原创 Michael Novinson
身份验证(Identity verification)历史上用于银行、赌博和加密货币等受监管行业的入职流程,但COVID-19引入了包括防欺诈在内的新的政府和劳动力相关用例。
Gartner副总裁分析师阿基夫·汗(Akif Khan)表示,如今,身份验证技术提供了新的应用场景,比如:在Airbnb这样的市场中建立信任,及通过验证用户凭证来防范勒索软件攻击。
图片
Gartner 在其首份《Magic Quadrant for Identity Verification》报告中将 Entrust、Incode、Jumio、Socure 和 Sumsub 评选为身份验证领域的***。该报告聚焦的是一个有望从数字交互增多、监管要求以及防欺诈需求的增长中获益的市场。
图片
Khan 表示:“劳动力领域的一个主要趋势是将身份验证(IDV)作为安全工具的应用。这在很大程度上是由去年九月针对拉斯维加斯米高梅赌场的勒索软件攻击所引发的。在那次攻击中,攻击者冒充用户致电IT服务台,通过社交工程手段诱使服务台代理重置凭证,随后利用这些凭证访问了相关服务。“
Khan 表示:“然而,在当前市场中,买家在评估身份验证厂商检测欺诈性文件的准确性方面面临较大困难。这主要源于缺乏标准化的测试方法。厂商通常通过配置简便性、预置集成和系统可访问性来标注自身,此外,工作流程定制工具及区域性文件支持使***企业脱颖而出。”
Khan指出:要对比厂商在准确性方面的能力***为困难,甚至可以说是不可能的。就好比我已完成对应领域的魔力象限(MQ)分析,并且是专注于该领域的 Gartner 分析师,我也没法告诉你哪家厂商在识别伪造美国驾照方面孰优孰劣。在厂商如何评估这一点上,既没有标准化测试,也缺乏一致性。
Khan 进一步指出,监管在塑造身份验证的采用情况方面起着重要作用,数据主权和可访问性法规会影响厂商的选择及运营策略。一些组织要求个人身份信息必须保留在特定的特定辖区内,这就需要建立本地化的数据中心。Khan 表示,未来的法规将进一步提升可访问性和合规性标准。
“未来几年,欧洲将出台有关在线服务更高规格的可访问性要求法规。我们的明智客户已开始前瞻性地审视这一趋势,察觉到这一点,并确保他们现在的厂商采购决策能够在未来这些监管框架生效时,为其将来的成功奠定坚实基础。“
从独立流程到便携式数字身份
Khan 预见,身份验证流程将从独立的单一流程转变为可携带的数字身份,利用存储在身份钱包中的已验证凭证,可在多个平台上重复使用。根据 Khan 的观点,这一变化将在政府倡议的推动下,如美国的移动驾驶执照和欧盟的数字身份钱包,未来数年内与传统身份验证方法并存。
Khan 指出:“下次您开立银行账户或注册网络游戏时,可能无需再次进行身份验证。相反,您将使用已在身份钱包中验证并存储的身份信息。在这方面,世界上已经有相关进展了。比如在美国,移动驾驶执照正逐渐获得关注。”
尽管机器学习技术取得了显著进展,Khan 强调,但机器审核仍无法可靠地去验证文件,人工审核在身份验证过程中仍然扮演着关键角色。这种“人机结合”的方法在如德国等市场占据主要方式,因为当地法规禁止***依赖自动化机器审核的流程。然而,Khan 指出,这种人机结合方法带来了处理时间、成本及数据安全方面的担忧。
他进一步说道:“在某些场景中,客户确实需要人工审核参与。然而,在其他场景中,人工审核参与可能会带来问题,因为这会增加处理时间和成本。此外,人工审核所在的具体地区位置也可能导致问题。例如,尽管您的公司总部位于某一地区,但如果厂商的人工位于其他地区,用户的个人身份信息(PII)可能需要跨越全球进行人工审核,从而涉及数据安全风险。”
Gartner对身份验证市场的评估
Gartner 评选 Incode Technologies 在身份验证领域具有***全面的愿景,Jumio 获得银奖,Entrust 获得铜奖,Sumsub 和 AU10TIX 分别位居第四和第五。从执行能力的角度来看,Persona 荣获金奖,Sumsub 获得银奖,Socure 获得铜奖,Entrust 和 Jumio 分别位居第四和第五。
在***之外,Gartner 对身份验证市场的其他参与者的看法如下:
Visionaries: AU10TIX、Mitek Systems;
Challengers: Persona
Niche Players: 1Kosmos, GB Group, Zoloz;
未入选名单(Missing the List): Advance.AI、Daon、ID-Pal、IDWise、Intellicheck、Inverid、Nametag、Regula 以及 Veridas,因未达到收入纳入标准而未被列入。
Entrust 通过收购 Onfido 加强欺诈检测与文件验证能力
Entrust 支付与身份识别总裁托尼·鲍尔(Tony Ball)表示,收购 Onfido 将增强 Entrust 在人工智能驱动的欺诈检测和文件验证方面的能力。Onfido 的文件拖拽方式引擎提升了 Entrust 服务的灵活性和整合性,而 Onfido 在可便携及可重复使用身份方面的投入与政府和金融机构不断变化的需求相契合。
鲍尔补充到,Entrust 的差异化优势在于利用人工智能和机器学习技术实现反偏见技术,以及通过生物识别活体检测和拖拽式工作流引擎提供服务。Entrust 计划在提高自动化率的同时,保持对人工干预的灵活性,它将在从公平的客户准入到定制化身份工作流等各个方面为金融机构提供支持。
鲍尔在接受媒体采访时表示:“我们***重要的能力之一是利用人工智能从深度伪造的角度预测欺诈行为的源头。能够借助文件和生物特征属性做到这一点确实是 Onfido 长期以来建立的一项优势,这对我们已有的能力是强有力的补充。”
