Kokumai

3年前 · 2 分の読書時間 · ~10 ·

ブログ Hitoshi
Identity Assurance - Sufficient and Necessary Conditions

Identity Assurance - Sufficient and Necessary Conditions


It is not easy to define the 'sufficient condition' for describing a set of processes used to establish that a natural person is real, unique, and identifiable; criminals keep coming up with hitherto unknown weapons to compromise the said processes.

But we are easily able to define the 'necessary condition'; it is that the 'secret credential', i.e., the likes of passwords, is absolutely indispensable for the processes to stay reliable.

Let us summarize the characteristics of the factors for the processes, namely, the authenticators, as follows.

1. Secret credentials are absolutely indispensable, without which identity assurance would be a disaster. (Ref. Removal of Passwords and Its Security Effect )

2. Two-factor authentication made of passwords and tokens provides a higher security than a single-factor authentication of passwords or

tokens. (Ref. Quantitative Examination of Multiple Authenticator Deployment )

3. Pseudo two-factor authentication made of biometrics and a password brings down the security to the level lower than a password-alone

authentication. (Ref. Negative Security Effect of Biometrics Deployed in Cyberspace )

4. Passwords are the last resort in such emergencies where we are naked and injured (Ref. Availability-First Approach

5. We could consider expanding the password systems to accept both images and texts to drastically expand the scope of secret credentials. (Ref. Proposition on How to Build Sustainable Digital Identity Platform )

As for Item 5, we could add the following.

Easy-to-Remember’ is one thing. Hard-to-Forget’ is another - The observation that images are easy to remember has been known for many decades; it is not what we discuss. What we discuss is that ‘images of our emotion-colored episodic memory’ is ‘Hard to Forget’ to the extent that it is ‘Panic-Proof’. This feature makes the applied solutions deployable in any demanding environments for any demanding use cases, with teleworking in stressful situations like pandemic included.

The password is easy to crack – Are you sure?

Quite a few security professionals say ‘Yes’ very loudly.

We would say that a ‘hard-to-crack’ password is hard to crack and an ‘easy-to-crack’ password is easy to crack, just as strong lions are strong and weak lions are weak; look at babies, the inured and aged.

However hard or easy to manage, the password is absolutely indispensable, without which digital identity would be just a disaster. We need to contemplate on how to make the password harder to crack while making it harder to forget.

This subject and related issues are also discussed on Payments Journal, InfoSec Buzz and Risk Group




Future society enabled by the expanded password system

Textual passwords could suffice two decades ago when computing powers were still limited, but the exponentially accelerating computing powers have now made the textual passwords too vulnerable for many of the cyber activities. The same computing powers are, however, now enabling us to handle images and making more and more of our digital dreams come true, some of which are listed below.

- Electronic Money & Crypto-Currency

- Hands-Free Payment & Empty-Handed Shopping

- ICT-assisted Disaster Prevention, Rescue & Recovery

- Electronic Healthcare & Tele-Medicine to support terminal care in homes

- Pandemic-resistant Teleworking

- Hands-Free Operation of Wearable Computing

- User-Friendlier Humanoid Robots

- Safer Internet of Things

- More effective Defense & Law Enforcement

all of which would be the pie in the sky where there is no reliable identity assurance.

< Related Articles >

History, Current Status and Future Scenarios of Expanded Password System

Negative Security Effect of Biometrics Deployed in Cyberspace

#identity #authentication #password #security #biometrics #ethic #privacy #democracy #emergency #disaster #panic #defense #government #pandemic #teleworking


Hitoshi Kokumaiの記事

2年前 · 2 分の読書時間

We’ve come up with a slide presentation for “Bring a healthy second life to your legacy password sys ...

2年前 · 2 分の読書時間

Another topic for today is “Passwordless made simple with user empowerment” · https://www.securitym ...

2年前 · 2 分の読書時間

I would like to take up this somewhat puzzling report - “Google advises passwords are good, spear ph ...


  • TransVision (トランスビジョン株式会社)

    IT Infrastructure Engineer

    次の場所にあります: beBee S2 JP - 1時間前

    TransVision (トランスビジョン株式会社) Fujisawa, 日本 フルタイム

    応募条件 · 日本語: 上級(ビジネス会話レベル) · ビザのスポンサーが可能 · 説明 · IT Infrastructure Engineer · TransVision Co. Ltd. is currently looking for an IT Infrastructure Engineer to join our team in Fujisawa, Kanagawa. This is a full-time position and Visa sponsorship is available for suitable candidate. A ...

  • マミー高円寺保育園


    次の場所にあります: beBee S2 JP - 1時間前

    マミー高円寺保育園 杉並区, 日本 TEMPORARY

    【マミー高円寺保育園 求人のポイント】 · ◆JR中央線 高円寺駅より徒歩8分 · ◆園児定員:72名(0歳~5歳) · ◆月給:210,000円~ · ◆賞与:年2回(計4.0か月) · ◆即日勤務OK · ◆認可保育園の栄養士 · ----- · 勤務地 · ----- · 東京都杉並区高円寺南2丁目40-45 · ----- · 最寄り駅 · ----- · JR中央線高円寺駅 徒歩8分 · ----- · 園名 · ----- · マミー高円寺保育園 · ----- · 施設形態 · ----- · 認可保育園 · ----- · 園児定員 · ...

  • YKK Chiyoda City, 日本 正社員

    職種 / 募集ポジション 【キャリア採用】アルミ形材の提案営業職 [初任地:東京・名古屋・大阪] 雇用形態 正社員 給与 年収 500万円 〜 1000万円 ※経歴、資格などにより応相談・給料改定 年1回(7月)・賞与 年2回(7月、12月) 勤務地 東京都墨田区亀沢3-22-1 YKK60ビル · 愛知県名古屋市中区栄 栄YFビル · 大阪府大阪市中央区谷町4-8-7 谷町YFビル · (雇入れ直後)YKK60ビル、栄YFビル、谷町YFビル※選考を通じて決定。オファー時に通知いたします。(変更の範囲)会社の定める就業場所※将来的に転勤の可能性がありま ...