Monday, August 14, 2006

Financial products have a Long Tail

I finally succumbed to the hype and an extended period of time waiting at Boston Logan airport. The opportunity to buy a real paper book presented itself in the form of Chris Anderson's The Long Tail. Sat in prime position on a Borders' display, it must be deserving of every penny of the $17.50 per year that few square inches of space cost the retailer in rent and overheads (my estimate from Anderson's figures!).

I was flying to Austin, Texas via Atlanta, to take a short notice trip to Vignette's HQ. By the way, one day very soon the company will complete the migration of its corporate www site to its V7 flagship product and I might actually be proud to link to it. In the meantime its just a courtesy. This introduction into my travel schedule is also an implicit excuse for a lack of posts over the next few days.

On the flights, fired by a lack of carry on luggage (I don't need the extra hassle of buying toothpaste and other necessary items every time I travel, so I'm happy not to have to fight the masses for another piece of prime real-estate, an overhead bin), I ploughed through the first 178 pages of the book. Which only leaves me about 50 for the return trip - best do some real work I suppose!

In any case, the book made me start thinking (and I apologize if this is addressed in the last 50 pages) how the Long Tail might be applied to financial products. I'm not thinking bank accounts, since I believe they probably need a bank to be relatively pervasive to work effectively right now, as I don't wan't ATM charges every time I need cash. More effective would be items like loans, insurance, mutual funds and annuities.


Financial product Long Tail

The Long Tail probably can apply quite effectively, assuming I limit the scope a little. For any of financial product where I invest my own money, I would suggest that the Long Tail applies to the multitude of products from recognized and reputable institutions that fall outside of the Top 500 'Hit' products. I don't want to include marginal or unheard of institutions into the mix since the risk of me losing my shirt is far higher than buying an unwanted birthday present from someone unknown on eBay. Although it has to be said that Zopa has a good model for investing in loans that people seem to trust, despite its relatively unknown status.

There are financial institutions that have built their brand on the ability to sell a vast array of securities, independent of popularity or ranking. Go to Fidelity, E*Trade, or another online brokerage and they will offer stock in many companies that could be considered to be in the mid-portion of the Long Tail, all as part of their standard low-cost service. And they provide many of the filtering and advice tools that Anderson suggests are necessary to help customers when facing a bewildering array of options.

This meets two of the requirements for the Long Tail according to Anderson (page 57):

  • Democratize distribution - e.g. Fidelity is just an aggegator of stock for sale
  • Connect supply and demand - e.g. E*Trade provides tools to enable customers to select stock based on many sources of information
The final force for the LT is 'democratize production'. Although I suppose anyone could run a public company, SEC regulations and Sarbanes-Oxley (SOX) seem to be making that harder and more expensive than ever. This could be considered as to ensure that production of public company stock is never really democratized, all in the best interests of the public investor (!).


The discontinuous Long Tail

Sliding down the slope to the more distant end of the LT appendage will place you into the 'penny' stocks. These don't meet the rules or the volume of trading that would have them listed on the Nasdaq, therefore making it more difficult to find out information about them, or even their current value. Given that, E*Trade for example will allow you to buy them online, although the restrictions really separate these stocks from those higher up the ranking. This is not the seamless LT that we see with iTunes, where rank does not affect the ease with which I can buy a track. With penny stock the LT is a little discontinuous, where we can no longer apply the common structure and rules of NASD to the items we want to buy. Its a bit like iTunes trying to sell vinyl albums when you get to an imaginary point in their database where the item you want exists but has not yet been digitized.


Complex products have more to gain

With complex products like annuities, where the number of combinations of securities components coupled with insurance components is enormous, the rules and potential benefits of LT could really kick in. Advanced consumers could benefit greatly from matching the endless array of products to exactly their requirements, if the information and access to products through a single online access-point was available. In this mode though there are many other issues that do not face Amazon and Google, like licensing of advisors and agents, assessing suitability for a product and so on.

The Long Tail could be enabled by the work that NAVA is doing to prepare the annuity industry for online account opening and management. Fidelity and E*Trade could for example start assembling and selling a far greater range of annuities, at a far lower cost of production. This matches the requirement for a LT to reduce the cost of production, with the brokerages standards for aggregating distribution and provide filtering to match products with people.


Summary

Financial products have probably followed a partial Long Tail model for a while, especially around the online stock brokerages we are familiar with. The costs of production may have risen, but to the customer the distribution costs and filtering / information tools have provided a far enhanced and more varied environment to trade in.

Other more complex products like annuities could greatly benefit from the Long Tail dynamics. The manufacturers of these items require a significant push, both in terms of standards, but maybe also something (or someone) else to put them into a state where they can benefit from this new model of selling 'less of more'.

[UPDATE: Apparently I messed up a couple of the links. All fixed now. Sorry!]

Technorati tags:

Friday, August 11, 2006

Citibank Hardware Tokens Defeated - but don't blame the tokens

A post today at Bankwatch » Citibank Hardware Tokens Defeated: The Beginning of the End
pointed to an AllPayNews article about the weakness of physical tokens (like the RSA SecurID). The article talks about how Citibank's online banking security was defeated by a fairly simple phishing method, despite the use of physical tokens.

As it turns out, the article was a push by a security token vendor, PhishCops. In any case, it did point out an apparent weakness of SecurID type security tokens when implemented without other anti-phishing measures.

