Less password, more security: the Italian Vemini at the front row

Using passwords for authentication often forces users to create and store different combinations of letters, numbers and symbols. 

Changing passwords frequently and not using the same one for multiple accounts are certainly good tips, but with the increase in digital services and tools, the tendency to forget the most basic security rules is almost inevitable.

According to the 2019 "Verizon Data Breach Investigations Report," 80% of hacking-related breaches involved compromised and weak credentials, and 29% of all breaches involved the use of stolen credentials. In addition, the cost of breaches is increasingly high in economic and social terms, both for the company or service that suffers it and for the user who has their personal data stolen.

The World Economic Forum report dated January 2020 ("Passwordless Authentication: The next breakthrough in secure digital transformation") asks serious questions about the effectiveness of classic password authentication, and then explores a future where passwords don't exist at all, introducing the concept of Passwordless Future.

Some industry leaders (Lenovo, PayPal, Google, Microsoft and others), brought together in the FIDO (Fast IDentity Online) Alliance, are already pushing for stronger authentication standards. In particular, these entities are considering moving from "Something you know" (e.g., a password) to more secure systems such as "Something you have" (e.g., a badge) or "Something you are" (e.g., with facial recognition). The latter in particular are part of the "Passwordless" category, which relies on user identification through methods that do not require a password to be entered, such as biometric systems, hardware and QR codes.

According to the WEF report, authentication without the classic "password system" offers four key advantages over traditional authentication:

  1. A financial benefit, increases revenues and reduces costs:
    Cybersecurity has traditionally been perceived as one of the largest cost items for a company. The financial benefit, then, is perhaps the most important reason why companies should consider transitioning to passwordless authentication. Not only does it reduce the costs associated with password management, data breaches and risk management, but it actually improves revenue through increased productivity and positive customer reviews. To confirm this fact, the financial services industry is currently at the forefront of adopting next-generation authentication technologies, having verified a significant impact on ROI (Return On Investment);
  2. Provides a better user experience by facilitating the end customer:
    If a platform's authentication experience is poor, customers will prefer a platform with inferior services but a better experience. In other words, passwordless authentication is becoming a competitive differentiator. Essa can emulate the way humans have recognized each other for millennia: by searching for or identifying personal traits, such as face, height or body shape;
  3. From a strategic perspective, it can help redefine competition through the value of interoperability:
    Adopting an approach based on a common standard means that much of the implementation work is already done through a public API that Web developers can easily use. Vendors, on the other hand, can more quickly begin deploying the service through a scalable framework;
  4. Significantly improves security: because no personal information is required to be stored for authentication purposes, no information is transmitted within the Network, making man-in-the-middle attacks virtually impossible.
    In addition, there is no set of user biometric data to access for authentication purposes, as a result, the likelihood of online fraud and identity theft is greatly reduced.

Within this sector, Italian startup Vemini, founded in 2019, wants to play an absolute leading role.

"We redefine the paradigm of authentication": this is the mission that Vemini proposes to pursue. The objective is to create a point of rupture with previous technologies regarding the concept of authentication and security. Today customers are forced to set up a different account for each service they use, and the recommendation made before creating any account is to choose a secure password, taking into account certain characteristics, never to use it on other platforms and not to write it down anywhere. How can such a system survive in a present that is increasingly rich in digital services and, therefore, in digital identities that are diverse and complex both to use and to protect?

This criticality is underlined by Nicolò Debenedetti: "Security should not be something complex, if it is people lose focus on it, they become more vulnerable and expose themselves". The discourse is accentuated if you take into consideration the specific case of Italy, the oldest country in Europe: "The Italian economy is supported by elderly people, so it is essential that they know how to use certain technologies. No more passwords, codes or badges, but a secure digital identity and an authentication protocol that is simple, direct and understandable for everyone: Vemini aims to revolutionize a fundamental branch of Cyber Security. How to implement such a revolution? By redefining the paradigm of security access and authentication process through a solution that is resilient to human error, as well as vulnerabilities related to centralization and possible future pitfalls.

The solution that Vemini proposes is an omnichannel ecosystem for decentralized authentication and identity management, based on biometric identity; in particular, the system relies on three fundamental features:

  • Biometric: Vemini offers a password-free login platform in which each VEMINI ID is associated with the user's biometric identity based on technology called SoulScan: it is centered on scanning the veins of the palm of the hand through the use of the best available technology of infrared beams that allow a false acceptance rate of less than 0.001%;
  • IoT connectivity: a single IoT access point will remain connected to the control panel. This type of connection allows remote management of each access point, establishing different levels of credentials in a distributed ecosystem;
  • Blockchain: VEMINI security protocol uses a multi-storage structure integrating a distributed ledger technology in order to store every biometric digital identity preventing any potential single point of attack given by centralized storage points. Such a structure is nothing but a digital register: inside the register all entries are organized in blocks concatenated together in chronological order and encrypted. The content of each block is unchangeable and uneliminable.

These features, defined by the company itself as its "sacred trilogy", allow it to create the first open ecosystem that is "private by design" and that does not require, as in the cases of traditional digital identity protection technologies, a trade off between security and usability. The technologies have been integrated within a protocol developed by Vemini called Decentralized Multilayered Identity Fragmentation (DMIF). The latter uses a specific technology called "Distributed ledger" that is associated with asymmetric cryptography and biometrics. For these characteristics, DMIF is not only more performing and secure than traditional tools based on password authentication, but it is also enhanced compared to other innovative standards such as FIDO (Fast Identity Online) since it does not refer to "proof of knowledge" mechanisms, nor to centralized databases for the management of personal credential data. This makes VEMINI a completely password-free solution and extremely more secure, immediate, and difficult to attack.