Gartner 批评 Entrust 在多年期合约中折扣力度不足,对全球文件的收费高于美国文件,并且在身份验证检查中常常需要人工参与。鲍尔回应称,Entrust 的混合方法在机器审核与必要的人工审核之间取得了平衡,合规性和安全性方面的投资证明了其定价的合理性,尤其是在欧洲等受监管的市场。
鲍尔说:“尽可能减少人工干预这一点确实有其合理性。但另一方面,有时确实需要人工干预,而这种混合方法对我们的部分目标受众来说是有价值的。具备这种灵活性也是一种竞争优势,就如同在一些客户眼中***自动化是一种优势一样。”
Jumio 利用人工智能、机器学习与生物识别技术提升身份验证
Jumio ***营销官安娜·康弗里(Anna Convery)表示,Jumio 在人工智能、机器学习和生物识别技术方面进行了大量投资,以提升身份验证能力。该公司的全球系统能够处理众多身份证件,并适应立法变化。她还提到,Jumio 通过趋势分析打击深度伪造,并通过活体检测增强了检测能力。
Convery说,Jumio 的优势在于其在超过 200 个国家开展业务,并拥有庞大的身份证件数据库。Jumio 对创新与客户执行的双重关注,形成了平衡的战略,不同于那些可能偏重某一方面的竞争对手。她表示,Gartner 的认可反映了Jumio在这快节奏的身份验证领域的领导地位。
Convery 表示:“掌握数据以洞察趋势和动态至关重要。我们花费大量时间去审视身份的整体情况,确保留意每一个迹象、每一个触发因素,这些能让我们明白这个人并非其自称的那样,甚至可能根本就不是真人。”
Gartner 批评 Jumio 配置复杂、全球文件收费高于美国文件,并且在身份验证检查中常需人工参与。Convery回应称,工作流的复杂性正在通过更便捷的客户配置工具加以解决,人工干预往往是由法律或地域要求所驱动的,而较高的定价反映了 Jumio 所具备的强大工具。
Convery 说:”我们一直在努力实现自动化,部分客户已达到 100% 自动化,但取决于组织机构、所处行业以及具体用例,有时候情况***敏感且特殊,要是有需要的话,能够利用人工参与其中其实是有好处的,我们会在有需要的地方提供这种混合式的灵活性。”
Sumsub 专注于深度伪造检测与活体验证
Sumsub 增长主管伊利亚·布罗文(Ilya Brovin)表示,Sumsub 一直致力于深度伪造检测和活体验证以应对欺诈问题,为整个用户生命周期打造了一个综合性的验证平台,并且扩大了其电子及可便携数字身份系统的使用,以取代传统的基于文件的验证方式。
Brovin 说,该公司将基于人工智能的工具、大量的流量数据以及人工监督相结合,以提高其深度伪造检测的准确性,Sumsub 的系统能够检测数字伪影,并观察到合成图像中所缺失的微小动作。布罗文称,Sumsub 通过其端到端的验证解决方案彰显自身特色,这些解决方案集成了用户准入、监测以及合规检查等功能。
Brovin告诉媒体:“实际上,检测深度伪造并非单一技术能够完成的任务。需要多层次的工具,才能有效地保障整个流程的安全。深度伪造检测只是攻击途径之一,而你要做的基本上是弄清楚你在和谁打交道。”
Gartner 批评 Sumsub 在其路线图上没有专注于身份验证相关的特定功能,没有将专有的人脸匹配算法提交给NIST,也没有自愿采用产品评估模板。Brovin表示,Sumsub 在自愿性产品可访问性模板(VPAT)合规性以及可便携数字身份系统方面已经取得了进展,并且称鉴于美国国家标准与技术研究院认证的适用范围有限以及在美国之外的关联性不大,其认证延迟是合理的。
Brovin说:”这些测试在审查内容和范围上通常***有限。实际上,在现实应用中,我们使用活体验证和深度伪造检测的方式要比这些测试所审查的范围广泛得多。我们一直在与客户合作,对现实生活中我们的活体验证和深度伪造检测解决方案进行质量把控,而且我们相信这能带来***高质量的结果。”
Socure 利用 OCR 技术增强文件验证功能
Socure ***人兼***执行官约翰尼·艾尔斯(Johnny Ayers)表示,Socure 正在开拓身份验证的新方法,包括(OCR)技术增强文件验证、通过无监督机器学习进行预测分析,以及开发应对深度伪造攻击的新方法。公司强调速度和准确性,近期在基于人脸的重新验证和跨语言文档处理方面取得了进展。
Ayers说,收购 Berbix 进一步增强了 Socure 在文件验证方面的能力,实现了深度伪造检测和条形码验证等创新功能,同时收购的技术团队的整合加速了公司的创新流程。Ayers 表示,Socure 的市场领导地位源于公司的技术实力及其对美国全球企业的战略聚焦。
Ayers 告诉媒体:”我们具备在***国家通过仅查看一两份文件进行培训的能力,基本上不再依赖模板。现在,我们可以利用 OCR 技术,以全自动化的方式将***语言的文件转换为纯文本英文。”
Gartner 批评Socure 几乎所有处理的文件都来自北美,这使得客户很难提供他们自己的代理,并且该公司没有依照国际标准化组织(ISO)的标准来测试其活体验证能力。Ayers表示,Socure 聚焦于立足美国的业务是出于战略考量,使用自动化而非人工代理提高了效率和准确性,而且对相关认证的重视程度没那么高。
Ayers进一步指出:”作为一名消费者,你是愿意得到 1.75 秒的响应时间,还是愿意等待两到三周去参加视频面试呢?” 艾尔斯说道,“在疫情期间,你也看到了,要访问 ID.me 有时得等上两个月 —— 而我们用不到两秒钟就能处理好的事。所以我认为这(自动化带来的快速响应)是一件好事。”
Incode 的产品获赞誉,客户流失遭诟病