According to the AllPayNews article, the scam worked like this:
In a textbook example of a "man-in-the-middle" attack, Citibank business customers were lured to dozens of counterfeit websites located in Russia where they were prompted to supply their token-generated passwords and other credentials. The counterfeit websites then swiftly sent the solicited credentials to the genuine Citibank website where they were used to access the accounts.
For background on tokens, see my recent posts around electronic signatures and the use of physical tokens
to strengthen the standard username/password pair for user authentication at online banking and other financial sites.


How did this work?

A valid Citibank online service would prompt the user for their standard login details, an account ID and password. Knowing which account the customer is attempting to access, the service now requests a one-time number to be entered from the user's token. SecurID and similar tokens rely on a user specific number being generated that remains valid for 30-60 seconds after being displayed on the device's LCD screen. The user enters this number into the online prompt, confirming that they are in possession of the token. The two-factor approach, an item that is memorized (password) and an item that is in-hand (token) ensures the authenticity of the customer.

The problem is that the scam used an advanced phishing approach. Not only did the scam direct customers to a website that presumably appeared exactly like a Citibank website, prompting them for all of their credentials, it immediately used these to access the real Citibank online service with the provided information. Assuming that the scam site completed this within the lifetime of the one-time password (30-60 seconds), it would be successfully authenticated, enabling the scammers to perform fraudulent transactions on the customer's account.


Tokens don't work?

Tokens with a limited lifetime passcode are still very valuable devices to ensure authentication of users. Even if both password and one-time passcode are stolen, the fraudulent user has to exercise them in a very short amount of time. Certainly this is a strong barrier preventing many keylogging and phishing attempts, but as is demonstrated here, not all.

The problem is that tokens don't close the loop. Although the banking service can confirm that the user credentials entered truly are the two-factor identification for the customer, the customer still has no way of being sure that the site they are entering this information into is real.


Need to prevent users entering credentials into fake sites

It is essential that online services provide a mechanism for very obviously confirming to users that they are using the real site. Educating users to study the URL is really insufficient. Anti-phishing toolbars are also an option, but since many users who travel may use PCs that are not their own for access to online services, this is also impractical to depend on. A good option is the SiteKey as used by Bank of America.

SiteKey is a way of demonstrating to a customer that they are looking at a valid BoA site. When attempting to login, the only information requested on the front screen is basic ID, the account number and state you live in. This is submitted to a the secure site, which retrieves a picture and a phrase. These two items were selected by the user when the online account was setup, and are only known to them. Users learn that they should only enter their password if they see this personal SiteKey. The SiteKey page shows how this works visually.


PhishCops goes a step further

The PhishCops 'virtual' token claims to be able to counter phishing sites, since even if the user's credentials are handed over, fraudulent use of them is impossible without the PhishCops token on the user's PC. PhishCops is not a physical device, and claims to be purely browser based.

The 'how' is not entirely clear to me, but it seems to be done by handling two way authentication and authorization of specific user PCs (I wasn't going to open the MS Powerpoint presentation to find out). It seems that the secure site presents a one-time key that the user enters into PhishCop, then the virtual token returns a one-time passcode to be entered into the website. This seems like a great idea, since it validates to the user that the website is real before they ever enter their credentials, and validates to the website that the token and user credentials are real.

The downside that I see is the need to pre-authenticate different computers that you want to use with the system. The process for performing this, and its complexity is not clear. I also wonder whether keylogging software, and scripting hacks could also break the system. A physical token is powerful since it is completely separated from a PC.


Summary

Physical tokens are not dead. But as the Citibank example has shown, without providing additional layers of protection to users to help them avoid phishing, a well crafted, realtime scam can defeat even this two factor authentication.

If Citibank had used a site authentication approach like SiteKey to prevent phishing sites easily convincing user to give up their personal credentials, it is likely that there would have been no question about the security of their physical tokens. SiteKey is not perfect, but probably reasonably effective.

PhisingCops may provide an approach, though I am wary of software based tokens as being thoroughly secure. Unfortunately, a hardware equivalent may be more bulky and expensive to produce and distribue. Banks will need to balance the risks and provide as much information as they can to users to protect them online.


Technorati tags:

Thursday, August 10, 2006

IBM platform for massive systems re-engineering?

This morning's announcement by IBM that it intends to acquire FileNet was a little surprising. Many observers had been suggesting that FileNet would drop soon, but I don't believe anyone guessed to IBM. My outsider view was that there was far too much overlap in their offerings for this to make sense from a technology viewpoint.

Thinking again, there seems to be a little sense to the acquisition, beyond absorbing a competitor. As Sandy Kemsley suggests in her Column 2 blog, the IBM SOA/integration capabilities paired with FileNet BPM could be a powerful combination. According to Sandy:
This is an area where FileNet provides a quite different and possibly complementary product to IBM, so I think that FileNet's BPM product could actually survive, get properly integrated with the IBM integration substructure, and become the product that it should have been years ago.


Much of the IBM data integration capability comes from their acquisition of Ascential, around March 2005. Combining the capabilities of WebSphere Information Integrator to access and manage a range of datasources with Ascential's abilities to transform and integrate the data into something meaningful, for migration or pure business intelligence, is quite powerful. One use case quoted is:
For example, a company trying to consolidate data from multiple ERP systems into a single system could leverage WebSphere Information Integrator to access various mainframe or distributed sources for profiling and assessment, and then use Ascential Software's data migration and transformation capabilities to integrate the data.