How does this technology compare to alternative digital authentication systems? Currently the alternatives are facial recognition, fingerprint, voice recognition, finger vein scanning and retinal recognition. While voice recognition is a technology that is better associated with other types of services (e.g. Siri), the two most insidious technologies from the point of view of diffusion and user experience are facial recognition and fingerprinting: almost every mobile device today is equipped with one of the two technologies, while no smartphone is equipped with palm vein recognition technology. So we decided to compare facial recognition and SoulScan to understand which one is better from different points of view.

From a privacy perspective, facial recognition shows several critical issues, this is because the face is an element of the human being that, regardless of the recent Covid-19 pandemic that forces people to wear masks, is easy to identify at a distance, quickly and without consent. 3D scanning technology shows lower error rates than 2D technology, however both show non-negligible error rates. On the other hand, palm vein scanning is a "private-by-design" technology, impossible to copy and very difficult to capture except through an ultra-HD camera using infrared rays at very low distance.

As for the accuracy of the technologies taken into consideration, here too it is possible to denote a considerable difference. The accuracy of biometric recognition technologies can be assessed on the basis of two factors: the False Rejection Rate and the False Acceptance Rate.

From the graph above you can see that the two technologies are at antipodes: the Palm Vein technology is 260 times more accurate in terms of FRR and 130,000 times more accurate in terms of FAR. In addition, facial recognition has been proven to be less effective on women and people of color. These data allow us to see that from a security point of view VEMINI offers a cutting-edge technology, even compared to technologies widely exploited and extended in certain markets such as smartphones. Should Palm Vein technology be introduced in smartphones as well? No. In spite of the lower accuracy, facial recognition is extremely well suited to the needs of a smartphone: the quick access without having to perform any action means that all access to sensitive data is subject to the user's consent. Therefore, facial recognition is more convenient, but only when used for private purposes and devices. On the other hand, when we talk about mass use to be introduced in corporate or public realities, taking into account a large amount of people, vein scanning is the best and safest solution.

Regarding regulatory compliance and privacy, facial recognition can capture sensitive user data even without consent; on the other hand, a scan of the palm of the veins assumes automatic consent: the interaction with the hardware and the authentication process occur only when consent is given.

After providing an overview of some focal points of both technologies, it is possible to conclude that facial recognition is a technology more suitable for deployment on private devices, but that it cannot be considered suitable for deployment in companies or public services. For these situations is instead simpler, safer and more convenient the use of Palm Vein scanner.

Biometric palm-reading technology is not the only solution to the current password authentication problem: other alternative technologies or processes are currently in use or increasing their market penetration.

First of all, the new authentication protocol FIDO2 created by the FIDO Alliance, which includes industry leaders such as Apple and Google, is receiving attention and praise from many parts of the cybersecurity world. It is based on a hybridization of so-called multi-factor authentication over "mobile" and biometric recognition technologies, such as fingerprint, voice and face. Using the FIDO2 protocol, after entering their username, a user can use a smartphone as an access key to their digital account, without needing any password, thanks to the authentication given by the biometric system of their device.

Some startups are already making the FIDO2 protocol commercially available, however its scope of application is purely digital: it has not been structured to enable authentication in physical spaces. 

The same can be said of the process innovation introduced by the concept of "zero-trust" or "continuous" authentication. These methods bring a totally different approach of perceiving cybersecurity: a company no longer protects its perimeter from external attacks, but continuously monitors the account behavior of each user. For example, a software of this type is able to detect malware installed on the user's device, or recognize the usual patterns of use by the user and compare them every time the user logs in. In case the software detects any suspicious behavior, the user would be immediately logged out of the session.
Again, this protocol only applies in digital contexts, and could hardly be replicated in physical spaces. Furthermore, a privacy issue is evident: this cybersecurity system records a large amount of user actions and potentially gains access to a lot of sensitive information, first and foremost the IP address.

The latest solution under study, although still in its early stages, is authentication via blockchain technology. This would be a real identity verified through the same principle that governs transactions with cryptocurrencies: a widespread and non-centralized registry system, in which each node verifies a transaction performed. Such an identity would be publicly verified and therefore difficult to falsify. Potentially, this technology could also be used to access physical spaces, and its scope is certainly not limited to online transactions. However, the path to a blockchain identity technology is still a long one, estimated to be between 5 and 10 years, and after that there will need to be high market penetration to ensure access to this technology at an acceptable cost.

To date, it is clear that integrated solutions that use biometrics have a competitive advantage over others, both in terms of the maturity of the technology and the ease with which it can be adopted by users.

Vemini proposes itself as a breaking point in the world of Cyber Security, turning its gaze and confidence towards a future that is increasingly Passwordless. A future that belongs to talented, "hungry" and curious young people just like Nicolò Debenedetti, founder of the Italian startup.

"In life there are things you know, things you know you don't know and things you don't know you don't know, and you discover these things only by bumping into them, you find them in your face" - Nicolò Debenedetti

Written by Jacopo Carlo Canale, Luca Mocci, Edoardo Alberto Donolato, Francesco Paolo Defendi and Gianni Morelli

of the VGen Hub Bocconi

Receive the report

Fill out the form to request the free report "Cosa cercano i talenti STEM dalle aziende." Our team will respond to your request as soon as possible!

vgen logo
Panoramica privacy

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.