Gartner 对 Incode 表示肯定,因其拥有易于配置的工具,能将服务水平协议(SLAs)与转化率以及欺诈防范成果相挂钩,并且在对核心功能进行增强的同时,还为员工使用场景增添了新特性。Incode 近期新增了一款无代码编排工具和年龄估算产品,还计划加强注入攻击检测,并专门针对员工使用场景构建一站式功能。
分析机构批评 Incode 存在营销执行效果低于平均水平、客户流失率较高以及仅依靠净***值来评估客户满意度的问题。Incode 的高管未能接受电话采访。
原文链接:
https://www.inforisktoday.com/entrust-jumio-sumsub-lead-identity-verification-gartner-mq-a-26844
Entrust, Jumio, Sumsub Lead Identity Verification Gartner MQ
Gartner Publishes First Identity Verification MQ as Workforce-Related Uses Multiply
Michael Novinson (MichaelNovinson) • November 18, 2024
facebook sharing button Sharetwitter sharing button Tweetlinkedin sharing button Share Credit Eligible
Entrust, Jumio, Sumsub Lead Identity Verification Gartner MQ
Identity verification was historically used for regulated onboarding in industries like banking, gambling and cryptocurrency, but COVID-19 introduced new government and workforce-related use cases including fraud prevention. Today, identity verification technology offers emerging applications in trust building in marketplaces like Airbnb and safeguarding against ransomware attacks by verifying user credentials, said Gartner Vice President Analyst Akif Khan.
See Also: 2024 Threat Hunting Report: Insights to Outsmart Modern Adversaries
Gartner recognized Entrust, Incode, Jumio, Socure and Sumsub as identity verification leaders in its first Magic Quadrant for Identity Verification report, which focuses on a market expected to benefit from the rise in digital interactions, regulatory demands and fraud prevention requirements.
“The larger trend in the workforce space is the use of IDV as a security tool,” Khan said. “A lot of that has been sparked by the ransomware attacks that were carried out against the MGM casino in Las Vegas last September, in which the attackers called the IT help desk, pretending to be a user, socially engineered the Help Desk agent into resetting credentials, and then used those credentials to access services.”
But it’s hard for buyers in this market to distinguish between identity verification vendors when it comes to their accuracy in detecting fraudulent documents. And that’s due to a lack of standardized testing, he said. Vendors typically try to differentiate themselves through ease of configuration, pre-built integrations and accessibility, with workflow customization tools and regional document support also setting leading firms apart, he said.