This gave IBM a sound basis for integration, migration and business intelligence at a technical level. Now add to that IBM's desire to strengthen its vertical solution plays. The acquisition of Webify to provide industry specific integration accelerators last week makes a lot of sense. Worked well, this gives IBM the ability to get at even more data from common vertical industry systems, especially across Insurance and Healthcare, with ready built adaptors and tools. Far more rapid deployment of systems becomes possible with this technology, as well as the opportunity to dislodge the niche integration vendors in certain industry segments, enabling IBM to own far more of an organization's overall architecture.

In combination, the integration pieces also enable IBM to handle one of the trickiest parts of systems combining a range of business applications and business process management. With some smart thinking they should be able to work out how to integrate the data to more easily provide a common structured datastore, enabling simplified synchronization of all of the data from all of the system components including BPM.

Organizations will benefit from this at several levels. From the technical level they will benefit if IBM can make this synchronization of shared data simpler and more accurate. From a business level they will benefit from enhanced data accuracy and consistency driving better customer service and reduced rate of operational errors.

I have no idea if IBM has a formal vision for how all of these pieces look outside of a spending-spree. From a generic systems standpoint, I would see a common architecture a little like this:


This architecture gives IBM the ability to:

  • Orchestrate human and systems processes (BPM)
  • Manage a central integration infrastructure (WebSphere Integrator)
  • Migrate and integrate data to a central datastore (Ascential / DB2)
  • Access a range of industry specific datasources (Webify)
  • Store unstructured data related to business processes (Content Manager / FileNet)
  • Manage information lifecycle of all unstructured (documents) AND structured (systems data) through records retention policies (Records Manager)
  • Present user and analytics applications through a common portal interface
This is a powerful architectural mix that very few (if any) organizations can provide without requiring them to partner with other vendors.

With the FileNet acquisition, IBM gains a foot in the door to many corporations that have problems that they may have been attempting to solve with SOA and BPM in a piecemeal fashion. With the other recent acquisitions IBM could claim the ability to approach these problems in a broader, all encompassing technical approach.

If IBM really pushes this hard we could be about to experience the next generation of organizations bravely attempting massive systems re-engineering exercises, this time with a suite of products from a single vendor. Big Blue will again be the central figure of IT in many organizations.


Technorati tags:

Wednesday, August 09, 2006

Long term document format portability is not important

A post by David Perry on the Freeform Comment blog ODF Debate: A real world view caught my eye. The competitive nature of the Open Document Format and Microsoft's new Open XML format for Office 2007 are discussed.

An interesting point is raised:
We must also remember that Microsoft has serious plans to build a developer community around Office 2007 so, just as with .Net, and Visual Basic, we can anticipate a growing level of support for Open XML from ISVs that is likely outstrip ODF, at least in the short to medium term. If you have an application or service that you think should be integrated with or accessible through an “office like” application, or has the ability to manipulate an office style document, should you build around Open XML and reach 90% plus of the market, or ODF and reach a minority - no-brainer really. Perhaps it ain’t fair, possible it ain’t right, but that’s the real world.

This makes sense for document editing applications. As David also says, setting yourself up for document compatibility problems is unthinkable in a business sense, when you suddenly can't read mission critical documents 25 years after their initial creation. Being able to view documents long-term is essential, and ODF v. Open XML presents a challenge to that.

I look at the problem of document standards over the lifecycle of the document:




The lifecycle works such that the draft, review or 'work in progress' timeline is typically relatively short, compared to the timeline after the point of publishing where, in a well controlled organization the document is made an official record.

ODF and Open XML apply to the document in its 'work in progress' state. PDF/A should be the published format that provides a perfectly repeatable rendition of the document on every view, but does not require further editing.

To my mind the most important task for the work in progress formats (ODF and Open XML) is enabling editing in whichever application the user chooses. That said, early in the document lifecycle, which is fairly short, file format portability is most important only within the limited set of versions of applications available at that time. In an ideal world Open Office should not have to provide support for a MSFT Office format version that is not current. Vice versa, MSFT Office should not have to provide support for an ODF format that is not current. By current I mean with a significant number of users authoring documents. In both cases I am just worried about the editing of work in progress documents, and that happens over a fairly short period of time and therefore with a limited set of available application versions (nobody in the real world uses MS Word prior to v6 to do they?).

After publishing my primary concern as a user is being able to read the document, exactly as published, time after time. PDF/A is the enabling format for this, supported by almost everyone. Whether this will be achieved is a little dependent on whether MSFT gets over its spat with Adobe and just uses PDF/A, rather than Adobe's proprietary PDF format.

This does not mean that organizations do not need the ability to edit published document year in year out. These type of vital documents are handled by retaining an editable version of the document alongside the published version. If the document is edited over time, the portability between tools will remain current and changes to the standard tool used in an organization will be handled by saving to the new format on the next round of editing.


Summary

Document format portability is essential to allow organizations to select their editing application of choice, and to be sure that their partners can collaborate with them in the editing of work in progress documents. The portability of every combination of document format version across every version of the tool is not required, since editing should be over a relatively short period of time compared to the overall document lifecycle.

PDF has been adopted by almost every organization for publishing final documents, so there is no fear that they will not be able to read those document into the future.

The ODF v. Open XML argument for long term viewing of documents is moot: do not rely on document formats designed for editing to provide long term viewing capability - use PDF/A instead.


