Project

Back to overview

Sound-Proof - Proof of Concept Integration

English title Sound-Proof - Proof of Concept Integration
Applicant Marforio Claudio
Number 173846
Funding scheme Bridge - Proof of Concept
Research institution
Institution of higher education ETH Zurich - ETHZ
Main discipline Information Technology
Start/End 01.03.2017 - 30.04.2018
Approved amount 129'982.00
Show all

Keywords (6)

backend; security; two-factor authentication; privacy; 2fa; usability

Lay Summary (Italian)

Lead
Al giorno d'oggi una grande quantità di dati personali viene digitalizzata, utilizzata e salvata online per le più svariate applicazioni: energia, governo, educazione, finanza, salute, assicurazione, solo per fare qualche esempio. Contemporaneamente, mentre la quantità di dati privati salvata online aumenta in maniera esponenziale, la consapevolezza verso i rischi informatici rimane bassa e questi non vengono presi abbastanza in considerazione. Sound-Proof è una tecnologia che facilita l'implementazione e l'utilizzo di autenticazione a due fattori, per rendere i dati online più sicuri.
Lay summary
Soggetto e obiettivo

Il nostro obiettivo principale è stato rendere Sound-Proof affidabile per la maggior parte di utilizzi e facilmente integrabile nei sistemi di autenticazione utilizzati oggi nell'industria. Più precisamente, (i) abbiamo testato la tecnologia sviluppata presso il gruppo di sicurezza informatica dell'ETH di Zurigo in maniera approfondita con diversi sistemi di cellulari (svariati modelli) e computer e (ii) abbiamo sviluppato un numero di punti di integrazione per diversi back-end attraverso il design di API generiche e di facile utilizzo. Inoltre, (iii) abbiamo testato queste API per sicurezza, stabilità e possibilità di scalabilità per supportare il maggior numero possibile di applicazioni online fino al raggiungimento di un setup per test fino a 500'000 utenti.

Contesto socio-scientifico

Il nostro lavoro ha reso l'integrazione di Sound-Proof più semplice e veloce in un gran numero di sistemi informatici in diversi settori della finanza, assicurazione, educazione e salute. Questa integrazione permetterà a tutti i cittadini di avere un accesso sicuro ai propri dati che i vari operatori salvano online, senza dover, necessariamente, utilizzare sistemi complicati e fastidiosi.
Direct link to Lay Summary Last update: 31.10.2018

Responsible applicant and co-applicants

Name Institute

Employees

Name Institute

Collaboration

Group / person Country
Types of collaboration
System Security Group Switzerland (Europe)
- Research Infrastructure

Knowledge transfer events

Active participation

Title Type of contribution Date Place Persons involved
START St.Gallen Performances, exhibitions (e.g. for education institutions) 16.03.2018 St. Gallen, Switzerland Marforio Claudio;
IT-SA Conference Performances, exhibitions (e.g. for education institutions) 10.10.2017 Nuremberg, Germany Marforio Claudio;
Finovate - NYC Performances, exhibitions (e.g. for education institutions) 11.09.2017 New York City, United States of America Marforio Claudio;


Abstract

More and more user data is digitalized, processed and stored on the cloud in areas like health, financial services, energy, e-governance, food or education. Yet, as the amount of sensitive data exponentially increases, the awareness for security risks is low and badly acted upon.Sound-Proof provides secure and user-friendly (zero-user interaction) authentication solutions to businesses and individuals to protect their accounts and data. In addition, Sound-Proof is committed to improve education and awareness campaigns for end-user security. Communication around security should empower businesses rather than instilling fear.Sound-Proof offers unique, fast, two-factor authentication (2FA), continuous authentication (next generation access management to pre-emptively secure inactive sessions) and traditional two-factor authentication solutions with a focus on ease-of-use for the end-user. The Unique Selling Proposition (USP) of Sound-Proof products is to provide affordable, easy to understand and strong authentication solutions that are hands-off for the end-user.Sound-Proof, as a technology, has been shown to be an accurate way to authenticate users without imposing additional burden on them. To bring this technology to the market we performed a number of tasks as part of this proof of concept project. In particular, we tested the technology on a larger array of hardware components and tweaked necessary components to ensure deployability and usability is not degraded.Aside from further testing, we designed the backend components in order for Sound-Proof to be easily integrated with existing authentication infrastructures. We defined a set of APIs to be able to communicate with existing authentication servers used for both web servers and other software used to connect to a network (e.g., SSH or VPN). During the project we further tested different cloud-based deployment solutions to ensure high-availability of the Sound-Proof back-end components for populations upwards of half a million users.With the funding from the BRIDGE Program, we started to take Sound-Proof from a prototype research project to a product that is marketable to a large number of companies in different market clusters (e.g., digital health, banking and financial sector). Benefits will be for both companies, in reduced cyber-security costs as well as new product offering capabilities, and all individuals, that will be able to finally have the option to secure their online data and accounts with an hands-off solution that they will want to use.The applicant has performed a preliminary market analysis and started discussions with potential customers in order to understand the requirements from the industry to accept an innovative security solution. Discussion led to idea including multi-account by default in a secure application, as well as the design of mobile SDKs for iOS and Android smartphones.
-