Keyless Recognized by Gartner as a Leading Decentralized Biometrics Vendor
Keyless has been recognized as a
decentralized biometrics vendor in Gartner’s latest
Innovation Insight for Biometric Authentication report. This report details Gartner's recommendations for Identity and Access Management (IAM) leaders considering biometric authentication solutions.
Gartner makes six key recommendations and highlights 32 supporting pieces of evidence for adopting biometric authentication.
Below are three takeaways that stand out:
Addressing the Security Gaps of Local or Device-Based Biometrics
Banks report concerns that fraudsters can register their own biometric data (e.g., face or fingerprint) on stolen or compromised phones. Once enrolled, they can bypass security measures meant to protect accounts.
Banking clients have expressed concerns that a customer’s spouse or child might have enrolled their fingerprints on the customer’s phone, thus enabling that other person to masquerade as the customer. There is no technical way to restrict this, but banks typically ask a customer setting up biometric authentication to assert that no one else has enrolled their fingerprints.
To prevent this, many banks fall back on passwords, PINs, or SMS OTPs - but these are weak security measures. If a fraudster has access to the victim’s phone, they probably also have access to these fallback options.
FaceID and fingerprint authentication alone aren’t enough. In order to know that the person making a payment is the person that enrolled, banks should use third-party biometric authentication systems linked to an identity verification (IDV) provider.
Implementing Third-Party Biometric Authentication Solutions for High-Risk Scenarios
IAM leaders should use third-party biometrics (centralized or decentralized) for authentication, including:
Step-up authentication for high-risk actions.
Account recovery when passwords or devices are lost.
Support across multiple operating systems.
Third-party biometrics offer greater control over enrollment and configuration than device-native biometrics, better omnichannel support, and enable integration of authentication and identity verification (IDV).
Unlike local biometrics, third-party biometric authentication links a user’s credentials to their biometrics. A bank is able to tell that the person logging in or making a payment is the same person that originally passed the KYC check.
Mitigating the Privacy Concerns of Centralized or Cloud-Based Biometrics with Decentralized Biometrics
Gartner recommends local or decentralized biometrics for privacy protection over centralized models. Centralized biometric systems store data in the cloud, making them a target for cyberattacks.
Choose vendors that are certified against recognized data protection criteria. Prefer local or decentralized deployment options, which can enhance privacy. Ensure the vendor has implemented security controls that meet or exceed the organization’s standards.
Decentralized biometric systems like Keyless eliminate the risk of biometric data leaks by ensuring that biometric data is never stored anywhere - neither on the cloud or the device.
Instead, Keyless stores zero-knowledge biometric data.
Why Decentralized Biometric Authentication is Growing in Popularity
Gartner’s research highlights an emerging trend: decentralized biometrics offer the best balance of security, privacy, and user experience.
They create a link between a person’s face and their online credentials.
They work across devices, unlike local biometrics.
They protect privacy better than centralized biometrics, which still store sensitive data.
They reduce reliance on passwords and SMS OTPs, making authentication both safer and easier.
For IAM leaders looking to adopt secure, future-proof authentication, Keyless' Zero-Knowledge Biometrics™ aligns with Gartner’s vision - offering privacy, security, and simplicity without the risks of traditional biometric models.