Technorati tags:

Tuesday, August 08, 2006

Identity theft: banks must start monitoring

Identity theft is a big issue, as we are constantly being reminded by our banks and credit card companies. Some even appear to try and profit from the fear of this problem by offering fee-based monitoring services, often by offering customers a copy of their free credit report as an enticement.

A Bank Systems & Technology article Agencies Issue Proposed Rule on Identity Theft 'Red Flags' reports that US federal banking regulators are proposing new rules requiring banks to perform monitoring of customers' accounts as part of their standard operations:
The proposed regulations include guidelines listing patterns, practices and specific forms of activity that should raise a "red flag" signaling a possible risk of identity theft. Under proposed regulations, an identity theft prevention program established by a financial institution or creditor would have to include policies and procedures for detecting any "red flag" relevant to its own operations and implementing a mitigation strategy appropriate for the level of risk, according to a release from the agencies.

Although it is likely that banks will come back with questions regarding this proposal, an identity theft program seems close enough in appearance to their ongoing anti-money laundering (AML) programs that there will be little additional compliance burden. Specifically, the program as mandated by the Bank Secrecy Act (BSA) requires monitoring for suspicious activity, including specific money laundering 'red-flags'.

It is likely that financial institutions will be able to leverage current technology, or use this event as a driver to invest in appropriate technology, to perform automated monitoring and analysis of transactions and activities to also encompass the identity theft 'red flags'. From the Bank Systems & Technology report:

The proposal lists 31 red flags in connection with an account application or an existing account, including:

  • A notice of address discrepancy is provided by consumer reporting agency.
  • The photograph of physical description on the identification is not consistent with the pearance of the applicant or customer presenting the identification.
  • An account that has been inactive for a reasonably lengthy period of time is used.
  • The financial institution or creditor is notified that the customer is not receiving account statements.
  • An employee has accessed or downloaded an unusually large number of customer account records.

It would surprise me if some of these items were not already included in the AML program. For example, Know Your Customer requires that an institution verifies the identity of new customers. Discrepancies with other sources of information should automatically flag an issue. Not all 'red flags' will apply to every bank, and their risk assessments will help mould the scope of the new compliance program.

James Taylor often blogs about the capabilities of business rules and decision management to address these types of issues. Once in place these systems enable institutions to respond to this type of compliance monitoring rapidly and with minimal incremental cost. These approaches, along with basic monitoring within BPM processes such as New Account Opening could provide everything that is required across a range of identity theft, fraud and AML requirements. Another approach to look at is Aungate, which has examples of background monitoring capabilities.

As with any compliance regulation, the documentation and periodic audit of the program and controls may end up being larger than the effort to actually put it in place. Well designed automated systems reduce this burden by being effectively self-documenting and readily available for audit. A decent document management system, or an enterprise compliance management system (e.g. Certus) will hold all that documentation.

Since it seems that some banks already perform some of this monitoring as a fee-based service, this regulation may purely represent a revenue stream that may be going away soon.

Technorati tags:

Solutions innovation in a product driven company

Creating software solutions to business problems is an enjoyable, creative and fulfilling process. The full lifecycle of creating a true solution from nothing requires a range of skills that can only be successfully be contributed by a team with people from different backgrounds.

I'm writing this post for two reasons. Firstly, I'd like to lay out (38,000 feet view) for discussion how my team works to create commercial solutions from a blank page (much like the Account Opening solution I talk about on this blog). Secondly, the organization I'm in is rapidly evolving so I'm hoping that writing this down will help me absorb and respond to how I best fit. When there are changes to the people around me it still unsettles me, making it hard to concentrate on my real job - this is not fear of change, more the primeval fight or flight response kicking in.

What is a solution?

I work in a group that produces what Gartner seems to call Composite Process Solutions. For us these are solutions that exploit the strengths of the Vignette product set and competencies, more directly addressing business problems than the components can alone.

For a quick background, Vignette is an ECM vendor with core products offering best of breed web content management, portal, collaboration, document imaging, workflow and records management, so there are a lot of components to play with. At the same time, we acknowledge that we can't do everything, so we team with partners to help us create more complete solutions.

Account Opening

Account Opening for high-value financial services products is a solution that is being pushed through the lifecycle at Vignette. Few vendors can present a solution to the many business problems that financial institutions experience during account opening. Even the large consultancies and systems integrators are not presenting a clean, well defined story of what to do in this space, especially for high-value and high-risk products like annuities and mutual funds.

Perhaps the most complete vision that is out there right now is IBM with a heavy focus on banking. This was strengthened on August 2nd by its acquisition of Webify, strengthening IBM's online and SOA capabilities with Webify's prebuilt adapters and toolkits, alongside the standard IBM BPM and WebSphere 'integration' base. Smaller companies have reasonable solution sets for specific market segements. Fineos (from Ireland) have well packaged solutions for retail insurance, CashEdge has specific point components for banking.

Surprisingly the ECM/BPM vendors have not done a good job of leveraging their past experience in handling paper applications for finserv and insurance to address the new online world.

Rearing baby solutions

How do we create net-new solutions and raise them til they have flown the nest? I don't believe that there is anything proprietary in here and the process pulls from influences like Geoffrey Moore's Crossing the Chasm, Deloitte's PILM, Accenture's innovation strategies and our own thinking. Certainly at this level you wouldn't guess what it is that we are doing that is particularly novel. And not being in a consultancy firm, I'm not in a position to tell you the particularly smart things we do!