“It is incredibly difficult – if not impossible – to compare vendors in terms of their accuracy,” Khan told Information Security Media Group. “Even after having done the MQ and being a Gartner analyst who focuses on this area, I couldn’t tell you which vendor is better or worse at spotting a fake U.S. driver’s license. There is no standardized testing or consistency in terms of how vendors are assessing this.”
Regulation plays a major role in shaping identity verification adoption, Khan said, with data sovereignty and accessibility regulations influencing vendor selection and operational strategies. Some organizations require personally identifiable information to remain within specific jurisdictions, necessitating localized data centers. Khan said future regulations will elevate accessibility and compliance standards further (see: The Evolution of Identity Verification).
“There is regulation coming in Europe in the next couple of years around high levels of accessibility required for online services,” Khan said. “The smart clients of ours are starting to look ahead and starting to see that and are starting to make sure that the vendor purchasing decisions they’re making now set them up for success as those regulatory frameworks come into force in the coming years.”
From Stand-Alone Processes to Portable Digital Identities
Khan envisions a shift from stand-alone identity verification processes to portable digital identities that use verified credentials stored in identity wallets for reuse across multiple platforms. The change will coexist with traditional identity verification methods for years, driven by government initiatives including mobile driver’s licenses in the U.S. and digital identity wallets in the European Union, according to Khan.
“The next time you open a bank account or register for an online game, you won’t necessarily go through identity verification again,” Khan said. “Instead, you will assert the identity that’s been already verified and stored in your identity wallet. And so, there are things already happening in the world in that respect. Mobile drivers’ licenses are starting to gain some traction in the U.S.”
Despite advancements in machine learning, Khan said humans play a critical role in identity verification for scenarios where automated systems cannot confidently verify documents. This “human in the loop” approach is essential in markets like Germany – where regulations prohibit fully automated processes – but Khan said it raises concerns about processing time, cost and data security.
