7 minute read
NS ALLIANCE, AUTHENTICATION AT YOUR FINGERTIPS
Tailor-Made project/CLIENT CASE NS ALLIANCE, Authentication at your fingertips
In partnership with EBRC, NS Alliance has developed a revolutionary authentication solution based on the biometric data of each individual. Among other things, it allows users to initiate payment transactions with just their fingerprint, while their phone stays in their pocket. This allows for simpler and faster transactions while guaranteeing a high level of security in retail, banking and even online operations. The solution is being progressively deployed internationally.
Advertisement
The players who stand out will be those who manage to propose a user experience of higher quality than what their competitors offer. A considerable number of businesses, therefore, strive to reduce the friction that can occur at the heart of a commercial relationship. How can you facilitate the checkout process without forcing the client to look for money or his payment card? How can you enable a secure online transaction without forcing the user to take out his token?
Pay without the need to search for your means of payment
In the context of a project initiated within the framework of the e-commerce center for excellence in the Lille region in France, a group of actors has been working since 2006 on the development of simple, secure and easy-to-use solutions to simplify transactions. “We quickly realised we wanted to develop a solution that would allow us to carry out commercial transactions without the need to take out any means of payment, explains Cédric Hozanne, CEO of NS Alliance. The idea behind it was to end up with a simple process, like the handshake that allows us to seal a deal, without sacrificing the increasingly important high level of security.”
Natural Security was born at the end of 2008 out of the merger between retail, banking and industry players, with the ambition to develop an innovative authentication solution to facilitate transactions in a few years. It was able to count on the support of its members, which include BNP Paribas, Crédit Agricole, Safran Morpho, Oney Bank, Crédit Mutuel Arkéa, Carrefour Banque, Ingenico, Leroy Merlin and Groupe Auchan, to name only a few.
Biometrics and communication technology
“We have combined the potential of biometrics with the opportunities offered by mid-range telecommunications technologies, adds the CEO. With our solution, paying is now as simple as putting your finger on a biometric authentication terminal.”
The use of biometrics, the most personal data available to an individual, requires strict precautions. Within the framework of the protection of personal data (GDPR), NS Alliance has developed an innovative system allowing it to authenticate users without maintaining a central register of all of their biometric data. The centralised management of such data would be too risky. “We have developed an extremely secure mobile application through which each user records and retains his own data”, Cédric Hozanne explains.
Passing through the cash register with your finger, while the smartphone stays in your pocket
“The user has his biometric data with him, encrypted in our application, which is stored on his smartphone. We do not have access to that data. Our solution allows us to authenticate people we do not know.
Cédric Hozanne, CEO, NS Alliance
Based on two factors specific to the user, we can guarantee his authentication for the service provider who then proposes to carry out a transaction.” With the smartphone in his pocket, the user only has to put his finger on a reader. He is thus located in the right place and his data stored in the application ensures that it is indeed the right person. Behind the scenes, the NS Alliance solution checks whether the authentication factors match and confirms that it is the right person, according to the principles in this area. “Our solution's only purpose is the user authentication. The resulting transaction does not depend on us, but on our client. The possible applications, therefore, are vast. We can easily use the solution to initiate a payment at the cash register, or to open a door in the context of better access management”, adds Cédric Hozanne.
A strategic partnership with EBRC
This “Powered by EBRC” solution is distributed as a SaaS based in the Tier IV Data Centres of EBRC, the European leader in sensitive data management. In addition to being hosted by EBRC, the Natural Security solution is operated and fully managed by the IT expert and support PFS. “From the beginning, our members' goal was to define a new standard. We want to widely deploy the technology in the months and years to come”, highlights Cédric Hozanne. The association's model, based on open governance, makes it easy to welcome new members, even if they compete with the existing ones. Sharing technology should be even faster as a result. “But to meet the challenge, we have to convince both those who propose the transaction and the end users of the advantages. And to do so, we need to provide strong guarantees. It is both a matter of protecting and managing sensitive data and of guaranteeing critical transactions. We need to gain the trust of those who implement the solution just as much as the trust of the end users, says the CEO. For this purpose, we have developed strong strategic partnerships. The software solution, designed in partnership with Trust Designer, without a central biometric database, responds by design to the issues of data protection. On the other hand, we had to guarantee the highest availability of the service. Ease of access is essential for the adoption of our tool. The partnership with EBRC, which operates the solution, gives us a high level of certification (ISO27001, ISO20000, ISO27018), very high quality infrastructures (three Tier-IV-certified Data Centres), protection against cyberthreats and 24/7 availability, which is essential for this kind of activity.” According to NS Alliance, it is a real partnership between the association and EBRC, rather than a client-provider relationship. “In implementing this solution, EBRC acts like an entrepreneur in the project. We sought a partner who believes in our solution and who is able to help us deploy it by taking into consideration the requirements of this model. We have found a player in Luxembourg who shares our desire to innovate and to strengthen our services through solutions like the one we now offer together”, adds Cédric Hozanne.
A rapidly adopted technology
The solution is now mature. The first proof of concept dates back to early 2013. Back then, the solution was deployed for six months, with the authorisation of the
CNIL, in shops (Auchan, Leroy-Merlin, Flunch, Decathlon, small retailers,...) and three banks in the French cities of Lille and Angoulême. 1000 users were able to carry out transactions without having to take out any means of payment. “The feedback was excellent, which confirmed our approach. We found that the technology works, that it is appealing and ergonomic, but also that biometrics are not scary. An additional advantage is that the solution is effective and attractive regardless of age or sex. It has even been met with increased interest among the elderly, who adopted it quickly.”
The solution responds to regulatory issues such as the requirements defined by the PSD2 directive. “The other advantage lies in the fact that a single application allows users to access the services of all the partners who have chosen to work with us”, explains Cédric Hozanne.
Deployment on a large scale with an international scope
Today, NS Alliance has embarked on a mission to deploy the solution on a larger scale. In the Lille region, two places have already been equipped with it since January: the EDHEC Business School and the headquarters of the bank ONEY, which both totalised more than 2000 transactions since the beginning of the year. The solution was also implemented in San José, California, where it is used to enable access to a university restaurant. In the coming weeks, the association will launch the solution in the restaurants of several companies. Additional deployments are also being considered in Romania, in stores of the Auchan Group
in Bucharest, and in several large stores in France.
On the other hand, the solution also meets the needs for strong authentication outside of brick and mortar shops. For example, it allows you to authenticate yourself when carrying out transactions online, without the need to enter anything. “Banks can simplify access to web banking while enhancing security. The standards we implemented meet the reinforced requirements defined by the European Banking Authority (EBA). Our own and the EBA's goal is to enhance safety while improving the user experience”, summarises Cédric Hozanne.
NS Alliance is also talking about other major announcements in the coming months. Deployment is expected to accelerate. The solution is going viral because users, who are satisfied with the results, are looking forward to seeing it implemented by other merchants.