CardLab Innovation QuardCard
Full privacy protection
Biometric authentication system
CardLab Innovation provides a biometric card with "system on card" solution capable of storing your personal data that only can be released by presenting the correct fingerprint to the card. It is a "Plug & play" solution with backend authentication system knowing the card and the token generator in the card to be able to check tokens generated to secure the unique identity of the user. The card transforms the personal identity to a token and sends any data in encrypted format which ensures your full protection against data loss and identity theft from "man in the middle" attack.
The solution enables you to carry personal data, medical record, drivers license, voting ID etc. in one card out of hacker reach as it works offline and secures your control of own data as it can only be opened by the correct fingerprint. This secures democratic rights based on your identity and a strong GDPR compliance.
Solution location:CardLab Innovation, Hoerkaer 14A, 1., DK-2730 Herlev, Denmark
Solution's stage of development:
What makes the solution innovative:
The combination of technologies is new combining offline authentication on the card with online operation making use of internet convenience but also all other local infrastructure.
CardLab Innovation is the first company to provide cards that can communicate with all existing infrastructure and produce the cards in volume and is in addition the only company to have the combination of biometric verification on the card combined with a backend token authentication before data is unlocked.
No other solution ensures same level of unique identification and privacy protection.
How the solution demonstrates 'privacy by design':
The solution is built around privacy by design as we have developed the solution around:
- no signatures as they can be falsified or not usable by ilerate people
- biometric fingerprint template stored in the card only reducing hacking risk on databases.
- Any needed personal data can be stored in an offline server and be accessed on a need to know only.
- The card can interface to any media via displayed OTP tokens, NFC, BLE or other communication interfaces.
- Your biometric verification if succesful turns you into an encrypted token so your identity is totally unidentifiable to persons not having access to authentication and HSM server on a central or local basis.
- Central biometric databases can be avoided reducing hacker risk and the risk of identity loss dramatically.
How the solution can be incorporated into digital identification systems:
- The card automatically creates a digital dynamic identity in form of tokens that can be identified if needed by the backend authentication system.
- The system can also be delivered so different authorities can have different access rights to data in the card, but they will all be depending on that the card holder will present the right fingerprint. Until then the card remains a dum peace of plastic for anybody, ensuring the cardholders privacy.
- Different agencies (medical, police, polling station, community office etc.)can read the card by a selected interface once the cardholder has given access by presenting the correct fingerprint.
- This means that the cardholder can decide what to give access to and depending on different countries infrastructure the card can be used to grant access to data in a database via the backend authentication system or give direct access to data depending on reader authorization if data are stored in the card.
How the solution is 'user-friendly':
From test we have graded it extremely user friendly as it takes less than 3 minutes for a user to enroll his biometrics in the card and the backend system has in demo projects been up and running in less than 1 hour starting from no solution at all.
Personal identification takes place in less than 2 seconds afterwards whether ID, access, payment or other situation.
How the solution ensures interoperability:
Solution is based on standard protocols and can be accessed via NFC, BLE or other interfaces and does have a display to show tokens to be used in normal web interface. Any vendor with the right skill can connect to the system and the system can connect to any existing infrastructure.
How the solution accounts for low connectivity environments and for users with low literacy and numeracy levels:
The solution only requires the user to show his fingerprint and an instruction on enrolling with out using numbers and letters can be provided. The card can work as a standalone tool with its own battery source which can be rechargeable
Vision over the next three to five years to implement or grow the solution to affect the lives of more people:
The solution will help a lot of people who today are extremely exposed due to lack of cyber security and thereof following data breaches. The card and the backend system will bring control of own data back to the user as he/she can carry them on own person all the time and be the one to decide when to disclose data.
How the solution team is organized:
How many people work on the solution:
The organizations applicants are currently working with:
I am the CEO of CardLab Innovation that consists of a team of skilled developers and we are working together with the company QuardLock that provides the backend authentication solution.
My role is to set the strategic direction and practical coaching and motivation of the team
Applicant skills that can attract the different resources needed to succeed and make an impact:
We have some of the worlds most experienced engineers in embedded microelectronics and electronic Smart Card solutions making it very attractive to work with CardLab as we are working on cutting edge technology bringing a lot of new benefits to the users in form of unique identity and privacy protection.
CardLab Innovation has a number of standard card solutions sold to different customers where some of the sale id sale of licenses to CardLab technology.
In addition to this we have a card customization team putting together card solutions for customer taking into account specific security and/or convenience demands.
We are a technology provider to the electronic card industry and have added a partnership with QuardLock so we together are able to provide complete solution with fully secure biometric cards and a secure backend authentication system.
CardLab also has its own lamination factory for especially electronic cards and laminate own products and customer cards into finished card products.
Reason for applying to the Mission Billion Challenge:
Our participation is aimed at bringing our solution to a broader audience to show it is possible to provide unique identification and full privacy protection at the same time. We hope to bring attention to the solution and bring on more large scale pilots to help more people with better protection and ability to enjoy democratic rights despite illiteracy and powerty. By more attention we can get more input to make the solution fully mature and ready for mass production.
Key barriers to the solution:
People need to understand this is a offline solution providing much better privacy protection then online solutions and central databases that can be hacked. This can be overcome by continuos information to the market and close collaboration with existing customers.
Production ramp up is a challenge being addressed by a present fund raising round to be able to raise production capacity to 1 million cards per month.