Imagine a rough view of a solution lifecycle, starting at nothing and progressing (hopefully) through to being a fully commercial contributor to the company's bottom line:




I know that there are many ways to run through this process and many people will have their own view on this type of 'innovation lifecycle'.

My group is responsible for developing ideas from the many feeds we have, creating business cases and seeking funding for those solutions that appear to have real market requirement that we can address, so that eventually we can produce a commercial solution or two that provides an ROI on our investment. Then we "repeat as necessary".

Its all a fairly intuitive thing: you create new ideas, filtering them as they pass through a funnel so that those that don't fit your profile drop out, giving the best ideas that are potentially most profitable a chance to be developed and commercialized. At each stage the filter focuses on different things, ensuring that the company doesn't just keep pouring resources into a money pit if earlier observations or assumptions prove to be incorrect.

The non-intuitive piece is learning how to sell the best solutions to your own company. Not only do you need to sell to the executive team to gain investment (a good business case is essential), you also need to convince the field sales, marketing, product management, services, licensing, engineering, and others I may have forgotten to mention, that the solution is worth their effort to pay attention to. Without the support of the rest of the corporate world even the best solutions will just fade away without ever being seen by a potential customer.

My experience

In the last 18 months I have built out business cases for a range of compliance, governance, business improvement and online b2b solution use cases. Not all made it through the funnel - commercialization is our objective for the best-fit solutions only.

For several potential solutions we could not demonstrate that this group could provide value in developing the solutions further. That does not mean that they are not good opportunities for per-customer engagements. Most of our solutions are available to the field salesforce to chase on specific deals if they choose, so although our run rate may not be high on 'commercialized' solutions, little we produce is absolutely wasted.

And that is the joy of risk-taking. Choosing to bury a solution late in the process may be the most appropriate thing to do, given new priorities, new findings, or an unexpected response from the market segment you have selected.

An essential thing to bear in mind is that it is important not to become emotionally attached to any one pet solution. The strong opinions, weakly held approach is essential here, both when convincing the salesforce of the merit of what you are asking them to chase, as well as when making your own decisions about where to go next.

Teams are important

The group I work with I consider to be partially intrapreneurial - see Scott Gatz for an interesting post or two on this subject and my thoughts on it. We were, until last monday, a group of four, with a range of experience and skills: business analysis, accounting, product marketing, professional services, training, management, software development, systems architecture, sales. I fill the Solutions Architect role based on the broad but shallow set of skills I have within this set.

In the true spirit of intrapreneurship we accept a degree of risk that is unusual within the organization (outside of field sales maybe). We are all dependent on one another. An article from Pinchot & Company says this:
The purest intrapreneurial team consists of volunteers recruited to the idea by one or more lead intrapreneur(s). They form a core team which stays with the project from its early stages, well past its initial commercialization or implementation.

Because of the influence the 'lead' has and the requirement to work closely together as a tight group for quite a period of time, the team and especially the attitudes of the people within it, is extemely important.

Being honest to yourselves is essential.
Don't fall for your own hype. We are not entrepreneurs after all - my house and health are not riding on this one solution, so I can perhaps show a little more than blind faith in my approach being right. Being honest with those around me and assuming that it is mutual, is essential to what we are doing.

What next?

As I have hinted at all through, solutions are enjoyable beasts to work with, but they are truly wild animals. They are tamed by the people that lead them and refine them.

Right now my group is facing a lot of upheaval in terms of organizational change. This is distracting in terms of knowing what to focus on in the near term. This post has been tough to write, although its been useful to help me to get myself balanced for the next big shift. My apologies if its also been tough to read.

Either way, I hope that it has been a little insight into the world of solutions innovation, inside a company that is better at pure product technology innovation. We are all learning this stuff, and I hope we can continue to help the company truly capitalize on its investment.

Technorati tags:

Monday, August 07, 2006

Electronic signatures - physical tokens are coming

Last week I was talking about the different mechanisms that could be used by financial institutions to provide electronic signatures for users.

It seems that adoption of some of the more secure mechanisms for authenticating users and signing transactions is accelerating, to supplement the all too easy to obtain username and password credentials.

Electronic signatures replace the traditional wet signature on paper in several scenarios, when the customer:

  • Submits an application form for a new financial product or service
  • Acknowledges consent for a transaction
  • Requests access to online management of the account through a secure web-site
As I discussed in a background post, one of the hardest components of an electronic signature is not so much its use, but its initial creation with the identity of the customer. Once the customer is known and trusted by the institution there are many mechanisms that can be used to provide secure electronic signatures, the complexity and strength required is dependent on the value and risk of the transactions being performed.

Since username/password combinations are not considered particularly strong, either for transaction signatures or for online access to secure web-sites, biometric and smart-card type tokens were discussed. It seems that as they strive for greater online security, two UK banks are introducing token based systems to supplement username/password credential for access to their online banking secure sites and therefore providing more effective non-repudiation of transactions.

Bankwatch discusses two banks, Barclays and Lloyds TSB that are approaching the security issue with security tokens. In addition, the source of the Bankwatch information, the Scotsman.com: Banks introduce electronic password gadget to beat rise in internet fraud mentions that other UK banks are looking to distribute secure, one time password generation devices, to crack down on the GBP 23 million (approx. USD 40 million) in online fraud, and probably the more worrying abandonment of online services.

