Biometric Authentication

I think this topic needs some clarifications.

As far as I can tell Biometric Authentication is NOT about service providers
verifying that the end-user is authentic through some new protocol, it is only
about securely unlocking a cryptographic key.  That is, Biometric Authentication
is an alternative (or complement) to a PIN of the kind used for EMV cards.

It also means that Biometric Authentication is not really a payment protocol feature,
it is more related to provisioning of keys including policies.

I may have skimmed the WPIG documents too fast, but I couldn't find enrollment and
provisioning.  There are BTW no standards for provisioning cryptographic keys.

Anders

Received on Friday, 29 May 2015 09:40:07 UTC