“In some markets, clients will actually need a human in the loop,” he said. “But in other markets, having a human in the loop can be problematic because it adds to processing time. It adds to cost. Depending on where the humans are, it might mean that although you are based in this region, if your vendor has their humans in another region, your user’s PII is going around the world for humans to check it.”
Gartner rated Incode Technologies as having the most complete vision around identity verification, with Jumio taking the silver, Entrust getting bronze, and Sumsub and AU10TIX taking fourth and fifth place, respectively. From an execution ability standpoint, Persona snatched the gold, Sumsub took silver, Socure took the bronze, and Entrust and Jumio captured fourth and fifth place, respectively.
Outside of the leaders, here’s how Gartner sees the identity verification market:
Visionaries: AU10TIX, Mitek Systems;
Challenger: Persona;
Niche Players: 1Kosmos, GB Group, Zoloz;
Missing the List: Advance.AI, Daon, ID-Pal, IDWise, Intellicheck, Inverid, Nametag, Regula and Veridas, which didn’t meet the revenue inclusion criteria.
Entrust Boosts Fraud Detection, Doc Verification With Onfido Buy
The acquisition of Onfido will strengthen Entrust’s AI-driven fraud detection and document verification capabilities, according to Payments and Identity President Tony Ball. Onfido’s drag-and-drop workflow engine enhances Entrust’s flexibility and integration of services, while Onfido’s investments in portable and reusable identities align with the evolving needs of governments and financial institutions, Ball said.
Ball said Entrust differentiates itself by leveraging artificial intelligence and machine learning for its anti-bias technology as well as through biometric liveness detection and a drag-and-drop workflow engine. Entrust plans to increase automation rates while maintaining flexibility for manual interventions. It will support financial institutions in everything from equitable client onboarding to customized identity workflows (see: Entrust in Talks to Acquire Onfido for AI-Based ID Checks).
“One of the most substantial things that we have is the AI-driven capability for anticipating where fraud is emanating from, from a deepfake perspective,” Ball told ISMG. “Being able to do that with both a document and biometric attribute is really a strength that Onfido has built on for quite some time, so that strongly complements what we already have.”
Gartner criticized Entrust for low discounting on multi-year deals, charging more for global documents than U.S.-based documents, and for often requiring a human on identity verification checks. Ball said Entrust’s hybrid approach balances automation with necessary human overnight, adding compliance and security investments justify Entrust’s pricing, particularly in regulated markets like Europe.
“There is some validity in the fact that you always want to take as much of the manual intervention out as you can,” Ball said. “On the flip side, there is sometimes a need for manual intervention, and having that hybrid approach is seen as valuable to some of our target audience. Having that flexibility is also a competitive advantage, as much as it is to be in the eyes of some customers fully automated.”
Jumio Improves Identity Verification With AI, ML, Biometrics
Jumio has made significant investments in artificial intelligence, machine learning and biometrics to improve identity verification, with the company’s global system handling numerous identity documents and adapting to legislative changes, said Chief Marketing Officer Anna Convery. Jumio is also combating deepfakes through trend analysis and enhancing detection capabilities with liveness detection, she said.
Convery said Jumio stands out due to its work across more than 200 countries as well as its extensive database of identity documents. Jumio’s dual focus on innovation and customer execution creates a balanced strategy, Convery said, unlike competitors who may lean too far toward one or the other. Recognition by Gartner reflects Jumio’s leadership in the fast-paced identity verification space, she said (see: Reusable Digital Identities – The Future of Digital Identity).
“It’s very important to have the data to see the trends, to understand what’s going on,” Convery told ISMG. “We spend a lot of time looking at the overall picture of the identities and making sure that we look for every indication or every trigger that would have us understand that this person is not who they say they are, and maybe not even a person at all.”
Gartner criticized Jumio for a low ease of configuration, charging more for global documents than U.S.-based documents, and for often requiring a human on identity verification checks. She said workflow complexity is being addressed through better customer-accessible configuration, human intervention is often driven by legal or geographic requirements, and premium pricing reflects Jumio’s robust tools.