The additional security relies on the customer's possession of a physical token that enables him or her to generate a one-time password that is used for access to a specific account. The one-time password prevents phishing-scams, such as an official looking email from a scammer that directs a users to an official looking website requesting the user to log in to manage their account, thus capturing their online credentials, and trojans that read passwords entered into a browser. Even if a scammer gets hold of a user's credentials they are invalid.

Lloyds TSB and Barclays are approaching the tokens from different directions, although aiming to produce the same result:

  • Barclays: Bank card 'chip' reader, where the user pushes their card into a device that confirms their card is valid and generates a password for the web-site
  • Lloyds TSB: Rotating random password generator, key-fob with an LCD display
Both approaches ensure that the customer has the security token in their possession at the time of accessing the web-site.

The bank card approach relies on the European 'chip and PIN' technology that has a secure chip embedded in all credit and debit cards, and does not rely on the easily cloneable magnetic stripe. A single reader could be used by with cards for multiple accounts and provides a familiar approach to most UK and European card users.




The key-fob approach does not need a card reader device to be provided to customers, but does require distribution of battery powered key-fobs that will need to be periodically replaced, and will potentially require a fob to be provided for each account to be serviced online. These devices, like the SecurID from RSA have been trusted for access to secure IT systems for many years.



In the US, the FFIEC has mandated two-factor authentication, recognizing that a username and password pair is not enough security and is subject to trojans and phishing. At this moment the US banks have provided online approaches, not physical devices. Instead they try and offer a second customer visual or memory driven approach to recognizing secure sites.

As with many financial security issues in the US, the cost of infrastructure is often cited as a barrier to change. Perhaps the cost of online fraud and customer mistrust of online services are bigger drivers. By addressing the security of online banking style web-sites with physical tokens, financial institutions also provide an instant solution to providing secure electronic signatures for high value/risk transaction consent.

Technorati tags:

Thursday, August 03, 2006

Google AdSense to enhance corporate knowledge searching

Google AdSense is the technology that enables web publishers to present advertisements that are relevant to the content of the site and page. According to Google, the technology can understand the context of words on a page, to achieve more targeted ads. The assumption is that readers are most likely to be interested in, and therefore click on, ads that are most relevant to the text they are reading.


This is not a 'how to make money from blogging' post

You'll see I have experimented with some low-key ads at the top and bottom of each page, and have some thoughts about the technology -- I'm not qualified to suggest how to manipulate readers and Google ads in combination to achieve click through revenue (I'm not likely to become rich, or even moderately better off, through ads on this blog).

Instead I believe that the AdSense technology has some applicability to enterprise knowledge management applications, to facilitate the discovery of hidden information within and across enterprise knowledge stores, document libraries, intranet portals and other information resources. Let's call this capability KSense (K is for Knowledge...).



A use case
Imagine the following use case...

I'm sitting in Boston Logan airport, and have finally got my battered old T40 laptop's WiFi to connect. It's 6:30am (I'm not a morning person so I'm sitting close to Starbucks) and I'm doing a quick last minute piece of research around the use of enterprise portals in the federal government. I'll be flying down to see a certain potential customer with offices in a large, unusually shaped building in DC ('I could tell you, but I'd have to kill you' jokes get old fast).

I go to my corporate collaboration and knowledge management site (yes, Vignette my employer actually uses its own software, and its good), login and search for 'federal portal'. It returns me a list of workspaces and documents that meet the criteria: IRS, USPS, NASA...

As I click in to any of these items the system allows me to drill deeper and deeper into the information in that customer workspace. When a trail goes cold I come back up to the search results and traverse a different route.

What I really need is KSense.


Corporate knowledge AdSense

As I click through the corporate knowledge store I would like to see suggestions of related documents and workspaces, much like I see Google ads. These suggestions, KSense ads, would be based on the content of the current page or document I was viewing. Ads would be selected based on the content of other documents and workspaces, as well as their attributes or tags.

KSense ads related to my current view would allow me to follow my research trail by meandering across workspaces, libraries and information resources, gradually refining my context. WIth search I typically drill-down until I hit dead-ends then return to my search results to try again.

Some of the other ideas that drive AdSense could also be applicable. Document and workspace owners could rank the importance of their content for specific search terms, much like Google advertisers do, to promote ideas, or make common information easier to find from a single search.

For example, a product launch for new intranet portal capabilities could be tagged to appear in an ad banner at the top of search results for 'intranet portal', or through KSense relevant ads on a page containing portal information. For specific periods of time users' attention could be drawn to new information they may otherwise not be aware of. This enhances current search and subscription mechanisms significantly, and enables organizations to promote new information and products more effectively with their own employees.


Extending KSense

Although AdSense may present ads most relevant to the text on the page, it takes no account of the actual role of the reader. On this blog (here is an example page addressing BPM) the CIO of a major finserv organization may in fact be interested by the ad:

Improve your processes
A free guide to Business Process Management (BPM) solutions.
Ads by Phil

Despite the fact that the ad is well matched to the context of the page it is unlikely that a more typical reader will be so inclined to click, unless he or she is doing some serious research of BPM vendors.

For example, if AdSense knew that the profile of the user was 'software developer; gamer; Boston, age 26', and that she had just landed at this blog having clicked through from the Scobleizer (yeah, I'm dreaming), the following advertisement may be more likely to earn some click-through revenue:


WiCkEd-FaSt GrApHicS CaRd
Render 128 million pixels / sec for incredible Red-Sox gaming realism.
Ads by Phil

Without using nasty click-tracking and spyware on users' PCs this is not likely to happen in the web-world. In the corporate world its in big-brother's interest to know its users a little better, so KSense could benefit from user profiles and viewing habits.

