Biometric verification is performed for every critical operation

Aktiv company introduced "Rutoken Bio" — a USB token for authentication and electronic signature with three-factor protection. The device combines the token itself, a PIN code, and biometric verification via fingerprint.

To perform a critical operation, the user needs to connect the device, enter a PIN, and confirm the action with a fingerprint. Biometric verification is performed for every operation with protected keys, so stealing the token or intercepting the PIN code alone is not enough to gain access.

The reference fingerprint is registered by the administrator and stored inside a protected chip. Matching with the presented fingerprint is also performed directly on the device. It is impossible to extract or change the stored template after registration.

"Rutoken Bio" allows configuring different authentication requirements depending on the access level. For example, for office work, a token and PIN code can be used, while connecting to the corporate network via VPN will additionally require biometrics.

The new product is available in several case variants and is certified as a separate version of SKZI "Rutoken EDS 3.0". The BioSDK software kit is provided for integrating biometric verification into applications.