“We’ve been working a lot at automation, and some of our customers are 100% automated,” Convery said. “But depending on the organization, industry and use case, sometimes it is so sensitive and so particular that it’s actually good to be able to leverage a human in the loop if you need to, and we give that hybrid flexibility where it is needed.”
Sumsub Focuses on Deepfake Detection, Liveness Verification
Sumsub has concentrated its efforts on deepfake detection and liveness verification to address fraud, creating a comprehensive verification platform for the entire user life cycle, and expanding its use of electronic and portable digital identity systems to replace traditional document-based verification, according to Chief of Growth Ilya Brovin.
Brovin said the company has combined AI-based tools, extensive traffic data and human oversight to improve the accuracy of its deepfake detection, with Sumsub’s system detecting digital artifacts and observing micro-movements absent in synthetic images. Brovin said Sumsub differentiates itself through its end-to-end verification solutions, which integrate onboarding, monitoring and compliance checks.
“Actually detecting deepfakes is not one thing, where you can just have one piece of technology that detects them,” Brovin told ISMG. “You need to have multiple layers of tools in order to effectively secure the whole journey. Deepfake detection is one of the attack vectors, whereas what you’re trying to do is basically understanding that you know who you’re dealing with.”
Gartner criticized Sumsub for not focusing on identity-verification-specific features on its road map, not sending proprietary face-matching algorithms to NIST and not having a voluntarily product assessment template. He said Sumsub has made progress in VPAT compliance and portable digital identity systems, and said the NIST certification delay is justified given its limited scope and relevance outside the U.S.
“These tests are usually very narrow in terms of what they review and scope,” Brovin said. “In reality, the way we use our liveness and deepfake detection in the real-life case is much broader than what these tests review. We’re always working with our clients to do the quality control on our liveness and deepfake detection solution in real life, and we believe that provides very high-quality results.”
Socure Enhances Document Verification With OCR
Socure is pioneering new methods in identity verification, including enhanced document verification using OCR, predictive analytics through unsupervised machine learning, and novel methods to combat deepfake attacks, said Founder and CEO Johnny Ayers. The company emphasizes speed and accuracy, with recent developments in face-based re-verification and cross-language document processing.
The acquisition of Berbix enhanced Socure’s capabilities in document verification, enabling innovations like deepfake detection and barcode verification, while the integration of acquired technical teams has accelerated the company’s innovation pipeline, Ayers said. Socure’s market leadership stems from the company’s technological prowess and its strategic focus on U.S.-based global businesses, Ayers said (see: Socure to Fortify Identity Services With $136M Effectiv Buy).
“We have the ability to be able to train in any country by just seeing one or two documents, basically where previously you could use a template,” Ayers told ISMG. “Now we can use OCR and be able to extract any document in any language into plain-text English in a fully automated way.”
Gartner criticized Socure for drawing almost all of its processed documents from North America, making it difficult for customers to provide their own agents, and for not testing its liveness detection capability in conformance with ISO. Ayers said Socure’s focus on U.S.-based businesses is strategic, the use of automation over human agents boosts efficiency and accuracy, and certifications were deprioritized.
“As a consumer, would you rather have a 1.75-second response time or wait for a video interview for two or three weeks?” Ayers said. “You’ve seen during COVID some of the wait times to access ID.me were like two months – for a thing that we could do in less than two seconds. So I view that as a positive.”
Incode’s Product Earns Praise, Customer Churn Gets Scorn
Gartner praised Incode for having an easy-to-configure tool, linking SLAs to conversion rates and fraud outcomes, and balancing enhancements to core aspects with the addition of new features for workforce use cases. Incode recently added a no-code orchestration tool and age-estimation products, and plans to enhance injection attack detection and build turnkey features specifically for workforce use cases.
The analyst firm criticized Incode for below-average marketing execution, a high customer churn rate and relying solely on Net Promoter Score to assess customer satisfaction. Incode executives weren’t available for a telephone interview.