For example, within Vignette it could be that my profile says 'Solutions Architect; product experience: EDRMS, BPM;recently viewed: federal portal, DoD, intranet'. This should drive a different set of KSense ads for both search and browsing than my boss 'VP; product / solution marketing; management; recently viewed: vacation policy, competitive analysis'.


Summary

Enterprise search tools such as Endeca provide the ability to be presented with human classified categories to further refine search results. This is powerful, but it seems very tightly controlled through human categorization (for an example, see Forrester's view of search). Categories within search results can be used to drill down to the information you are hoping to find.

I would like to see the more freeform capabilities of KSense used in organizations. I think that the context aware and 'advertising' paradigm could help users find more useful information that would be otherwise lost in the cloud of traditional search results, and the typical route where users are forced to drill-down deeper at every click. The ability to meander across workspace and library boundaries through KSense ads seems to open up a lot of corporate knowledge and information.

Electronic signatures for financial services - management and mechanisms

In my previous post, Electronic signatures for financial services - a background, I laid out some of the issues that surround electronic signatures and identity when a customer attempts to open a new account for a financial services product.

The request for a customer's signature at the point of applicationis not a one off event just to confirm agreement with the terms. It is the mechanism that a customer uses to confirm that he is the same 'Mr X' that owns the account (not the other 'Mr X' who could be posing to be him). Signing a document is the ceremony that represents his acceptance of terms or consent to perform a transaction, and may be compared to the original if Mr X ever tries to claim an incorrect or fraudulent transaction.

In an online world it is tough to ensure the security and integrity of electronic signatures. For different scenarios something stronger than username and password is required, since the agreements and transaction consents may high value and high risk to both institution and customer.

Electronic signature approaches

For higher value or higher risk accounts, such as annuities, mutual funds, etc, the identification, profiling and signature requirements for opening the account are greater than those for a simple financial product. The customer needs to provide more profile information to enable product suitability to be assessed and is needs to demonstrate understanding of the product terms more effectively.

From a signature standpoint a simple username and password is not considered strong enough for authentication of identity, so other approaches to collecting signatures are being used or investigated by organizations:

1) Digital pen signature pad
2) Physical token
3) Biometric identification

Digital pen signature pad

The digital pen signature pad enables an institution to use a traditional written signature in an electronic form. It captures not only the signature shape, but also the pressure and velocity of the pen, enabling forensic proof to be applied to signatures if required.

To my mind this type of signature seems hard to validate automatically, although I have not really researched software that has been proven to do this. The limitations of 'sampled validation' performed by organizations with wet signatures may apply, where they only check a sample of set of signatures, since it could be impossible to reasonably check every signature.

The availability of signature pads may also limit its widespread adoption, especially since these devices are unlikely to be easily portable between PCs, limiting the mobility of online transactions, for example where a customer uses a home and office PC for financial matters.

One advantage of this type of signature is that it can be used to record the appearance of a traditional signature, where the institution may need a comparison for a wet signature in the future. An example is where an organization provides checks or plastic cards and needs to keep a 'signature card' for validating signed checks or debit/credit card slips.


Physical Token

The second option, using a physical token, has been deployed in some environments, requiring a customer to hold some type of smart card or electronic tag. The physical possession and use of the token only represents part of the signature, and is completed when combined with a traditional password.

Some tokens are limited by the need to swipe them over a reader, again limiting mobility of the usage to PCs with an appropriate reader. Tokens that provide an updating passcode display enable them to be used without being attached to a PC, promoting mobility. These devices have been trusted for remote administrative access to IT systems for several years and as such should be recognized by an organization's IT/IS group as being reliable.

The effectiveness of this approach as a signature comes from the possession of a token that is unique to the user. It ensures a far greater degree of certainty than a password alone, but must be used in combination with a password, much like you would expect to use a bank card in an ATM with a PIN. Pure possession of the token does not guarantee that the unseen user is the person that really owns the token, due to possible loss or theft.

A drawback of this approach is that it requires the physical distribution of a token by the financial institution, or the requirement that a customer already possess an accepted token from a third party.

Physical distribution (i.e. snail-mail) injects a lag into the account setup process, but also adds the opportunity to confirm the customer’s address is correct, since otherwise the token would be difficult to receive. In some circumstances snail-mail or other trusted delivery (FedEx, UPS) of a token, bank card or PIN is the only way to ensure that the customer's address is what they claimed on the application.


Biometric identification

Biometrics are a hot topic at the moment, and devices for reading fingerprints are becoming more common, as PC manufacturers (such as Lenovo) build them in to promote access security. This may be encouraging to financial services firms, since it enables them access to an authentication mechanism that is becoming widespread, and does not carry the distribution lag or cost associated with physical tokens.

In much the same way that a customer could sign up with Fidelity and select a username and password for their online identity, the customer could also just swipe their fingertip over a sensor on their laptop to be recorded on their digital signature card. In future, this fingerprint swipe acts as a signature consenting to a transaction.

Unfortunately, biometrics typically rely on identification markers on a human being that are readily visible, and therefore subject to spoofing. The Electronic Frontier Foundation has raised concerns around the use of biometrics.

When used in combination with a password (an attribute that is not visible), the security of the signature for non-repudiation purposes may be considered sufficient. Financial services institutions should be tracking this technology, and its effectiveness.


