Thursday, January 4, 2018

World without remembering passwords

This technology I am going to tell is based on bio-metric with more research to make it more robust. So first you need to have a wrist band or watch or health band in your hand. This band will identify with the owner based on biometrics like colour of your skin, complexion, grip on your hand, hair on your hand, length of hair as it grows, thickness of hair, distance between two hair strand, position of hair strand, pulse in your hand and new biometrics which can be tested in ur hand. In the future, I hope they scan your DNA. First we will consider offline scenario. So, when you are configuring Microsoft Windows, first you need to sync it with Microsoft watch ( hopefully soon), once you are done, there will be a password generator app in the watch as well as in Windows. It will generate password which will change every 2 minutes. Different algorithm for different users. You can update and change password generators any time. You can update only both at a time and keep it in sync. So every time you want login. Open Microsoft app in the watch. Ask for password , it will check your biometrics if found matching, it will generate a password and give it to you. Login. Online is much better, because you don't need to worry about whether password generator hardware is broken or not. In the future, may be there be a common password generator for mail, Internet banking and on and on so you install the app in your watch you click your intended option like hotmail, it checks your biometric and generates a password. Same as before. You can also make this password entering automatic. No need to manually enter. Even if loose ur watch, nobody can use it. You will be well aware if u have lost the watch, than cellphones. You can check the liveliness of your hand, whether it is live tissue or fake substance, video or whatever by asking the user to press the top of the watch at a point displayed by a compass on the screen. Campus will point to different points on the circumference during each check. Capture the picture and the video to check the liveliness of the hand.

If you say that it is possible to hack a watch. Let's make the watch simply a device to get your biometrics, it can work only online. Whenever you need a password, your device will take a picture of your hand and collect liveliness data. It simply sends the data to the server. Server holds all the biometric data. You can't hack a server, that much easily. It gets hardware-software combo information of the watch which will itself change every 10 minutes, not revealing anything about it to the user and biometrics. This information is a combination of software and hardware. This software uses thousands of algorithms, which changes from watch to watch and time to time. So the server compares biometric and encrypted hardware-software combo info with server data and sends you a password, which will last only 10 minutes. Even if you bypass this, which is impossible, I guess, the server will first send a beep signal to the watch, whenever some login happens, and only if you press a button in the watch, will a login happen. We can even set the time how much time a login last, before session expires. If you set half-an-hour, a small drop-down box comes every half-an-hour and asks for the current password. If you fail to provide latest password, it will logout. Also, if you want to change a setting, like time limit for logout. You have to enter new password and this will be generated immediately without waiting for 10 minutes. I think this is already existing procedure to ask password again. Only difference is a new password is created.

So basically, there is always a race between hackers and software producers. Who runs ahead will be the winner. If u are complacent and stand in a place, certainly one day hackers will run ahead of you. Software should always evolve with the time. No technology is unbreakable beyond a certain time.

Suppose military wants to use this technology. And u r caught in enemy territory with this watch, you have to utter a code( whatever u set), like AFD25, it will permanently lock the watch. Microsoft can even develop custom watches, which looks like ordinary or luxury watches, with this technology, for a premium fees for different needs, as required.

Tuesday, January 2, 2018

Instant Banking

In this idea, we can explore a new concept, never before tried in banks with currency notes. Here, Customer who wants to deposit from small amount of money like 100 rupees to 10,000/day can use this facility. The amount to deposit should be a single note( Notes of Rs.100,Rs.200,Rs.500,Rs.2000). A single customer can deposit up to 5 notes in a day.
First, the customer has to install Mobile Banking App in cell phone. The Mobile Banking App will have all the details of the customer’s account. In that App, a new option for scanning currency notes has to be provided. The App scans the currency note, the customer wants to deposit. App will take a picture of the currency note and reads the currency note number. It verifies the note number by asking confirmation from the customer. Currency Notes picture and number will be sent to Bank’s Central database. After this, the customer should go to the bank and simply deposit the currency note in a specially designed Currency Collector Machine. This Machine will receive currency note numbers from central database, updated every 5 minutes. When a customer feeds the Currency Note he has scanned in Mobile Banking, Currency Collector Machine simply scans the note and checks whether the note is not fake, not damaged. Then, checks if a match is found in the database, displays the name of the Account Holder in the display attached with the device. If Name is correct, the customer presses ok button. Then, the Transaction is approved and a confirmation slip with account number and a transaction number is ejected. The customer takes the slip and leaves. Once the transaction is approved, the Currency Note Number will be deleted from the bank’s central database and the note can be recycled for future transactions. If for some reason, the Currency note did not match ( the only criteria for approval), the note is ejected and returned back to the customer. Fake notes can be confiscated. Once approved, account will be updated with the money deposited within 5 minutes. Approval through sms will be sent to the account holder’s Cell Phone. This whole process will take maximum 10 seconds per transaction. There is no necessary for different banks to hold a common centralized database. Each can have it’s own separate Central Database. Because, even if same note is scanned in different banks, it has to be deposited in a bank to make the transaction complete. Once a Customer, scans a Currency Note in their mobile App, they will be allowed to hold on to the note for a maximum of 5 days. After that, the App will delete the hold and he has to scan again, with the Currency note (Same note, earlier used or a New note. It makes no difference). If a note is
scanned in a particular bank’s mobile App in an particular account, the same note will not be allowed to be scanned in a different account in the same bank. For recycle, either the time period of 5 days is exhausted for the first scan or the Currency Note is deposited and approved by the Currency Collector Machine.