Managing identity and recording signature transactions

Some Business Process Management (BPM) and document management systems support signature of actions (for FDA regulation 21 CFR part 11), and to sign the accuracy of documents for non-repudiation. In broader systems a third-party signature management capability may be required. An example of this is SignatureOne from CIC, which manages signature administration, authentication and transaction logs for a range of signature mechanisms as described above.

Special attention will be required to handle the sharing of signatures, signed transactions and documents. This will be maybe the toughest area to solve without standards in place.

In general, I need to do much more research in this area, but hopefully this short introduction provides a placeholder for future analysis. As ever, any feedback from anyone with experience in this area would be appreciated.

Summary

Financial service institutions need to be looking both at their own requirements for electronic signatures for high value and high risk accounts, as well as what the marketplace in general is likely to adopt. Widespread adoption of an approach will most likely lead to the most cost-effective and hopefully trusted mechanism for online signatures for authentication and non-repudiation.

There are a range of other issues to be addressed, from the recording of signatures against actions, to digitally signing documents to ensure accuracy, I have not addressed fully. Hopefully I will get round to doing this soon.

As ever, any feedback on the ideas and information I have presented here is welcome.

Technorati tags:

Wednesday, August 02, 2006

Electronic signatures for financial services - a background

Electronic signatures are core requirements for new account opening for financial services products. I certainly do not claim to be an expert in this area so I’m hoping to use this as a starting point, by laying out some of the issues that need to be addressed, and laying out a little of what I know as background.


What is a signature?

In simple terms a signature is a proof of identity or used to represent the intention of informed consent. Signing a document or contract is surrounded by a certain ceremony to reinforce the ‘will’ of the agreement – a signature is really not enforceable if the signing process was disguised or the agreement terms were hidden.

Wikipedia has some background on the meanings and traditions surrounding signatures.


A use case

Imagine that I go to Fidelity’s web site to apply for a new account. As a customer without a history with the institution there are various challenges to me opening a new account and signing an agreement as to my rights and obligations for running it.

Fidelity needs to enforce several steps:

  • Create a reusable identity for me
  • Ensure that I am who I say I am, and live where I say I live
  • Create a customer profile to enforce risk and Anti-Money Laundering controls
  • Gain and prove my acceptance of their agreement terms

In this online world they need to do all of this without ever seeing me in person, or seeing any physical evidence of who I claim to be. In the future, ensuring that I do not deny ownership of the account or agreement with its term is essential to the institution. Unfortunately non-repudiation is hard to achieve when an institution doesn’t already have a relationship me. In this case a signature without a valid and verifiable profile is worthless, either in the manual or online world.

Creating and confirming identity

The first step when setting up a relationship with a new customer is for the financial institution to create and confirm the customer’s identity. In its most basic form this is a set of some uniquely identifiable information about the customer, name, date of birth, residential address, social security number, etc. This provides a base identity for the person. A signature is then assigned to enable the customer to in future confirm they are who they say they are, for contracts and transactions, without having to re-examine their details in more depth.

In the paper application world, I would walk into a branch of Bank of America, fill in a form, present three forms of identification to the customer services rep and sign a ‘signature card’. The signature card provides a record of the customer’s signature for future reference if ever required to confirm the customer’s identity. In the US this signature card is rarely ever used. In France, for example, a certain percentage of checks written and signed by a customer must be compared to the signature on the signature card (a good reason why banks have been encouraging the use of plastic / electronic payment for years).

In the online world things work slightly differently, but the principles are the same. In this world I’ll go back to the Fidelity web site. I fill in a series of personal details that enables them to uniquely identify me. This enables Fidelity to pull my credit report from Equifax. Here I am presented a series of questions to confirm the providers of certain services that are listed on my report over the last few years. The combination of correct answers for these questions enables Fidelity to be reasonably sure that I am who I say I am, especially as the credit report is tied to my social security number and mailing address. After filling some more information I have to select a username and password for access to my new online account. For low value or low risk accounts (standard brokerage accounts being one), this is considered enough identification to authenticate my agreements and transactions with the username / password combination as my signature.


Legal background

For commercial consumer, especially financial services transactions, there are two key laws addressing the issue of electronic signature.

The Uniform Electronic Transactions Act (UETA) provides a uniform state legal framework for electronic transactions. This gives them the same legal weight as equivalent paper based processes and wet signatures.

The Electronic Signatures in Global and National Commerce Act (E-SIGN) provides a federal backdrop for electronic signatures, governing situations where there is an absence of state law, or states make changes to UETA.

Special provisions have been put in place to protect consumers, controlling when organizations can demand the use of electronic transactions and documents and how organizations ensure that customers have the facilities to accept electronic delivery of documents.

The financial services industry has looked at providing best practices and rules, combining electronic records and signatures issues. This is the Standards and Procedures for Electronic Records and Signatures (SPeRS).

Wikipedia refers to additional laws.


Summary

As you can see, many of the issues in financial services related to signatures are tightly coupled with validating, managing and authenticating the identity of an individual. The approaches that organizations take to perform this in an online world mirrors what is required in a paper world. For higher value and higher risk products the current online model is considered insufficient and much work is needed to strengthen both the signature and general identity management issues.


More to come

In the next post I will address some of the deeper issues around electronic signatures as they relate to higher value or higher risk accounts, as well as the hot topic of biometrics.


Technorati tags: